Sandboxes
Templates, network access, file transfer and the limits that apply to every sandbox.
Templates
Templates define the pre-installed packages and base configuration for a sandbox. Use built-in templates or create your own. Try them in the playground.
// Built-in templates
'playground' // General purpose
'rust' // Rust toolchain
'typescript' // Node.js + TS
'javascript' // Node.js
'php' // PHP 8.x
'sql' // PostgreSQL
'zig' // Zig compiler
'claude-agent' // Claude Managed Agents (8 GB)
// Custom template
const sb = await Sandbox.create('my-custom-template');Networking
Base templates (python-3.11, node-20) start with no internet access; agent templates always have internet on, and internet: false does not switch it off for them. With internet: false a base-template sandbox has no route out at all. With internet: true outbound egress is open.
internet: falsebooleaninternet: truebooleansniProxy + allowDomainsboolean · string[]The air-gap prevents data exfiltration for workloads that don't need the network. For workloads that need some outbound, an opt-in SNI egress proxy can restrict a sandbox to an allow-list of hosts: it inspects each TLS handshake on port 443 and only forwards connections whose server name matches your list. It is off by default.
const sandbox = await Sandbox.create('agent', {
internet: false
});
// internet: false → no route out (base templates)
// internet: true → open outbound egress
// HTTPS hostname allowlist: opt-in SNI proxy (sniProxy)File transfer
Upload and download files using signed, time-bound URLs. All file access is scoped to a single sandbox.
// Write a file to the sandbox
await sandbox.files.write(
'/tmp/input.json',
JSON.stringify(data)
);
// Read a file from the sandbox
const output = await sandbox.files.read(
'/tmp/result.csv'
);Limits
Each user can run up to 3 concurrent sandboxes by default. Creating a sandbox beyond this limit returns a 429 status code.
Sandboxes with no activity for 15 minutes are automatically killed. Sandboxes created with vaultInject: true are exempt from idle auto-kill.
// Concurrent sandbox limit: 3 per user
// Exceeding the limit returns HTTP 429
POST /sandboxes
// → 429 { "error": "concurrent sandbox limit reached" }
// Idle auto-kill: 15 minutes with no activity
// Vault-injected sandboxes are exempt