OAuth 2.0 authorization code + PKCE and device grant state machine for public clients, behind a host behaviour that mints the token.
-
Updated
Sep 3, 2026 - Elixir
OAuth 2.0 authorization code + PKCE and device grant state machine for public clients, behind a host behaviour that mints the token.
An egress credential proxy for sandboxed agents: CONNECT and absolute-form forward proxy that attaches the real credential where the sandbox sent a placeholder, behind a session-store behaviour.
A documentation manual embedded at compile time for a Phoenix app to serve, its sanitising markdown renderer, and the guardrail tests that keep it sound.
A client-side Agent Client Protocol session that outlives the turn, with a per-tool permission policy, block normalisation, usage accounting and a tracer, behind a writer callback.
How a coding agent CLI (claude, codex, gemini, opencode) gets into a sandbox and comes up speaking ACP: the adapter pins, the file layout, the instructions file, the credential env vars, the skills tree, and the per-runtime workarounds with their deletion conditions.
MCP authorization discovery with a server-side URL guard.
${VAR} substitution over nested config: eager, escapable, every missing key reported at once.
The self-hosted runner wire protocol: a WebSock connection process and a Managoat.Sandbox adapter over it, behind a host behaviour.
One sandbox behaviour over Sprites, E2B and Daytona, with the conformance suite a fourth adapter runs against.
To associate your repository with the managoat-library topic, visit your repo's landing page and select "manage topics."