Everything your agent needs. Nothing it doesn't.
A complete execution environment built from the ground up for AI agents. Hybrid execution, persistent storage, full bash, git — all accessible through a single REST API.
Four layers. One API.
SDK calls hit the Cloudflare Worker, which authenticates and routes to a per-sandbox Durable Object. The DO holds the Vm engine, virtual filesystem, and container connection.
Built different. Here's how.
Hybrid Execution Engine
Built-in POSIX commands (grep, sed, awk, find, xargs, and 35+ more) run directly in the V8 worker — sub-millisecond, zero container overhead. Unknown commands like node, python, or cargo automatically escalate to a container sandbox. Your agent doesn't need to know the difference.
The router inspects each command at execution time. Built-in commands stay in-process for maximum speed. Anything that needs a real binary gets transparently forwarded to the container. Bash scripts can mix both — the engine handles the routing per-pipeline-stage.
Persistent Virtual Filesystem
Every sandbox gets a ChunkedVFS — a virtual filesystem backed by Cloudflare R2 (object storage) and D1 (metadata). Files persist across pause/resume cycles. Read, write, search, and bulk upload/download through the API.
The VFS chunks large files automatically for R2 storage efficiency. Metadata (directory tree, permissions, timestamps) lives in D1 for fast lookups. On sandbox destroy, both R2 blocks and D1 metadata are garbage-collected.
Complete Bash Interpreter
Not a subset. A full bash interpreter that handles pipes, redirects, subshells, command substitution, arithmetic, globbing, here-docs, for/while/if/case, functions, traps, and environment variable expansion.
Built on codeboltshell's pure-JavaScript parser and evaluator. No native bindings, no subprocess spawning. The same interpreter runs identically in Workers, Node.js, Bun, and browsers.
Git Operations
Clone repositories, check status, create commits, view logs and diffs — all through the API. Powered by isomorphic-git running in the worker, not shelling out to a git binary.
Shallow clones with configurable depth. Full staging with file-level granularity. Commit with custom author info. Status returns a matrix of new/modified/deleted files. All operations run against the sandbox's VFS.
Multi-Provider Architecture
One API, multiple isolation backends. Run sandboxes in-process (fastest), in Docker containers (full Linux), on Cloudflare's edge (global scale), or on your own bare-metal servers.
Providers are swappable at sandbox creation time via the template/provider parameter. The API surface is identical regardless of backend. In-process is ideal for lightweight ops. Docker is best for agents needing system packages. Cloudflare gives you edge deployment with auto-scaling.
Usage Tracking & Plans
Every operation is metered. Commands, bash executions, file operations, sandbox creates — all tracked per-user with daily aggregates. Three built-in plans (Free, Pro, Enterprise) with configurable limits.
Usage events record the sandbox ID, execution location (worker/container/mixed), duration, and operation type. Plan enforcement happens at operation time — exceeding limits returns a 429 with the specific limit that was hit. Admins can adjust plan limits via the API.
Smart command routing. Zero configuration.
The command router decides at execution time whether a command runs in-worker or gets escalated to the container. Your agent code doesn't change.
Full REST API. SSE streaming.
Every operation is an HTTP call. Streaming endpoints use Server-Sent Events for real-time output.
Sandbox Lifecycle
Execution
Files
Git
Processes
40+ POSIX commands. Zero latency.
These run directly in the V8 worker — no container, no cold start, no network hop. Sub-millisecond execution.