AI writes the code. Reminix makes it safe for everyone to run.
Today, only the person who wrote a script can run it. Publish it to Reminix and anyone on your team can, from a form, through the API or as an agent's tool. Who may run it, and with which keys, are settings, not code.
- Each run on a fresh, isolated machine
- Keys added on the way out, never in the code
- Python, shell or Node, as it is
$ cat reminix.json
{
"slug": "refund-customer",
"command": "python refund.py {paymentId}",
"hosts": ["api.stripe.com"]
}
$ reminix scripts publish --publish
Published refund-customer version 2.Refund customer
Refunds a card payment in full.
pi_3QK8hT2eZvKYlo2Crefund-customer
- Support team may run it
- Stripe key: api.stripe.com only
- Approval: when an agent runs it
A script is a command you already run
Python, shell or Node, as it is. Say how it runs, as in python refund.py {paymentId}, and publish it with reminix scripts publish. The Stripe key lives in Reminix, which attaches it only to requests to the host you allow.
import sys, urllib.parse, urllib.request
payment = sys.argv[1]
print(f"refunding {payment}", file=sys.stderr)
# No key here: Reminix adds it to
# requests to api.stripe.com.
res = urllib.request.urlopen(
"https://api.stripe.com/v1/refunds",
urllib.parse.urlencode({"payment_intent": payment}).encode(),
)
print(res.read().decode())One publish, every way to run it
The inputs you describe become the form, the API's request and the agent's tool, so every way of running it checks the same things.
refund-customer
- Input: paymentId
- People on your teamA form in the app, made from the inputs
- Your softwarereminix.run("refund-customer", inputs)
- Your terminalreminix scripts run refund-customer
- AI agentsA tool over MCP: refund_customer
- A timetableA schedule, such as weekdays at 9:00
- Something that happenedA trigger, such as another run failing
The parts that are easy to get wrong
Sharing a script is easy. Sharing it safely is the hard part, and it's what Reminix does for you.
An API key in the code
You save a key once, and Reminix never shows it again. Reminix attaches each one only to the hosts you allow, and the code never holds it.
Code that calls somewhere unexpected
A script has no network until it lists its hosts, and every request it makes is in the run's log.
An agent running the wrong thing
Set a script so agents' runs wait for an owner or admin. On Business, every run can wait for approval.
A change that breaks it
Every change is a new version, and nothing goes live until someone publishes it. Rolling back is publishing the version before.
Who can run what
Share a script with everyone, or only with certain teams. Others don't see it at all, not even through the API.
Where Reminix fits
Most teams run shared scripts in one of these today. Each covers part of the job. Reminix runs the script you already have, keeps its keys out of the code, and lets the whole team run it.
| If you use | The gap | With Reminix |
|---|---|---|
| Your laptop or a shared server | Only you can run it, and the keys sit in files the script reads. | Anyone you allow can run it, and the script never sees the keys. |
| GitHub Actions, run by hand | Manual runs need write access to the repository, and the job can read its secrets. | A form for people without repository access. Reminix adds keys only to requests to the hosts you allow. |
| Windmill | Python scripts are rewritten around a main() function, and a script can read the secrets it uses. | Your command runs as it is, such as python refund.py {paymentId}, and never sees the keys. |
| Retool Workflows | You rebuild the logic as workflow blocks. | You publish the script you already have. |
| Modal or Val Town | They run your code, and secrets are environment variables your code reads. | Who may run it, which runs need approval, and a record of every run, with keys kept out of the code. |
Your coding agent can do the porting
Connect Claude Code or Codex to Reminix's MCP server and paste a prompt like this one. It writes the script, tests a draft, and publishes only when you say so.
Publish scripts/refund.py to Reminix. Search the team's scripts first in case one exists. Describe its inputs, write a short README, keep every secret out of the code and declare only the hosts it calls. Upload it as a draft, test-run it, show me the result, and ask me before publishing.Start with the free plan
Free for up to 3 authors; Team is $20 per author a month. People who only run scripts are included. No card needed.
We read every message. Compare the plans
