Skip to main content
The sandbox command group creates and manages AgentKit sandbox tools, then uses sandbox sessions to run commands, invoke agents, transfer files, open web previews, or inject local model subscription credentials. Current sandbox tool types are CodeEnv, SkillEnv, and Private.
Sandbox commands do not expose a --region flag. To set the AgentKit control-plane region, write it to .agentkit/sandbox.yaml with agentkit sandbox config --set region=<region>, or set AGENTKIT_SANDBOX_REGION. For TOS mounts, set AGENTKIT_SANDBOX_TOS_REGION; when it is omitted, the CLI infers the TOS region from the bucket or current cloud environment.
Session-oriented commands share the same tool and session selectors: -s, --session-id <id>, --sid <id> selects the user session id; --tool-id <id> selects a sandbox tool id; --tool-name <name> resolves by tool name; --tool-type <type> selects the tool type. If local config already stores tool-id, tool-name, tool-type, or session-id, commands use those defaults as described in each option table when the corresponding option is omitted.

Command overview

sandbox build

Build a custom sandbox image in cloud Code Pipeline. After a successful build, the CLI sets tool-type to Private and writes the generated image URL to .agentkit/sandbox.yaml for later sandbox create commands.
sandbox build uses cloud resources such as TOS, Container Registry, and Code Pipeline, which may incur charges. Confirm account permissions, the project directory, and image naming before running it. If the build fails, the CLI may write build logs under .agentkit/sandbox/build/ in the project.

sandbox init

Generate a sandbox Dockerfile template. When no template is specified, the command generates the skill template.

sandbox config

Configure local defaults for sandbox commands. The config file is .agentkit/sandbox.yaml in the current project. --list prints YAML after merging defaults and redacts model API keys and WebSearch API keys.
Supported config keys are listed below.

sandbox create

Create a sandbox tool. After creation, the CLI waits until the tool reaches Ready, then stores the tool id and name in local sandbox config.
sandbox create provisions cloud compute resources that may incur charges while they exist. Confirm the tool type, resource size, network settings, image, and TOS mount configuration before creating one. Delete unused tools with sandbox delete --tool-id <id> --force.
To create a custom Private tool, prepare an image URL first:

sandbox delete

Delete a sandbox tool or a specific session under a tool. When a session id is passed, the command deletes that session; when it is omitted, the command deletes the tool itself. Tool deletion must target exactly one tool with either --tool-id or --tool-name.
Deleting a sandbox tool or session cannot be undone. Files, runtime state, and session cache that were not persisted elsewhere may be lost. Confirm the target id or name and download required files before proceeding.

sandbox list

List locally cached sandbox sessions, or inspect one cached session. This command reads the local session cache and prints JSON; it does not list all cloud sandbox tools.

sandbox mount

Open a TOS-mounted sandbox session directory in TosBrowser. The target tool must already have a TOS mount, and a login profile usable for mount authorization must exist locally through agentkit login.

sandbox exec

Connect to a sandbox terminal and execute a command. Use --command to provide the initial command after connection; omit it to open a terminal connection. --mode tmux attaches to or creates a tmux session named after the session id.

sandbox invoke

Invoke an agent in a sandbox through A2A. The default tool type is SkillEnv, and output is JSON. With --async, the command returns immediately after creating the task; with --task-id, it polls an existing task.

sandbox run

Read a YAML file and convert its entries into agentkit sandbox exec commands. The default file name is agentkit-sandbox-run.yaml. The root can be a list, or an object containing exec, execs, tabs, or commands.
agentkit-sandbox-run.yaml
Entry fields include session_id, sid, tool_id, tool_type, command, mode, shell_id, git_config, model_name, model_api_key, model_provider, model_base_url, cwd, workdir, copy, and copies. You can also use args or argv to provide the raw sandbox exec argument list directly.

sandbox shell

Run a non-interactive shell command in the sandbox and print the JSON result. This command requires --command and is suited to scripts; use sandbox exec when you need an interactive terminal.

sandbox web

Open the sandbox web preview and print JSON containing the URL, tool id, session id, and whether the session was newly created.

sandbox codex-login

Inject local Codex or Claude subscription credentials into a sandbox session. model-login is equivalent to this command.
sandbox codex-login and sandbox model-login copy local subscription credentials into a remote sandbox session. Use them only with a trusted sandbox and a dedicated session, and avoid sharing that session. Delete the session or sandbox tool when finished.

sandbox model-login

model-login is equivalent to codex-login; it injects local Codex or Claude subscription credentials into a sandbox session.

sandbox scp

Transfer files or directories between local storage and an existing sandbox session. Remote paths must start with sandbox:; relative remote paths resolve under /home/gem. This command uses the local session cache, so create the target session first with sandbox exec, sandbox shell, sandbox web, sandbox invoke, or a login command.
Last modified on September 19, 2026