Skip to main content

boxkite-sandbox

The missing batteries-included, self-hostable sandbox for agent code execution.

Most "agent sandbox" projects give you raw isolation — a pod, a VM, a container — and leave you to build the tool surface an LLM agent needs on top of it. boxkite is the other half: a complete bash/python/file/ search/process tool surface (15 framework-agnostic tools — LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex, or plain OpenAI-style function calling) running inside real Kubernetes pod isolation, hardened with non-root execution, dropped Linux capabilities, a read-only root filesystem, default-deny network egress, and secret-scrubbed command output.

Who this is for: teams building their own agent products that need isolated, multi-tenant code execution at scale — one Kubernetes pod per session, many sessions, many tenants. If you just want your own coding assistant to run shell commands on your own machine, this is the wrong layer.

Install

pip install boxkite-sandbox

Note the PyPI name is boxkite-sandbox, not boxkite (already taken) — the import path is unaffected: import boxkite.

Quickstart

git clone https://github.com/EvAlssment/boxkite.git boxkite && cd boxkite
pip install -e .
boxkite up
boxkite exec "python3 -c 'print(1 + 1)'"
from uuid import uuid4
from boxkite import SandboxManager
from boxkite.tools import create_sandbox_tool_specs

manager = SandboxManager()
session_id = str(uuid4())
await manager.create_session(organization_id=uuid4(), session_id=session_id)

specs = create_sandbox_tool_specs(sandbox_manager=manager, session_id=session_id)
bash_tool = next(s for s in specs if s.name == "bash_tool")
result = await bash_tool.handler(command="echo hello from boxkite")

boxkite.tools.adapters converts the same tool specs for LangChain, LlamaIndex, the OpenAI Agents SDK, or plain OpenAI/Anthropic/Gemini/Mistral function-calling schemas — see the full integration table and every other runtime mode (real Kubernetes, docker-compose, the boxkite CLI) in the full README.

Security

boxkite executes arbitrary, agent-generated code — its security posture is layered defense in depth (non-root, dropped capabilities, read-only filesystem, per-exec network isolation, no credential injection into /exec). See SECURITY.md for the full model and known follow-ups before deploying this beyond local dev.

License

Apache 2.0 — permissive with an explicit patent grant, no restriction on self-hosting or competing hosted use.

Links

GitHub · Full README · Docs · Issues

Metadata

Release files for boxkite-sandbox 0.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for boxkite-sandbox 0.2.2
File Size Uploaded
boxkite_sandbox-0.2.2.tar.gz 413.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for boxkite-sandbox 0.2.2
File Interpreter ABI Platform
boxkite_sandbox-0.2.2-py3-none-any.whl Python 3 none any Details

Total release size: 680.5 kB

Release files / boxkite_sandbox-0.2.2.tar.gz

Download URL boxkite_sandbox-0.2.2.tar.gz
Size 413.4 kB
Tags Source
SHA-256 checksum
How to use checksums
b4a4bb3f5546027bf70f06bb6a6b6cec2020b46a1a540737d35b55de93f8d58c
BLAKE2b-256 checksum
How to use checksums
3f4c3c5ce47b0c0d468f8393d550fa7e9f4565cd3f81b39ae3225913075967fe
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.19 {"installer":{"name":"uv","version":"0.11.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release files / boxkite_sandbox-0.2.2-py3-none-any.whl

Download URL boxkite_sandbox-0.2.2-py3-none-any.whl
Size 267.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b0d79837e8851bd6993f8ae8561fa618f8eeefc7eefda457d79a684dd62fe70f
BLAKE2b-256 checksum
How to use checksums
f2fdf6262a849f2a659ad71f216cc73d4e6a17e09b71a5620032cc0762efe68d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via uv/0.11.19 {"installer":{"name":"uv","version":"0.11.19","subcommand":["publish"]},"python":null,"implementation":{"name":null,"version":null},"distro":{"name":"macOS","version":null,"id":null,"libc":null},"system":{"name":null,"release":null},"cpu":null,"openssl_version":null,"setuptools_version":null,"rustc_version":null,"ci":null}

Release history Release notifications | RSS feed

This release

0.2.2 This release

2 release files

0.2.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page