You can't run someone else's code on your laptop.
Whether it's an AI agent writing scripts, a customer uploading code, or a third-party plugin — once it executes locally, it has the same access you do. Mistakes, fork bombs, or worse.
Spin up an isolated environment with one API call. Run AI-generated code, untrusted scripts, or per-user workspaces — then pause, snapshot, or destroy. Built for real isolation and real speed, without sharing a kernel with your laptop.
// quickstart.ts› const sandbox = await client.sandboxes.createReady({ template: "python-3.12" });→ sandbox sbx_a1b2c3d4 ready iad-1 · 3.42s › await sandbox.exec({ cmd: "pip install anthropic" });Successfully installed anthropic-0.39.0→ exit 0 2.14s › await sandbox.runCode({ language: "python", code: "print(sum(range(10**6)))" });499999500000→ exit 0 0.18s › await sandbox.snapshots.create({ name: "agent-ready" });→ snapshot snap_e5f6g7 creating → ready 1.6s Whether it's an AI agent writing scripts, a customer uploading code, or a third-party plugin — once it executes locally, it has the same access you do. Mistakes, fork bombs, or worse.
VMs start in minutes and burn memory. Containers share a kernel with the host. Neither is the right tool for an ephemeral environment you spin up, use once, and throw away.
Coding playgrounds, AI agent tools, evaluation harnesses — they all need fresh, isolated workspaces per session. Building that yourself means orchestration, security, scheduling, and a lot of pager calls.
Real SDK, real API. First-party clients for TypeScript, Python, and Go — or just call the REST endpoints from anywhere. Pick a template, get a ready sandbox, and start executing.
npm install @brimble/sandbox1import { Sandbox } from "@brimble/sandbox";2 3const client = new Sandbox();4 5// 1. create a sandbox from a template6const sandbox = await client.sandboxes.createReady({7 template: "python-3.12",8 region: "auto",9 name: "agent-session",10});11 12// 2. run untrusted code inside it13const result = await sandbox.runCode({14 language: "python",15 code: "print(sum(range(10**6)))",16});17 18console.log(result.stdout); // "499999500000\n"19 20// 3. snapshot the filesystem, then clean up21await sandbox.snapshots.create({ name: "agent-ready" });22await sandbox.destroy();Every sandbox runs inside its own walled-off layer that sits between the code and the host — your machine and your other apps never see what happens inside. Sandboxes live on a host pool that never runs production apps, so a noisy one can't slow anything else down.
Step away from a long session and compute billing stops. Resume tomorrow and pick up exactly where you left off.
Capture a sandbox's filesystem, then restore into a fresh sandbox. Hand off a setup, or skip configuration next time.
await sandbox.snapshots.create({ name: "ready-to-go"});Sandboxes have normal network access by default. Pass blockOutbound: true at create time and the CNI policy denies all egress — useful when you're running something you don't fully trust.
Most sandboxes are throwaway and wipe on destroy. Attach a 10–50 GB volume and your files outlive the sandbox — then mount that same volume on a new one whenever you need it back.
Python, Node, Bun, Deno, Ubuntu — plus Claude Code, Codex, OpenCode, and Droid agent presets.
Same API surface across all three first-party SDKs. Or call the REST endpoints from any language.
putFile and getFile move bytes in and out. Pair with snapshots to ship environments to teammates.
Set a sandbox up exactly how you want it — packages installed, files in place, env wired up — then freeze that moment. New sandboxes boot from the frozen state in seconds. Hand one to a teammate, roll one back when something breaks, or fan out a hundred copies that all start where the work began.
Boot from where you left off — no more npm install loops
Hand a teammate the exact box — byte for byte, no setup notes
Rewind to a known-good state — before you touched anything risky
Fan out the same sandbox — one frozen state, many runners
// 1. Create a sandbox and set up your environmentconst sandbox = await client.sandboxes.createReady({ template: "node-22" });await sandbox.exec({ cmd: "npm install" });await sandbox.exec({ cmd: "npm run build" }); // 2. Capture the configured state as a snapshotconst snap = await sandbox.snapshots.create({ name: "ready-to-go" });console.log("snapshot ready:", snap.id); // 3. Restore into a fresh sandboxconst fast = await client.sandboxes.createReady({ fromSnapshot: snap.id }); // 4. Or fan out — many parallel sandboxes from one snapshotconst workers = await Promise.all([ client.sandboxes.createReady({ fromSnapshot: snap.id }), client.sandboxes.createReady({ fromSnapshot: snap.id }), client.sandboxes.createReady({ fromSnapshot: snap.id }),]);Create-to-ready in a few seconds, not minutes. Schedule, pull, isolate, attach network.
Five language runtimes plus four pre-installed AI coding agent presets.
TypeScript, Python, and Go — identical surface area across all three.
Attach a CSI-backed volume from 10 to 50 GB per sandbox; outlives the box.
Spend little to no time on DevOps and more time building. Super efficient way to host & scale your web app.