Skip to main content

boxxkite-sandbox

The missing batteries-included, self-hostable sandbox for agent code execution.

Most "agent sandbox" projects give you raw isolation — a pod, a VM, a container — and leave you to build the tool surface an LLM agent needs on top of it. boxxkite is the other half: a complete bash/python/file/ search/process tool surface (15 framework-agnostic tools — LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex, or plain OpenAI-style function calling) running inside real Kubernetes pod isolation, hardened with non-root execution, dropped Linux capabilities, a read-only root filesystem, default-deny network egress, and secret-scrubbed command output.

Who this is for: teams building their own agent products that need isolated, multi-tenant code execution at scale — one Kubernetes pod per session, many sessions, many tenants. If you just want your own coding assistant to run shell commands on your own machine, this is the wrong layer.

Install

pip install boxxkite-sandbox

Note the PyPI name is boxxkite-sandbox, not boxxkite (already taken) — the import path is unaffected: import boxxkite.

Quickstart

git clone https://github.com/EvAlssment/boxxkite.git boxxkite && cd boxxkite
pip install -e .
boxxkite up
boxxkite exec "python3 -c 'print(1 + 1)'"
from uuid import uuid4
from boxxkite import SandboxManager
from boxxkite.tools import create_sandbox_tool_specs

manager = SandboxManager()
session_id = str(uuid4())
await manager.create_session(organization_id=uuid4(), session_id=session_id)

specs = create_sandbox_tool_specs(sandbox_manager=manager, session_id=session_id)
bash_tool = next(s for s in specs if s.name == "bash_tool")
result = await bash_tool.handler(command="echo hello from boxxkite")

boxxkite.tools.adapters converts the same tool specs for LangChain, LlamaIndex, the OpenAI Agents SDK, or plain OpenAI/Anthropic/Gemini/Mistral function-calling schemas — see the full integration table and every other runtime mode (real Kubernetes, docker-compose, the boxxkite CLI) in the full README.

Security

boxxkite executes arbitrary, agent-generated code — its security posture is layered defense in depth (non-root, dropped capabilities, read-only filesystem, per-exec network isolation, no credential injection into /exec). See SECURITY.md for the full model and known follow-ups before deploying this beyond local dev.

License

Apache 2.0 — permissive with an explicit patent grant, no restriction on self-hosting or competing hosted use.

GitHub · Full README · Docs · Issues · Discord

Metadata

Release files for boxxkite-sandbox 0.6.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for boxxkite-sandbox 0.6.0
File Size Uploaded
boxxkite_sandbox-0.6.0.tar.gz 492.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for boxxkite-sandbox 0.6.0
File Interpreter ABI Platform
boxxkite_sandbox-0.6.0-py3-none-any.whl Python 3 none any Details

Total release size: 820.5 kB

Release files / boxxkite_sandbox-0.6.0.tar.gz

Download URL boxxkite_sandbox-0.6.0.tar.gz
Size 492.7 kB
Tags Source
SHA-256 checksum
How to use checksums
37e3d337a2669fb6927187518020864dad83ddc5ee62bf0e127f1dc7765817c4
BLAKE2b-256 checksum
How to use checksums
8626dd06aa400473cbb63be121c7dde1cc877977e5bd72b9295d74c545f69435
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.6

Release files / boxxkite_sandbox-0.6.0-py3-none-any.whl

Download URL boxxkite_sandbox-0.6.0-py3-none-any.whl
Size 327.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cf877a7dfd7c8bbd85f8b88e6f32b0615cf8e02cd1402ec60ebf6374ecdf5417
BLAKE2b-256 checksum
How to use checksums
55b04d7367b164ce91849f625c48571b863590693f11f6056f37148eddbaa17b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.14.6

Release history Release notifications | RSS feed

0.8.0

2 release files

0.7.0

2 release files

This release

0.6.0 This release

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.4

2 release files

0.2.3

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page