sandbox command group creates and manages AgentKit sandbox tools, then uses sandbox sessions to run commands, invoke agents, transfer files, open web previews, or inject local model subscription credentials. Current sandbox tool types are CodeEnv, SkillEnv, and Private.
Sandbox commands do not expose a
--region flag. To set the AgentKit control-plane region, write it to .agentkit/sandbox.yaml with agentkit sandbox config --set region=<region>, or set AGENTKIT_SANDBOX_REGION. For TOS mounts, set AGENTKIT_SANDBOX_TOS_REGION; when it is omitted, the CLI infers the TOS region from the bucket or current cloud environment.-s, --session-id <id>, --sid <id> selects the user session id; --tool-id <id> selects a sandbox tool id; --tool-name <name> resolves by tool name; --tool-type <type> selects the tool type. If local config already stores tool-id, tool-name, tool-type, or session-id, commands use those defaults as described in each option table when the corresponding option is omitted.
Command overview
sandbox build
Build a custom sandbox image in cloud Code Pipeline. After a successful build, the CLI setstool-type to Private and writes the generated image URL to .agentkit/sandbox.yaml for later sandbox create commands.
sandbox init
Generate a sandbox Dockerfile template. When no template is specified, the command generates theskill template.
sandbox config
Configure local defaults for sandbox commands. The config file is.agentkit/sandbox.yaml in the current project. --list prints YAML after merging defaults and redacts model API keys and WebSearch API keys.
sandbox create
Create a sandbox tool. After creation, the CLI waits until the tool reachesReady, then stores the tool id and name in local sandbox config.
Private tool, prepare an image URL first:
sandbox delete
Delete a sandbox tool or a specific session under a tool. When a session id is passed, the command deletes that session; when it is omitted, the command deletes the tool itself. Tool deletion must target exactly one tool with either--tool-id or --tool-name.
sandbox list
List locally cached sandbox sessions, or inspect one cached session. This command reads the local session cache and prints JSON; it does not list all cloud sandbox tools.sandbox mount
Open a TOS-mounted sandbox session directory in TosBrowser. The target tool must already have a TOS mount, and a login profile usable for mount authorization must exist locally throughagentkit login.
sandbox exec
Connect to a sandbox terminal and execute a command. Use--command to provide the initial command after connection; omit it to open a terminal connection. --mode tmux attaches to or creates a tmux session named after the session id.
sandbox invoke
Invoke an agent in a sandbox through A2A. The default tool type isSkillEnv, and output is JSON. With --async, the command returns immediately after creating the task; with --task-id, it polls an existing task.
sandbox run
Read a YAML file and convert its entries intoagentkit sandbox exec commands. The default file name is agentkit-sandbox-run.yaml. The root can be a list, or an object containing exec, execs, tabs, or commands.
agentkit-sandbox-run.yaml
session_id, sid, tool_id, tool_type, command, mode, shell_id, git_config, model_name, model_api_key, model_provider, model_base_url, cwd, workdir, copy, and copies. You can also use args or argv to provide the raw sandbox exec argument list directly.
sandbox shell
Run a non-interactive shell command in the sandbox and print the JSON result. This command requires--command and is suited to scripts; use sandbox exec when you need an interactive terminal.
sandbox web
Open the sandbox web preview and print JSON containing the URL, tool id, session id, and whether the session was newly created.sandbox codex-login
Inject local Codex or Claude subscription credentials into a sandbox session.model-login is equivalent to this command.
sandbox model-login
model-login is equivalent to codex-login; it injects local Codex or Claude subscription credentials into a sandbox session.
sandbox scp
Transfer files or directories between local storage and an existing sandbox session. Remote paths must start withsandbox:; relative remote paths resolve under /home/gem. This command uses the local session cache, so create the target session first with sandbox exec, sandbox shell, sandbox web, sandbox invoke, or a login command.