{
  "generated": "2026-10-03T13:58:35.775Z",
  "entity": {
    "name": "Promigence",
    "aliases": [
      "Promigence",
      "Promigence AI",
      "promigence.ai",
      "Promigence environment runtime",
      "Promigence sandbox"
    ],
    "url": "https://www.promigence.ai",
    "category": "Sandbox platform for AI agents",
    "definition": "Promigence is a sandbox platform for AI agents: production-grade, fully isolated sandboxes that start in milliseconds, stay fast at a thousand at once, and bill by the second.",
    "tagline": "Production-grade sandboxes for AI agents",
    "audience": "Anyone running AI agents: coding agents, evals, RL rollouts, agentic CI, background agents, or a sandbox per user inside an app.",
    "email": "support@promigence.ai"
  },
  "keyFacts": [
    "Promigence sells verified execution environments for AI agents, metered per second with the maximum cost of a run quoted and capped before it starts.",
    "A Promigence sandbox is ready for its first command in 8 ms at p50.",
    "Every Promigence environment is checked ready before you get it; a six-hour soak ran 108,929 of them with zero failures and zero leaks.",
    "A Promigence snapshot is stored only if it passes its own test at build time, so a broken environment never reaches an agent.",
    "Each Promigence environment is fully isolated from every other, and a busy environment is never killed for doing the work you asked for.",
    "The same Promigence snapshot hash returns a bit-identical environment on any later date, which makes an eval result citable.",
    "Every Promigence run reports environment failures separately from task failures, so a broken environment never counts against your agent.",
    "Promigence quotes the exact maximum cost of a run before it starts and enforces a hard spend cap.",
    "Promigence runs any coding-agent work, not only evaluations: an episode is fork, run the agent, terminate, so an eval episode, an RL rollout, a CI job and a queue of bug-fix tasks are the same shape to it.",
    "Promigence is model-neutral and lab-neutral, which is what a cross-lab evaluation requires."
  ],
  "primitive": [
    "verify",
    "snapshot",
    "fork(N)",
    "exec",
    "validity report"
  ],
  "guarantees": [
    {
      "n": 1,
      "title": "A busy environment is never marked unhealthy",
      "body": "Health checks cannot be starved by your workload, so nothing kills an environment for doing what you asked, even with every vCPU busy.",
      "mechanism": "health is never starved by your workload"
    },
    {
      "n": 2,
      "title": "A snapshot that fails its own test is never stored",
      "body": "Every snapshot runs your verify command at build time. If it fails, the build is rejected and you are not charged for it.",
      "mechanism": "verified builds, rejected builds are free"
    },
    {
      "n": 3,
      "title": "An environment that is not ready is never handed over",
      "body": "Every environment is checked ready before you get it. You never get a handle that looks healthy and is silently cold.",
      "mechanism": "checked ready before hand-over"
    },
    {
      "n": 4,
      "title": "Resource caps are checked at build time",
      "body": "Memory and disk ceilings are validated when the snapshot is built, so you learn your monorepo needs 12 GB during the build and not 762 seconds into a paid episode.",
      "mechanism": "build-time cap validation"
    },
    {
      "n": 5,
      "title": "Every failure is attributed",
      "body": "Each run splits environment failures from task failures. An agent that failed because the environment was broken is never counted as an agent that failed the task.",
      "mechanism": "validity report, environment versus task"
    },
    {
      "n": 6,
      "title": "The bill is quoted before the run and capped",
      "body": "`promigence run quote` returns the exact ceiling before anything starts. A run that would exceed your cap is refused, not truncated halfway.",
      "mechanism": "quote before run, hard spend cap"
    }
  ],
  "metrics": {
    "headline": [
      {
        "id": "e2e",
        "value": "207 ms",
        "label": "end to end, through the CLI",
        "claim": "Through the shipping path, a Promigence sandbox is ready for its first command in 207 ms at p50, and within 10 ms of that from any of three regions.",
        "status": "measured",
        "asOf": "2026-09-13",
        "source": "207 ms from the US east, 204 ms from the US west, 209 ms from Europe, all p50 as the client saw it. Measured 2026-09-13 through the path a customer uses: the promigence CLI, over the network, an 8 vCPU / 8 GiB sandbox, from clients in three regions."
      },
      {
        "id": "soak",
        "value": "108,929",
        "label": "forks in six hours, zero failures",
        "claim": "A six-hour soak ran 108,929 forks with zero failures, zero errors and zero leaks, and the median did not drift across the run.",
        "status": "measured",
        "asOf": "2026-09-14",
        "source": "5.99 h, p50 43 ms at the first hour and 43 ms at the last, slope −0.09 ms/hour. Measured on the server itself rather than over the network."
      },
      {
        "id": "burst",
        "value": "177 ms",
        "label": "at 200 concurrent, all served",
        "claim": "Two hundred sandboxes requested at once were all served at a 177 ms median and a 284 ms p99, with no retries.",
        "status": "measured",
        "asOf": "2026-09-14",
        "source": "200 at once, every one served on the first attempt, 0 retries. A thousand in waves of a hundred holds the same: p50 99 ms, p99 165 ms. Measured on the server itself rather than over the network."
      }
    ],
    "measured": [
      {
        "id": "coldstart",
        "value": "104 ms",
        "label": "cold start of an empty sandbox",
        "claim": "A Promigence sandbox with no snapshot to restore from cold starts in 104.3 ms at the smallest sellable tier.",
        "status": "measured",
        "asOf": "2026-09-14",
        "source": "Per tier: 104 ms small, 127 ms medium, 142 ms large."
      },
      {
        "id": "warmfork",
        "value": "39 ms",
        "label": "warm fork on the box",
        "claim": "A warm fork completes in 39 ms, and a hundred at once still land at 122 ms.",
        "status": "measured",
        "asOf": "2026-09-14",
        "source": "One at a time 39.4 ms, a hundred at once 121.6 ms, two hundred at once 177.3 ms with all 200 served. Measured on the server itself rather than over the network."
      },
      {
        "id": "coldnode",
        "value": "987 ms",
        "label": "first copy on a server that has never held it",
        "claim": "A server that has never held the environment before serves its first copy in 987 ms.",
        "status": "measured",
        "asOf": "2026-09-14",
        "source": "The first copy of a 12.94 GB environment on a server that had not held it before."
      },
      {
        "id": "burst-bimodal",
        "value": "12 → 100",
        "label": "how far one provider's burst moved in 12 days",
        "claim": "Burst capacity in this category is bimodal rather than broken. One provider went from serving 12 of 100 concurrent sandboxes to all 100 within two weeks, so a single good day proves nothing about the next one.",
        "status": "measured",
        "asOf": "2026-09-16",
        "source": "An independent public burst test: time-to-init, 100 concurrent, 120 s timeout. Not our measurement; read from its published raw results."
      }
    ]
  },
  "pricing": {
    "model": "per second",
    "rates": {
      "vcpuHourUsd": 0.0504,
      "gibHourUsd": 0.0162,
      "minBillableSeconds": 1
    },
    "episodeDefinition": "fork → execute → terminate, 15 minutes by default and up to an hour in the private beta; the unit a quote and a spend cap are written against",
    "currency": "USD",
    "tiers": [
      {
        "id": "small",
        "name": "Small",
        "spec": "2 vCPU · 4 GiB",
        "list": "$0.17",
        "volume": "$0.000046",
        "note": "per hour",
        "typical": "A SWE-bench-class episode: clone, patch, run the failing test. Ten minutes costs about $0.03."
      },
      {
        "id": "medium",
        "name": "Medium",
        "spec": "4 vCPU · 16 GiB",
        "list": "$0.46",
        "volume": "$0.000128",
        "note": "per hour",
        "typical": "Monorepo typechecks and mid-size builds."
      },
      {
        "id": "large",
        "name": "Large",
        "spec": "8 vCPU · 32 GiB",
        "list": "$0.92",
        "volume": "$0.000256",
        "note": "per hour",
        "typical": "Heavy builds and memory-hungry test suites."
      }
    ],
    "plans": [
      {
        "id": "free",
        "name": "Free",
        "price": "$0",
        "cadence": "pay as you go",
        "usage": {
          "included": "$50 of free credit",
          "then": "Per second at list, only what you use"
        },
        "blurb": "Start free, then pay only for the seconds you run.",
        "includes": [
          "$50 of free credit to start",
          "20 sandboxes at once, sessions up to an hour",
          "Validity report on every run",
          "Quote and hard spend cap on every run"
        ],
        "cta": {
          "label": "Sign up for free",
          "href": "#waitlist"
        }
      },
      {
        "id": "pro",
        "name": "Pro",
        "price": "$50",
        "cadence": "per month",
        "usage": {
          "included": "More usage than you pay for",
          "then": "Per second past it"
        },
        "blurb": "For teams running agents, evals and CI every day.",
        "includes": [
          "Everything in Free, plus $50 of free credit",
          "More compute each month than the plan costs",
          "Up to 100 sandboxes at once",
          "Verified snapshot builds, failed builds free",
          "Harness adapters: Inspect, Harbor, SWE-bench",
          "Email support"
        ],
        "cta": {
          "label": "Sign up for free",
          "href": "#waitlist"
        },
        "featured": true
      },
      {
        "id": "max",
        "name": "Max",
        "price": "$500",
        "cadence": "per month",
        "usage": {
          "included": "About 10× the usage of Pro",
          "then": "Below list, by commitment"
        },
        "blurb": "For large eval fleets, RL and continuous agentic CI.",
        "includes": [
          "Everything in Pro, plus $50 of free credit",
          "About 10× the usage of Pro",
          "Up to 1,000 sandboxes at once",
          "Capacity held warm for your snapshots",
          "Shared Slack channel"
        ],
        "cta": {
          "label": "Sign up for free",
          "href": "#waitlist"
        }
      },
      {
        "id": "vendor",
        "name": "Custom",
        "price": "Custom",
        "cadence": "volume pricing, set on one call",
        "usage": {
          "included": "Set on the call",
          "then": "Volume rates"
        },
        "blurb": "For vendors and labs running millions of episodes.",
        "includes": [
          "Everything in Max, plus $50 of free credit",
          "Committed capacity contracts and reserved capacity",
          "Running it in your own cloud account: talk to us",
          "Custom environment shapes",
          "Direct line to engineering"
        ],
        "cta": {
          "label": "Talk to us, live in an hour",
          "href": "/validity-report"
        },
        "ctaNote": "No sales cycle. One call with an engineer, a plan shaped on that call, and your first run the same hour."
      }
    ],
    "extras": [
      {
        "item": "Verified snapshot build",
        "price": "$1 per build",
        "note": "A build that fails its own verify command is not charged."
      },
      {
        "item": "Snapshot storage",
        "price": "Included",
        "note": "Included in every plan."
      },
      {
        "item": "Paused time",
        "price": "Not billed",
        "note": "A paused environment accrues nothing, and nothing accrues before one is handed to you."
      },
      {
        "item": "Egress",
        "price": "Included",
        "note": "Registries and git hosts are not metered separately. The trial caps data out at 20 GB a month."
      }
    ],
    "comparison": [
      {
        "provider": "Self-hosted Docker, raw cloud compute",
        "cost": "~$0.014",
        "note": "Before engineering time, image maintenance and burst orchestration, with unknown validity."
      },
      {
        "provider": "Typical managed sandbox, list",
        "cost": "~$0.03",
        "note": "The same rate we charge. The difference is the 60 to 100 s of cold setup you pay for on every episode."
      },
      {
        "provider": "Premium managed sandbox, list",
        "cost": "~$0.06",
        "note": "Roughly three times the typical per-vCPU rate."
      },
      {
        "provider": "Promigence, list",
        "cost": "~$0.03",
        "note": "Warm verified fork, validity report, reproducible by hash, quoted and capped before the run.",
        "us": true
      }
    ],
    "principles": [
      {
        "title": "The same rate as the market, per second",
        "body": "$0.0504 per vCPU-hour and $0.0162 per GiB-hour, the market's standard list rate. A price nobody can compare against is worth very little, so we did not invent a new unit."
      },
      {
        "title": "You see the ceiling before the run",
        "body": "`promigence run quote` returns the exact maximum before a single environment starts. `--cap` refuses a run that would exceed it rather than stopping halfway and charging for the half."
      },
      {
        "title": "A faster run is a cheaper run",
        "body": "The meter runs from the moment an environment is handed to you until it ends. Starting warm instead of cold cuts 60 to 100 seconds off every episode, and that comes straight off the bill."
      },
      {
        "title": "Our failures are on us",
        "body": "A build that fails its own verify command is not charged. Neither is an episode the environment broke, when our side can show the failure was ours. We can only refuse to bill for that category because we measure it."
      }
    ]
  },
  "useCases": [
    {
      "slug": "agent-evals",
      "url": "https://www.promigence.ai/for/agent-evals",
      "title": "Run agent evaluations on environments you can prove were valid",
      "audience": "Evaluation and platform engineers at AI agent companies, benchmark producers, and eval-as-a-service teams.",
      "summary": "Promigence verifies every environment before an agent runs in it, forks a thousand from one snapshot, and reports which failures were the environment's and which were the agent's. That distinction is the difference between an eval number you can publish and one you cannot."
    },
    {
      "slug": "rl-environments",
      "url": "https://www.promigence.ai/for/rl-environments",
      "title": "Reinforcement-learning environments that cannot poison the reward",
      "audience": "RL environment vendors, data vendors, and labs' own post-training teams running coding agents.",
      "summary": "Promigence runs thousands of concurrent RL environments forked from one verified snapshot, each proven to work before the episode starts. A broken environment does not just lose you an episode: the optimiser treats its failure as real and the model learns from something that never happened."
    },
    {
      "slug": "swe-bench",
      "url": "https://www.promigence.ai/for/swe-bench",
      "title": "SWE-bench and friends, without the broken-environment tax",
      "audience": "Teams publishing or consuming SWE-bench, SWE-rebench, Terminal-Bench, SetupBench and similar results.",
      "summary": "Promigence runs SWE-bench-class benchmarks on environments verified before the instance starts and reproducible from a hash afterwards. Published work has found roughly a third of the hardest instances broken at the environment level, a tax paid out of every score computed on them."
    },
    {
      "slug": "agentic-ci",
      "url": "https://www.promigence.ai/for/agentic-ci",
      "title": "Agentic CI with a known cost before every run",
      "audience": "Platform teams running coding agents against their own repositories in CI.",
      "summary": "Promigence gives every agentic CI job a warm environment forked from a verified snapshot of your repo, so an agent starts at a built tree rather than at a `git clone`. Most of an agent-heavy CI bill is repeated setup. Forking removes it, and a quote before each run keeps the monthly number predictable."
    },
    {
      "slug": "ci-runners",
      "url": "https://www.promigence.ai/for/ci-runners",
      "title": "CI runners that finish the same job 2–3.5× sooner",
      "audience": "Teams on GitHub Actions or GitLab CI whose jobs are slow, costly, or too big for the default runner.",
      "summary": "Promigence runs your existing GitHub Actions and GitLab CI jobs in its sandboxes. One line of the workflow changes (`runs-on: promigence`, or a runner tag in GitLab), the job itself does not. On the same job at the same size, measured against two hosted runner services, it finished 2–3.5× sooner and cost 7–10× less. Coding agents working inside CI have their own page, Agentic CI."
    },
    {
      "slug": "coding-agents",
      "url": "https://www.promigence.ai/for/coding-agents",
      "title": "Coding agents that start work on a repo that is already built",
      "audience": "Teams building coding-agent products and software factories that run agents against customer repositories.",
      "summary": "Promigence gives a coding agent a sandbox forked from a verified snapshot of the repository, with dependencies installed and the build done. The agent starts at a built tree instead of a git clone, so its edit-and-check loop runs at warm speed from the first step."
    },
    {
      "slug": "background-agents",
      "url": "https://www.promigence.ai/for/background-agents",
      "title": "Background agents with a full dev environment, and no bill while they wait",
      "audience": "Platform teams building internal background agents, and teams running vendor coding agents on their own pool.",
      "summary": "Promigence gives background agents a full development environment forked from a verified snapshot: your repository, its services and its build, ready when the agent starts. A long-running agent can pause while it waits on a person, a queue or a timer, and paused time is not billed."
    },
    {
      "slug": "code-review",
      "url": "https://www.promigence.ai/for/code-review",
      "title": "AI code review that checks every pull request on a warm, built repo",
      "audience": "Companies building AI code-review products, and teams running review agents on their own repositories.",
      "summary": "Promigence gives an AI code-review agent a sandbox forked from a verified, already-built snapshot of the repository, so it can build, run the tests and check its suggestions on every pull request without paying for a fresh clone and install each time."
    },
    {
      "slug": "code-interpreters",
      "url": "https://www.promigence.ai/for/code-interpreters",
      "title": "Code interpreters that answer while your user is still looking",
      "audience": "Teams building AI analysts, chat-with-your-data features and any AI app that runs code for its users.",
      "summary": "Promigence runs the code your AI app writes in an isolated sandbox that is ready in milliseconds. In our benchmark a code-interpreter session took 1.15 seconds from start to result at the median, and Promigence works with the sandbox API many AI apps already use."
    },
    {
      "slug": "agent-builders",
      "url": "https://www.promigence.ai/for/agent-builders",
      "title": "A sandbox backend for agent-builder and workflow platforms",
      "audience": "Agent-builder, workflow-automation and low-code AI platforms that run user-defined code or agents.",
      "summary": "Promigence gives agent-builder and workflow platforms a sandbox backend for the code their users' agents run: isolated, ready in milliseconds, billed by the second, and compatible with the sandbox API many platforms already integrate. It fits as a second provider next to the one you have."
    },
    {
      "slug": "ai-pentest",
      "url": "https://www.promigence.ai/for/ai-pentest",
      "title": "AI pentest agents that attack a fresh copy of the target every time",
      "audience": "Teams building AI penetration-testing and offensive-security agents.",
      "summary": "Promigence lets an offensive-security agent fork the same prepared target as many times as it needs, so every exploit attempt starts from an identical, clean state, behind an outbound allow-list."
    }
  ],
  "glossary": [
    {
      "slug": "environment-runtime",
      "url": "https://www.promigence.ai/glossary/environment-runtime",
      "term": "Environment runtime",
      "aliases": [
        "agent environment runtime",
        "execution plane"
      ],
      "definition": "An environment runtime is infrastructure that builds, verifies, reproduces and forks the environment an AI agent runs inside, treating the environment itself as the product."
    },
    {
      "slug": "verified-environment",
      "url": "https://www.promigence.ai/glossary/verified-environment",
      "term": "Verified environment",
      "aliases": [],
      "definition": "A verified environment is one that ran its own declared test command at build time, so it is known to work before an agent is placed inside it."
    },
    {
      "slug": "episode",
      "url": "https://www.promigence.ai/glossary/episode",
      "term": "Episode",
      "aliases": [],
      "definition": "An episode is one environment's complete life, fork, execute, terminate, and it is the unit a quote and a spend cap are written against."
    },
    {
      "slug": "snapshot-fork",
      "url": "https://www.promigence.ai/glossary/snapshot-fork",
      "term": "Snapshot fork",
      "aliases": [
        "warm fork"
      ],
      "definition": "A snapshot fork creates a new environment from an already-warm one that has finished installing and building, so it costs milliseconds rather than seconds."
    },
    {
      "slug": "warm-start",
      "url": "https://www.promigence.ai/glossary/warm-start",
      "term": "Warm start",
      "aliases": [],
      "definition": "A warm start begins work in an environment where dependencies are installed and caches are populated, so the first command you run is the one you care about."
    },
    {
      "slug": "validity-report",
      "url": "https://www.promigence.ai/glossary/validity-report",
      "term": "Validity report",
      "aliases": [
        "environment validity"
      ],
      "definition": "A validity report states, for one run, how many environments were verified, which failed, and whether each failure belonged to the environment or the task."
    },
    {
      "slug": "poisoned-reward",
      "url": "https://www.promigence.ai/glossary/poisoned-reward",
      "term": "Poisoned reward",
      "aliases": [],
      "definition": "A poisoned reward is a training signal produced by a broken environment rather than by the agent's behaviour, so the model learns from an outcome that never happened."
    },
    {
      "slug": "burst-capacity",
      "url": "https://www.promigence.ai/glossary/burst-capacity",
      "term": "Burst capacity",
      "aliases": [],
      "definition": "Burst capacity is how many environments a provider actually delivers when many are requested at once, which is often very different from its advertised latency for one."
    },
    {
      "slug": "flight-recorder",
      "url": "https://www.promigence.ai/glossary/flight-recorder",
      "term": "Flight recorder",
      "aliases": [],
      "definition": "A flight recorder is a per-episode log of every command executed and every file diff produced, kept so a failed episode can be read rather than guessed at."
    }
  ],
  "cli": {
    "globalFlags": [
      {
        "name": "--json",
        "summary": "one JSON document on stdout; the default whenever stdout is not a TTY, except for exec --sandbox"
      },
      {
        "name": "--text",
        "summary": "human-readable text"
      },
      {
        "name": "--api-key",
        "arg": "KEY",
        "summary": "precedence: --api-key > PROMIGENCE_API_KEY > ~/.config/promigence/credentials"
      },
      {
        "name": "--version",
        "summary": "print the version"
      },
      {
        "name": "--help",
        "summary": "help; `promigence <command> --help` for one command"
      }
    ],
    "groups": [
      {
        "name": "Setup",
        "blurb": "Sign up, check the install, and get an agent oriented in about 1,200 tokens.",
        "commands": [
          {
            "name": "promigence login",
            "summary": "sign up or sign in (email; GitHub/Google where enabled); stores a new API key",
            "flags": [
              {
                "name": "--provider",
                "arg": "NAME",
                "summary": "a sign-in method the API offers (email; github|google where enabled): skip the chooser"
              },
              {
                "name": "--no-browser",
                "summary": "headless: print the URL, paste the code back"
              },
              {
                "name": "--key-name",
                "arg": "N",
                "summary": "label for the key this login mints (default cli@<host>)"
              },
              {
                "name": "--api-url",
                "arg": "URL",
                "summary": "sign in to this API instead of the default (no prompt)"
              },
              {
                "name": "--yes",
                "summary": "accept a non-default API from PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--ref",
                "arg": "CODE",
                "summary": "a referral code (new accounts)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence signup",
            "summary": "create an account (asks for an invite code first while invite-only)",
            "flags": [
              {
                "name": "--invite",
                "arg": "CODE",
                "summary": "the code (prefer the prompt; argv is visible)"
              },
              {
                "name": "--provider",
                "arg": "NAME",
                "summary": "a sign-in method the API offers (email; github|google where enabled): skip the chooser"
              },
              {
                "name": "--no-browser",
                "summary": "headless: print the URL, paste the code back"
              },
              {
                "name": "--key-name",
                "arg": "N",
                "summary": "label for the key this sign-in mints (default cli@<host>)"
              },
              {
                "name": "--api-url",
                "arg": "URL",
                "summary": "sign up on this API instead of the default (no prompt)"
              },
              {
                "name": "--yes",
                "summary": "accept a non-default API from PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--ref",
                "arg": "CODE",
                "summary": "a referral code (new accounts)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence logout",
            "summary": "forget this CLI's key (revoked when `promigence login` minted it)",
            "flags": [
              {
                "name": "--keep-key",
                "summary": "only forget it locally; the key keeps working"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence auth login",
            "summary": "store an API key (--from-env VAR | stdin; never on argv)",
            "flags": [
              {
                "name": "--from-env",
                "arg": "VAR",
                "summary": "read the key from an environment variable"
              },
              {
                "name": "--api-key",
                "arg": "K",
                "summary": "accepted but warns: key on argv"
              }
            ],
            "by": "Nov 22 2026"
          },
          {
            "name": "promigence keys list",
            "summary": "your org's API keys",
            "flags": [
              {
                "name": "--all",
                "summary": "include revoked keys"
              },
              {
                "name": "--project",
                "arg": "P",
                "summary": "another project's"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "with --project: in this org"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence keys create",
            "summary": "mint a key (secret printed once)",
            "flags": [
              {
                "name": "--name",
                "arg": "N",
                "summary": "label, e.g. ci-prod"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "in this org (default: this key's)"
              },
              {
                "name": "--project",
                "arg": "P",
                "summary": "in this project"
              },
              {
                "name": "--service",
                "summary": "owners: outlives your membership (CI)"
              },
              {
                "name": "--expires",
                "arg": "WHEN",
                "summary": "30d, 1y, a date; default never"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence keys revoke",
            "args": "KEY_ID",
            "summary": "revoke a key",
            "flags": [
              {
                "name": "--project",
                "arg": "P",
                "summary": "a key in another project"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "with --project: in this org"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org list",
            "summary": "your organizations (* = default)",
            "flags": [
              {
                "name": "--all",
                "summary": "every one"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org create",
            "args": "NAME",
            "summary": "create one you own (no trial credit)",
            "flags": [
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org switch",
            "args": "ORG",
            "summary": "sign in, make ORG the default, store a key for it",
            "flags": [
              {
                "name": "--project",
                "arg": "P",
                "summary": "the new key's project"
              },
              {
                "name": "--keep-old-key",
                "summary": "keep the replaced key working"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org members",
            "summary": "members and roles",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org invite",
            "args": "EMAIL",
            "summary": "invite an email (owners)",
            "flags": [
              {
                "name": "--role",
                "arg": "R",
                "summary": "owner|member (member)"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org invites",
            "summary": "pending invites (14-day expiry)",
            "flags": [
              {
                "name": "--mine",
                "summary": "sent to you"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org uninvite",
            "args": "INVITE_ID",
            "summary": "revoke an invite (owners)",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org role",
            "args": "USER_ID ROLE",
            "summary": "set owner|member (owners)",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org remove",
            "args": "USER_ID",
            "summary": "remove a member; their keys die (owners)",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org leave",
            "args": "[ORG]",
            "summary": "leave an organization",
            "flags": [
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org join",
            "args": "INVITE_ID",
            "summary": "accept an invite sent to you",
            "flags": [
              {
                "name": "--decline",
                "summary": "decline it instead"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org audit",
            "summary": "who did what (owners; needs --sign-in)",
            "flags": [
              {
                "name": "--before",
                "arg": "SEQ",
                "summary": "older entries"
              },
              {
                "name": "--limit",
                "arg": "N",
                "summary": "how many (100)"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--sign-in",
                "summary": "sign in in your browser: the log is read as you, never with a key"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence org delete",
            "args": "ORG",
            "summary": "delete it; keys die (owners)",
            "flags": [
              {
                "name": "--confirm",
                "arg": "NAME",
                "summary": "its name (required)"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence project list",
            "summary": "projects (keys belong to one)",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence project create",
            "args": "NAME",
            "summary": "create a project",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence project rename",
            "args": "PROJECT NAME",
            "summary": "rename (not `default`)",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence project delete",
            "args": "PROJECT",
            "summary": "delete an empty one (owners)",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence project cap",
            "args": "PROJECT USD|off",
            "summary": "monthly USD cap, or off (owners)",
            "flags": [
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence project move",
            "args": "PROJECT",
            "summary": "to another org; keys die (owners)",
            "flags": [
              {
                "name": "--to",
                "arg": "ORG",
                "summary": "yours, with a card"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "another org than this key's"
              },
              {
                "name": "--no-browser",
                "summary": "sign in headless (or PROMIGENCE_ID_TOKEN)"
              },
              {
                "name": "--yes",
                "summary": "sign in to PROMIGENCE_API_URL without the prompt"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence me",
            "summary": "plan, concurrency in use, trial credit, spend, limits",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence billing card",
            "summary": "add a card: prints a checkout URL (trial credits kept)",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 30 2026"
          },
          {
            "name": "promigence doctor",
            "summary": "check client, auth and API",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 22 2026"
          },
          {
            "name": "promigence init",
            "summary": "write promigence.toml",
            "flags": [
              {
                "name": "--repo",
                "arg": "U",
                "summary": "git URL (default: the `origin` remote)"
              },
              {
                "name": "--commit",
                "arg": "SHA",
                "summary": "commit to pin (default: HEAD)"
              },
              {
                "name": "--setup",
                "arg": "CMD",
                "summary": "override the inferred setup step"
              },
              {
                "name": "--verify",
                "arg": "CMD",
                "summary": "override the inferred verify command"
              },
              {
                "name": "--tier",
                "arg": "xsmall|small|medium|large|xlarge|2xlarge",
                "summary": "default medium"
              },
              {
                "name": "--force",
                "summary": "overwrite an existing promigence.toml"
              },
              {
                "name": "--print",
                "summary": "write nothing; print what it would write"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence examples",
            "summary": "what forks with no build (no auth)",
            "flags": [
              {
                "name": "--limit",
                "arg": "N",
                "summary": "how many to list (default 20)"
              },
              {
                "name": "--bundle",
                "summary": "write each public snapshot as a .promigence file (none yet)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence agent-guide",
            "summary": "~1.2k-token guide for agents (--section commands|errors|cost)",
            "flags": [
              {
                "name": "--section",
                "arg": "commands|errors|cost",
                "summary": "one section instead of the core"
              },
              {
                "name": "--code",
                "arg": "C",
                "summary": "the entry for one error code"
              },
              {
                "name": "--format",
                "arg": "md|json",
                "summary": "default md"
              },
              {
                "name": "--install",
                "summary": "write the fence into AGENTS.md/CLAUDE.md, .claude/skills, .cursor/rules"
              },
              {
                "name": "--create",
                "summary": "with --install: create AGENTS.md if neither file exists"
              },
              {
                "name": "--check",
                "summary": "report what --install would change; write nothing"
              }
            ],
            "by": "Oct 25 2026"
          },
          {
            "name": "promigence mcp",
            "summary": "MCP server on stdio: `claude mcp add promigence -- promigence mcp` (Windows: `-- cmd /c promigence mcp`)",
            "flags": [
              {
                "name": "--read-only",
                "summary": "offer only the tools that read: list, read a file, fetch output, a report"
              },
              {
                "name": "--allow-tools",
                "arg": "A,B",
                "summary": "offer only these tools (comma-separated names)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "spend cap for every sandbox and batch it starts (else PROMIGENCE_SPEND_CAP, else the org default)"
              },
              {
                "name": "--keep",
                "summary": "leave the sandboxes this session created running at shutdown"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence status",
            "summary": "regions · your concurrency in use vs your limit",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence billing usage",
            "summary": "this month's spend: plan, usage by tier, credits, next invoice",
            "flags": [
              {
                "name": "--ledger",
                "summary": "also print this key's project's metered rows"
              },
              {
                "name": "--limit",
                "arg": "N",
                "summary": "with --ledger: how many rows (default 20)"
              },
              {
                "name": "--cursor",
                "arg": "C",
                "summary": "with --ledger: the next_cursor of an earlier page"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 30 2026"
          },
          {
            "name": "promigence referrals",
            "summary": "your referral code, its offer, your referrals",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence referrals apply",
            "args": "<code>",
            "summary": "apply a code (owner, before the first paid invoice)",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence pricing",
            "summary": "the price list, live (yours with a key)",
            "flags": [
              {
                "name": "--new-account",
                "summary": "what a new account gets"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence credits",
            "summary": "your free-credit offer: state, credit, expiry, campaign",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence credits claim",
            "summary": "open the claim page (accept the terms in the browser); prints its URL",
            "flags": [
              {
                "name": "--no-open",
                "summary": "print the URL, open nothing"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence billing portal",
            "summary": "manage the card on file and past invoices: prints a portal URL",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 30 2026"
          }
        ]
      },
      {
        "name": "Snapshots",
        "blurb": "Build a verified environment once. Everything after this is a fork of it.",
        "commands": [
          {
            "name": "promigence snapshot create",
            "summary": "build + verify a snapshot (--image | --dockerfile | --devcontainer)",
            "flags": [
              {
                "name": "--repo",
                "arg": "R",
                "summary": "owner/name (connected GitHub) or a git URL"
              },
              {
                "name": "--ref",
                "arg": "R",
                "summary": "with owner/name: branch|tag|sha"
              },
              {
                "name": "--commit",
                "arg": "SHA",
                "summary": "40-char sha, never a branch"
              },
              {
                "name": "--image",
                "arg": "REF",
                "summary": "a tag (we pin it) or REF@sha256:D"
              },
              {
                "name": "--dockerfile",
                "arg": "PATH",
                "summary": "a Dockerfile we build"
              },
              {
                "name": "--context",
                "arg": "DIR|URL@SHA",
                "summary": "default: the Dockerfile's dir"
              },
              {
                "name": "--devcontainer",
                "arg": "PATH",
                "summary": "a devcontainer.json (default: the one here)"
              },
              {
                "name": "--no-devcontainer",
                "summary": "ignore the repo's devcontainer.json"
              },
              {
                "name": "--dir",
                "arg": "PATH",
                "summary": "upload the files git tracks there"
              },
              {
                "name": "--from",
                "arg": "SNAP",
                "summary": "owner/name|--dir: start from (base)"
              },
              {
                "name": "--track",
                "summary": "owner/name: rebuild on every push"
              },
              {
                "name": "--setup",
                "arg": "CMD",
                "summary": "setup step (ordered)"
              },
              {
                "name": "--verify",
                "arg": "CMD",
                "summary": "must exit 0 or nothing is stored"
              },
              {
                "name": "--start",
                "arg": "CMD",
                "summary": "background process kept running"
              },
              {
                "name": "--tier",
                "arg": "xsmall|small|medium|large|xlarge|2xlarge",
                "summary": "build and fork size"
              },
              {
                "name": "--alias",
                "arg": "N",
                "summary": "unique per org"
              },
              {
                "name": "--grade",
                "arg": "CMD",
                "summary": "score the work in a clean env"
              },
              {
                "name": "--fresh",
                "summary": "no 10-min replay (identical inputs still reuse their snapshot)"
              },
              {
                "name": "--wait",
                "summary": "bounded by --wait-timeout (default 100s)"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "bound (100s); expiry = exit 11, nothing killed"
              },
              {
                "name": "--idempotency-key",
                "arg": "K",
                "summary": "a key you pick (24 h)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Oct 25 2026"
          },
          {
            "name": "promigence snapshot status",
            "args": "<build_id>",
            "summary": "poll a build by build_id",
            "flags": [
              {
                "name": "--wait",
                "summary": "bounded by --wait-timeout (default 100s)"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "bound (100s); expiry = exit 11, nothing killed"
              },
              {
                "name": "--log",
                "arg": "N",
                "summary": "print the last N lines of the build log"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Oct 25 2026"
          },
          {
            "name": "promigence snapshot list",
            "summary": "list snapshots in your org",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 22 2026"
          },
          {
            "name": "promigence snapshot inspect",
            "args": "<hash>",
            "summary": "show a snapshot manifest",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 22 2026"
          },
          {
            "name": "promigence snapshot verify",
            "args": "<hash>",
            "summary": "re-verify a snapshot in a fork",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence snapshot export",
            "args": "<hash>",
            "summary": "write a portable .promigence bundle (commit it, cite it, mail it)",
            "flags": [
              {
                "name": "--out",
                "arg": "FILE",
                "summary": "default <alias>.promigence; `-` or a pipe writes stdout"
              },
              {
                "name": "--no-layers",
                "summary": "citation form: identity + provenance + verification, no chunk table"
              },
              {
                "name": "--layers",
                "summary": "keep the chunk table however large (default: drop it above 100 kB)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence image resolve",
            "args": "REF",
            "summary": "resolve REF (python:3.12) to REF@sha256:… without a local container runtime",
            "flags": [
              {
                "name": "--registry-secret",
                "arg": "NAME",
                "summary": "stored secret holding user:password for a private registry"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence github connect",
            "summary": "install the GitHub App (browser); waits for it",
            "flags": [
              {
                "name": "--no-open",
                "summary": "print the link, open nothing"
              },
              {
                "name": "--no-wait",
                "summary": "print the link and return"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "for the install (10m); expiry = exit 11"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence github status",
            "summary": "connected accounts, pending installs, tracked branches",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence github disconnect",
            "args": "<installation_id|account>",
            "summary": "stop building from a GitHub account",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence github untrack",
            "args": "<track_id|alias>",
            "summary": "stop rebuilding on push (the snapshot stays)",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence repos",
            "summary": "repos your GitHub connection reads (for --repo)",
            "flags": [
              {
                "name": "--page",
                "arg": "N",
                "summary": "page (100 a page)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence snapshot delete",
            "args": "<hash|alias>",
            "summary": "remove one of your snapshots (refused while a fork of it is alive)",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence snapshot builds",
            "summary": "your builds, newest first (a rejected build keeps its reason)",
            "flags": [
              {
                "name": "--limit",
                "arg": "N",
                "summary": "how many (default 20)"
              },
              {
                "name": "--state",
                "arg": "S",
                "summary": "only this state, e.g. running | rejected"
              },
              {
                "name": "--cursor",
                "arg": "C",
                "summary": "the next_cursor of an earlier page"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence snapshot alias",
            "args": "<hash> [NAME]",
            "summary": "name a snapshot, or clear its name (unique per org)",
            "flags": [
              {
                "name": "--clear",
                "summary": "remove the alias instead"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          }
        ]
      },
      {
        "name": "Runs",
        "blurb": "Quote, cap, fork N copies, execute, and read which copies were valid.",
        "commands": [
          {
            "name": "promigence run",
            "args": "-- CMD",
            "summary": "fork N, exec CMD in each, print the validity report",
            "flags": [
              {
                "name": "--snapshot",
                "arg": "H",
                "summary": "id | alias[@commit7] | ./env.promigence (default promigence/base)"
              },
              {
                "name": "--image",
                "arg": "REF",
                "summary": "not with --snapshot: a tag or REF@sha256:D"
              },
              {
                "name": "--count",
                "arg": "N",
                "summary": "sandboxes; each has PROMIGENCE_INDEX (0..N-1) and PROMIGENCE_SEED",
                "required": true
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "sandbox timeout (15m)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "spend cap; refused above it (exit 5)",
                "required": true
              },
              {
                "name": "--allow-partial",
                "summary": "start what the cap allows; the rest not_started"
              },
              {
                "name": "--secret",
                "arg": "NAME",
                "summary": "stored secret as an env var"
              },
              {
                "name": "--verify-each",
                "summary": "verify forks before hand-over"
              },
              {
                "name": "--network",
                "arg": "none|egress",
                "summary": "default egress"
              },
              {
                "name": "--allow",
                "arg": "HOST",
                "summary": "outbound allow-list"
              },
              {
                "name": "--optimize-for",
                "arg": "start|compute",
                "summary": "default start"
              },
              {
                "name": "--keep-delta",
                "summary": "keep the writable delta"
              },
              {
                "name": "--label",
                "arg": "K=V",
                "summary": "run label"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "bound (100s); expiry = exit 11, nothing killed"
              },
              {
                "name": "--grade",
                "arg": "CMD",
                "summary": "score the work in a clean env"
              },
              {
                "name": "--holdout",
                "arg": "CMD",
                "summary": "second test set; gap reported"
              },
              {
                "name": "--grade-score",
                "arg": "M",
                "summary": "exit|last_line_json|tap (exit); JSON: {\"score\":0.8,\"pass\":true}"
              },
              {
                "name": "--grade-timeout",
                "arg": "DUR",
                "summary": "per grader (10m)"
              },
              {
                "name": "--grade-output",
                "summary": "keep last 16 KiB"
              },
              {
                "name": "--fail-on",
                "arg": "task|env|none",
                "summary": "what exits non-zero (task)"
              },
              {
                "name": "--keep",
                "summary": "keep sandboxes after CMD"
              },
              {
                "name": "--stream",
                "summary": "live output (auto on a TTY)"
              },
              {
                "name": "--no-stream",
                "summary": "one envelope even on a TTY"
              },
              {
                "name": "--max-output",
                "arg": "BYTES",
                "summary": "output cap (64k)"
              },
              {
                "name": "--idempotency-key",
                "arg": "K",
                "summary": "a key you pick (24 h)"
              },
              {
                "name": "--verbose",
                "summary": "text: fork timings and totals too"
              }
            ],
            "by": "Oct 25 2026"
          },
          {
            "name": "promigence run quote",
            "summary": "price a run before launch",
            "flags": [
              {
                "name": "--snapshot",
                "arg": "H",
                "summary": "id | alias[@commit7] | ./env.promigence (default promigence/base)"
              },
              {
                "name": "--count",
                "arg": "N",
                "summary": "number of sandboxes",
                "required": true
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "sandbox timeout (15m)"
              },
              {
                "name": "--tier",
                "arg": "T",
                "summary": "must match the snapshot's assigned tier"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "price it against this cap; spends nothing"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Oct 25 2026"
          },
          {
            "name": "promigence run report",
            "args": "ID",
            "summary": "validity report: env vs task failures",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              },
              {
                "name": "--sandboxes",
                "arg": "all|failed",
                "summary": "default: summary + non-completed sandboxes"
              },
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "one sandbox"
              },
              {
                "name": "--repro",
                "summary": "print the repro command for --sandbox"
              },
              {
                "name": "--limit",
                "arg": "N",
                "summary": "text rows before '… N more' (50; 0 = all). --json is never paged"
              }
            ],
            "by": "Oct 25 2026"
          },
          {
            "name": "promigence run status",
            "args": "ID",
            "summary": "poll a run",
            "flags": [
              {
                "name": "--wait",
                "summary": "bounded by --wait-timeout (default 100s)"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "bound (100s); expiry = exit 11, nothing killed"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Oct 25 2026"
          },
          {
            "name": "promigence run cancel",
            "args": "ID",
            "summary": "stop queued starts",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence run kill",
            "args": "ID",
            "summary": "kill every sandbox of a run",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence run replay",
            "args": "ID",
            "summary": "replay sandboxes (client-triggered, never automatic)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "only these sandboxes"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence run open",
            "args": "ID",
            "summary": "reopen a failed sandbox as a live one, at the moment it failed",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "which failure (default: the only one)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "what the reopened sandbox may spend"
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "how long it may run (default: the run's)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence run captures",
            "args": "ID",
            "summary": "what of this run is preserved, and when it expires",
            "flags": [
              {
                "name": "--delete",
                "arg": "SNAPSHOT_ID",
                "summary": "destroy one now, before it expires"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence run list",
            "summary": "your runs, newest first",
            "flags": [
              {
                "name": "--limit",
                "arg": "N",
                "summary": "how many (default 20)"
              },
              {
                "name": "--state",
                "arg": "S",
                "summary": "only this state"
              },
              {
                "name": "--cursor",
                "arg": "C",
                "summary": "the next_cursor of an earlier page"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          }
        ]
      },
      {
        "name": "Sandboxes",
        "blurb": "Long-lived sandboxes you drive command by command: exec, files, pause, resume, fork.",
        "commands": [
          {
            "name": "promigence fork",
            "summary": "fork N sandboxes from a snapshot (--count --cap)",
            "flags": [
              {
                "name": "--snapshot",
                "arg": "H",
                "summary": "snap_<id> | alias[@commit7] | ./env.promigence (default promigence/base)"
              },
              {
                "name": "--count",
                "arg": "N",
                "summary": "number of sandboxes",
                "required": true
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "sandbox timeout (15m)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "spend cap; refused above it (exit 5)",
                "required": true
              },
              {
                "name": "--allow-partial",
                "summary": "start what the cap allows; the rest not_started"
              },
              {
                "name": "--secret",
                "arg": "NAME",
                "summary": "stored secret as an env var"
              },
              {
                "name": "--verify-each",
                "summary": "verify forks before hand-over"
              },
              {
                "name": "--network",
                "arg": "none|egress",
                "summary": "default egress"
              },
              {
                "name": "--allow",
                "arg": "HOST",
                "summary": "outbound allow-list"
              },
              {
                "name": "--optimize-for",
                "arg": "start|compute",
                "summary": "default start"
              },
              {
                "name": "--keep-delta",
                "summary": "keep the writable delta"
              },
              {
                "name": "--label",
                "arg": "K=V",
                "summary": "run label"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "bound (100s); expiry = exit 11, nothing killed"
              },
              {
                "name": "--no-wait",
                "summary": "return after POST /runs"
              },
              {
                "name": "--fresh",
                "summary": "skip idempotent replay"
              },
              {
                "name": "--stream",
                "summary": "live output (auto on a TTY)"
              },
              {
                "name": "--no-stream",
                "summary": "one envelope even on a TTY"
              },
              {
                "name": "--idempotency-key",
                "arg": "K",
                "summary": "a key you pick (24 h)"
              },
              {
                "name": "--verbose",
                "summary": "text: fork timings and totals too"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence exec",
            "args": "-- CMD",
            "summary": "run CMD in a sandbox (--sandbox SID) or a run (--run ID --all)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "stdout is the child's own bytes (JSON only with --json or PROMIGENCE_OUTPUT=json); its exit code passes through; not found 127; Promigence's own failures 125"
              },
              {
                "name": "--run",
                "arg": "ID",
                "summary": "with --all: every ready sandbox; queued reported skipped unless --wait"
              },
              {
                "name": "--all",
                "summary": "0 if every child exits 0, else 4"
              },
              {
                "name": "--no-passthrough",
                "summary": "return 0–12 instead of the child's code"
              },
              {
                "name": "--background",
                "summary": "with --sandbox: start it, print its exec_id, return now"
              },
              {
                "name": "--stdin",
                "summary": "with --background: keep stdin open for `promigence exec stdin`"
              },
              {
                "name": "--secret",
                "arg": "NAME",
                "summary": "stored secret as an env var"
              },
              {
                "name": "--stream",
                "summary": "live output (auto on a TTY)"
              },
              {
                "name": "--no-stream",
                "summary": "one envelope even on a TTY"
              },
              {
                "name": "--max-output",
                "arg": "BYTES",
                "summary": "per stream (64k; 32m, the most, into a pipe or file); past it the rest is cut, and text exits 12"
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "child timeout (default 15m)"
              },
              {
                "name": "--wait",
                "summary": "bounded by --wait-timeout (default 100s)"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "bound (100s); expiry = exit 11, nothing killed"
              },
              {
                "name": "--idempotency-key",
                "arg": "K",
                "summary": "a key you pick (24 h)"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence exec output",
            "args": "EXEC_ID",
            "summary": "an exec's output by id (background x_…: --follow)",
            "flags": [
              {
                "name": "--range",
                "arg": "A-B",
                "summary": "byte range, 0-based and B inclusive; `A-` runs to the end"
              },
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "resolve the exec inside this sandbox (required for x_…)"
              },
              {
                "name": "--run",
                "arg": "ID",
                "summary": "resolve the exec inside this run"
              },
              {
                "name": "--stderr",
                "summary": "the child's stderr instead of its stdout"
              },
              {
                "name": "--follow",
                "summary": "background exec: stream until it exits, pass its code through"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence exec ps",
            "summary": "list a sandbox's background execs",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence exec stdin",
            "args": "EXEC_ID",
            "summary": "write to a background exec's stdin (needs `exec --background --stdin`)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox it runs in",
                "required": true
              },
              {
                "name": "--data",
                "arg": "TEXT",
                "summary": "write this (default: read stdin to EOF)"
              },
              {
                "name": "--file",
                "arg": "P",
                "summary": "write this local file's bytes"
              },
              {
                "name": "--eof",
                "summary": "close stdin after writing (implied when reading a pipe)"
              },
              {
                "name": "--no-eof",
                "summary": "keep it open after piped input"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence exec kill",
            "args": "EXEC_ID",
            "summary": "signal a background exec (default SIGKILL)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox it runs in",
                "required": true
              },
              {
                "name": "--signal",
                "arg": "SIG",
                "summary": "TERM | INT | HUP | KILL | a number"
              },
              {
                "name": "--forget",
                "summary": "then drop its handle and buffered output"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence files put",
            "args": "SRC DST",
            "summary": "copy a local file into a sandbox (--recursive: a directory)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "target sandbox",
                "required": true
              },
              {
                "name": "--recursive",
                "summary": "SRC is a local directory; DST is a directory in the sandbox"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 22 2026"
          },
          {
            "name": "promigence files get",
            "args": "SRC DST",
            "summary": "copy a file out of a sandbox (--recursive: a directory)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "source sandbox",
                "required": true
              },
              {
                "name": "--recursive",
                "summary": "SRC is a directory in the sandbox; DST a local directory"
              },
              {
                "name": "--exclude",
                "arg": "GLOB",
                "summary": "with --recursive: leave these out, e.g. .git"
              },
              {
                "name": "--keep-links",
                "summary": "with --recursive: keep links leaving DST"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 22 2026"
          },
          {
            "name": "promigence files ls",
            "args": "[PATH]",
            "summary": "list a directory in a sandbox (lstat per entry)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--recursive",
                "summary": "walk below PATH, not one level"
              },
              {
                "name": "--depth",
                "arg": "N",
                "summary": "with --recursive: how many levels"
              },
              {
                "name": "--limit",
                "arg": "N",
                "summary": "stop after N entries (truncated is reported)"
              },
              {
                "name": "--no-hidden",
                "summary": "drop dotfiles (they are listed by default)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence files search",
            "args": "[PATH]",
            "summary": "find files by name glob and/or text inside them",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--name",
                "arg": "GLOB",
                "summary": "name glob, e.g. '*.py'"
              },
              {
                "name": "--contains",
                "arg": "TEXT",
                "summary": "literal text to find inside matching files"
              },
              {
                "name": "--ignore-case",
                "summary": "case-insensitive --contains"
              },
              {
                "name": "--limit",
                "arg": "N",
                "summary": "stop after N hits (truncated is reported)"
              },
              {
                "name": "--no-hidden",
                "summary": "skip dotfiles and dot-directories"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence files mkdir",
            "args": "PATH",
            "summary": "create a directory in a sandbox",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--parents",
                "summary": "mkdir -p: intermediate directories, and no error if it exists"
              },
              {
                "name": "--mode",
                "arg": "OCTAL",
                "summary": "e.g. 755"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence files mv",
            "args": "SRC DST",
            "summary": "move or rename a path inside a sandbox",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--overwrite",
                "summary": "replace DST if it is already there"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence files cp",
            "args": "SRC DST",
            "summary": "copy a path inside a sandbox (both ends are in the sandbox)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--recursive",
                "summary": "a directory and everything under it"
              },
              {
                "name": "--overwrite",
                "summary": "replace DST if it is already there"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence files chmod",
            "args": "PATH",
            "summary": "change mode and/or owner of a path in a sandbox",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--mode",
                "arg": "OCTAL",
                "summary": "e.g. 755"
              },
              {
                "name": "--uid",
                "arg": "N",
                "summary": "owner"
              },
              {
                "name": "--gid",
                "arg": "N",
                "summary": "group"
              },
              {
                "name": "--recursive",
                "summary": "the directory and everything under it"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence agent start",
            "args": "claude|codex|opencode",
            "summary": "a coding agent in a new sandbox",
            "flags": [
              {
                "name": "--key-secret",
                "arg": "NAME[=VAR]",
                "summary": "stored secret with the model key (default ANTHROPIC_API_KEY; codex: OPENAI_API_KEY)"
              },
              {
                "name": "--key-from-env",
                "arg": "VAR",
                "summary": "store the key from this variable first (never argv)"
              },
              {
                "name": "--snapshot",
                "arg": "H",
                "summary": "start from this snapshot (default promigence/base; the agent is installed if missing)"
              },
              {
                "name": "--image",
                "arg": "REF@sha256:D",
                "summary": "instead of --snapshot"
              },
              {
                "name": "--repo",
                "arg": "URL",
                "summary": "clone this public repository and start the agent in it"
              },
              {
                "name": "--prompt",
                "arg": "TEXT",
                "summary": "work on this task headless, in the background"
              },
              {
                "name": "--attach",
                "summary": "open the agent's terminal now"
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "sandbox lifetime (default 1h)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "spend cap (else PROMIGENCE_SPEND_CAP, else the org default)"
              },
              {
                "name": "--wait-timeout",
                "arg": "DUR",
                "summary": "bound (100s); expiry = exit 11, nothing killed"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox kill",
            "args": "SID",
            "summary": "kill one sandbox",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence sandbox network",
            "args": "SID",
            "summary": "what this sandbox may reach, and every host it was refused",
            "flags": [
              {
                "name": "--cut",
                "summary": "cut this sandbox's egress now; it cannot be turned back on"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox shell",
            "args": "SID [-- CMD]",
            "summary": "interactive terminal (raw TTY, follows window size)",
            "flags": [
              {
                "name": "--cmd",
                "arg": "CMD",
                "summary": "run this instead of the login shell (sh -c)"
              },
              {
                "name": "--cwd",
                "arg": "DIR",
                "summary": "start in this directory"
              },
              {
                "name": "--env",
                "arg": "K=V",
                "summary": "environment variable"
              },
              {
                "name": "--secret",
                "arg": "NAME[=VAR]",
                "summary": "stored secret in the terminal's environment; NAME=VAR binds it to VAR"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox ssh",
            "args": "SID [-- CMD]",
            "summary": "log in over SSH (scp, sftp and -L work too)",
            "flags": [
              {
                "name": "--config",
                "summary": "print an ssh config block instead of logging in"
              },
              {
                "name": "--print",
                "summary": "print the connection details instead of logging in"
              },
              {
                "name": "--key",
                "arg": "PATH",
                "summary": "use this key pair instead of making one"
              },
              {
                "name": "--ttl",
                "arg": "S",
                "summary": "how long the access lasts (default 3600, max 3600)"
              },
              {
                "name": "--idle",
                "arg": "S",
                "summary": "close a session after this long with no activity"
              },
              {
                "name": "--proxy",
                "summary": "carry one connection on stdin/stdout (used by ssh itself)"
              },
              {
                "name": "--list",
                "summary": "the keys that have access, then exit"
              },
              {
                "name": "--revoke",
                "arg": "KEY_ID",
                "summary": "end one key's access (and its tunnel credential), then exit"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence port expose",
            "args": "PORT",
            "summary": "publish a port as a preview URL (anyone with it can reach it)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence port list",
            "summary": "list a sandbox's preview URLs",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence port revoke",
            "args": "TOKEN|PORT",
            "summary": "take a preview URL down (a token, or every URL for a port)",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence secrets set",
            "args": "NAME",
            "summary": "store secret NAME (env/file/stdin, never argv)",
            "flags": [
              {
                "name": "--from-env",
                "arg": "VAR",
                "summary": "read the value from an environment variable"
              },
              {
                "name": "--from-file",
                "arg": "P",
                "summary": "read the value from a file"
              },
              {
                "name": "--host",
                "arg": "HOST",
                "summary": "bind it to a host: sandboxes get a placeholder, replaced by the value only in requests sent to the address this command prints for HOST"
              },
              {
                "name": "--header",
                "arg": "NAME",
                "summary": "with --host: the request header the key is sent in (default: the usual key headers)"
              },
              {
                "name": "--no-raw",
                "summary": "with --host: the value itself can never be given to a sandbox"
              },
              {
                "name": "--list",
                "summary": "list stored secret names (no values, ever)"
              },
              {
                "name": "--delete",
                "summary": "remove NAME"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 8 2026"
          },
          {
            "name": "promigence sandbox list",
            "summary": "your sandboxes, newest first",
            "flags": [
              {
                "name": "--limit",
                "arg": "N",
                "summary": "how many (default 50)"
              },
              {
                "name": "--state",
                "arg": "S",
                "summary": "only these states, e.g. running,ready"
              },
              {
                "name": "--label",
                "arg": "K=V",
                "summary": "only sandboxes whose run carries every label given"
              },
              {
                "name": "--cursor",
                "arg": "C",
                "summary": "the next_cursor of an earlier page"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox pause",
            "args": "SID",
            "summary": "park a sandbox: it holds no capacity and bills no seconds",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox resume",
            "args": "SID",
            "summary": "bring a paused sandbox back and restart its clock",
            "flags": [
              {
                "name": "--optimize-for",
                "arg": "start|compute",
                "summary": "default: as created"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox snapshot",
            "args": "SID",
            "summary": "snapshot it without stopping it",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              },
              {
                "name": "--alias",
                "arg": "NAME",
                "summary": "name it"
              },
              {
                "name": "--move-alias",
                "summary": "take the alias from the snapshot that has it"
              },
              {
                "name": "--force",
                "summary": "take it even though the sandbox was given a secret; the snapshot, and what starts from it, can then contain that value"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence secrets list",
            "summary": "stored secret names (never a value)",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence secrets delete",
            "args": "NAME",
            "summary": "remove a stored secret",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox info",
            "args": "SID",
            "summary": "one sandbox: state, tier, time left, cost so far, and its execs",
            "flags": [
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox extend",
            "args": "SID",
            "summary": "give a live sandbox more time, within its run's quote and --cap (exit 5 past them)",
            "flags": [
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "the new total timeout",
                "required": true
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox autopause",
            "args": "SID",
            "summary": "pause it once it has sat idle, or read the rule it is under",
            "flags": [
              {
                "name": "--after",
                "arg": "DUR",
                "summary": "idle this long and it pauses itself (2s or more)"
              },
              {
                "name": "--off",
                "summary": "never pause it on idle; only its timeout ends it"
              },
              {
                "name": "--mode",
                "arg": "MODE",
                "summary": "requests (default) | activity: also no CPU, no bytes, no open connection inside"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence sandbox probe",
            "args": "SID",
            "summary": "is this still the verified environment? (its recorded paths, or --path)",
            "flags": [
              {
                "name": "--path",
                "arg": "P",
                "summary": "check these paths instead; PATH=blake3:<hex> where the snapshot recorded none (base, --image)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence files rm",
            "args": "PATH",
            "summary": "delete a path in a sandbox",
            "flags": [
              {
                "name": "--sandbox",
                "arg": "SID",
                "summary": "the sandbox",
                "required": true
              },
              {
                "name": "--recursive",
                "summary": "a directory and everything under it"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          }
        ]
      },
      {
        "name": "Ops",
        "blurb": "Accounts, keys, billing, organisations, connections and CI runners.",
        "commands": [
          {
            "name": "promigence bench burst",
            "summary": "N sandboxes at once: hand-off percentiles + success rate",
            "flags": [
              {
                "name": "--snapshot",
                "arg": "H",
                "summary": "snap_<id> | alias[@commit7] | ./env.promigence",
                "required": true
              },
              {
                "name": "--count",
                "arg": "N",
                "summary": "number of sandboxes",
                "required": true
              },
              {
                "name": "--timeout",
                "arg": "D",
                "summary": "per-sandbox timeout (default 120s, the public burst harness's)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "spend cap for the burst (required unless PROMIGENCE_SPEND_CAP is set)"
              },
              {
                "name": "--keep",
                "summary": "leave the sandboxes running (default: killed once measured)"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Nov 22 2026"
          },
          {
            "name": "promigence runners github",
            "summary": "GitHub Actions jobs in sandboxes: `runs-on: promigence` (until Ctrl-C)",
            "flags": [
              {
                "name": "--repo",
                "arg": "OWNER/REPO",
                "summary": "take this repository's jobs"
              },
              {
                "name": "--org",
                "arg": "ORG",
                "summary": "or every repository's of an organization"
              },
              {
                "name": "--runner-group",
                "arg": "NAME",
                "summary": "with --org: the runner group (Default)"
              },
              {
                "name": "--token-env",
                "arg": "VAR",
                "summary": "variable holding a GitHub token (GH_TOKEN, then GITHUB_TOKEN)"
              },
              {
                "name": "--labels",
                "arg": "A,B",
                "summary": "the runs-on labels (promigence); promigence-small|medium|large pick a size"
              },
              {
                "name": "--tier",
                "arg": "small|medium|large",
                "summary": "size of a job that names none (small)"
              },
              {
                "name": "--warm",
                "arg": "N",
                "summary": "keep N runners waiting: instant pickup, billed while idle"
              },
              {
                "name": "--max",
                "arg": "M",
                "summary": "sandboxes at once (10)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "most one job may cost (default: its timeout at its size)"
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "longest job (default: your plan's longest sandbox)"
              },
              {
                "name": "--idle-timeout",
                "arg": "DUR",
                "summary": "stop an on-demand runner no job took (90s)"
              },
              {
                "name": "--kill-on-exit",
                "summary": "Ctrl-C cancels running jobs instead of waiting"
              },
              {
                "name": "--prepare",
                "summary": "build the --tier runner snapshot, then exit"
              },
              {
                "name": "--yes",
                "summary": "build a missing runner snapshot (the build price, per size) without asking"
              },
              {
                "name": "--github-api",
                "arg": "URL",
                "summary": "GitHub Enterprise Server's API URL"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          },
          {
            "name": "promigence runners gitlab",
            "summary": "GitLab CI jobs in sandboxes, as a runner with your tags (until Ctrl-C)",
            "flags": [
              {
                "name": "--url",
                "arg": "URL",
                "summary": "your GitLab (https://gitlab.com)"
              },
              {
                "name": "--token-env",
                "arg": "VAR",
                "summary": "variable holding the runner authentication token (GITLAB_RUNNER_TOKEN)"
              },
              {
                "name": "--executor",
                "arg": "docker|shell",
                "summary": "jobs in containers (docker) or in the sandbox"
              },
              {
                "name": "--default-image",
                "arg": "REF",
                "summary": "docker: image of a job with no image: (ubuntu:24.04)"
              },
              {
                "name": "--pool",
                "arg": "N",
                "summary": "runners kept up, billed while idle (1)"
              },
              {
                "name": "--api-token-env",
                "arg": "VAR",
                "summary": "read_api token: start runners only for pending jobs"
              },
              {
                "name": "--max",
                "arg": "M",
                "summary": "sandboxes at once (10)"
              },
              {
                "name": "--tier",
                "arg": "small|medium|large",
                "summary": "runner size (small)"
              },
              {
                "name": "--cap",
                "arg": "USD",
                "summary": "most one job may cost (default: its timeout at its size)"
              },
              {
                "name": "--timeout",
                "arg": "DUR",
                "summary": "longest job (default: your plan's longest sandbox)"
              },
              {
                "name": "--idle-timeout",
                "arg": "DUR",
                "summary": "with --api-token-env: a runner no job took exits (90s)"
              },
              {
                "name": "--kill-on-exit",
                "summary": "Ctrl-C cancels running jobs instead of waiting"
              },
              {
                "name": "--prepare",
                "summary": "build the --tier runner snapshot, then exit"
              },
              {
                "name": "--yes",
                "summary": "build a missing runner snapshot (the build price) without asking"
              },
              {
                "name": "--json",
                "summary": "force the JSON envelope"
              }
            ],
            "by": "Dec 15 2026"
          }
        ]
      }
    ]
  },
  "errors": {
    "exitCodes": [
      {
        "code": 0,
        "meaning": "Success",
        "billed": "billed"
      },
      {
        "code": 1,
        "meaning": "Internal error on our side",
        "billed": "not billed"
      },
      {
        "code": 2,
        "meaning": "Usage error, bad or missing arguments",
        "billed": "not billed"
      },
      {
        "code": 3,
        "meaning": "Environment failure, the environment was at fault, not your command",
        "billed": "not billed when our side shows it was ours"
      },
      {
        "code": 4,
        "meaning": "Task failure, your command exited non-zero",
        "billed": "billed"
      },
      {
        "code": 5,
        "meaning": "Refused: the quote exceeds your spend cap",
        "billed": "not billed"
      },
      {
        "code": 6,
        "meaning": "The snapshot is not verified",
        "billed": "not billed"
      },
      {
        "code": 7,
        "meaning": "Missing or invalid API key",
        "billed": "not billed"
      },
      {
        "code": 8,
        "meaning": "Not found",
        "billed": "not billed"
      },
      {
        "code": 9,
        "meaning": "Unreachable",
        "billed": "not billed"
      },
      {
        "code": 10,
        "meaning": "Rate limited",
        "billed": "not billed"
      },
      {
        "code": 11,
        "meaning": "A --wait expired. Nothing was killed",
        "billed": "unchanged"
      },
      {
        "code": 12,
        "meaning": "Partial, some environments did not start, or were stopped at the cap boundary",
        "billed": "billed for what ran"
      },
      {
        "code": 130,
        "meaning": "Interrupted by the client",
        "billed": "billed for what ran"
      }
    ],
    "codes": [
      {
        "code": "fork_failed",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The sandbox could not be started.",
        "fix": "Not billed. A run with a command is retried once automatically; otherwise re-run. If it repeats, re-verify the snapshot: `promigence snapshot verify {snapshot_id}`.",
        "billed": false
      },
      {
        "code": "liveness_timeout",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The sandbox did not answer its first command within {deadline_ms} ms.",
        "fix": "Not billed. A run with a command is retried once automatically; otherwise re-run the fork. If it keeps happening, tell support@promigence.ai the run id.",
        "billed": false
      },
      {
        "code": "probe_warm_failed",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The sandbox failed its readiness check.",
        "fix": "The sandbox was discarded, not billed. Re-run; if it keeps failing, re-verify the snapshot: `promigence snapshot verify {snapshot_id}`.",
        "billed": false
      },
      {
        "code": "warm_ratio_failed",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "Verify cpu_ms {verify_cpu_ms} exceeds max(2 x {baseline_cpu_ms}, {baseline_cpu_ms} + 250).",
        "fix": "The fork was not warm; not billed. Re-run. If steady, re-verify the snapshot: `promigence snapshot verify {snapshot_id}`.",
        "billed": false
      },
      {
        "code": "verify_each_failed",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "Verify_each run failed in the fork (exit {exit_code}, digest {digest}).",
        "fix": "Not billed. A run with a command is retried once automatically. If it repeats, the snapshot no longer reproduces: rebuild with `promigence snapshot create ...`.",
        "billed": false
      },
      {
        "code": "toolchain_mismatch",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "Toolchain check `{argv}` in the fork gave digest {got}, the verified snapshot recorded {expected}.",
        "fix": "The fork's toolchain differs from the verified snapshot; not billed. Re-run; if it repeats, rebuild the snapshot.",
        "billed": false
      },
      {
        "code": "guest_agent_lost",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The sandbox stopped responding.",
        "fix": "Billed for the time used: nothing on our side explains it. Never retried automatically after hand-off. Replay: `promigence run replay {run_id} --sandbox {sandbox_id}`; if you think it was ours, tell support@promigence.ai the run id.",
        "billed": true
      },
      {
        "code": "oom_within_tier",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The sandbox was killed by a memory fault on our side while under the tier's {tier_mib} MiB.",
        "fix": "Our fault, not yours: the work lost since your last snapshot of this sandbox is credited back, up to 24 hours (a sandbox under 24 hours with no snapshot is never charged). Replay: `promigence run replay {run_id} --sandbox {sandbox_id}`.",
        "billed": false
      },
      {
        "code": "disk_full_within_tier",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "A storage fault on our side while the sandbox was under its {tier_disk_gib} GiB quota.",
        "fix": "Our fault, not yours: the work lost since your last snapshot of this sandbox is credited back, up to 24 hours (a sandbox under 24 hours with no snapshot is never charged). Replay: `promigence run replay {run_id} --sandbox {sandbox_id}`.",
        "billed": false
      },
      {
        "code": "node_lost",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The host running the sandbox became unreachable.",
        "fix": "Credited back: the work lost since your last snapshot of this sandbox, up to 24 hours (a sandbox under 24 hours with no snapshot is never charged). Replay: `promigence run replay {run_id}`.",
        "billed": false
      },
      {
        "code": "layer_integrity",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The environment differs from the verified snapshot at {path}.",
        "fix": "Not billed when the verified snapshot itself differs; when only this sandbox's copy changed, the time used is billed. Replay: `promigence run replay {run_id} --sandbox {sandbox_id}`.",
        "billed": false
      },
      {
        "code": "egress_unavailable",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "The sandbox's network egress check failed.",
        "fix": "Not billed when we confirm the outage on our side; otherwise the time used is billed. Replay: `promigence run replay {run_id}`.",
        "billed": false
      },
      {
        "code": "infra_timeout",
        "category": "env",
        "http": 504,
        "exit": 3,
        "message": "An internal deadline ({deadline_ms} ms) fired before your timeout.",
        "fix": "Our deadline fired before the command returned. When the cause was ours (our service restarted), the work lost since your last snapshot of this sandbox is credited back, up to 24 hours; otherwise the time used is billed. Set `timeout_ms` for long commands. Replay: `promigence run replay {run_id} --sandbox {sandbox_id}`.",
        "billed": true
      },
      {
        "code": "preempted",
        "category": "preempt",
        "http": 502,
        "exit": 3,
        "message": "The sandbox was stopped because the capacity it was running on had to be given back.",
        "fix": "Our doing, not yours: the work lost since your last snapshot of this sandbox is credited back, up to 24 hours (a sandbox under 24 hours with no snapshot is never charged). This run asked for preemptible capacity, which is priced below on-demand for exactly this reason. Replay: `promigence run replay {run_id} --sandbox {sandbox_id}`; or re-run without `preemptible` to pay the standard rate and not be interrupted.",
        "billed": false
      },
      {
        "code": "verify_did_not_cover",
        "category": "snapshot",
        "http": 422,
        "exit": 4,
        "message": "`{path}` is missing but was not under a verified path; the snapshot's verify did not cover it.",
        "fix": "Billed: the environment matched what `verify` checked. Broaden `verify` (or `setup`) so the path is produced and covered, then `promigence snapshot create ...`.",
        "billed": true
      },
      {
        "code": "grader_failed",
        "category": "grader",
        "http": 422,
        "exit": 3,
        "message": "The grade could not be computed ({kind}).",
        "fix": "Not a task failure. The time your grader ran is billed like the sandbox's own; a grade that failed on our side is not. Check that `grade.cmd` exits within `grade.timeout_ms` and that its output matches `grade.score` (exit | last_line_json | tap), then re-run.",
        "billed": true
      },
      {
        "code": "nonzero_exit",
        "category": "task",
        "http": 422,
        "exit": 4,
        "message": "Command exited {exit_code}.",
        "fix": "The environment was verified; the command failed. Inspect: `promigence exec output {exec_id}`.",
        "billed": false
      },
      {
        "code": "grade_not_passed",
        "category": "task",
        "http": 422,
        "exit": 4,
        "message": "The task completed and its grade did not pass (the grader exited {exit_code}).",
        "fix": "Your grader failed the work; the task's command succeeded.",
        "billed": false
      },
      {
        "code": "task_timeout",
        "category": "task",
        "http": 422,
        "exit": 4,
        "message": "Command exceeded timeout_ms={timeout_ms}.",
        "fix": "Raise `--timeout` (billed per second used, so a longer timeout only costs what runs) or shorten the task.",
        "billed": true
      },
      {
        "code": "oom_over_tier",
        "category": "task",
        "http": 422,
        "exit": 4,
        "message": "The process was killed for exceeding the tier's {tier_mib} MiB of memory.",
        "fix": "Rebuild the snapshot on a larger tier (`promigence snapshot create … --tier medium|large`; see `promigence agent-guide --section cost`) or reduce the task's memory.",
        "billed": false
      },
      {
        "code": "disk_over_tier",
        "category": "task",
        "http": 422,
        "exit": 4,
        "message": "The sandbox ran out of its {tier_disk_gib} GiB of disk.",
        "fix": "Pick a larger tier or write less; the disk is sized to the tier quota.",
        "billed": false
      },
      {
        "code": "shutdown_by_task",
        "category": "task",
        "http": 422,
        "exit": 4,
        "message": "The sandbox shut itself down ({kind}).",
        "fix": "Billed as the task's outcome: a command in the sandbox rebooted, powered off, halted or crashed it, or ended process 1. Keep the task from doing that; if nothing in it should have, check what the agent ran.",
        "billed": true
      },
      {
        "code": "modified_by_task",
        "category": "task",
        "http": 422,
        "exit": 4,
        "message": "`{missing}` was removed or changed inside the sandbox; the snapshot's copy is intact.",
        "fix": "Billed as the task's outcome: the sandbox started verified and something it ran deleted or changed `{path}`. Keep the task from modifying verified paths, or recreate what it needs first.",
        "billed": true
      },
      {
        "code": "cap_killed",
        "category": "cap",
        "http": 402,
        "exit": 12,
        "message": "Sandbox killed when its accrued spend reached the spend cap ({spend_cap}).",
        "fix": "The seconds it ran are billed, up to the cap. Raise `--cap` or `PATCH /sandboxes/:id` earlier.",
        "billed": true
      },
      {
        "code": "cap_exceeded",
        "category": "cap",
        "http": 409,
        "exit": 5,
        "message": "Quote {max_cost} exceeds remaining spend cap {remaining}.",
        "fix": "Raise `--cap`, lower `--count`/`--timeout`, or pass `--allow-partial` to launch what fits.",
        "billed": false
      },
      {
        "code": "aborted_by_client",
        "category": "other",
        "http": 200,
        "exit": 130,
        "message": "Sandbox killed by the client.",
        "fix": "Nothing to fix; billed for the seconds used.",
        "billed": true
      },
      {
        "code": "expired",
        "category": "other",
        "http": 200,
        "exit": 12,
        "message": "Sandbox timeout reached (counted from hand-off).",
        "fix": "Raise `--timeout` if the task needs longer.",
        "billed": false
      },
      {
        "code": "not_started",
        "category": "other",
        "http": 200,
        "exit": 12,
        "message": "Sandbox not started: outside the spend cap.",
        "fix": "Raise `--cap`; with `--allow-partial` only what fits is launched.",
        "billed": false
      },
      {
        "code": "superseded",
        "category": "other",
        "http": 200,
        "exit": 0,
        "message": "Attempt 1 superseded by a successful retry.",
        "fix": "Nothing to fix; attempt 1 is unbilled.",
        "billed": false
      },
      {
        "code": "usage",
        "category": "other",
        "http": 400,
        "exit": 2,
        "message": "{detail}.",
        "fix": "{detail}. See `promigence {command} --help`.",
        "billed": false
      },
      {
        "code": "internal",
        "category": "other",
        "http": 500,
        "exit": 1,
        "message": "Internal error.",
        "fix": "Not your fault. Re-run; if it repeats, tell support@promigence.ai the run or sandbox id and the time.",
        "billed": false
      },
      {
        "code": "auth",
        "category": "other",
        "http": 401,
        "exit": 7,
        "message": "Missing or invalid API key.",
        "fix": "Set PROMIGENCE_API_KEY or run `promigence auth login --from-env VAR`. No key yet: `promigence login` (sign in) or https://promigence.ai.",
        "billed": false
      },
      {
        "code": "forbidden",
        "category": "other",
        "http": 403,
        "exit": 7,
        "message": "{detail}.",
        "fix": "Do what the message names: sign in (`promigence login`), use a key from that org, or ask an owner.",
        "billed": false
      },
      {
        "code": "not_found",
        "category": "other",
        "http": 404,
        "exit": 8,
        "message": "{kind} `{id}` not found.",
        "fix": "Check the id; aliases resolve in your org first, then public snapshots (`promigence examples`).",
        "billed": false
      },
      {
        "code": "unreachable",
        "category": "other",
        "http": 503,
        "exit": 9,
        "message": "Cannot reach {url}.",
        "fix": "Retry in a moment. If the API answered this, the fault is ours: if it repeats, email support@promigence.ai with the sandbox or run id. If the API itself did not answer, check PROMIGENCE_API_URL and your connection.",
        "billed": false
      },
      {
        "code": "rate_limited",
        "category": "other",
        "http": 429,
        "exit": 10,
        "message": "Rate limited by {host}; retry after {retry_after_s} s.",
        "fix": "Wait `Retry-After` seconds, then retry. If the limit is an image registry's, not this API's, a `registry_secret` holding your own login for it usually raises it. Otherwise lower concurrency (see `GET /me` limits).",
        "billed": false
      },
      {
        "code": "timeout",
        "category": "other",
        "http": 504,
        "exit": 11,
        "message": "Wait of {wait_timeout} expired; nothing was killed.",
        "fix": "Run the id-based command: `{next}`.",
        "billed": false
      },
      {
        "code": "not_verified",
        "category": "other",
        "http": 409,
        "exit": 6,
        "message": "Snapshot {snapshot_id} is not verified (build {build_id}: {state}).",
        "fix": "Wait for the build: `promigence snapshot status {build_id} --wait`.",
        "billed": false
      },
      {
        "code": "pool_exhausted",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "No capacity free right now.",
        "fix": "Not billed. Nothing was free in time: start it again in a few minutes, or lower `--count` to need fewer at once.",
        "billed": false
      },
      {
        "code": "quota_exhausted",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "{region} is at capacity right now.",
        "fix": "Not billed. Retry shortly, or lower `--count`.",
        "billed": false
      },
      {
        "code": "region_exhausted",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "{region} has no free capacity right now.",
        "fix": "Not billed. Retry shortly, or lower `--count`.",
        "billed": false
      },
      {
        "code": "builder_unavailable",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "New snapshots cannot be built right now.",
        "fix": "Not billed, and nothing was stored. Nothing here can build at all, so this is not a busy queue and does not clear itself by waiting, and a smaller run does not help. Snapshots you have already built still run, so re-use one (`promigence snapshot list`). If you asked for a `cpu_class`, drop it to build on any host; otherwise retry shortly, and tell support@promigence.ai the time if it keeps happening.",
        "billed": false
      },
      {
        "code": "builder_busy",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "Snapshot builds are backed up; retry after {retry_after_s} s.",
        "fix": "Not billed, and nothing was stored. Other builds are ahead of this one: submit it again in {retry_after_s} s. Builds already accepted keep their place in the queue and finish on their own (`promigence snapshot status <build_id> --wait`).",
        "billed": false
      },
      {
        "code": "overloaded",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "The API is at capacity; retry in {retry_after_s} s.",
        "fix": "Not billed, and nothing was started. Send the same request again in {retry_after_s} s; the SDKs and the CLI do this for you.",
        "billed": false
      },
      {
        "code": "tier_unavailable",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "The {tier} tier ({vcpus} vCPU / {mem_gib} GiB) is not available here yet.",
        "fix": "Not billed. Use a smaller tier (`promigence snapshot create … --tier`; a fork runs on its snapshot's), or write to support@promigence.ai to have {tier} enabled for your account.",
        "billed": false
      },
      {
        "code": "snapshot_unavailable",
        "category": "env",
        "http": 409,
        "exit": 3,
        "message": "Snapshot {snapshot_id} is no longer available: the capacity that held it was retired before it was saved.",
        "fix": "Not billed, and nothing was started. It cannot be started again: take a new snapshot of a running sandbox (`promigence sandbox snapshot <sandbox_id>`) or build it again (`promigence snapshot create ...`), then remove this one: `promigence snapshot delete {snapshot_id}`.",
        "billed": false
      },
      {
        "code": "capacity_limit",
        "category": "env",
        "http": 409,
        "exit": 3,
        "message": "{requested} {tier} sandboxes at once is more than can run together; at most {max_at_once} at once.",
        "fix": "Not billed; nothing started. Run at most {max_at_once} at once (lower `--count`), or use a smaller tier.",
        "billed": false
      },
      {
        "code": "build_timeout",
        "category": "other",
        "http": 422,
        "exit": 4,
        "message": "The build ran past its {limit_min}-minute limit.",
        "fix": "Not billed; nothing stored. Shorten `setup` (at most 64 steps, {limit_min} minutes in all) or bake the slow part into the image.",
        "billed": false
      },
      {
        "code": "dockerfile_build_failed",
        "category": "other",
        "http": 400,
        "exit": 2,
        "message": "Your image could not be built from the Dockerfile: {detail}.",
        "fix": "Nothing was stored and nothing was billed. Fix the Dockerfile (the lines above are the end of your own build output) and run `promigence snapshot create --dockerfile PATH ...` again.",
        "billed": true
      },
      {
        "code": "image_unresolvable",
        "category": "other",
        "http": 422,
        "exit": 2,
        "message": "`{image}` could not be resolved to a digest: {detail}.",
        "fix": "Nothing was stored and nothing was billed. Check the name and tag; a private image needs `registry_secret` naming a stored secret that holds `user:password` (`promigence secrets set`). You can also pass the image already pinned as NAME@sha256:<digest>.",
        "billed": true
      },
      {
        "code": "registry_unavailable",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "`{image}` could not be resolved to a digest because its registry did not answer usably: {detail}.",
        "fix": "Not billed, and nothing was stored. Your image is not at fault: submit it again in {retry_after_s} s. Snapshots you have already built from it still run (`promigence snapshot list`).",
        "billed": false
      },
      {
        "code": "enoent",
        "category": "other",
        "http": 404,
        "exit": 8,
        "message": "`{argv0}` not found in the sandbox.",
        "fix": "Check the command name; install the program in the image or in a setup step; for a shell builtin or a pipeline, run it through a shell: `-- sh -c '...'`.",
        "billed": false
      },
      {
        "code": "trial_credits_exhausted",
        "category": "cap",
        "http": 402,
        "exit": 5,
        "message": "Trial credits left ({remaining}) do not cover this ({needed}).",
        "fix": "Add a card to keep going (owners: `promigence billing card`, or POST /v1/billing/checkout; members ask an owner). Remaining credits are used first; running sandboxes finish.",
        "billed": false
      },
      {
        "code": "credit_unclaimed",
        "category": "other",
        "http": 402,
        "exit": 5,
        "message": "This account has free credit waiting to be claimed.",
        "fix": "Claim it in your browser: `promigence credits claim` (owners; members ask an owner). Or add a card: `promigence billing card`. Nothing was started or charged.",
        "billed": false
      },
      {
        "code": "card_required",
        "category": "other",
        "http": 402,
        "exit": 5,
        "message": "A card is required for new work since {effective_at}.",
        "fix": "Add a card (owners: `promigence billing card`, or POST /v1/billing/checkout; members ask an owner). Your trial credits are kept and used first; reads and results stay available.",
        "billed": false
      },
      {
        "code": "billing_unavailable",
        "category": "other",
        "http": 503,
        "exit": 5,
        "message": "Card payments are not open yet.",
        "fix": "Nothing was charged. Your trial credits are kept and used first; for more credits, email support@promigence.ai.",
        "billed": false
      },
      {
        "code": "concurrency_limit",
        "category": "other",
        "http": 409,
        "exit": 5,
        "message": "{live} live + {requested} requested sandboxes is over your limit of {limit}.",
        "fix": "Wait for sandboxes to end or lower `--count` (`--allow-partial` covers the spend cap only); a retry of the same request fails the same way. Trial orgs get {trial_limit}; to raise it, email support@promigence.ai.",
        "billed": false
      },
      {
        "code": "egress_cap_reached",
        "category": "other",
        "http": 403,
        "exit": 10,
        "message": "Monthly data-out cap reached: {used_gb} of {cap_gb} GB.",
        "fix": "Use `--network none` (still allowed) or wait for the 1st (UTC). On the trial, add a card to lift the cap (owners: `promigence billing card`); with a card, choose a plan that includes more data out, or email support@promigence.ai.",
        "billed": false
      },
      {
        "code": "project_cap_reached",
        "category": "cap",
        "http": 403,
        "exit": 5,
        "message": "Project {project} has {remaining} of its {limit} monthly cap left; this needs {needed}.",
        "fix": "Ask for less (`--count`, `--cap`, a shorter extension), wait for the 1st (UTC), or have an owner raise it: `promigence project cap {project} <usd>`.",
        "billed": false
      },
      {
        "code": "spend_limit_reached",
        "category": "cap",
        "http": 402,
        "exit": 5,
        "message": "Today's spend limit {limit} has {remaining} left; this needs {needed}.",
        "fix": "Running sandboxes finish. The limit resets at 00:00 UTC and grows with each paid invoice; ask for less, or email support@promigence.ai. After a failed payment, new work waits until it is paid (owners: `promigence billing portal`).",
        "billed": false
      },
      {
        "code": "tier_over_plan",
        "category": "other",
        "http": 403,
        "exit": 2,
        "message": "The {tier} tier ({vcpus} vCPU) is over the {limit} vCPU per-sandbox limit of your {plan} plan.",
        "fix": "Use a tier of at most {limit} vCPU (`promigence snapshot create … --tier {max_tier}` is the largest; a fork runs on its snapshot's), or move to a plan that allows it: `promigence billing portal`.",
        "billed": false
      },
      {
        "code": "network_host_refused",
        "category": "other",
        "http": 403,
        "exit": 9,
        "message": "{host} is not on this sandbox's allowed list, so the connection was refused.",
        "fix": "Add it when you start the sandbox — `--allow {host}` — or drop `--allow` to let the sandbox reach anything. `promigence sandbox network <id>` lists everything that has been refused.",
        "billed": false
      },
      {
        "code": "network_policy_unsupported",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "This sandbox asked to reach only {allow}, and that could not be applied where it was placed.",
        "fix": "Nothing ran and nothing was billed: the sandbox was discarded rather than started without the restriction you asked for. Re-run; if it repeats, tell support@promigence.ai the run id.",
        "billed": true
      },
      {
        "code": "secrets_in_snapshot",
        "category": "other",
        "http": 409,
        "exit": 2,
        "message": "Sandbox {sandbox_id} was given a secret's value, so a snapshot of it can contain that value.",
        "fix": "To take it anyway, pass `force: true` (`promigence sandbox snapshot {sandbox_id} --force`): that snapshot, and every sandbox started from it, can then contain the secret. Otherwise snapshot a sandbox that was never given a secret, and name the secret on the runs you start from it.",
        "billed": false
      },
      {
        "code": "secrets_unavailable",
        "category": "env",
        "http": 503,
        "exit": 3,
        "message": "Secrets cannot be used right now.",
        "fix": "Not billed, and nothing that names a secret was started. Runs, commands and terminals that name no secret are unaffected, and stored secrets can still be listed and deleted. Retry shortly; if it keeps happening, tell support@promigence.ai the time.",
        "billed": false
      },
      {
        "code": "secret_binding_unsupported",
        "category": "env",
        "http": 502,
        "exit": 3,
        "message": "A secret bound to a host could not be set up for this sandbox.",
        "fix": "Nothing ran, nothing was billed, and the value never entered the sandbox. Re-run; if it repeats, tell support@promigence.ai the run id.",
        "billed": true
      },
      {
        "code": "idempotency_key_reused",
        "category": "other",
        "http": 409,
        "exit": 2,
        "message": "This Idempotency-Key was used for a different request.",
        "fix": "Nothing was started. Use a new key for a new request; send the original request again to get its original answer.",
        "billed": false
      },
      {
        "code": "idempotency_key_in_use",
        "category": "env",
        "http": 409,
        "exit": 3,
        "message": "A request with this Idempotency-Key is still running.",
        "fix": "Not billed; nothing new was started. Send the same request again in {retry_after_s} s for the first one's answer; the SDKs do this for you.",
        "billed": false
      },
      {
        "code": "repo_credentials_not_supported",
        "category": "other",
        "http": 400,
        "exit": 2,
        "message": "Credentials in repository URLs are not accepted ({field}).",
        "fix": "Nothing was built or billed. Private repositories are not supported yet: name a public repository by its plain https:// URL, with no user name, password, token, query string or fragment in it. For private code, build the image elsewhere, push it to a registry and create the snapshot from that image (`promigence snapshot create --image REF`).",
        "billed": true
      },
      {
        "code": "account_exists",
        "category": "other",
        "http": 409,
        "exit": 7,
        "message": "This email address has an account that signs in with {sign_in_with}.",
        "fix": "Nothing was created. Sign in with {sign_in_with} instead: `{sign_in_command}`. If the browser signs you in with the method you just used, open the sign-in link in a private window. If you did not create that account, write to support@promigence.ai.",
        "billed": false
      },
      {
        "code": "invite_invalid",
        "category": "other",
        "http": 403,
        "exit": 7,
        "message": "This invite code is not valid.",
        "fix": "Nothing was created. Check the code and try `promigence signup` again, or ask the person who invited you for a new code.",
        "billed": false
      },
      {
        "code": "invite_required",
        "category": "other",
        "http": 403,
        "exit": 7,
        "message": "New accounts need an invite code right now.",
        "fix": "Nothing was created. Run `promigence signup` and enter your invite code when asked. If you already have an account, sign in with the method you used before (`promigence login`).",
        "billed": false
      },
      {
        "code": "key_expired",
        "category": "other",
        "http": 401,
        "exit": 7,
        "message": "This API key expired at {expired_at}.",
        "fix": "Create a new key (`promigence keys create`, or sign in again with `promigence login`) and replace this one wherever it is used.",
        "billed": false
      }
    ]
  },
  "faq": [
    {
      "question": "What is Promigence?",
      "answer": "Promigence is a sandbox platform for AI agents: production-grade, fully isolated sandboxes that start in milliseconds, stay fast at a thousand at once, and bill by the second. It runs coding agents, background agents, evals and RL environments, each in its own sandbox built from your repository.",
      "category": "Product"
    },
    {
      "question": "What is an environment runtime?",
      "answer": "An environment runtime treats the execution environment as the product: it proves the environment works before anything runs in it, reproduces it exactly from a hash, and forks it many times over. A sandbox provider gives you a box that starts; an environment runtime gives you an environment that is known good.",
      "category": "Product"
    },
    {
      "question": "What problem does Promigence solve?",
      "answer": "Promigence solves silently broken environments. In a thousand-episode run some environments fail to install or come back cold, and that shows up as the agent failing the task, which corrupts the eval number and poisons the reward signal in RL. Promigence verifies every environment first and reports environment failures separately from task failures.",
      "category": "Product"
    },
    {
      "question": "Who is Promigence for?",
      "answer": "Promigence is for teams that run AI agents: agent companies building products on them, eval and platform engineers, benchmark producers and RL environment vendors. Any agent work fits, from one interactive sandbox to thousands of episodes at once.",
      "category": "Product"
    },
    {
      "question": "Is Promigence an eval platform?",
      "answer": "No. Promigence is the execution plane eval platforms run on, it has no datasets, scorers, judges or experiment tracking, which belong to your eval tools. It provides the verified environment the episode runs inside, and plugs in as a backend for those harnesses.",
      "category": "Product"
    },
    {
      "question": "What is a validity report?",
      "answer": "A validity report is what Promigence returns after every run: how many environments were verified, which failed, and whether each failure was the environment's or the task's. Most teams running evals today cannot produce that number, which means they cannot say how much of their result is real.",
      "category": "Product"
    },
    {
      "question": "What is an episode in Promigence?",
      "answer": "An episode is one environment's life in Promigence: fork, execute, terminate: 15 minutes by default, up to an hour in the private beta. Usage is metered per second, like the rest of the market, but the episode is the unit a quote and a spend cap are written against, so the maximum cost of a run is a multiplication you can do before you start it.",
      "category": "Product"
    },
    {
      "question": "Does Promigence support long-running or interactive sandboxes?",
      "answer": "Yes. A sandbox pauses when it goes idle, wakes on the next request, and bills only while it is awake.",
      "category": "Product"
    },
    {
      "question": "How is Promigence different from other sandbox providers?",
      "answer": "Promigence is built around four things together: sandboxes that are ready in milliseconds and stay fast at a thousand at once, environments verified before an agent runs in them, a report that labels every failed run as the task's, the environment's or Promigence's, and a bill that is quoted and capped before the run starts. Runs that fail because of Promigence are not billed when our side can show the failure was ours.",
      "category": "Comparisons"
    },
    {
      "question": "Why not just run Docker on my own cloud machines?",
      "answer": "Because a do-it-yourself setup cannot tell you how many of your environments were broken on the last run. What Promigence adds is verification, reproducibility, burst scheduling and nobody on call.",
      "category": "Comparisons"
    },
    {
      "question": "How much does Promigence cost?",
      "answer": "Promigence meters per second at $0.0504 per vCPU-hour plus $0.0162 per GiB-hour, the market's standard list rate. That works out at $0.17 an hour for a small sandbox (2 vCPU, 4 GB), $0.46 for medium (4 vCPU, 16 GB) and $0.92 for large (8 vCPU, 32 GB). New accounts get $50 of free credit for 30 days: $10 straight away with no card, and $40 more once a card is added (card payments open after the private beta).",
      "category": "Pricing"
    },
    {
      "question": "Does Promigence bill per second or per run?",
      "answer": "Per second, at the market's standard list rate, because that is what the market meters and a price nobody can compare against is worth very little. The episode survives as the unit you are quoted in: `promigence run quote` returns the maximum a run can cost before it starts, and `--cap` refuses one that would go past your ceiling.",
      "category": "Pricing"
    },
    {
      "question": "Can I know what a run will cost before it starts?",
      "answer": "Yes. `promigence run quote` returns the exact maximum cost before any environment starts, and `--cap` refuses a run that would exceed your ceiling rather than stopping halfway through. Paused time is not invoiced, and nothing accrues before an environment is handed to you.",
      "category": "Pricing"
    },
    {
      "question": "Is there a free trial?",
      "answer": "Yes: $50 of free credit for 30 days, $10 straight away with no card and $40 more once you add one (card payments open after the private beta), with 20 concurrent sandboxes and sessions up to an hour. During the private beta, signing up needs an invite code. Separately, any team can send their environments in for 1,000 verified episodes, a validity report and an exact bill quote, free and once.",
      "category": "Pricing"
    },
    {
      "question": "How does Promigence work?",
      "answer": "Promigence runs one primitive: verify, snapshot, fork, exec, report. You declare a container image, setup steps (a clone of your repository at a pinned commit among them) and a verify command. The snapshot is stored only if verification passes. You then copy it N times into warm environments and get back a validity report and a bill that never exceeds the quote you saw first.",
      "category": "Technical"
    },
    {
      "question": "How are Promigence environments isolated?",
      "answer": "Each environment is fully isolated from every other, and nothing is shared with another customer. We test that boundary by attacking it rather than asserting it, and runs can start with no network at all.",
      "category": "Technical"
    },
    {
      "question": "How does Promigence make a fork start warm?",
      "answer": "Promigence copies an environment that has already finished installing and building, instead of booting and installing it again. A copy takes 39 ms, and a hundred at once still land at 122 ms.",
      "category": "Technical"
    },
    {
      "question": "What does reproducible mean in Promigence?",
      "answer": "The same snapshot hash returns a bit-identical environment on any later date, so an eval you ran in October can be re-run in March and the comparison means something. That is stronger than a recipe that re-resolves package versions underneath you on every build.",
      "category": "Technical"
    },
    {
      "question": "Does Promigence work with existing eval harnesses?",
      "answer": "Yes. Adapters for common eval harnesses are in pre-release, and the TypeScript SDK exposes a compatibility `Sandbox` class with the familiar sandbox calls, so existing call sites run unchanged.",
      "category": "Technical"
    },
    {
      "question": "How are secrets handled?",
      "answer": "You store a secret once and name it on the runs or commands that need it (`--secret NAME`). It is encrypted at rest, given only to the commands that name it, and removed from logs and outputs. It is never written into a snapshot you build, and a snapshot of a sandbox that was given a secret is refused unless you force it.",
      "category": "Technical"
    },
    {
      "question": "Can Promigence run inside my own cloud account?",
      "answer": "Not as a self-serve product today. If your data cannot leave your boundary, talk to us about running it in your own cloud account.",
      "category": "Technical"
    },
    {
      "question": "What happens when an environment fails mid-run?",
      "answer": "Promigence records the failure as the environment's in the validity report. A sandbox that fails before hand-over is retried once automatically; one that fails mid-run can be re-run with `promigence run replay`, as a new sandbox billed under the run's cap. A run with a 3% environment failure rate reports 3%, instead of quietly reporting a 3% worse agent.",
      "category": "Reliability"
    },
    {
      "question": "How do I know the reliability numbers are real?",
      "answer": "Every figure on the benchmarks page states its date, its sample size and the conditions it was measured under, and the free validity report runs your own workload so you can check the numbers yourself.",
      "category": "Reliability"
    },
    {
      "question": "How do I get access to Promigence?",
      "answer": "Promigence is in a private beta: signing up needs an invite code, and support@promigence.ai is where to ask for one. New accounts get $50 of free credit: $10 straight away with no card, and $40 more once a card is added (card payments open after the private beta). Teams who want a number on their own workload first can send their environments in for a free 1,000-episode run and a validity report.",
      "category": "Company"
    },
    {
      "question": "Is Promigence tied to a particular model provider or lab?",
      "answer": "No. Promigence is not owned by a lab or a hyperscaler and runs any vendor's agent. Neutrality is a requirement rather than a stance: a cross-lab evaluation cannot run inside one lab's harness.",
      "category": "Company"
    }
  ]
}
