Hoplite
Also known as: Hoplite, hoplite.sh, Carbon Copy Markets
Cloud coding agents in isolated sandboxes that import your local Claude Code, Codex or OpenCode setup, run in parallel, start from Slack, Linear, Sentry or a schedule, and hand back a pull request to review.
Hoplite runs coding agents in isolated cloud sandboxes and makes the pull request the interface. A team connects a GitHub repository and imports its local setup from Claude Code, Codex or OpenCode, including session history, skills, MCP servers and the command line tools a project needs. Each thread then gets its own machine with dependencies installed, tests running and the app booted on a live preview URL.
Threads run in parallel, so a whole backlog can be fanned out at once and reviewed as each one finishes. Work starts by hand in the web app or the Mac desktop app, from a Slack mention, from iMessage or from a Linear issue.
Automations start work without anyone asking. They fire on a schedule or a cron expression, on GitHub pull request events and failed CI checks, on new or regressed Sentry issues, on Linear and Slack events, when another thread finishes, or on a request to a webhook URL. Four templates ship ready to switch on: a daily digest, issue triage, dependency patrol and Sentry alert triage. A separate PR Auto-fix loop watches checks and review threads and keeps pushing fixes to the same branch until everything is green.
Every thread is shared with the workspace, so teammates can watch a run, steer it and approve sensitive steps. Shell commands, edits to protected files such as credentials, environment and CI configuration, and disruptive sandbox operations pause for approval. Agents cannot mark their own preview checklist as reviewed. An activity timeline records each operation the agent called and the result it received.
Workspace roles run from owner and admin through member and viewer, and changing an MCP server needs a fresh owner or admin check. MCP credentials are encrypted individually with AWS KMS, and repository access is brokered through short lived, repository scoped GitHub installation tokens. SOC 2 is stated as in progress, with no report published yet.
Customers set the model per project or per automation from a list that includes Luna, Terra, Sonnet 5, GLM 5.3 and DeepSeek V4 Flash, and can bring their own keys. A public API with an OpenAPI specification, an OAuth protected MCP server and an npm command line client let other systems and agents start and inspect threads.
Vendor details
Canonical URL
https://hoplite.sh
Category
Coding agent
Subcategory
Cloud coding agent platform with parallel sandboxes and a pull request workflow
Funding status
Y Combinator, Summer 2026 batch; no priced round disclosed
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
GitHub for repositories, pull requests, checks and reviews through a GitHub App; Linear for issues; Slack and iMessage for starting and steering work; Sentry for error triage and status updates; Sazabi; any remote MCP server added per project. Inbound webhooks start automations, and a public API, MCP server and npm command line client let outside systems drive the platform.
In practice
A new Sentry regression lands overnight. An automation opens a thread for it, the agent runs a root cause pass, writes a failing test, fixes the bug and opens a pull request, and updates the Sentry status for the morning review.
A founder has twelve small backlog tickets. Each goes to its own Hoplite thread in parallel, and every agent checks its change against a live preview of the app before handing back a pull request.
An engineer is midway through a Claude Code session when it is time to leave. The command line client hands the conversation to a cloud thread that keeps working, and a teammate picks it up in the shared workspace.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
11.5 / 14 capabilities · 82%
| Integrations & Tool Calling | Full |
|---|---|
|
Agents take authenticated action in outside systems: native GitHub tools open, update, review and merge pull requests through repository scoped installation tokens, Sentry comments and status changes run on the integration's write capability with approval, Linear and Slack start and steer work, and any remote MCP server can be added per project with its own credentials. Hoplite tools and permissions docs, automations page and llms.txt, 1 Oct 2026. Sourcehoplite.sh/docs/agent/toolsread 2026-10-01 |
|
| Workflow Orchestration | Full |
|
Multi agent execution is documented: a parent run delegates through subagent_control to child agents that share its workspace or get their own, threads run in parallel in separate sandboxes, and automations chain when one thread finishing starts another, capped at 16 hops with repeat events suppressed. No branching or retry model inside a run is documented beyond failed starts retried for 30 minutes, hence medium. Hoplite tools docs and automations page, 1 Oct 2026. Sourcehoplite.sh/docs/agent/toolsread 2026-10-01 |
|
| Knowledge Grounding & RAG | Partial |
|
Context is assembled per run: each thread works from a checkout of the connected GitHub repository, repository instructions and skills are read from disk, and agents can search thread history within the project. No persistent index, graph or embeddings layer over the codebase or the customer's knowledge is documented. Missing: a maintained retrieval structure. Hoplite docs index, tools docs and llms.txt, 1 Oct 2026. Sourcehoplite.sh/docsread 2026-10-01 |
|
| Human Oversight & Guardrails | Full |
|
Vendor shipped approval surface: sensitive tool calls pause in the shared thread for approve or deny, with expiry and resume, covering shell commands, protected file edits (credentials, environment files, CI, infrastructure, paths outside the repository), disruptive sandbox operations, Sentry writes and the agent's own project settings, and agents cannot mark their own preview checklist as reviewed. Confidence held at medium because four first party statements disagree on scope: the security doc says every file write waits, the tools doc says routine edits proceed, the homepage says pull request actions can be gated, and a 21 Sep blog says source control calls including merge need no separate prompt. Hoplite security and tools docs, homepage and blog, 1 Oct 2026. Sourcehoplite.sh/docs/workspace/securityread 2026-10-01 |
|
| Security, Identity & Governance | Partial |
|
Access half answered: workspace roles of owner, admin, member and viewer, a fresh owner or admin check on any MCP server change, scoped API keys, and MCP credentials encrypted individually with AWS KMS with decryption recorded in CloudTrail. No SSO, SAML or SCIM is documented on the pages read. Compliance half known absent: the homepage states SOC 2 in progress, so under Q140 the hedge cannot carry the attestation half and the controls alone route is closed. Contradiction recorded: the security doc says no GitHub credential reaches the sandbox shell, the tools doc says a scoped token sits in repository local CLI configuration inside it. Moves to Full on a published SOC 2 report. Hoplite homepage, security and tools docs, automations FAQ, 1 Oct 2026. Sourcehoplite.sh/docs/workspace/securityread 2026-10-01 |
|
| Observability & Auditability | Full |
|
Runtime audit of agent actions: the activity timeline shows each operation the agent actually called and the result it received, every thread streams live and stays visible to the workspace, automations keep a run history with each run's thread, status and duration, and transcript export and organization wide thread history are documented. Retention is not stated on the pages read, hence medium. Hoplite tools docs, security docs and automations page, 1 Oct 2026. Sourcehoplite.sh/docs/agent/toolsread 2026-10-01 |
|
| Memory & State Persistence | Partial |
|
A cloud thread owns its workspace across runs and follow up messages resume it, a sandbox keeping its own state (Q175, Partial); local Claude Code, Codex or OpenCode session history can be imported, and agents can read past threads in the project. Repository instructions and skills are instructions the product applies (Q102). No memory layer with a stated scope and lifetime is documented. Hoplite docs index, security docs and llms.txt, 1 Oct 2026. Sourcehoplite.sh/docsread 2026-10-01 |
|
| Deployment & Data Residency | Partial |
|
Managed cloud sandboxes with no documented region choice, VPC or self hosted option. The Partial rests on the Enterprise tier's one line offer of private networking and retention with custom pricing shaped around the customer's deployment (Q41, a claim with no named mechanism). Near miss: the Mac desktop app runs local threads against a folder on the user's machine through local providers, which is the customer's own agent rather than Hoplite's runtime. Hoplite pricing page and docs index, 1 Oct 2026. Sourcehoplite.sh/pricingread 2026-10-01 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Four automation templates switch on in one click and each does its own job: daily digest, issue triage, dependency patrol, and Sentry alert triage, which runs a root cause pass, fixes the issue, opens a pull request and updates the Sentry status. Built in hosted skills are also documented. Hoplite automations page and tools docs, 1 Oct 2026. Sourcehoplite.sh/product/automationsread 2026-10-01 |
|
| Triggers & Channel Coverage | Full |
|
Schedules by preset or cron in a chosen timezone, plus events: GitHub pull request changes and failed CI checks, new or regressed Sentry issues, Linear issue changes, Slack messages or reactions, a finished Hoplite thread, and a per automation webhook URL, with filters on event data; threads also start from Slack mentions and iMessage. Hoplite automations page, 1 Oct 2026. Sourcehoplite.sh/product/automationsread 2026-10-01 |
|
| Model Flexibility & Routing | Full |
|
Customer controls model choice: a project default plus a per automation model, chosen from Luna, Terra, Sonnet 5, GLM 5.3 and Flash, and DeepSeek V4 Flash on the published plans, with bring your own keys stated on the homepage. Hoplite pricing page, automations page and homepage, 1 Oct 2026. Sourcehoplite.sh/product/automationsread 2026-10-01 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A documented public API for the vendor's own platform with an OpenAPI specification, scoped API keys sent as X-Api-Key or Bearer, events and webhooks for building a budgeted task pipeline, an OAuth protected streamable HTTP MCP server at api.hoplite.sh/mcp with a discovery manifest, and the @usehoplite/cli npm client. Hoplite llms.txt and docs index, 1 Oct 2026. Sourcehoplite.sh/llms.txtread 2026-10-01 |
|
| Testing, Debugging & Optimization | Partial |
|
The agent runs the project's own test suite, checks its change against a managed preview and can record video of new features, and the PR Auto-fix loop iterates until CI checks pass, but those are gates the customer already owns. No evaluation harness, scored test cases or optimization loop for the agent itself is documented; a blog post on evaluating an agent over 30 backlog tickets is a buyer study design, not a product surface. Hoplite homepage, llms.txt and blog, 1 Oct 2026. Sourcehoplite.sh/llms.txtread 2026-10-01 |
|
| Browser & Computer Use | Full |
|
Browser automation is a documented agent capability run through the sandbox shell, and browser actions are listed among the operations that proceed without approval; the agent drives a browser against a managed preview of the running app to verify its own change, inside a sandbox the vendor operates. The browser engine is not named, hence medium. Hoplite tools and security docs and blog, 1 Oct 2026. Sourcehoplite.sh/blog/verify-agent-work-with-tests-and-a-browserread 2026-10-01 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Unable to verify against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
$99/seat/mo ($82.50 yearly) · Free plan
seats, with a monthly usage allowance per seat consumed by model and sandbox use; optional spend limit per automation
Included quota
Free: one user, 5 concurrent 2 CPU and 8 GB cloud sessions, 2 projects, and 2x usage on OpenAI and Anthropic models. Pro: a monthly usage allowance per seat, not quantified on the pricing page, plus team seats, shared workspaces and bigger sandboxes.
What is public
Three tiers on 1 Oct 2026: Free at $0 with a card required (one user, 5 concurrent 2 CPU and 8 GB sessions, 2 projects, models Luna, Terra, Sonnet 5, GLM 5.3 and Flash, and DeepSeek V4 Flash); Pro at $99 per seat per month or $82.50 billed yearly (17 percent saving) with a per seat usage allowance, team seats and higher limits; Enterprise custom and annual.
Billing mechanics
Per seat subscription, monthly or yearly, with included usage per seat. Automations can carry their own spend limit, and the Slack and iMessage assistant's own replies are paid by Hoplite under a daily fair use limit while the coding threads it starts use workspace credits.
Cost watchouts
The Pro allowance is the real unit of cost and it is not quantified. The Free plan's 2x usage on OpenAI and Anthropic models has no stated baseline. Bring your own keys is stated on the homepage, which would move inference cost to the customer's provider bill. Custom security, private networking, contractual SLAs and architecture review sit in the annual Enterprise tier.
Variable cost rationale
The seat price is fixed, but agent work draws down a per seat usage allowance whose size is not published and no overage rate is stated, so a heavy workload either stops at the allowance or changes the bill on terms a buyer cannot model from the page. Per automation spend limits and workspace caps bound the risk without pricing it.
Additional watchouts
Cost cannot be modeled past the seat price because the allowance and overage are unpublished. The Free plan requires a card.
Overage / add-ons
Not published on the pricing page. The documentation index names credit holds and spending caps, and automations back off for an hour when the workspace is out of credits, so the observed behavior is that work stops rather than that an overage rate applies.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free solo plan, card required and nothing charged; a 14 day Pro trial is offered on the automations page
Lowest paid plan
Pro at $99 per seat per month ($82.50 per seat per month billed yearly)
Commercial notes
Self serve signup on Free and Pro; Enterprise is booked by email to sales. Plans can be switched or cancelled at any time per the pricing page description.
Key ambiguities
The page calls the pricing simple and transparent, with no mental maths, yet the included usage allowance per Pro seat is not stated and neither is what happens past it. It is also unclear whether bring your own keys usage counts against the allowance.
Missing data
Pro allowance size, overage rate, the baseline behind 2x usage, Enterprise floor, and whether bring your own keys usage is metered.
Related vendors
- Cognition — Maker of Devin, an autonomous AI software engineer
- 10Web — Agentic website platform whose specialized AI agents build, host,…
- Aider — Open source, model agnostic terminal coding agent that edits your…
- Anthropic Claude Code — Anthropic's agentic coding system across terminal, desktop, IDE, web…
- AppFactor — Agentic platform that runs persistent agents across an enterprise…
- Augment Code — AI coding assistant evolving into an AI-native engineering platform