io.github.gradion-ai/ipybox MCP Server
io.github.gradion-ai/ipybox
Unified execution environment for Python code, shell commands, and MCP tool calls with optional sandboxing.
What is the io.github.gradion-ai/ipybox MCP server?
The ipybox MCP server is a unified execution environment that runs Python code, shell commands, and programmatic MCP tool calls in a stateful IPython kernel. It generates typed Python APIs for MCP tools via mcpygen and supports application-level approval of tool calls and shell commands, with optional OS-level sandboxing via sandbox-runtime.
ipybox enables AI agents to execute code blocks combining Python, shell commands, and MCP tool calls in a single stateful environment. It runs locally on your machine with no cloud dependencies, offering protected access to your local data and tools through optional sandboxing and approval workflows.
How to install io.github.gradion-ai/ipybox
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
Code execution— Execute Python code in a stateful IPython kernel with persistent state across executionsShell command execution— Run shell commands via !cmd syntax and capture output into Python variablesProgrammatic MCP tool calls— Call MCP tools via generated typed Python APIs rather than JSON, with automatic schema-to-code generationApplication-level approval— Request approval for individual tool calls and shell commands before executionKernel sandboxing— Optional OS-level isolation of kernels using Anthropic's sandbox-runtime with filesystem and network restrictions
Use cases
- Execute Python scripts with persistent state while calling external MCP tools programmatically
- Run shell commands and capture their output directly into Python variables for further processing
- Build agents that require approval workflows for sensitive tool calls and shell commands
- Develop applications with local data access and tool execution without cloud dependencies
- Combine multiple execution modes (Python, shell, MCP tools) in a single code block for complex workflows
io.github.gradion-ai/ipybox MCP server FAQ
ipybox is a unified execution environment that runs Python code, shell commands, and MCP tool calls in a stateful IPython kernel. It generates typed Python APIs for MCP tools and supports optional sandboxing and approval workflows.
Yes, ipybox is open-source software available on PyPI under a license (check GitHub for details). It runs locally on your machine with no cloud dependencies or subscription fees.
Install via pip: `pip install ipybox`. It's available on PyPI and can be used as a Python SDK, MCP server, or Claude Code plugin.
No authentication is required. ipybox runs locally on your machine. You may need to configure MCP servers or tools you want to call, but ipybox itself has no auth requirements.
Yes, ipybox supports optional OS-level kernel isolation using Anthropic's sandbox-runtime, which enforces filesystem and network restrictions at the operating system level.
The README does not specify Python version requirements. Check the PyPI page or GitHub repository for compatibility details.
README (reference)
Source of truth, from the repository.
ipybox
mcp-name: io.github.gradion-ai/ipybox
<p align="left"> <a href="https://gradion-ai.github.io/ipybox/"><img alt="Website" src="https://img.shields.io/website?url=https%3A%2F%2Fgradion-ai.github.io%2Fipybox%2F&up_message=online&down_message=offline&label=docs"></a> <a href="https://pypi.org/project/ipybox/"><img alt="PyPI - Version" src="https://img.shields.io/pypi/v/ipybox?color=blue"></a> <a href="https://github.com/gradion-ai/ipybox/releases"><img alt="GitHub Release" src="https://img.shields.io/github/v/release/gradion-ai/ipybox"></a> <a href="https://github.com/gradion-ai/ipybox/actions"><img alt="GitHub Actions Workflow Status" src="https://img.shields.io/github/actions/workflow/status/gradion-ai/ipybox/test.yml"></a> <a href="https://github.com/gradion-ai/ipybox/blob/main/LICENSE"><img alt="GitHub License" src="https://img.shields.io/github/license/gradion-ai/ipybox?color=blueviolet"></a> </p>ipybox is a unified execution environment for Python code, shell commands, and programmatic MCP tool calls.
Overview
ipybox executes code blocks in a stateful IPython kernel. A code block can contain any combination of Python code, shell commands, and programmatic MCP tool calls. Kernels can be sandboxed with sandbox-runtime, enforcing filesystem and network restrictions at OS level.
It generates Python APIs for MCP server tools via mcpygen, and supports application-level approval of individual tool calls and shell commands during code execution. ipybox runs locally on your computer, enabling protected access to your local data and tools.
[!NOTE] Next generation ipybox
This is the next generation of ipybox, a complete rewrite. Older versions are maintained on the 0.6.x branch and can be obtained with
pip install ipybox<0.7.
Documentation:
- 📚 Documentation
- 🏗️ Architecture
- 🤖 llms.txt
- 🤖 llms-full.txt
Capabilities
| Capability | Description |
|---|---|
| Stateful execution | State persists across executions in IPython kernels |
| Unified execution | Combine Python code, shell commands, and programmatic MCP tool calls in a code block |
| Shell command execution | Run shell commands via !cmd syntax, capture output into Python variables |
| Programmatic MCP tool calls | MCP tools called via generated Python API ("code mode"), not JSON directly |
| Python tool API generation | Typed functions and Pydantic models generated from MCP tool schemas via mcpygen |
| Application-level approval | Individual approval of tool calls and shell commands during code execution |
| Lightweight sandboxing | Optional kernel isolation via Anthropic's sandbox-runtime |
| Local execution | No cloud dependencies, everything runs locally on your machine |
Usage
| Component | Description |
|---|---|
| Python SDK | Python API for building applications on ipybox |
| MCP server | ipybox as MCP server for code actions and programmatic tool calling |
| Claude Code plugin | Plugin that bundles the ipybox MCP server and a code action skill |
[!TIP] Freeact agent
Freeact is a general-purpose agent built on ipybox.
Related MCP servers

Access Grafana dashboards, datasources, and observability data through Claude and Cursor.

Chart Library — Market-state research
Market memory for AI: historical market states, published research, and source evidence for agents.

io.github.grahamnotgrant/blacksmith
MCP server for Blacksmith CI - query runs, analyze test failures, detect flaky tests.

acdoyle
Agent-to-agent gateway routing tasks to Sherlock, Watson, or Moriarty for one decisive answer.

Twitter/X MCP
Read public X posts, replies, profiles, and search results through Rettiwt or the official API.

GraphPilot
Structural memory for coding agents: persistent code graph with callers, callees, blast radius, and evidence anchors.