Favicon of OpenSandbox

OpenSandbox

Self-hosted AI agent sandbox infrastructure runs locally with Docker or on Kubernetes, with network controls and an Apache 2.0 license.

Screenshot of OpenSandbox website

OpenSandbox gives AI agents isolated working environments on infrastructure you control. It's open source under Apache 2.0 and runs locally with Docker or on a Kubernetes cluster. It's for developers building coding agents, browser automation, or applications that execute model-generated code.

Agents can run shell commands, read and write files, use code interpreters, and operate browsers or desktops inside a sandbox. Examples cover Claude Code, Gemini CLI, and Codex, plus Chrome and Playwright workloads. It can also host VS Code Web for remote development. Outputs, logs, and metrics stream back to the application.

The same sandbox API covers local and cluster deployments, so applications can keep their integration when moving between them. Lifecycle controls include creating, monitoring, pausing, resuming, and terminating environments. Firecracker sandboxes preserve memory and disk state across pauses; resource pools and batch creation support agent evaluation and reinforcement learning workloads.

Network policies control outbound access for each sandbox, while an ingress gateway handles inbound traffic. A credential vault lets agents call external services without exposing real credentials to the code running inside their environments.

SDKs support Python, Java/Kotlin, JavaScript/TypeScript, C#/.NET, and Go. An MCP server connects clients such as Claude Code and Cursor to sandbox creation, command execution, and text file operations. Defined lifecycle and execution APIs also support custom runtime integrations.

Similar to OpenSandbox