Jio works well as a disposable or retained workspace for terminal-based coding agents. The current CLI has a first-party shortcut for Codex; other agents can use the same shell and lifecycle commands.
Run Codex in Jio
Install and log in to Jio, then create a VM:
jio createCopy your local Codex login into the current VM and open Codex in /workspace:
jio yolo codexTo choose another VM, pass its ID:
jio yolo codex <session-id>Full VM access
jio yolo codex disables Codex approvals and its application sandbox. Isolation
comes from the microVM and its trusted host operator. Review the repository and
credentials you place in that VM.
Use jio login codex [session-id] when you only want to transfer the login and
will start Codex yourself.
Use another shell agent
Connect to a VM and install the agent through its supported installation path:
jio connect <session-id>Keep the agent's repository, configuration, and credentials inside the VM. Do not put API keys in reusable templates or commit them to the project.
Give the agent a lifecycle rule
Add a short instruction to the repository file your agent already reads:
Use this Jio VM as the isolated workspace.
Keep project files under /workspace.
Do not print or commit credentials.
Before destructive or external actions, follow the project's approval rules.MicroVM isolation does not replace least-privilege credentials or application-level approvals.
End the session
Exit the agent, then choose the lifecycle that matches your endpoint:
jio stop <session-id> # retained endpoints only
jio destroy <session-id> # permanent cleanupRead Agents for the generic onboarding contract and Security & Privacy before transferring credentials.