SYSTEM Cited by 5 sources
Cloudflare Sandbox SDK¶
Sandbox SDK is Cloudflare's higher-level developer API for running untrusted or agent-generated code inside isolated Cloudflare Containers from a Workers application. It was announced in mid-2025 and is positioned as the structural answer to AI agents needing to execute arbitrary code securely without a user-managed container-lifecycle layer.
What the SDK gives you¶
Instead of raw Container APIs, the SDK exposes a small, ergonomic TypeScript surface for:
- Command execution:
sandbox.exec('node -v') - Filesystem management:
sandbox.mkdir(path, { recursive: true }) - Code contexts / REPL-style execution:
sandbox.createCodeContext({ language: 'python' })thensandbox.runCode(...)with persistent state across calls - Background processes
- Service exposure from inside the container
- Per-key sandbox instances:
getSandbox(env.Sandbox, 'user-123')— per-user or per-session isolation without the app managing lifecycle sandbox.mountBucket()— mount an R2 bucket as a filesystem partition inside the container, giving ephemeral containers a durable working directory with zero application code changes (canonical instance of mountable-persistent-storage)
The SDK owns container lifecycle, networking, file systems, process management, and the Worker↔container channel — letting the developer focus on application logic.
Relationship to Cloudflare Containers¶
Sandbox SDK is built on top of Cloudflare Containers. Containers are inherently ephemeral (durable-vs-ephemeral-sandbox); Sandbox SDK adds the ergonomic layer and the mountable-persistence escape hatch via R2.
Example¶
import { getSandbox } from '@cloudflare/sandbox';
export { Sandbox } from '@cloudflare/sandbox';
export default {
async fetch(request: Request, env: Env): Promise<Response> {
const sandbox = getSandbox(env.Sandbox, 'user-123');
await sandbox.mkdir('/workspace/project/src', { recursive: true });
const version = await sandbox.exec('node -v');
const ctx = await sandbox.createCodeContext({ language: 'python' });
await sandbox.runCode('import math; radius = 5', { context: ctx });
const result = await sandbox.runCode('math.pi * radius ** 2', { context: ctx });
return Response.json({ version, result });
}
};
Sandbox SDK 1.0 — utilities, not a base class (2026-09-30)¶
When Containers launched, Cloudflare deliberately hid the Durable Object
behind the Container class, and the Sandbox SDK was built on that class —
filling real gaps (native command execution, outbound request interception,
snapshots) in userspace. The 2026-09 Containers rearchitecture made those
capabilities native on ctx.container, and the cost of the abstraction became
clear: hiding the DO made it hard to combine its identity/state/coordination
with the Container it controls, and nearly every team needed something slightly
different from the generic lifecycle (own sleep policy, own credential handling,
own eval-run tracking). (Source:
sources/2026-09-30-cloudflare-containers-rebuilt-to-scale-agent-sandboxes)
So Cloudflare made the Durable Object explicit in the developer experience:
- New capabilities are native-only. The
durable_objectscheduling policy, faster startup, runtime image/instance selection, and filesystem snapshots are available only throughctx.container— not through the SDK's base class. Container+ legacySandboxclasses maintained through 2026-12-31. Existing deployments keep running after that date but the classes stop getting updates; Cloudflare recommends migrating toctx.container.- Sandbox SDK 1.0 is a set of utilities, not a base class. Its helpers work
inside your own Durable Object class, alongside
ctx.container. @cloudflare/computeris offered as the higher-level environment (Dynamic Workers + Containers + synchronized filesystem) for teams that want more than raw primitives.
Migration is mostly changing extends Container to extends DurableObject and
calling this.ctx.container directly.
Seen in¶
-
sources/2026-09-30-cloudflare-containers-rebuilt-to-scale-agent-sandboxes — canonical wiki instance of the Sandbox SDK 1.0 reframing: the SDK moves from a base
Container/Sandboxclass to a set of utilities usable inside your own DurableObject class, as the DO becomes the explicit Container controller viactx.container. Legacy classes maintained only through 2026-12-31; new capabilities (scheduling policy, snapshots, runtime image selection) are native-only. -
sources/2026-05-19-cloudflare-announcing-claude-managed-agents-on-cloudflare — canonical wiki instance of Sandbox SDK as the operator- facing surface for Cloudflare's hands deployment of Claude Managed Agents. The launch's microVM tier exposes its filesystem / exec / context-creation / mount surface to the brain (Claude) via Sandbox SDK; the integration's pre-bundled tools (
browser_search,screenshot,email_read, etc.) are Sandbox-SDK-shaped operations the agent's tool calls bottom out into. - sources/2026-01-29-cloudflare-moltworker-self-hosted-ai-agent —
canonical wiki instance. Moltworker runs
Moltbot's Gateway runtime inside a per-user
Sandbox; uses
sandbox.mountBucket()to turn R2 into the agent's durable filesystem; uses the SDK's command-exec surface to issue callbacks into the container, establishing a two-way channel with the entrypoint Worker. - sources/2026-04-20-cloudflare-internal-ai-engineering-stack — referenced alongside Dynamic Workers as the tier for running agent-generated code securely in Cloudflare's internal stack.
- sources/2026-04-15-cloudflare-project-think-building-the-next-generation-of-ai-agents
— positioned as Tier 4 of the Project Think
execution ladder — the top rung
where agent-generated code runs in a full-OS sandbox configured
with toolchains, repos, and dependencies (
git clone,npm test,cargo build). "Bidirectionally synced with the Workspace" — the Tier-0 filesystem is visible from the Tier-4 Sandbox. Integrated viacreateSandboxTools(env.SANDBOX)in Think'sgetTools(). - sources/2026-05-01-cloudflare-introducing-dynamic-workflows-durable-execution-that-follows-the-tenant
— heavy-corners tier in the CI/CD showcase. When a step
needs
docker build, an integration suite with Postgres, or a Rust 8-core compile, the dispatcher escalates from Dynamic Workers into a Sandbox. "Snapshots to R2 mean even those warm-start in a couple of seconds." Composes with Artifacts + ArtifactFS (checkout), Dynamic Workers (lightweight steps), and Dynamic Workflows (durable orchestration) in the
customer-authored CI pipeline pattern.
Related¶
- systems/cloudflare-containers — the lower-level container primitive Sandbox SDK wraps.
- systems/cloudflare-workers — the compute tier that drives Sandbox SDK.
- systems/cloudflare-r2 — mounted as durable filesystem via
mountBucket(). - systems/project-think — agent SDK that exposes Sandbox SDK as Tier 4 of the execution ladder.
- systems/dynamic-workers — the adjacent Tiers 1-3 isolate tier; the ladder escalates from Dynamic Workers to Sandbox when the workload needs full OS semantics.
- durable-vs-ephemeral-sandbox — the problem shape.
- execution-ladder — Tier 4 capability.
- mountable-persistent-storage — the R2-as-FS solution shape.
- additive-capability-ladder — the ladder pattern Sandbox SDK slots into.
- companies/cloudflare — operator.