Run untrusted code safely
Execute code in isolated Linux containers with managed infrastructure. One function call creates a sandbox, runs your command, and cleans up automatically. We handle provisioning, isolation, and teardown.
Built into the SDK
Sandboxes are part of the Agentuity runtime. Access them from your agent context without additional dependencies or configuration.
One Function Call
Create a container, run your code, get results, destroy the container. All in one call. No lifecycle management. No cleanup code. We handle the infrastructure.
Managed Infrastructure
No containers to provision. No orchestration to configure. Agentuity handles sandbox creation, resource allocation, and teardown automatically.
Secure by Default
Network disabled by default. Resource limits enforced. Execution timeouts prevent runaway processes. You enable capabilities explicitly, not disable them after the fact.
Simple API, powerful execution
Run any command in an isolated container. Pass files in, get output back. The sandbox handles the rest.
const result = await ctx.sandbox.run({
command: { exec: ['bun', 'run', 'index.ts'] },
resources: { memory: '256Mi' },
});
return { output: result.stdout, exitCode: result.exitCode };
Pre-configured environments with snapshots
Create a sandbox, install your dependencies, save a snapshot. Future sandboxes start from that snapshot instantly. Tag snapshots for versioning and roll back when needed.
See it in action
Watch this 1-minute overview to see how to execute untrusted code in isolated containers with managed infrastructure using Agentuity's built-in Sandboxes.
Use Cases
What agents use sandboxes for
LLM-Generated Code
Run code the model writes without risking your infrastructure.
Data Processing
Parse files, transform data, run analysis in isolated containers.
Build & Test
Compile code, run test suites, generate artifacts in clean environments.
Tool Execution
Invoke CLI tools, run scripts, execute binaries safely.
Resources
[Running Code in Sandboxes] (https://agentuity.dev/services/sandbox) - Execute code in isolated Linux containers with configurable resource limits, network controls, and execution timeouts.
[Using the Sandbox API] (https://agentuity.dev/services/sandbox/sdk-usage) - Programmatic API for creating sandboxes, writing files, streaming output, and managing sandbox lifecycle.
[Creating and Using Snapshots] (https://agentuity.dev/services/sandbox/snapshots) - Save sandbox filesystem states for faster cold starts. Skip dependency installation with pre-configured environments.
[Sandbox CLI Commands] (https://agentuity.dev/reference/cli/sandbox) - Create sandboxes, execute commands, manage snapshots, and debug execution from the terminal.
Frequently Asked Questions
What runtimes do sandboxes support?
How fast do sandboxes start?
Are sandboxes secure?
Ready to run code safely?
Isolated execution with managed infrastructure. Get started in minutes.