# microsandbox > Easy, fast microVMs for untrusted workloads, on your machine or in the cloud - [Introduction](https://docs.microsandbox.dev/getting-started/introduction.md): Easy, fast microVMs for untrusted workloads - [Quickstart](https://docs.microsandbox.dev/getting-started/quickstart.md): Get a sandbox running in under 5 minutes. - [Cloud](https://docs.microsandbox.dev/cloud/overview.md): Run the same sandboxes on hosted infrastructure with an API key - [AI agents](https://docs.microsandbox.dev/getting-started/agents.md): Connect AI agents to isolated microsandbox machines - [Overview](https://docs.microsandbox.dev/sandboxes/overview.md): What sandboxes are and how to configure them - [Lifecycle](https://docs.microsandbox.dev/sandboxes/lifecycle.md): Create, start, stop, and manage sandbox state - [Commands](https://docs.microsandbox.dev/sandboxes/commands.md): Execute commands, stream output, and interact with sandboxes - [Filesystem](https://docs.microsandbox.dev/sandboxes/filesystem.md): Read and write files inside a running sandbox - [Secrets](https://docs.microsandbox.dev/sandboxes/secrets.md): Let sandboxed code use credentials without receiving their values - [Images](https://docs.microsandbox.dev/images/overview.md): Use OCI container images or boot from disk image files - [Volumes](https://docs.microsandbox.dev/sandboxes/volumes.md): Persist and share data across sandboxes - [SSH](https://docs.microsandbox.dev/sandboxes/ssh.md): Connect to sandboxes through SSH protocol sessions - [Snapshots](https://docs.microsandbox.dev/sandboxes/snapshots.md): Save files or running workloads and restore them into new sandboxes - [Live Modify](https://docs.microsandbox.dev/sandboxes/tuning.md): Resize a running sandbox and update its configuration without replacing it - [Labels](https://docs.microsandbox.dev/sandboxes/labels.md): Organize sandboxes, act on them in bulk, and attribute metrics - [Logs](https://docs.microsandbox.dev/sandboxes/logs.md): Capture, read, and diagnose sandbox output - [Metrics](https://docs.microsandbox.dev/sandboxes/metrics.md): Monitor sandbox resource usage - [Bootstrap](https://docs.microsandbox.dev/sandboxes/bootstrap.md): Prepare scripts, patches, and PID 1 before work starts - [Overview](https://docs.microsandbox.dev/networking/overview.md): Control network access and isolation - [TLS inspection](https://docs.microsandbox.dev/networking/tls.md): Inspect HTTPS traffic and manage certificate trust - [DNS](https://docs.microsandbox.dev/networking/dns.md): Control how sandboxes resolve domain names - [Proxies](https://docs.microsandbox.dev/networking/outbound-proxy.md): Route outbound sandbox traffic through an HTTP CONNECT or SOCKS proxy - [Host sockets](https://docs.microsandbox.dev/networking/host-sockets.md): Connect a sandbox to a Unix socket or Windows named pipe - [Local or cloud](https://docs.microsandbox.dev/operations/backends.md): Choose where CLI and SDK operations run - [Configuration](https://docs.microsandbox.dev/operations/configuration.md): Understand how global defaults, sandbox YAML, CLI flags, SDK inputs, and managed settings determine sandbox configuration. - [Observability](https://docs.microsandbox.dev/observability/msb-metrics.md): Export microsandbox metrics to an OpenTelemetry-compatible backend - [Performance](https://docs.microsandbox.dev/sandboxes/optimization.md): Choose the settings that can improve local sandbox performance - [Linux](https://docs.microsandbox.dev/troubleshooting/linux.md): Diagnose KVM, permissions, and host runtime setup on Linux - [macOS](https://docs.microsandbox.dev/troubleshooting/macos.md): Diagnose Apple Silicon and local runtime setup on macOS - [Windows](https://docs.microsandbox.dev/troubleshooting/windows.md): Diagnose Windows Hypervisor Platform, doctor checks, and terminal setup - [Overview](https://docs.microsandbox.dev/sdk/overview.md): Install a microsandbox SDK, create your first microVM sandbox, and find API references for TypeScript, Rust, Python, Go, and Ruby. - [Runtime setup](https://docs.microsandbox.dev/sdk/setup.md): Prepare a local runtime before creating your first sandbox. - [Error handling](https://docs.microsandbox.dev/sdk/errors.md): Handle sandbox errors and clean up resources across the microsandbox SDKs. - [Global configuration](https://docs.microsandbox.dev/configuration.md): Configure microsandbox defaults for the CLI and SDKs using the shared config.json file. - [Sandbox](https://docs.microsandbox.dev/sdk/typescript/sandbox.md): Create and manage microVM sandboxes with the TypeScript SDK. - [Execution](https://docs.microsandbox.dev/sdk/typescript/execution.md): Run sandbox commands and stream their output with the TypeScript SDK. - [SSH](https://docs.microsandbox.dev/sdk/typescript/ssh.md): Open sandbox SSH sessions and transfer files over SFTP with the TypeScript SDK. - [Filesystem](https://docs.microsandbox.dev/sdk/typescript/filesystem.md): Read, write, and stream sandbox files with the TypeScript SDK. - [Volumes](https://docs.microsandbox.dev/sdk/typescript/volumes.md): Create and mount persistent sandbox volumes with the TypeScript SDK. - [Networking](https://docs.microsandbox.dev/sdk/typescript/networking.md): Configure sandbox network policies with the TypeScript SDK. - [Proxies](https://docs.microsandbox.dev/sdk/typescript/proxies.md): Route outbound sandbox connections through an HTTP CONNECT, SOCKS4, or SOCKS5 proxy with the TypeScript SDK. - [VSock](https://docs.microsandbox.dev/sdk/typescript/vsock.md): Connect a sandbox to host Unix sockets or local Windows named pipes over virtio-vsock with the TypeScript SDK. - [Secrets](https://docs.microsandbox.dev/sdk/typescript/secrets.md): Configure destination-bound sandbox credentials with the TypeScript SDK. - [Snapshots](https://docs.microsandbox.dev/sdk/typescript/snapshots.md): Create and restore sandbox snapshots with the TypeScript SDK. - [Images](https://docs.microsandbox.dev/sdk/typescript/images.md): Inspect and manage the local OCI image cache with the TypeScript SDK. - [Agent client](https://docs.microsandbox.dev/sdk/typescript/agent-client.md): Send requests to the sandbox guest agent with the TypeScript SDK. - [Sandbox](https://docs.microsandbox.dev/sdk/rust/sandbox.md): Create and manage microVM sandboxes with the Rust SDK. - [Execution](https://docs.microsandbox.dev/sdk/rust/execution.md): Run sandbox commands and stream their output with the Rust SDK. - [SSH](https://docs.microsandbox.dev/sdk/rust/ssh.md): Open sandbox SSH sessions and transfer files over SFTP with the Rust SDK. - [Filesystem](https://docs.microsandbox.dev/sdk/rust/filesystem.md): Read, write, and stream sandbox files with the Rust SDK. - [Volumes](https://docs.microsandbox.dev/sdk/rust/volumes.md): Create and mount persistent sandbox volumes with the Rust SDK. - [Networking](https://docs.microsandbox.dev/sdk/rust/networking.md): Configure sandbox network policies with the Rust SDK. - [Proxies](https://docs.microsandbox.dev/sdk/rust/proxies.md): Route outbound sandbox connections through an HTTP CONNECT, SOCKS4, or SOCKS5 proxy with the Rust SDK. - [VSock](https://docs.microsandbox.dev/sdk/rust/vsock.md): Connect a sandbox to host Unix sockets or local Windows named pipes over virtio-vsock with the Rust SDK. - [Secrets](https://docs.microsandbox.dev/sdk/rust/secrets.md): Configure destination-bound sandbox credentials with the Rust SDK. - [Snapshots](https://docs.microsandbox.dev/sdk/rust/snapshots.md): Create and restore sandbox snapshots with the Rust SDK. - [Images](https://docs.microsandbox.dev/sdk/rust/images.md): Inspect and manage the local OCI image cache with the Rust SDK. - [Agent client](https://docs.microsandbox.dev/sdk/rust/agent-client.md): Send requests to the sandbox guest agent with the Rust SDK. - [Sandbox](https://docs.microsandbox.dev/sdk/python/sandbox.md): Create and manage microVM sandboxes with the Python SDK. - [Execution](https://docs.microsandbox.dev/sdk/python/execution.md): Run sandbox commands and stream their output with the Python SDK. - [SSH](https://docs.microsandbox.dev/sdk/python/ssh.md): Open sandbox SSH sessions and transfer files over SFTP with the Python SDK. - [Filesystem](https://docs.microsandbox.dev/sdk/python/filesystem.md): Read, write, and stream sandbox files with the Python SDK. - [Volumes](https://docs.microsandbox.dev/sdk/python/volumes.md): Create and mount persistent sandbox volumes with the Python SDK. - [Networking](https://docs.microsandbox.dev/sdk/python/networking.md): Configure sandbox network policies with the Python SDK. - [Proxies](https://docs.microsandbox.dev/sdk/python/proxies.md): Route outbound sandbox connections through an HTTP CONNECT, SOCKS4, or SOCKS5 proxy with the Python SDK. - [VSock](https://docs.microsandbox.dev/sdk/python/vsock.md): Connect a sandbox to host Unix sockets or local Windows named pipes over virtio-vsock with the Python SDK. - [Secrets](https://docs.microsandbox.dev/sdk/python/secrets.md): Configure destination-bound sandbox credentials with the Python SDK. - [Snapshots](https://docs.microsandbox.dev/sdk/python/snapshots.md): Create and restore sandbox snapshots with the Python SDK. - [Images](https://docs.microsandbox.dev/sdk/python/images.md): Configure sandbox image sources and manage the local cache with the Python SDK. - [Agent client](https://docs.microsandbox.dev/sdk/python/agent-client.md): Send requests to the sandbox guest agent with the Python SDK. - [Sandbox](https://docs.microsandbox.dev/sdk/go/sandbox.md): Create and manage microVM sandboxes with the Go SDK. - [Execution](https://docs.microsandbox.dev/sdk/go/execution.md): Run sandbox commands and stream their output with the Go SDK. - [SSH](https://docs.microsandbox.dev/sdk/go/ssh.md): Open sandbox SSH sessions and transfer files over SFTP with the Go SDK. - [Filesystem](https://docs.microsandbox.dev/sdk/go/filesystem.md): Read, write, and stream sandbox files with the Go SDK. - [Volumes](https://docs.microsandbox.dev/sdk/go/volumes.md): Create and mount persistent sandbox volumes with the Go SDK. - [Images](https://docs.microsandbox.dev/sdk/go/images.md): Inspect and manage the local OCI image cache with the Go SDK. - [Networking](https://docs.microsandbox.dev/sdk/go/networking.md): Configure sandbox network policies with the Go SDK. - [Proxies](https://docs.microsandbox.dev/sdk/go/proxies.md): Route outbound sandbox connections through an HTTP CONNECT, SOCKS4, or SOCKS5 proxy with the Go SDK. - [VSock](https://docs.microsandbox.dev/sdk/go/vsock.md): Connect a sandbox to host Unix sockets or local Windows named pipes over virtio-vsock with the Go SDK. - [Secrets](https://docs.microsandbox.dev/sdk/go/secrets.md): Configure destination-bound sandbox credentials with the Go SDK. - [Snapshots](https://docs.microsandbox.dev/sdk/go/snapshots.md): Create and restore sandbox snapshots with the Go SDK. - [Agent client](https://docs.microsandbox.dev/sdk/go/agent-client.md): Send requests to the sandbox guest agent with the Go SDK. - [Sandbox](https://docs.microsandbox.dev/sdk/ruby/sandbox.md): Create and manage microVM sandboxes with the Ruby SDK. - [Configuration](https://docs.microsandbox.dev/sdk/ruby/configuration.md): Select a backend and configure the local runtime with the Ruby SDK. - [Execution](https://docs.microsandbox.dev/sdk/ruby/execution.md): Run commands and collect output with the Ruby SDK. - [SSH](https://docs.microsandbox.dev/sdk/ruby/ssh.md): Run SSH commands with the Ruby SDK. - [Filesystem](https://docs.microsandbox.dev/sdk/ruby/filesystem.md): Read, write, and transfer guest files with the Ruby SDK. - [Volumes](https://docs.microsandbox.dev/sdk/ruby/volumes.md): Create and manage named volumes with the Ruby SDK. - [Networking](https://docs.microsandbox.dev/sdk/ruby/networking.md): Configure network access, proxies, and secret injection with the Ruby SDK. - [VSock](https://docs.microsandbox.dev/sdk/ruby/vsock.md): Connect a sandbox to host Unix sockets or local Windows named pipes over virtio-vsock with the Ruby SDK. - [Snapshots](https://docs.microsandbox.dev/sdk/ruby/snapshots.md): Capture and manage snapshots with the Ruby SDK. - [Images](https://docs.microsandbox.dev/sdk/ruby/images.md): Inspect and manage cached images with the Ruby SDK. - [CLI overview](https://docs.microsandbox.dev/cli/overview.md): Install the microsandbox CLI and manage local or cloud microVM sandboxes from your terminal. - [Configuration](https://docs.microsandbox.dev/cli/configuration.md): Configure sandbox resources, networking, and storage with reusable microsandbox CLI YAML files. - [Sandbox commands](https://docs.microsandbox.dev/cli/sandbox-commands.md): Create, run, connect to, and remove microVM sandboxes with the microsandbox CLI. - [Snapshot commands](https://docs.microsandbox.dev/cli/snapshot-commands.md): Capture, inspect, restore, and transfer sandbox snapshots with the microsandbox CLI. - [SSH commands](https://docs.microsandbox.dev/cli/ssh-commands.md): Connect to running sandboxes and serve SSH endpoints with the microsandbox CLI. - [Volume commands](https://docs.microsandbox.dev/cli/volume-commands.md): Create, mount, and manage persistent sandbox volumes with the microsandbox CLI. - [Storage accounting and cleanup](https://docs.microsandbox.dev/cli/storage-commands.md): Inspect local storage and safely reclaim unused runtime memory backing - [Image commands](https://docs.microsandbox.dev/cli/image-commands.md): Pull, inspect, and manage cached OCI images with the microsandbox CLI. - [Registry commands](https://docs.microsandbox.dev/cli/registry-commands.md): Manage container registry credentials for local OCI image pulls with the microsandbox CLI. - [CLI management](https://docs.microsandbox.dev/cli/management.md): Inspect the active backend, diagnose runtime setup, and manage the microsandbox CLI installation. - [Overview](https://docs.microsandbox.dev/api-reference/overview.md): Authenticate cloud REST API requests with API keys or personal tokens, and handle errors and pagination. - [List sandboxes](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/list-sandboxes.md): List the organization's sandboxes with cursor pagination and optional label filtering. - [Create a sandbox](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/create-a-sandbox.md): Create a sandbox, optionally start it immediately, and optionally wait until it is ready. - [Get a sandbox by name](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/get-a-sandbox-by-name.md): Retrieve one sandbox by its organization-scoped name. - [Delete a sandbox by name](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/delete-a-sandbox-by-name.md): Delete a sandbox selected by its organization-scoped name. Resource cleanup continues asynchronously. - [Start a sandbox by name](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/start-a-sandbox-by-name.md): Start a sandbox selected by its organization-scoped name. - [Stop a sandbox by name](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/stop-a-sandbox-by-name.md): Stop a running sandbox selected by its organization-scoped name. - [Get a sandbox](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/get-a-sandbox.md): Retrieve one sandbox by its unique identifier. - [Delete a sandbox](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/delete-a-sandbox.md): Delete a sandbox. Resource cleanup continues asynchronously. - [Update a sandbox](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/update-a-sandbox.md): Rename a sandbox by updating its display name or slug. - [Get sandbox metrics](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/get-sandbox-metrics.md) - [Start a sandbox](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/start-a-sandbox.md): Start a sandbox and optionally wait until it is running. - [Stop a sandbox](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/stop-a-sandbox.md): Stop a running sandbox. - [List mounted volumes](https://docs.microsandbox.dev/api-reference/endpoints/sandboxes/list-mounted-volumes.md) - [List snapshot candidates](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/list-snapshot-candidates.md): List persistent, stopped sandboxes supported by the current disk snapshot policy. - [List snapshot operations](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/list-snapshot-operations.md): List asynchronous snapshot operations requested by this organization. - [Get a snapshot operation](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/get-a-snapshot-operation.md): Poll an asynchronous snapshot operation. - [List snapshots](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/list-snapshots.md): List the organization's managed disk snapshots. - [Create a snapshot](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/create-a-snapshot.md): Create a managed or host-volume disk snapshot asynchronously. - [Get a snapshot by name](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/get-a-snapshot-by-name.md): Retrieve a managed disk snapshot by its organization-unique name. - [Delete a snapshot by name](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/delete-a-snapshot-by-name.md): Delete a managed disk snapshot by its organization-unique name. - [Get a snapshot](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/get-a-snapshot.md): Retrieve a managed disk snapshot by its immutable identifier. - [Delete a snapshot](https://docs.microsandbox.dev/api-reference/endpoints/snapshots/delete-a-snapshot.md): Delete a managed disk snapshot by its immutable identifier. - [List volumes](https://docs.microsandbox.dev/api-reference/endpoints/volumes/list-volumes.md): List persistent volumes available to the organization, including current usage. - [Create a volume](https://docs.microsandbox.dev/api-reference/endpoints/volumes/create-a-volume.md): Create a named persistent volume with optional capacity and labels. - [Get the default volume](https://docs.microsandbox.dev/api-reference/endpoints/volumes/get-the-default-volume.md) - [Delete a volume](https://docs.microsandbox.dev/api-reference/endpoints/volumes/delete-a-volume.md): Schedule an unused named volume for deletion. - [Update a volume](https://docs.microsandbox.dev/api-reference/endpoints/volumes/update-a-volume.md): Update a named volume's capacity limit or labels. - [List directory contents](https://docs.microsandbox.dev/api-reference/endpoints/volumes/list-directory-contents.md) - [Delete a file or directory](https://docs.microsandbox.dev/api-reference/endpoints/volumes/delete-a-file-or-directory.md) - [Read a file](https://docs.microsandbox.dev/api-reference/endpoints/volumes/read-a-file.md) - [Write a file](https://docs.microsandbox.dev/api-reference/endpoints/volumes/write-a-file.md) - [Copy a file or directory](https://docs.microsandbox.dev/api-reference/endpoints/volumes/copy-a-file-or-directory.md) - [Check if a file exists](https://docs.microsandbox.dev/api-reference/endpoints/volumes/check-if-a-file-exists.md) - [Create a directory](https://docs.microsandbox.dev/api-reference/endpoints/volumes/create-a-directory.md) - [Move a file or directory](https://docs.microsandbox.dev/api-reference/endpoints/volumes/move-a-file-or-directory.md) - [Get file details](https://docs.microsandbox.dev/api-reference/endpoints/volumes/get-file-details.md) - [Get volume metrics](https://docs.microsandbox.dev/api-reference/endpoints/volumes/get-volume-metrics.md) - [Get quota usage](https://docs.microsandbox.dev/api-reference/endpoints/quotas/get-quota-usage.md): Return current resource usage, plan limits, and organization-specific quota overrides. - [Get billing summary](https://docs.microsandbox.dev/api-reference/endpoints/billing/get-billing-summary.md) - [List invoices](https://docs.microsandbox.dev/api-reference/endpoints/billing/list-invoices.md) - [Get an invoice](https://docs.microsandbox.dev/api-reference/endpoints/billing/get-an-invoice.md) - [List billing plans](https://docs.microsandbox.dev/api-reference/endpoints/billing/list-billing-plans.md) - [Get a usage summary](https://docs.microsandbox.dev/api-reference/endpoints/billing/get-a-usage-summary.md): Return billable usage for the organization. - [Get per-sandbox usage](https://docs.microsandbox.dev/api-reference/endpoints/billing/get-per-sandbox-usage.md): Return billable usage grouped by sandbox for a selected UTC time range. - [Get per-volume storage usage](https://docs.microsandbox.dev/api-reference/endpoints/billing/get-per-volume-storage-usage.md): Return persistent storage usage grouped by volume for a selected UTC time range. - [List audit events](https://docs.microsandbox.dev/api-reference/endpoints/audit-events/list-audit-events.md): List audit events for the organization with cursor pagination and optional filters. - [Get an audit event](https://docs.microsandbox.dev/api-reference/endpoints/audit-events/get-an-audit-event.md): Retrieve one audit event by its identifier. - [Get the current organization](https://docs.microsandbox.dev/api-reference/endpoints/organization/get-the-current-organization.md): Returns the organization associated with the current credential. - [List organization members](https://docs.microsandbox.dev/api-reference/endpoints/members/list-organization-members.md): List organization members and their roles with cursor pagination. - [Get your profile](https://docs.microsandbox.dev/api-reference/personal/account/get-your-profile.md) - [Delete your account](https://docs.microsandbox.dev/api-reference/personal/account/delete-your-account.md): Deletes the account's personal information, signs out active sessions, removes organization memberships, and revokes pending invitations sent by the user. Audit history is retained. - [Update your profile](https://docs.microsandbox.dev/api-reference/personal/account/update-your-profile.md) - [List your organizations](https://docs.microsandbox.dev/api-reference/personal/organization/list-your-organizations.md) - [Create an organization](https://docs.microsandbox.dev/api-reference/personal/organization/create-an-organization.md): The current user becomes its owner. - [Get an organization](https://docs.microsandbox.dev/api-reference/personal/organization/get-an-organization.md) - [Delete an organization](https://docs.microsandbox.dev/api-reference/personal/organization/delete-an-organization.md): Hides the organization immediately and schedules its resources for cleanup. The request must confirm the organization slug. - [Update an organization](https://docs.microsandbox.dev/api-reference/personal/organization/update-an-organization.md) - [List organization members](https://docs.microsandbox.dev/api-reference/personal/members/list-organization-members.md) - [Remove a member](https://docs.microsandbox.dev/api-reference/personal/members/remove-a-member.md) - [Change a member's role](https://docs.microsandbox.dev/api-reference/personal/members/change-a-members-role.md) - [Accept an invite](https://docs.microsandbox.dev/api-reference/personal/invites/accept-an-invite.md) - [Decline an invite](https://docs.microsandbox.dev/api-reference/personal/invites/decline-an-invite.md) - [List pending invites](https://docs.microsandbox.dev/api-reference/personal/invites/list-pending-invites.md) - [Invite a member](https://docs.microsandbox.dev/api-reference/personal/invites/invite-a-member.md) - [Cancel an invite](https://docs.microsandbox.dev/api-reference/personal/invites/cancel-an-invite.md) - [Get organization SSO settings](https://docs.microsandbox.dev/api-reference/personal/oidc/get-organization-sso-settings.md) - [Configure organization SSO](https://docs.microsandbox.dev/api-reference/personal/oidc/configure-organization-sso.md) - [Remove organization SSO settings](https://docs.microsandbox.dev/api-reference/personal/oidc/remove-organization-sso-settings.md) - [List API keys](https://docs.microsandbox.dev/api-reference/personal/credentials/list-api-keys.md): Admins and owners see all keys. Members see only their own keys. - [List personal tokens](https://docs.microsandbox.dev/api-reference/personal/credentials/list-personal-tokens.md): Returns metadata without token values. - [Revoke a personal token](https://docs.microsandbox.dev/api-reference/personal/credentials/revoke-a-personal-token.md): Returns not found when the token is missing or already revoked. - [List registry credentials](https://docs.microsandbox.dev/api-reference/personal/registry-credentials/list-registry-credentials.md): Returns credential metadata without secret values. - [Create or update a registry credential](https://docs.microsandbox.dev/api-reference/personal/registry-credentials/create-or-update-a-registry-credential.md): Each registry host can have one stored credential. - [Delete a registry credential](https://docs.microsandbox.dev/api-reference/personal/registry-credentials/delete-a-registry-credential.md) - [Check sandbox name availability](https://docs.microsandbox.dev/api-reference/personal/sandboxes/check-sandbox-name-availability.md): Check whether the sandbox slug is valid and available. - [Suggest a sandbox name](https://docs.microsandbox.dev/api-reference/personal/sandboxes/suggest-a-sandbox-name.md): Generate an available sandbox slug. - [List sandboxes](https://docs.microsandbox.dev/api-reference/personal/sandboxes/list-sandboxes.md) - [Create a sandbox](https://docs.microsandbox.dev/api-reference/personal/sandboxes/create-a-sandbox.md): By default, the sandbox is created without starting. Use `start=true` to start it immediately and `wait_for=running` to wait until it is ready. - [Get a sandbox](https://docs.microsandbox.dev/api-reference/personal/sandboxes/get-a-sandbox.md) - [Delete a sandbox](https://docs.microsandbox.dev/api-reference/personal/sandboxes/delete-a-sandbox.md): Resource cleanup continues asynchronously. - [Update a sandbox](https://docs.microsandbox.dev/api-reference/personal/sandboxes/update-a-sandbox.md) - [Get sandbox metrics](https://docs.microsandbox.dev/api-reference/personal/sandboxes/get-sandbox-metrics.md): Returns CPU, memory, disk, and network metrics for a time range. - [Start a sandbox](https://docs.microsandbox.dev/api-reference/personal/sandboxes/start-a-sandbox.md) - [Stop a sandbox](https://docs.microsandbox.dev/api-reference/personal/sandboxes/stop-a-sandbox.md) - [List mounted volumes](https://docs.microsandbox.dev/api-reference/personal/sandboxes/list-mounted-volumes.md) - [List sandboxes available for snapshots](https://docs.microsandbox.dev/api-reference/personal/snapshots/list-sandboxes-available-for-snapshots.md) - [List snapshot operations](https://docs.microsandbox.dev/api-reference/personal/snapshots/list-snapshot-operations.md) - [Get a snapshot operation](https://docs.microsandbox.dev/api-reference/personal/snapshots/get-a-snapshot-operation.md) - [List snapshots](https://docs.microsandbox.dev/api-reference/personal/snapshots/list-snapshots.md) - [Create a snapshot](https://docs.microsandbox.dev/api-reference/personal/snapshots/create-a-snapshot.md) - [Get a snapshot by name](https://docs.microsandbox.dev/api-reference/personal/snapshots/get-a-snapshot-by-name.md) - [Delete a snapshot by name](https://docs.microsandbox.dev/api-reference/personal/snapshots/delete-a-snapshot-by-name.md) - [Get a snapshot by ID](https://docs.microsandbox.dev/api-reference/personal/snapshots/get-a-snapshot-by-id.md) - [Delete a snapshot by ID](https://docs.microsandbox.dev/api-reference/personal/snapshots/delete-a-snapshot-by-id.md) - [List volumes](https://docs.microsandbox.dev/api-reference/personal/volumes/list-volumes.md) - [Create a volume](https://docs.microsandbox.dev/api-reference/personal/volumes/create-a-volume.md) - [Get the default volume](https://docs.microsandbox.dev/api-reference/personal/volumes/get-the-default-volume.md) - [Delete a volume](https://docs.microsandbox.dev/api-reference/personal/volumes/delete-a-volume.md) - [Update a volume](https://docs.microsandbox.dev/api-reference/personal/volumes/update-a-volume.md) - [List directory contents](https://docs.microsandbox.dev/api-reference/personal/volumes/list-directory-contents.md) - [Delete a file or directory](https://docs.microsandbox.dev/api-reference/personal/volumes/delete-a-file-or-directory.md) - [Read a file](https://docs.microsandbox.dev/api-reference/personal/volumes/read-a-file.md) - [Write a file](https://docs.microsandbox.dev/api-reference/personal/volumes/write-a-file.md) - [Copy a file or directory](https://docs.microsandbox.dev/api-reference/personal/volumes/copy-a-file-or-directory.md) - [Check if a file exists](https://docs.microsandbox.dev/api-reference/personal/volumes/check-if-a-file-exists.md) - [Check if files exist](https://docs.microsandbox.dev/api-reference/personal/volumes/check-if-files-exist.md) - [Create a directory](https://docs.microsandbox.dev/api-reference/personal/volumes/create-a-directory.md) - [Move a file or directory](https://docs.microsandbox.dev/api-reference/personal/volumes/move-a-file-or-directory.md) - [Get file details](https://docs.microsandbox.dev/api-reference/personal/volumes/get-file-details.md) - [Get volume metrics](https://docs.microsandbox.dev/api-reference/personal/volumes/get-volume-metrics.md) - [Get quota usage](https://docs.microsandbox.dev/api-reference/personal/quotas/get-quota-usage.md) - [Get billing summary](https://docs.microsandbox.dev/api-reference/personal/billing/get-billing-summary.md) - [Cancel the subscription](https://docs.microsandbox.dev/api-reference/personal/billing/cancel-the-subscription.md): Cancellation takes effect at the end of the billing period. - [List invoices](https://docs.microsandbox.dev/api-reference/personal/billing/list-invoices.md) - [Get an invoice](https://docs.microsandbox.dev/api-reference/personal/billing/get-an-invoice.md) - [Open the payment portal](https://docs.microsandbox.dev/api-reference/personal/billing/open-the-payment-portal.md): Returns a URL for managing payment methods. - [Change the billing plan](https://docs.microsandbox.dev/api-reference/personal/billing/change-the-billing-plan.md) - [List billing plans](https://docs.microsandbox.dev/api-reference/personal/billing/list-billing-plans.md) - [Get estimated usage costs](https://docs.microsandbox.dev/api-reference/personal/billing/get-estimated-usage-costs.md): Includes the subscription and estimated overage for the current period. - [Get sandbox usage](https://docs.microsandbox.dev/api-reference/personal/billing/get-sandbox-usage.md): Groups compute usage by sandbox and day for the requested time range. - [Get storage usage](https://docs.microsandbox.dev/api-reference/personal/billing/get-storage-usage.md): Groups persistent storage usage by volume and day for the requested time range. - [List audit events](https://docs.microsandbox.dev/api-reference/personal/audit-events/list-audit-events.md): Returns customer-visible audit events with optional filters. - [Get an audit event](https://docs.microsandbox.dev/api-reference/personal/audit-events/get-an-audit-event.md) - [Examples](https://docs.microsandbox.dev/examples/overview.md): Practical, tested microsandbox workflows for agents, CI, automation, tooling, browsers, data, and files - [Claude Code](https://docs.microsandbox.dev/examples/agents/claude-code.md): Run Anthropic's Claude Code against a project on your host - [Codex CLI](https://docs.microsandbox.dev/examples/agents/codex.md): Run OpenAI Codex CLI against a project on your host - [OpenCode](https://docs.microsandbox.dev/examples/agents/opencode.md): Run the OpenCode terminal agent against a project on your host - [OpenClaw](https://docs.microsandbox.dev/examples/agents/openclaw.md): Onboard OpenClaw and run its persistent gateway inside a microVM - [Goose](https://docs.microsandbox.dev/examples/agents/goose.md): Run the native Goose coding agent against a project on your host - [Gemini CLI](https://docs.microsandbox.dev/examples/agents/gemini-cli.md): Run Google's Gemini CLI against a project on your host - [Hermes Agent](https://docs.microsandbox.dev/examples/agents/hermes-agent.md): Set up Hermes Agent from its official image and persist its state - [Pi coding agent](https://docs.microsandbox.dev/examples/agents/pi.md): Run the Pi terminal coding agent against a project on your host - [Using with VS Code](https://docs.microsandbox.dev/examples/development/vscode.md): Edit files and run tools in a sandbox with VS Code Remote-SSH - [Use JetBrains with a sandboxed agent](https://docs.microsandbox.dev/examples/development/jetbrains-acp.md): Run OpenCode in a sandbox and chat with it from your JetBrains IDE - [code-server](https://docs.microsandbox.dev/examples/development/code-server.md): Open an isolated VS Code workspace in the browser - [JupyterLab](https://docs.microsandbox.dev/examples/development/jupyterlab.md): Run token-authenticated notebooks in an isolated Python environment - [VNC desktop](https://docs.microsandbox.dev/examples/development/vnc-desktop.md): Open a modern CPU-only Linux desktop in the browser with LXQt, TigerVNC, and noVNC - [Run GitHub Actions in a microVM](https://docs.microsandbox.dev/examples/ci-cd/github-actions-runner.md): Give one self-hosted job a disposable runner - [Run isolated PR checks](https://docs.microsandbox.dev/examples/ci-cd/pr-checks.md): Stream a commit into a bounded microVM and run its tests there - [Run Docker Compose integration tests](https://docs.microsandbox.dev/examples/ci-cd/compose-tests.md): Run a Compose stack without exposing the host Docker socket - [Create an ephemeral preview deploy](https://docs.microsandbox.dev/examples/ci-cd/preview-deploys.md): Serve a built site from a time-limited microVM - [Schedule dependency audits](https://docs.microsandbox.dev/examples/automation/dependency-audits.md): Run npm audit in a short-lived sandbox and copy out the report - [Fan out isolated batch jobs](https://docs.microsandbox.dev/examples/automation/parallel-batch-jobs.md): Run independent inputs in parallel microVMs and collect their output - [Start warm workers from a snapshot](https://docs.microsandbox.dev/examples/sandboxing/warm-workers.md): Install a toolchain once and launch clean workers from the captured disk state - [Browser Use](https://docs.microsandbox.dev/examples/browser-automation/browser-use.md): Run an AI browser agent with isolated Chromium inside a microVM - [Playwright](https://docs.microsandbox.dev/examples/browser-automation/playwright.md): Capture pages or expose a remote browser server without a GPU - [Crawl a site with Scrapy](https://docs.microsandbox.dev/examples/web-automation/scrapy.md): Run a bounded crawler with a single-site network allowlist - [Convert documents and render PDFs](https://docs.microsandbox.dev/examples/file-processing/libreoffice-pdf.md): Prepare LibreOffice once, then convert untrusted documents without network access - [Transcode media with FFmpeg](https://docs.microsandbox.dev/examples/file-processing/ffmpeg.md): Prepare FFmpeg once and process untrusted media in an offline worker - [Docker in a sandbox](https://docs.microsandbox.dev/examples/docker/docker-in-sandbox.md): Start dockerd inside a microsandbox VM and run containers from an interactive shell - [Run microsandbox in Docker](https://docs.microsandbox.dev/examples/docker/docker.md): Run the microsandbox CLI from a Linux container with KVM access - [Using local Docker images](https://docs.microsandbox.dev/examples/docker/local-images.md): Use locally built Docker images with microsandbox - [Booting under systemd](https://docs.microsandbox.dev/examples/guest/systemd-services.md): Hand PID 1 to systemd inside the guest so services run under a real init - [Vet a Terraform provider offline](https://docs.microsandbox.dev/examples/plugins/terraform.md): Download a provider once, then validate and plan without network access - [Mount S3 with JuiceFS](https://docs.microsandbox.dev/examples/data/juicefs-s3.md): Mount an S3-backed JuiceFS filesystem and verify persistent file operations inside a sandbox - [PostgreSQL](https://docs.microsandbox.dev/examples/data/postgresql.md): Run a persistent PostgreSQL service with a localhost-only forwarded port - [Rehearse a database migration](https://docs.microsandbox.dev/examples/data/migration-rehearsal.md): Snapshot PostgreSQL, apply a risky migration, and restore the baseline - [Redis](https://docs.microsandbox.dev/examples/data/redis.md): Run an authenticated Redis service with persistent data - [Grafana Cloud](https://docs.microsandbox.dev/examples/metrics-backends/grafana-cloud.md): Ship msb-metrics output to Grafana Cloud's OTLP gateway - [Grafana Alloy](https://docs.microsandbox.dev/examples/metrics-backends/grafana-alloy.md): Forward msb-metrics output to Grafana Cloud (or anywhere) via local Alloy - [otel-collector](https://docs.microsandbox.dev/examples/metrics-backends/otel-collector.md): Inspect msb-metrics output locally with the OpenTelemetry Collector - [Prometheus](https://docs.microsandbox.dev/examples/metrics-backends/prometheus.md): Ship msb-metrics output directly to Prometheus's OTLP ingestion endpoint - [Datadog](https://docs.microsandbox.dev/examples/metrics-backends/datadog.md): Ship msb-metrics output to Datadog via the Datadog Agent's OTLP receiver - [Enterprise deployment](https://docs.microsandbox.dev/enterprise.md): Choose a deployment approach for employee devices or your own infrastructure - [Prepare your environment](https://docs.microsandbox.dev/enterprise/prepare-environment.md): Prepare and test one local installation before deploying to the team - [Configure company networking](https://docs.microsandbox.dev/enterprise/corporate-networking.md): Use company routing, DNS, certificates, and registries with local sandboxes - [Enforce team settings](https://docs.microsandbox.dev/enterprise/managed-configuration.md): Define the settings your team must use and protect them on employee devices - [Deploy and verify](https://docs.microsandbox.dev/enterprise/deploy-and-verify.md): Pilot your configuration, distribute it to employee devices, and manage updates - [Talk to the microsandbox team](https://docs.microsandbox.dev/enterprise/contact.md): Let’s plan your microsandbox deployment - [Security model](https://docs.microsandbox.dev/security/overview.md): The trust boundary microsandbox enforces, what it protects, and what it leaves to you - [Isolation boundary](https://docs.microsandbox.dev/security/isolation.md): The microVM boundary, the host-guest control channel, and in-guest privilege - [Filesystem & images](https://docs.microsandbox.dev/security/filesystem.md): Private root, mounts, snapshots, and the image supply chain - [Network defenses](https://docs.microsandbox.dev/security/network.md): Egress filtering, SSRF, DNS rebinding, and cloud-metadata protection - [Secret handling](https://docs.microsandbox.dev/security/secrets.md): How credentials stay on the host, and the exact boundary of the guarantee - [Hardening](https://docs.microsandbox.dev/security/hardening.md): Dial the controls to match your threat level - [Migrating from v0.6 to v0.7](https://docs.microsandbox.dev/migrations/v0.7.md): Upgrade existing sandboxes, update secret and snapshot code, and understand rollback limits. - [v0.7.6](https://docs.microsandbox.dev/changelog/v0.7.6.md): Host paths stay fixed after a sandbox is created, and local volume operations stay inside the volume. - [v0.7.5](https://docs.microsandbox.dev/changelog/v0.7.5.md): Fork running sandboxes with clearer commands, run scripted commands without stdin, and opt in to readable network denials. - [v0.7.4](https://docs.microsandbox.dev/changelog/v0.7.4.md): More reliable secret scanning, writable macOS hard links, and typed Ruby errors. - [v0.7.3](https://docs.microsandbox.dev/changelog/v0.7.3.md): Enforce team settings, work with simpler snapshot commands, and wait for sandboxes in scripts. - [v0.7.2](https://docs.microsandbox.dev/changelog/v0.7.2.md): Upgrade your local sandbox database without stopping running sandboxes. - [v0.7.1](https://docs.microsandbox.dev/changelog/v0.7.1.md): Choose how snapshots save pending disk writes, with fixes for upgrades and Node package installation. - [v0.7.0](https://docs.microsandbox.dev/changelog/v0.7.0.md): Save running sandboxes, branch them into independent copies, and resume work from a checkpoint. - [Week of September 25, 2026](https://docs.microsandbox.dev/changelog/2026-09-25.md): v0.7.3 fixes for saved sandbox configuration and macOS runtime discovery, plus snapshot upgrade guidance. - [Week of September 11, 2026](https://docs.microsandbox.dev/changelog/2026-09-11.md): Strict hostname policy mode for network allowlists, standard stream devices in the guest, and forward-compatible cloud request handling. - [Week of September 4, 2026](https://docs.microsandbox.dev/changelog/2026-09-04.md): Outbound SOCKS proxies for sandbox traffic, SOCKS5 UDP relay and proxy authentication, and a fix for upgrades from earlier releases. - [Week of August 28, 2026](https://docs.microsandbox.dev/changelog/2026-08-28.md): Guest ownership for directory mounts, sparse layered sandbox configuration, Go SDK MSB_HOME support, isolated single-file mounts, and fixes for read-only mounts, log retrieval, and network slot exhaustion. - [Week of August 26, 2026](https://docs.microsandbox.dev/changelog/2026-08-26.md): Reuse named sandboxes safely across every SDK. - [Week of August 21, 2026](https://docs.microsandbox.dev/changelog/2026-08-21.md): Configurable SSH inactivity timeout, plural resource list shortcuts, precompiled Ruby platform gems, a fallible lazy local backend builder, faster Windows root-disk copies, and reliability fixes across networking, mounts, runtime bootstrap, and Linux releases. - [Week of August 14, 2026](https://docs.microsandbox.dev/changelog/2026-08-14.md): Per-sandbox network rate limits, NUMA-aware placement profiles, sparse configuration patches with reusable config files, guest-to-host vsock routes, deployment profile from config.json, and reliability fixes across Windows attach, cloud request shapes, image archives, and DNS rules. - [Week of August 7, 2026](https://docs.microsandbox.dev/changelog/2026-08-07.md): A first-class Ruby SDK, flat OCI root disks, deployment profiles, default-workload execution, host performance improvements, cloud volume filesystem access, and reliability fixes. - [Week of July 31, 2026](https://docs.microsandbox.dev/changelog/2026-07-31.md): Unified cloud backend in every SDK with paginated sandbox listings, per-registry insecure and custom-CA overrides in Go and Python, msb completion for shell tab-completion, a shared log registry for tailing many sandboxes, and fixes for guest TCP half-close, DNS upstream failover, and cloud exec rec… - [Week of July 24, 2026](https://docs.microsandbox.dev/changelog/2026-07-24.md): Composable network profiles across CLI and SDKs, bidirectional snapshot migration with msb self downgrade, msb run -d that honors image CMD, TTY resize in every SDK, and Go SDK on Windows. - [Week of July 17, 2026](https://docs.microsandbox.dev/changelog/2026-07-17.md): Image archives on every SDK, a finalized snapshot API with dest_dir and --from-snapshot, hole-perfect snapshot archives across platforms, a newer guest kernel, and a batch of secret, snapshot, and SDK fixes. - [Week of July 10, 2026](https://docs.microsandbox.dev/changelog/2026-07-10.md): Structured root disk for OCI sandboxes, default symlink protection on mount roots, secret modify across every SDK, offline OCI upper growth, cleaner guest shutdown, and a batch of snapshot, filesystem, and lifecycle fixes. - [Week of July 5, 2026](https://docs.microsandbox.dev/changelog/2026-07-05.md): Modify existing sandboxes, inspect resize headroom, trust private TLS upstreams, load images faster, and pick up CLI, network, and SDK fixes. - [Week of June 26, 2026](https://docs.microsandbox.dev/changelog/2026-06-26.md): Windows host support, guest-write quotas for virtiofs mounts, host-directory bind rootfs across all SDKs, non-PTY bidirectional `exec --stream`, upper disk usage metrics, an `msb doctor` command, runtime-owned ephemeral cleanup, and a round of SDK and runtime fixes. - [Week of June 19, 2026](https://docs.microsandbox.dev/changelog/2026-06-19.md): Local and cloud backend routing in the SDKs, detached image init entrypoints, shared sandbox spec types, secret substitution through HTTP CONNECT tunnels and plain HTTP, and snapshot import hardening. - [Week of June 12, 2026](https://docs.microsandbox.dev/changelog/2026-06-12.md): Guest runtime metrics, idempotent named volumes, unified sandbox lifecycle APIs, explicit mount kind flags, cleaner installer, raw agent socket paths, and richer secret violation logs. - [Week of June 5, 2026](https://docs.microsandbox.dev/changelog/2026-06-05.md): OTLP sandbox metrics, SSH TCP forwarding, image archive commands, pruning, Python image management, Homebrew install, and smoother host upgrades. - [Week of May 29, 2026](https://docs.microsandbox.dev/changelog/2026-05-29.md): Native SSH and SFTP, configurable OCI root disk size, msb copy and rootfs patch flags, hardened mount options, env-backed secret shorthand, and a fix for multi-second published-port stalls. - [Week of May 22, 2026](https://docs.microsandbox.dev/changelog/2026-05-22.md): Rotation-aware log streaming, raw agent client across SDKs, per-mount passthroughfs policies, network policy CLI cleanup, configurable port bind addresses, and ergonomic --script. - [Week of May 15, 2026](https://docs.microsandbox.dev/changelog/2026-05-15.md): Go SDK, file-first disk snapshots, guest init handoff, exec and boot logs, and DNS egress policy. - [Week of May 1, 2026](https://docs.microsandbox.dev/changelog/2026-05-01.md): TypeScript SDK redesign, network policy redesign, disk-image volumes, and more. - [Week of April 24, 2026](https://docs.microsandbox.dev/changelog/2026-04-24.md): Block-backed OCI rootfs, guest rlimits, and TypeScript SDK improvements. - [Week of April 17, 2026](https://docs.microsandbox.dev/changelog/2026-04-17.md): New Python SDK, Docker image publishing, and TLS proxy fixes. - [Week of April 10, 2026](https://docs.microsandbox.dev/changelog/2026-04-10.md): File-level volume mounts, TypeScript SDK streams, and `msb shell` removal. - [Week of April 3, 2026](https://docs.microsandbox.dev/changelog/2026-04-03.md): The microsandbox rewrite around an embeddable SDK, smoltcp networking, and a composable filesystem. ## OpenAPI Specs - [openapi](/api-reference/openapi.json) - [openapi.personal](/api-reference/openapi.personal.json) This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.