Skip to main content

boxxkite-sandbox

The missing batteries-included, self-hostable sandbox for agent code execution.

Most "agent sandbox" projects give you raw isolation — a pod, a VM, a container — and leave you to build the tool surface an LLM agent needs on top of it. boxxkite is the other half: a complete bash/python/file/ search/process tool surface (15 framework-agnostic tools — LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex, or plain OpenAI-style function calling) running inside real Kubernetes pod isolation, hardened with non-root execution, dropped Linux capabilities, a read-only root filesystem, default-deny network egress, and secret-scrubbed command output.

Who this is for: teams building their own agent products that need isolated, multi-tenant code execution at scale — one Kubernetes pod per session, many sessions, many tenants. If you just want your own coding assistant to run shell commands on your own machine, this is the wrong layer.

Install

pip install boxxkite-sandbox

Note the PyPI name is boxxkite-sandbox, not boxxkite (already taken) — the import path is unaffected: import boxxkite.

Quickstart

git clone https://github.com/EvAlssment/boxxkite.git boxxkite && cd boxxkite
pip install -e .
boxxkite up
boxxkite exec "python3 -c 'print(1 + 1)'"
from uuid import uuid4
from boxxkite import SandboxManager
from boxxkite.tools import create_sandbox_tool_specs

manager = SandboxManager()
session_id = str(uuid4())
await manager.create_session(organization_id=uuid4(), session_id=session_id)

specs = create_sandbox_tool_specs(sandbox_manager=manager, session_id=session_id)
bash_tool = next(s for s in specs if s.name == "bash_tool")
result = await bash_tool.handler(command="echo hello from boxxkite")

boxxkite.tools.adapters converts the same tool specs for LangChain, LlamaIndex, the OpenAI Agents SDK, or plain OpenAI/Anthropic/Gemini/Mistral function-calling schemas — see the full integration table and every other runtime mode (real Kubernetes, docker-compose, the boxxkite CLI) in the full README.

Security

boxxkite executes arbitrary, agent-generated code — its security posture is layered defense in depth (non-root, dropped capabilities, read-only filesystem, per-exec network isolation, no credential injection into /exec). See SECURITY.md for the full model and known follow-ups before deploying this beyond local dev.

License

Apache 2.0 — permissive with an explicit patent grant, no restriction on self-hosting or competing hosted use.

Links

GitHub · Full README · Docs · Issues · Discord

Metadata

Release files for boxxkite-sandbox 0.8.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for boxxkite-sandbox 0.8.0
File Size Uploaded
boxxkite_sandbox-0.8.0.tar.gz 492.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for boxxkite-sandbox 0.8.0
File Interpreter ABI Platform
boxxkite_sandbox-0.8.0-py3-none-any.whl Python 3 none any Details

Total release size: 820.5 kB

Release files / boxxkite_sandbox-0.8.0.tar.gz

Download URL boxxkite_sandbox-0.8.0.tar.gz
Size 492.7 kB
Tags Source
SHA-256 checksum
How to use checksums
bc9d55b7e08d7f3b939e90d50be4a1e1d1ced5595abe0a21cff95fc71f555f16
BLAKE2b-256 checksum
How to use checksums
3a0f659627c3e755f3f4257a9c6259ae8bfb350e0003d639a8901f348a58c8cf
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / boxxkite_sandbox-0.8.0-py3-none-any.whl

Download URL boxxkite_sandbox-0.8.0-py3-none-any.whl
Size 327.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
26d1a1f0961aa8ddfaf9448f57a7a265aa05bcecf044807ca94be36656de7c5c
BLAKE2b-256 checksum
How to use checksums
5b88a7513286b794ea8d53d35465fd491d8d3dd2fa79ba7519c20cf0bd6d7b3c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

This release

0.8.0 This release

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.4

2 release files

0.2.3

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page