msb CLI starts it as a child process on your machine or on microsandbox cloud, then talks to the guest agent to run commands, move files, and control lifecycle.
The security boundary is hardware virtualization, not Linux namespaces. That makes sandboxes a good fit for untrusted workloads: user-submitted code, AI agent actions, plugins, dependency installs, CI jobs, scrapers, and tools that should not inherit the host process’s full privileges.
Create a sandbox
At minimum, a sandbox needs a name and an image. Everything else has defaults: 1 vCPU, 512 MiB memory, public-only networking, and/bin/sh as the default shell.
Common configuration
max_cpus and max_memory reserve live resize headroom. They default to the
starting cpus and memory values, so set them higher when a sandbox may need
to grow later. See Live Modify for the full change
model.
Labels are arbitrary key=value metadata attached to a sandbox. They can be set
at create time or changed while the sandbox is running, and they also select
sandboxes in bulk. See Labels for naming guidance, bulk
actions, metric attribution, and OCI image labels.
Image sources
Most sandboxes start from an OCI image:Naming conflicts
Creating a sandbox fails if another sandbox already has the same name. Useconnect_or_create when you want to reuse the current persisted identity and its configuration. Use replace when you explicitly want a fresh sandbox with that name:
replace_with_timeout or --replace-with-timeout when the workload needs a longer grace period.
Reference
For the complete sandbox API, see TypeScript, Rust, Python, or Go. For terminal and REST workflows, see Sandbox commands and the Cloud API.Where to go next
- Lifecycle: start, stop, detach, wait, and remove sandboxes
- Commands: run commands and stream output
- Filesystem: read, write, and transfer files
- Secrets: inject credentials without exposing values
- Images: choose OCI, directory, or disk-image roots
- Volumes: persist or share data
- SSH: connect with SSH and SFTP clients
- Snapshots: capture and reuse writable sandbox state
- Live Modify: change settings after create
- Labels: organize, select, and attribute sandboxes
- Logs: inspect workload and runtime output
- Metrics: monitor sandbox resource usage
- Bootstrap: prepare scripts, patches, and PID 1
- Networking: control egress, ingress, DNS, and ports