cua-sandbox
Sandboxed VM environments with a unified Python API. Cloud by default.
pip install cua-sandbox
Fleet support is provided by the published cua-fleet wheel. It bundles the platform-specific fleet_sdk native binding.
Install from the Cua wheel index when resolving dependencies with pip:
pip install --extra-index-url https://wheels.cua.ai/simple cua-sandbox
Ephemeral sandbox
Created on enter, destroyed on exit.
from cua_sandbox import Sandbox, Image
async with Sandbox.ephemeral(Image.linux()) as sb:
await sb.shell.run("uname -a")
await sb.screenshot()
Persistent sandbox
Provision a new sandbox that stays alive after your script exits.
from cua_sandbox import Sandbox, Image
sb = await Sandbox.create(Image.linux())
await sb.shell.run("uname -a")
print(sb.name) # save this to reconnect later
await sb.disconnect()
Connect to existing sandbox
Attach to a sandbox that's already running. Works as a plain await or context manager.
from cua_sandbox import Sandbox
# plain await
sb = await Sandbox.connect("my-sandbox")
await sb.shell.run("whoami")
await sb.disconnect()
# context manager — disconnects on exit, sandbox keeps running
async with Sandbox.connect("my-sandbox") as sb:
await sb.shell.run("whoami")
Destroy a sandbox
await sb.destroy() # disconnect + permanently delete
Local VM
Spins up a local VM using QEMU or Lume, destroyed on exit.
from cua_sandbox import Sandbox, Image
from cua_sandbox.runtime import QEMURuntime
async with Sandbox.ephemeral(Image.linux(), local=True, runtime=QEMURuntime()) as sb:
await sb.shell.run("uname -a")
Localhost (unsandboxed)
Direct host control — not sandboxed, use with caution.
from cua_sandbox import Localhost
async with Localhost.connect() as host:
await host.shell.run("echo hello")
await host.screenshot()
Cloud sandbox
Fleet is the OAuth cloud backend. Configure OAuth credentials once; Fleet uses https://run.cua.ai by default and can be overridden with configure(fleet_base_url=...) or CUA_FLEET_BASE_URL. The legacy API-key VM API continues to use https://api.cua.ai. Cloud images must use a registry reference; expose() declares additional Fleet services.
Fleet does not support snapshots or custom disks, and currently supports only us-east-1. await sb.tunnel.forward(3000) returns the authenticated Fleet service URL for an exposed port; it does not open a local SSH tunnel.
Fleet pools
Use a pool to keep reusable registry-image sandboxes warm. Reconciliation is idempotent: it creates a missing pool or updates the existing pool with the same name. Each claim is released when the context exits, including when the block raises.
from cua_sandbox import Image, Pool
pool = await Pool.reconcile({
"name": "foo",
"image": Image.from_registry("registry.example/workspace:latest"),
})
async with pool.claim() as sb:
result = await sb.shell.run("echo hello")
# Requests use the same authenticated Fleet claim.
response = await sb.services.request(
"mcp", method="POST", path="/mcp", json={"jsonrpc": "2.0", "method": "tools/list", "id": 1}
)
response.raise_for_status()
For scripts that use the synchronous facade:
from cua_sandbox import Image
from cua_sandbox.sync import Pool
pool = Pool.reconcile({"name": "foo", "image": Image.from_registry("example:latest")})
with pool.claim() as sb:
result = sb.shell.run("echo hello")
import os
import cua_sandbox as cua
from cua_sandbox import Image, Sandbox
cua.configure(
client_id=os.environ["CUA_CLIENT_ID"],
client_secret=os.environ["CUA_CLIENT_SECRET"],
)
async with Sandbox.ephemeral(
Image.from_registry("registry.example/desktop-workspace@sha256:...").expose(3000)
) as sb:
await sb.shell.run("uname -a")
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file cua_sandbox-0.1.20.tar.gz.
File metadata
- Download URL: cua_sandbox-0.1.20.tar.gz
- Upload date:
- Size: 152.5 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.11.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
cd631128e5fdada45fa254ff5ea53f5e53a30ff103f31d98ebc617b4f5c740c8
|
|
| MD5 |
9700f8094efac75bc597c7cb5d07c194
|
|
| BLAKE2b-256 |
2835cff780bb19a1a121cb28fc673a0dadf19c39bd33257a25d1a422b17a9bf4
|
File details
Details for the file cua_sandbox-0.1.20-py3-none-any.whl.
File metadata
- Download URL: cua_sandbox-0.1.20-py3-none-any.whl
- Upload date:
- Size: 186.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via:
twine/7.0.0 CPython/3.11.9
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
b85b1f4ec39facf4caf1692436817b01cea81ef13fdd1f88bb7174a566411dde
|
|
| MD5 |
049c576f93373daac3dff103fd791de8
|
|
| BLAKE2b-256 |
6382cca8720316a7f6ed280617f6c5cc00259d50a73a1f660504c347ef7e71f8
|