Skip to content

Sandboxes

Tested with: zb CLI 0.1 · MCP (zb-mcp) · REST API v1

A sandbox is a short-lived, isolated runtime for code you do not trust: code written by an AI agent, user-submitted scripts, or a one-off build. Create one, run commands with streamed output, copy files in and out, snapshot its workspace, and kill it. Templates come with Python 3, Node.js and Git.

shell
id=$(zb sandbox create --template python --timeout 600)
zb sandbox cp ./analysis.py "$id:analysis.py"
zb sandbox exec "$id" -- python3 analysis.py # streams output, exits with the command's code
zb sandbox cp "$id:out/report.csv" .
zb sandbox kill "$id"
  • Isolation: each sandbox is its own gVisor container, non-root, on nodes separate from databases, with no Kubernetes credentials and a read-only system: /workspace and /tmp are writable.
  • Lifetime: a sandbox stops after its timeout (default 5 minutes) or when it has been idle (no command) for its idle timeout, whichever comes first. Warm spares make creation fast.
  • Commands run without a shell unless you ask for one (-- sh -c '...'); arguments are never re-parsed.
  • Snapshots save /workspace (zb sandbox snapshot) and restore it into a new sandbox (zb sandbox create --from-snapshot snap_...). They expire after their retention.
  • Billing is per second at the size’s hourly price while the sandbox runs.

By default a sandbox has no network at all (no DNS either). Choose per sandbox:

--egressWhat the sandbox can reach
none (default)Nothing.
internetThe public internet (never private, link-local or cloud metadata addresses; SMTP port 25 is closed).
allowlistOnly the hosts and public CIDRs you list with --allow (pypi.org:443, *.pythonhosted.org, 45.60.12.0/24:5432).

Allow-listed hosts go through the region’s egress proxy, which re-checks every address it connects to, so a name that resolves to an internal address is refused.

Give a sandbox an API key without giving it the key:

shell
zb secrets set OPENAI_KEY=sk-... # a project secret
zb sandbox create --allow api.openai.com --secret [email protected]

Inside the sandbox OPENAI_API_KEY holds a placeholder (zbcloak_...). When the code sends that placeholder in a header or query parameter to api.openai.com, the egress proxy swaps in the real value. Sent anywhere else, the request is refused and the attempt is recorded as a security event, so a malicious dependency cannot exfiltrate the key. Request bodies are not rewritten.

Sandbox sizes: vCPU, memory and price
Size vCPU Memory $ / hour
x1 1 1 GiB $0.05
x2 2 2 GiB $0.1
x4 4 4 GiB $0.2
Platform usage prices and the allowance each plan includes per month
Meter Price FreeSoloTeamEnterprise
Sandbox compute Coming soon By size, per running second Not availablePay as you goPay as you goPay as you go
Platform limits on each plan
Limit FreeSoloTeamEnterprise
Concurrent sandboxes Coming soon None550Unlimited