Provision a sandbox
Creates a sandbox and returns immediately with a sandbox_id — the container boots in the background, so the sandbox is not usable yet when this call returns.
Next step: call POST /sandboxes/wait to block until it is ready, or poll GET /sandboxes/detail/{sandbox_id} until status is running. The sandbox_url is only populated once the sandbox is running.
Supply either image_id (a registered image, recommended) or image (a raw Docker reference). Set ttl_seconds so the sandbox is reclaimed automatically even if the caller crashes.
Authentication
Bearer authentication of the form Bearer <token>, where token is your auth token.
Headers
UUID of the workspace that scopes this request. List the workspaces you belong to with GET /workspaces.
Request
Your unique name for this sandbox. Reuse it to destroy, wait on or query the sandbox later. Must be unique among live sandboxes — a UUID or a per-session id works well.
Raw Docker image reference. Prefer image_id, which also carries memory, TTL and readiness settings. Ignored when image_id is set.
Id of a registered image from GET /sandbox-images. Recommended: it applies the image's memory, readiness and TTL defaults, and handles private-registry authentication.
If neither image_id nor image is supplied, the deployment's default image is used — pass one explicitly for reproducibility.
Environment variables injected into the container. Use this to pass configuration, or the standard HTTP_PROXY/HTTPS_PROXY variables to route egress through a proxy.
Destroy the sandbox automatically after this many seconds (60–86400). Overrides the image default. Always set this for agent workloads so a crashed caller cannot leak resources.
Response
Where to reach the sandbox and the token to authenticate with. The URL is known immediately, but only answers once status is running.
Absolute URLs for what this sandbox exposes, keyed by capability (exec, files, and depending on the image terminal, vnc, cdp, mcp). Read this instead of assuming paths — they differ between images.
Id of the new sandbox. Poll GET /sandboxes/detail/{sandbox_id} with it.
Lifecycle state at the time of the response. Always provisioning here — the container is still booting.
Public URL of the sandbox. Null until the status becomes running — read it from GET /sandboxes/detail/{sandbox_id}.
Failure reason when success is false.