Skip to content

Cloudflare Sandbox SDK

TrendingActive
cloudflare/sandbox-sdk

Run untrusted or AI-generated code in isolated per-user Linux sandboxes on Cloudflare, with file streaming, bucket mounts and backups.

View on GitHub
Stars
1.1k
Forks
117
Watchers
1.1k
Open issues
47

Overview

The Cloudflare Sandbox SDK lets you run untrusted or AI-generated code inside an isolated Linux environment that belongs to a single user, task, or session. It is a natural fit for coding agents, code interpreters, online IDEs, and CI-style jobs that need a real shell rather than a JavaScript isolate.

A sandbox is a Durable Object plus the Container it starts. Your Worker stays in control: it decides who gets a sandbox, which hosts that sandbox may reach, and which credentials never enter it.

What the SDK Adds

On top of the Containers API, @cloudflare/sandbox provides:

  • Files — stream files in and out of the running instance, with familiar Linux errors such as ENOENT
  • S3Mount — mount an S3-compatible bucket at a path; the Worker signs every storage request, so credentials stay outside the sandbox
  • DirectoryBackup — save a directory to R2 and restore it into any container, even one running a newer image

What You Can Build

  • Run a script and read its output
  • Keep a dev server or long build running in the background
  • Open an interactive terminal in the browser
  • Process files from an R2 bucket
  • Save a workspace and resume it later
  • Preview a web app while you edit it, including on its own hostname
  • Restrict which network hosts a sandbox can reach
  • Run a coding agent against a repository

Getting Started

Create a project from the minimal template:

npm create cloudflare@latest -- my-sandbox --template=cloudflare/sandbox-sdk/examples/minimal

The template gives each name in the URL its own sandbox. Your Durable Object starts the container on demand, writes a script with Files, executes it, and returns the output — and the Worker picks the right sandbox for each user with env.SANDBOX.getByName(...). The Worker needs the nodejs_compat flag, and the container image must include the helper used by Files.

If you only need to run JavaScript or Python without a full Linux environment, Cloudflare’s Dynamic Workers are a lighter option.

Upgrading from 0.x

Version 1.0 moved container ownership into your own Durable Object; the package now focuses on file operations, bucket mounts, and backups. An official migration guide maps every 0.x API to its replacement.

Use Cases

  • AI coding agents that need to clone repos, install packages, and run tests
  • Online code playgrounds and interpreters
  • Per-user build or data-processing jobs with strict network egress control

Similar open-source projects, ranked by shared categories and tags.

All AI projects →