You click an app. About a minute later you have your own copy of it running at a private address, signed in, with a fictional company already inside it. Fifteen minutes later the machine is destroyed.
Every demo boots a fresh virtual machine with its own kernel. Not a container on a shared host, and not a recording. It runs the project's own published image, pinned to an exact version, so what you click is what you would get if you installed it yourself.
Nobody else is in there. When your time is up the whole machine goes, along with anything you typed.
This is the part that makes a demo worth anything. An RSS reader with no feeds, an uptime monitor with nothing to monitor, a mail client with an empty inbox — you learn nothing from those. So we run the whole surrounding world inside your session, stocked with the same invented company throughout. Read about that company →
Real An actual implementation. If it works here it works anywhere. Stand-in Shaped like the vendor, but not the vendor.
A stand-in is not proof. If an app talks to Stripe here, that tells you the app tried, not that it works against Stripe. So every demo writes a record of every hostname the software reached for, captured outside the machine where the software cannot edit it.
The record is yours, outlives the demo, and marks which answers came from a stand-in. Only your account can read what your demos did — but every run feeds a shared count, so a record also tells you how many other people's demos reached the same hostname, and whether yours is the first that ever did.
Every run you have ever started is kept under History, together with one fold of everywhere your demos have been.
The stand-in is the default, and it is the version a person actually verified before the app was listed. It is the recommended path, not the cheap one.
But a stand-in only proves the app can call the endpoint and read the reply. Where a project's recipe allows it, you can supply your own credential for a single run and watch it work against the real service instead.
Some things are never yours to supply. The browser a demo drives is always ours, inside the session: handing untrusted software a real credential is the thing the boundary exists to prevent.
A build passing only proves a process started. Before an app appears in the catalogue, a person launches it here, signs in using only what the page showed them, and reaches a screen that does something. A login form, an installer or a health check does not count. When that fails, the version stays hidden and the recipe gets fixed.