Skip to main content

boxxkite-sandbox

The missing batteries-included, self-hostable sandbox for agent code execution.

Most "agent sandbox" projects give you raw isolation — a pod, a VM, a container — and leave you to build the tool surface an LLM agent needs on top of it. boxxkite is the other half: a complete bash/python/file/ search/process tool surface (15 framework-agnostic tools — LangChain, LangGraph, CrewAI, AutoGen, LlamaIndex, or plain OpenAI-style function calling) running inside real Kubernetes pod isolation, hardened with non-root execution, dropped Linux capabilities, a read-only root filesystem, default-deny network egress, and secret-scrubbed command output.

Who this is for: teams building their own agent products that need isolated, multi-tenant code execution at scale — one Kubernetes pod per session, many sessions, many tenants. If you just want your own coding assistant to run shell commands on your own machine, this is the wrong layer.

Install

pip install boxxkite-sandbox

Note the PyPI name is boxxkite-sandbox, not boxxkite (already taken) — the import path is unaffected: import boxxkite.

Quickstart

git clone https://github.com/EvAlssment/boxxkite.git boxxkite && cd boxxkite
pip install -e .
boxxkite up
boxxkite exec "python3 -c 'print(1 + 1)'"
from uuid import uuid4
from boxxkite import SandboxManager
from boxxkite.tools import create_sandbox_tool_specs

manager = SandboxManager()
session_id = str(uuid4())
await manager.create_session(organization_id=uuid4(), session_id=session_id)

specs = create_sandbox_tool_specs(sandbox_manager=manager, session_id=session_id)
bash_tool = next(s for s in specs if s.name == "bash_tool")
result = await bash_tool.handler(command="echo hello from boxxkite")

boxxkite.tools.adapters converts the same tool specs for LangChain, LlamaIndex, the OpenAI Agents SDK, or plain OpenAI/Anthropic/Gemini/Mistral function-calling schemas — see the full integration table and every other runtime mode (real Kubernetes, docker-compose, the boxxkite CLI) in the full README.

Security

boxxkite executes arbitrary, agent-generated code — its security posture is layered defense in depth (non-root, dropped capabilities, read-only filesystem, per-exec network isolation, no credential injection into /exec). See SECURITY.md for the full model and known follow-ups before deploying this beyond local dev.

License

Apache 2.0 — permissive with an explicit patent grant, no restriction on self-hosting or competing hosted use.

Links

GitHub · Full README · Docs · Issues · Discord

Metadata

Release files for boxxkite-sandbox 0.7.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for boxxkite-sandbox 0.7.0
File Size Uploaded
boxxkite_sandbox-0.7.0.tar.gz 492.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for boxxkite-sandbox 0.7.0
File Interpreter ABI Platform
boxxkite_sandbox-0.7.0-py3-none-any.whl Python 3 none any Details

Total release size: 820.5 kB

Release files / boxxkite_sandbox-0.7.0.tar.gz

Download URL boxxkite_sandbox-0.7.0.tar.gz
Size 492.7 kB
Tags Source
SHA-256 checksum
How to use checksums
1629e211e21e5fe4e4a2be8b239d44f17cd90bd9bcd2c4a4e1a2207cb03dd269
BLAKE2b-256 checksum
How to use checksums
80705be6d24c31e5a329383367b6579e1321a9ef9115d3161d64c7e262c900ce
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release files / boxxkite_sandbox-0.7.0-py3-none-any.whl

Download URL boxxkite_sandbox-0.7.0-py3-none-any.whl
Size 327.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
5aa3a8297099c7360250432cf2e22ade93e9c6bcc7df14f4e295a94859f585cd
BLAKE2b-256 checksum
How to use checksums
3fc77c4cb0d31fc9189b5809a60df178ce0993adfe7ed8efea7dba0f9380907e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.6

Release history Release notifications | RSS feed

0.8.0

2 release files

This release

0.7.0 This release

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.1

2 release files

0.3.0

2 release files

0.2.4

2 release files

0.2.3

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page