If it runs in a browser tab, it belongs here.
Not just web pages. A demo is one self-contained file that runs in the visitor’s own browser — which is exactly why it is safe to run a stranger’s code, free to serve to everyone, and open with no gate. Four runtimes fit inside that one rule, and most people are surprised how much that covers.
JavaScript
runs · source-visible · can earn ✓Canvas, WebGL, WebAudio, the DOM — anything the browser can already do. Games, tools, visualisations, generative art.
Real Python
runs · source-visible · can earn ✓CPython compiled to WebAssembly. numpy, pandas, and much of scikit-learn run in the tab — the same engine as Jupyter-in-the-browser. Simulations, data analysis, notebooks.
WebAssembly
runs · source-visible · can earn ✓Rust, Go, C, C++ or Zig compiled to WASM. Ship the compiled module inside your file and it runs at near-native speed.
AI apps (your key)
runs · source-visible · can earn ✓Call Claude or another model straight from the demo using the visitor’s own API key — nothing is stored, the key stays in their browser. Chatbots, agents, LLM tools.
“But my project needs a server”
Plenty of good ideas have a backend — a database, a big trained model, a job queue. The answer here is always the same, and it is one thing: bring the interactive part into the browser.
Show the interactive slice the way it’s done here
The strongest demo is rarely the whole system — it is the one moment someone can feel. Stand in for the backend right in the tab: bake in a sample response, run the model client-side with Pyodide or WebAssembly, or drive it live with BYOK using the visitor’s own key. It runs forever, shows its source, and earns the green ✓ like anything else. The writeup carries the rest of the architecture — the demo carries the part people can touch.
What we don’t do — and why
Reach out to a live server elsewhere not a demo here
A demo that phones your own backend can’t keep the one promise this place is built on: we cannot see or vouch for what runs on that server. It can change after review, it breaks the moment the server goes down, and half of it is never source-visible. So the demo stays whole and in the browser — the sandbox only lets it talk to sloprun and, for BYOK, the model API. Nothing else.
Embed a whole app hosted somewhere else blocked
Framing someone’s entire live site as a “demo” is the one thing the sandbox blocks outright. An outside page can show reviewers one thing and visitors another later, and none of it is source-visible. Every promise here — contained, honest, still running in a year — dies at that iframe. So it stays shut.
Is that safe? Yes — because everything runs here. A demo lives on a throwaway origin with no cookies and no reach into your account, and by design it can only talk to sloprun itself (and the model API for BYOK). There is no outside server in the loop to trust, which is exactly why a stranger’s code is safe to press run.
ready to post? sign in · deploys go through the same content screen · the rules