From API call to result. In milliseconds.
AgentRunBox gives your AI agent an isolated environment to execute code. Here's what happens under the hood — from sandbox creation to command execution to cleanup.
Create a Sandbox
A single POST request creates an isolated sandbox. Choose a template (base, node, python, rust, go), set environment variables, configure timeout, and optionally seed files.
Under the hood: a row is inserted into D1, a Durable Object is instantiated, and a Vm is lazily initialized on first use. The sandbox ID follows the format sbx_*.
Execute Commands
Run individual commands or full bash scripts. The hybrid engine automatically routes each command to the fastest execution path — worker for built-ins, container for binaries.
Responses include stdout, stderr, exit code, execution duration, and where the command ran (worker, sandbox, or mixed for bash scripts that use both).
The command router.
Every command passes through the router. Built-in POSIX commands stay in the worker for sub-millisecond execution. Unknown binaries are transparently escalated to the container.
Manage Files & Git
Read, write, search, and organize files through the REST API. Clone repositories, check status, stage changes, and commit — all without shelling out to git.
Bulk operations let you upload or download multiple files in a single request. File search supports regex patterns with glob filtering. Git operations use isomorphic-git running directly in the worker.
Pause, resume, destroy. Automatic cleanup.
Sandboxes can be paused to save costs (filesystem persists in R2), resumed when needed, and destroyed when done. Idle timeouts auto-pause after configurable inactivity.
Running
Active sandbox. Vm is initialized, commands execute, files are read/written. Metered usage.
Paused
Container stopped, Vm released. Filesystem persists in R2. No compute charges. Resume in <50ms.
Destroyed
Everything cleaned up. R2 blocks deleted, D1 metadata removed. No lingering state or cost.
JWT + API Keys. Plan enforcement.
Two authentication methods. JWT tokens for sessions (7-day expiry). API keys (arb_* prefix) for programmatic access. Plans enforce limits on sandbox count, commands per day, storage, and timeout.