Skip to main content

agentbox

Self-hosted code execution sandbox for AI agents — one docker compose up gives you an HTTP API for running untrusted code in isolated environments.

PyPI License: MIT Python 3.11+ CI

Status: v0.6 — Python + Node subprocess sandbox, timeouts, memory limits, Linux default-deny egress (unshare/bwrap) with network_isolated, TypeScript client, workspace snapshots.

60-second try

pip install agentbox-sandbox
agentbox serve   # API on :8080
# or: docker compose up agentbox
curl -s http://localhost:8080/health
curl -s -X POST http://localhost:8080/v1/run \
  -H 'Content-Type: application/json' \
  -d '{"code":"print(sum(range(10)))"}'

Why this vs alternatives

Approach Strength Gap
agentbox Self-hosted HTTP API + SDK, one compose file Subprocess isolation today, not gVisor
Hosted sandboxes (E2B, etc.) Strong isolation, managed Per-second cost; data leaves your network
Raw docker exec Familiar No agent-oriented API / snapshots / limits
YOLO in the agent process Zero infra Full host compromise risk

Problem

Every agent that writes and runs code needs a safe execution environment. Teams either YOLO in shared containers or pay per-second for hosted sandboxes. Self-hosting gVisor/Firecracker is weeks of work.

Key features (v0.6)

  • HTTP API: POST /v1/run executes Python or JavaScript
  • Per-request limits.timeout_seconds (HTTP 408 on timeout)
  • Per-request limits.memory_mb (sets RLIMIT_AS; 16–8192); response includes limits_applied + oom_killed
  • AGENTBOX_MAX_MEMORY_MB clamps requested memory
  • Default-deny egress when possible: Linux wraps with unshare --net or bwrap --unshare-net; response includes network_isolated
  • Workspace snapshots: "snapshot": true then "snapshot_id"
  • Python SDK + TypeScript client (sdk/ts/client.ts)
  • Docker image includes Node.js for the JS runtime
  • Credential stripping when the backend is not unrestricted (macOS stays scrub-only)

Architecture

Agent / SDK
    └── POST /v1/run
            └── SubprocessSandbox (MVP)
                    └── (next) gVisor / Docker backend
Component Technology Why
API FastAPI Async-ready, OpenAPI docs, widely adopted
Server uvicorn Standard ASGI server
Config pydantic-settings Typed env config
Tests pytest + httpx TestClient Fast API testing

Installation

pip install agentbox-sandbox
pip install -e ".[dev]"

Usage

Start server

agentbox serve
# or
docker compose up agentbox

Run code

curl -X POST http://localhost:8080/v1/run \
  -H 'Content-Type: application/json' \
  -d '{"code": "print(sum(range(10)))"}'

curl -X POST http://localhost:8080/v1/run \
  -H 'Content-Type: application/json' \
  -d '{"code": "x = bytearray(10**9)", "limits": {"memory_mb": 64, "timeout_seconds": 5}}'

Python SDK

from agentbox.sdk.client import AgentboxClient

client = AgentboxClient("http://localhost:8080")
print(client.health())
print(client.run("print('hello')"))
print(client.run("console.log('hello')", language="javascript", timeout_seconds=5))
print(client.run("x = bytearray(10**8)", memory_mb=64))
snap = client.run("open('memo.txt','w').write('kept')", snapshot=True)
print(client.run("print(open('memo.txt').read())", snapshot_id=snap["snapshot_id"]))
client.close()

Docker

docker compose up agentbox        # start API on :8080
docker compose run --rm test    # run unit tests

Configuration

Variable Default Description
AGENTBOX_HOST 0.0.0.0 Bind host
AGENTBOX_PORT 8080 Bind port
AGENTBOX_DEFAULT_TIMEOUT_SECONDS 30 Execution timeout
AGENTBOX_DEFAULT_MEMORY_MB unset Optional default RLIMIT_AS cap
AGENTBOX_MAX_MEMORY_MB unset Clamp requested memory_mb to this max
AGENTBOX_SANDBOX_BACKEND subprocess Backend selector
AGENTBOX_SNAPSHOT_DIR /tmp/agentbox-snapshots Workspace snapshot store

Running tests

pytest tests/ -v

Roadmap

  • Node.js runtime + TypeScript client + per-run timeout
  • Filesystem snapshot/restore (tar workspaces)
  • limits.memory_mb via RLIMIT_AS
  • Default-deny egress via Linux netns (unshare/bwrap) when available
  • gVisor runsc backend with warm pool
  • Egress allowlists (beyond all-or-nothing netns)

License

MIT

Known limitations (v0.6)

  • Subprocess sandbox only — not production-grade isolation
  • RLIMIT_AS is a soft address-space cap, not a cgroup memory controller
  • Default-deny egress uses Linux unshare/bwrap when present; macOS stays credential-scrub only (network_isolated: false)
  • Single-node, no warm pool
  • TypeScript client is source-only (not published to npm)

Release files for agentbox-sandbox 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for agentbox-sandbox 0.6.0
File Size Uploaded
agentbox_sandbox-0.6.0.tar.gz 102.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for agentbox-sandbox 0.6.0
File Interpreter ABI Platform
agentbox_sandbox-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size:113.9 kB

Release files / agentbox_sandbox-0.6.0.tar.gz

Download URL agentbox_sandbox-0.6.0.tar.gz
Size 102.4 kB
Tags Source
SHA-256 checksum
How to use checksums
eb6ac675d5d1843a93cd40d397f987f22794a2dd497bedfbeb2bdc8318a156cf
BLAKE2b-256 checksum
How to use checksums
944f572ca122085ec6bd4568e43eb3008210ac420df15af1e3ce07d06b19dd77
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release files / agentbox_sandbox-0.6.0-py3-none-any.whl

Download URL agentbox_sandbox-0.6.0-py3-none-any.whl
Size 11.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ac96293fc1c6d58ac0bb4675fc28977f08719ff277d778d8d2a35207e64c74b6
BLAKE2b-256 checksum
How to use checksums
1ad2b5c31160ab9a0a06b44cd2113a8e4a0e346637f0b627eb7c3aace82a8c70
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.14

Release history Release notifications | RSS feed

0.8.0

2 release files

This release

0.6.0 This release

2 release files

0.5.0

2 release files

0.4.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page