
OpenSandbox gives AI agents isolated working environments on infrastructure you control. It's open source under Apache 2.0 and runs locally with Docker or on a Kubernetes cluster. It's for developers building coding agents, browser automation, or applications that execute model-generated code.
Agents can run shell commands, read and write files, use code interpreters, and operate browsers or desktops inside a sandbox. Examples cover Claude Code, Gemini CLI, and Codex, plus Chrome and Playwright workloads. It can also host VS Code Web for remote development. Outputs, logs, and metrics stream back to the application.
The same sandbox API covers local and cluster deployments, so applications can keep their integration when moving between them. Lifecycle controls include creating, monitoring, pausing, resuming, and terminating environments. Firecracker sandboxes preserve memory and disk state across pauses; resource pools and batch creation support agent evaluation and reinforcement learning workloads.
Network policies control outbound access for each sandbox, while an ingress gateway handles inbound traffic. A credential vault lets agents call external services without exposing real credentials to the code running inside their environments.
SDKs support Python, Java/Kotlin, JavaScript/TypeScript, C#/.NET, and Go. An MCP server connects clients such as Claude Code and Cursor to sandbox creation, command execution, and text file operations. Defined lifecycle and execution APIs also support custom runtime integrations.
Claim this page with an email at open-sandbox.ai. OpenSandbox gets the verified badge, and you can upgrade the listing to be featured on localhosted. Proud to be listed? Put our badge on your site.
Want more people to find OpenSandbox?Promote it
Something wrong or outdated on this page?
1.1KUpdated 17 hours agoMIT
Docker#Code execution#MCP#Tool calling
LLM Sandbox is a Python library for developers building AI agents and applications that need to execute model-generated code. It runs that code in isolated containers on infrastructure you control, with Docker and Podman backends or Kubernetes for cluster deployments. The project is open source under the MIT license.
9.5KUpdated 2 days agoApache-2.0
Docker · Web#Guardrails#MCP#Tool calling
12.8KUpdated 4 days agoApache-2.0
Docker#Agent Skills#Code execution#Distributed execution
1.2KUpdated 2 days agoApache-2.0
Linux · Docker#Code execution#Git integration#Guardrails
Coding Tools MCP gives AI chat apps and agents access to a codebase on your own machine through the Model Context Protocol (MCP). It's for developers who want their existing client to read files, edit code and run tests, with access confined to a chosen workspace. The Python server is open source under Apache 2.0 and can also run in Docker.
814Updated 15 hours ago
macOS · Linux · Docker · Web#Agent Client Protocol#Code execution#Git integration
Helix is a paid, self-hosted platform for engineering teams running coding agents in parallel. Each task gets an isolated Linux desktop with an editor, browser and terminal, so agents can build and test applications while teammates watch or take control through their browsers.
1.8KUpdated 3 months agoApache-2.0
macOS · Windows · Linux · Docker#Agent Client Protocol#Code execution#Guardrails
Higress is a self-hosted AI gateway for developers and teams managing model APIs and the tools their AI agents call. It puts LLM traffic and MCP servers behind a shared entry point, with authentication, traffic controls and monitoring. The open-source edition uses the Apache 2.0 license and runs locally in Docker without registration. Alibaba Cloud also offers a fully managed gateway.
AX is Google's self-hosted AI agent orchestrator for teams running autonomous workloads on a Kubernetes cluster. It uses Agent Substrate to isolate agent execution and manages the workspaces and model settings each task needs. The project is open source under Apache 2.0.
Stakpak is an open source AI agent for developers and DevOps teams who want to run production operations on their own machines or servers. It can work interactively in a terminal or run continuously in the background, investigating app health problems, taking corrective action and notifying a human when it needs help.