How Reminix works
Where code runs
Section titled “Where code runs”Each version of a script runs in its own isolated sandbox. A run sees only its inputs: not other scripts, not your workspace’s data, not Reminix itself. When you publish, Reminix bundles the entry file and everything it imports (at most 5 MB), so a run never installs anything.
A run has up to 30 seconds. On Team and Business, a script can ask for longer, up to the plan’s limit (10 or 15 minutes); such a long run answers at once, shows its progress, and can be cancelled.
What code can reach
Section titled “What code can reach”A script has no network access until its version lists the hosts it may call. Then it can reach only those, over HTTPS, at most 50 requests a run. Reminix writes every request to the run’s log. Anything else fails with “Host not allowed”.
Secrets
Section titled “Secrets”You save an API key once. Reminix encrypts it with a key for your workspace and never shows it again. Each secret lists the hosts it may be sent to. When a
script’s request goes to one of those hosts, Reminix adds the secret
(as a header such as Authorization: Bearer …) on the way out. The code
doesn’t hold the value, so it can’t log it or send it anywhere else. See
Secrets.
How changes go live
Section titled “How changes go live”Uploading code makes a draft version. Nothing changes for your team until a version is published, by the script’s owner or a workspace owner or admin. An AI agent’s publish always waits for a person, and a workspace can require a second person for every publish. Rolling back is publishing an earlier version. A draft can be test-run before anyone publishes it.
Who can do what
Section titled “Who can do what”- Who sees and runs a script: everyone in the workspace, or only chosen teams. Others don’t see it at all, in the app, the API or as an agent’s tool.
- Which runs wait for approval: none, those started by AI agents, or every run (Business). An owner or admin approves or denies; Reminix cancels a run that nobody decides within a day.
- Who manages secrets: workspace owners and admins. Members see their names and hosts, never their values. Agents can’t save or change them.
These are settings on the script, never part of its code, so publishing new code can’t loosen them. See Governance.
Every run on record
Section titled “Every run on record”For each run, Reminix records its inputs, the version it used, and who started it from where: the app, the API, the command line, an agent, a schedule or a trigger. It also records how the run ended, its output or error, and its log. Reminix keeps logs for your plan’s period (7, 30 or 90 days). Changes to access, policies, secrets and publishing are in the workspace’s audit log.
Retries
Section titled “Retries”Reminix marks an interrupted run failed, and never retries it automatically, because a retry could repeat what it did, such as sending an email twice. Starting a run is safe to retry with an idempotency key.