Features

Everything your agent needs. Nothing it doesn't.

A complete execution environment built from the ground up for AI agents. Hybrid execution, persistent storage, full bash, git — all accessible through a single REST API.

Architecture

Four layers. One API.

SDK calls hit the Cloudflare Worker, which authenticates and routes to a per-sandbox Durable Object. The DO holds the Vm engine, virtual filesystem, and container connection.

CLIENT / SDK @agentrunbox/sdk · REST API · SSE Streaming CLOUDFLARE WORKER Auth · Rate Limits · Plan Enforcement · Routing · Usage Tracking DURABLE OBJECT (SandboxDO) 1 per sandbox · Holds Vm instance · Idle timeout · Alarm-based lifecycle Vm ENGINE Bash interpreter 40+ POSIX commands isomorphic-git CHUNKED VFS R2 block storage D1 metadata Persistent FS CONTAINER Cloudflare Container node python cargo Auto-escalation
Deep Dive

Built different. Here's how.

01

Hybrid Execution Engine

Built-in POSIX commands (grep, sed, awk, find, xargs, and 35+ more) run directly in the V8 worker — sub-millisecond, zero container overhead. Unknown commands like node, python, or cargo automatically escalate to a container sandbox. Your agent doesn't need to know the difference.

The router inspects each command at execution time. Built-in commands stay in-process for maximum speed. Anything that needs a real binary gets transparently forwarded to the container. Bash scripts can mix both — the engine handles the routing per-pipeline-stage.

02

Persistent Virtual Filesystem

Every sandbox gets a ChunkedVFS — a virtual filesystem backed by Cloudflare R2 (object storage) and D1 (metadata). Files persist across pause/resume cycles. Read, write, search, and bulk upload/download through the API.

The VFS chunks large files automatically for R2 storage efficiency. Metadata (directory tree, permissions, timestamps) lives in D1 for fast lookups. On sandbox destroy, both R2 blocks and D1 metadata are garbage-collected.

03

Complete Bash Interpreter

Not a subset. A full bash interpreter that handles pipes, redirects, subshells, command substitution, arithmetic, globbing, here-docs, for/while/if/case, functions, traps, and environment variable expansion.

Built on codeboltshell's pure-JavaScript parser and evaluator. No native bindings, no subprocess spawning. The same interpreter runs identically in Workers, Node.js, Bun, and browsers.

04

Git Operations

Clone repositories, check status, create commits, view logs and diffs — all through the API. Powered by isomorphic-git running in the worker, not shelling out to a git binary.

Shallow clones with configurable depth. Full staging with file-level granularity. Commit with custom author info. Status returns a matrix of new/modified/deleted files. All operations run against the sandbox's VFS.

05

Multi-Provider Architecture

One API, multiple isolation backends. Run sandboxes in-process (fastest), in Docker containers (full Linux), on Cloudflare's edge (global scale), or on your own bare-metal servers.

Providers are swappable at sandbox creation time via the template/provider parameter. The API surface is identical regardless of backend. In-process is ideal for lightweight ops. Docker is best for agents needing system packages. Cloudflare gives you edge deployment with auto-scaling.

06

Usage Tracking & Plans

Every operation is metered. Commands, bash executions, file operations, sandbox creates — all tracked per-user with daily aggregates. Three built-in plans (Free, Pro, Enterprise) with configurable limits.

Usage events record the sandbox ID, execution location (worker/container/mixed), duration, and operation type. Plan enforcement happens at operation time — exceeding limits returns a 429 with the specific limit that was hit. Admins can adjust plan limits via the API.

Execution

Smart command routing. Zero configuration.

The command router decides at execution time whether a command runs in-worker or gets escalated to the container. Your agent code doesn't change.

API REQUEST COMMAND ROUTER grep? awk? → WORKER node? python? → CONTAINER BUILT-IN ESCALATE V8 WORKER grep sed awk find xargs cat sort wc git diff ... <1ms CONTAINER node python cargo go npm pip any binary ~2s JSON RESPONSE
API Surface

Full REST API. SSE streaming.

Every operation is an HTTP call. Streaming endpoints use Server-Sent Events for real-time output.

Sandbox Lifecycle

POST /sandboxes
GET /sandboxes
GET /sandboxes/:id
DELETE /sandboxes/:id
POST /sandboxes/:id/pause
POST /sandboxes/:id/resume

Execution

POST /sandboxes/:id/commands
POST /sandboxes/:id/commands/stream
POST /sandboxes/:id/bash
POST /sandboxes/:id/bash/stream

Files

GET /sandboxes/:id/files/*
PUT /sandboxes/:id/files/*
DELETE /sandboxes/:id/files/*
POST /sandboxes/:id/files/search
POST /sandboxes/:id/files/upload

Git

POST /sandboxes/:id/git/clone
GET /sandboxes/:id/git/status
POST /sandboxes/:id/git/commit
GET /sandboxes/:id/git/log

Processes

POST /sandboxes/:id/processes
GET /sandboxes/:id/processes
DELETE /sandboxes/:id/processes/:pid
GET /sandboxes/:id/processes/:pid/logs/stream
Built-in Commands

40+ POSIX commands. Zero latency.

These run directly in the V8 worker — no container, no cold start, no network hop. Sub-millisecond execution.

grep sed awk find xargs cat head tail wc sort uniq tr cut paste tee diff echo printf test expr seq yes true false ls mkdir rmdir rm cp mv touch chmod basename dirname realpath readlink sha256sum md5sum base64 od hexdump env printenv date sleep git