Skip to main content
A sandbox is an isolated code or skill environment. The sandbox command group covers its full lifecycle—create, list, show, update, delete—and its operations: run commands in a session, open an interactive terminal, transfer files, open a web preview, inject subscription credentials, and manage sessions.
run, shell, cp, web, and login share a set of session and sandbox flags: -s, --session <id> (session id, reused if it exists, else generated), --tool-id <id> (sandbox id), --type <type> (sandbox type code | skill, default code), --auto-create (always create a new sandbox, even if some already exist), -r, --region <region> (Volcengine region), and -p, --project <name> (AgentKit project, default default). sessions, logs, and rm accept only the subset used to resolve a sandbox; see each command’s table for its exact flags. attach is an alias for shell.When --tool-id is omitted and --auto-create is not set, the CLI looks for a sandbox of the requested type in the project: exactly one is used automatically; when several exist the command fails and asks you to pass --tool-id; when none exist you need --auto-create. Passing --auto-create always provisions a brand-new sandbox—even when the project already has some—and waits for it to become ready before use. Having several code sandboxes in a project is common, so run agentkit sandbox list to find the target id and pass it via --tool-id.

sandbox create

Create a sandbox (a code or skill environment).
sandbox create provisions cloud compute resources that may incur charges while they exist. Confirm the project, region, resource size, and image source before creating one. Delete the sandbox with sandbox delete when it is no longer needed.
The following example creates a web sandbox from a custom image. Replace the image URL with one that your project can access:

sandbox list

List sandboxes (the code and skill environments in the project).

sandbox show

Show a sandbox’s details.

sandbox update

Update a sandbox’s configuration.

sandbox delete

Delete a sandbox—the environment itself. To delete a single session instead, use sandbox rm.
Deleting a sandbox cannot be undone. Its sessions and files that were not stored elsewhere may be lost with it. Confirm the sandbox ID and download or persist required files before proceeding.

sandbox run

Run a command in a sandbox session and print its output.
A one-shot run waits for the command to finish, so an interactive program—an editor, a REPL, or codex launched with no arguments—would block until the timeout elapses. Open an interactive session with agentkit sandbox shell instead, or raise --timeout (or set it to 0) for long-running non-interactive jobs.

sandbox shell

Open an interactive terminal in a sandbox session (Ctrl-] to detach). sandbox attach is an alias for this command.

sandbox cp

Copy files to/from a sandbox session — prefix the remote side with :.

sandbox web

Open the sandbox web preview in a browser.

sandbox login

This command copies a local subscription credential into a remote sandbox session. Use it only with a trusted sandbox and a dedicated session, and do not share that session with others. When finished, delete the session with agentkit sandbox rm <session> -y.
Inject your local codex/claude subscription into a sandbox session.

sandbox sessions

List active sandbox sessions.

sandbox logs

Show a sandbox session’s logs.

sandbox rm

Stop and delete a sandbox session (or --all). To delete the sandbox environment itself, use sandbox delete.
Last modified on September 19, 2026