OmniRunDocs

Sandboxes

Templates, network access, file transfer and the limits that apply to every sandbox.

TemplatesInternet on or off15-minute idle auto-kill

Templates

Templates define the pre-installed packages and base configuration for a sandbox. Use built-in templates or create your own. Try them in the playground.

Available templates
// Built-in templates
'playground'   // General purpose
'rust'         // Rust toolchain
'typescript'   // Node.js + TS
'javascript'   // Node.js
'php'          // PHP 8.x
'sql'          // PostgreSQL
'zig'          // Zig compiler
'claude-agent' // Claude Managed Agents (8 GB)

// Custom template
const sb = await Sandbox.create('my-custom-template');
Try it — Python Sandbox

Networking

Base templates (python-3.11, node-20) start with no internet access; agent templates always have internet on, and internet: false does not switch it off for them. With internet: false a base-template sandbox has no route out at all. With internet: true outbound egress is open.

internet: falseboolean
No route out of the VM (base templates; agent templates keep internet on).
internet: trueboolean
Open outbound egress.
sniProxy + allowDomainsboolean · string[]
Only HTTPS (port 443) connections to the listed hostnames, matched by the SNI proxy. Off by default.

The air-gap prevents data exfiltration for workloads that don't need the network. For workloads that need some outbound, an opt-in SNI egress proxy can restrict a sandbox to an allow-list of hosts: it inspects each TLS handshake on port 443 and only forwards connections whose server name matches your list. It is off by default.

A guard rail, not an exfiltration control. The proxy filters HTTPS by hostname only: traffic on other ports is not filtered by it, and a client can present an allowed server name to a different host behind the same CDN (domain fronting).
Toggle internet access
const sandbox = await Sandbox.create('agent', {
  internet: false
});

// internet: false → no route out (base templates)
// internet: true  → open outbound egress
// HTTPS hostname allowlist: opt-in SNI proxy (sniProxy)
Try it — Network Isolation

Read the security model

File transfer

Upload and download files using signed, time-bound URLs. All file access is scoped to a single sandbox.

Upload & download
// Write a file to the sandbox
await sandbox.files.write(
  '/tmp/input.json',
  JSON.stringify(data)
);

// Read a file from the sandbox
const output = await sandbox.files.read(
  '/tmp/result.csv'
);
Try it — File I/O

Limits

Each user can run up to 3 concurrent sandboxes by default. Creating a sandbox beyond this limit returns a 429 status code.

Sandboxes with no activity for 15 minutes are automatically killed. Sandboxes created with vaultInject: true are exempt from idle auto-kill.

Limit behavior
// Concurrent sandbox limit: 3 per user
// Exceeding the limit returns HTTP 429

POST /sandboxes
// → 429 { "error": "concurrent sandbox limit reached" }

// Idle auto-kill: 15 minutes with no activity
// Vault-injected sandboxes are exempt