Skip to main content
Create a sandbox for an agent’s task, wait for it to deploy, and delete it when the work finishes. Use the dashboard to explore images and options, the Baseten CLI to do the same from a terminal, or a Baseten SDK to do it from an application. Each SDK creates and refreshes sandbox access tokens for you. You need permission to create resources in your team.

Set up

Install the CLI or an SDK:
The CLI examples use $SANDBOX_NAME for the sandbox name:
Sandbox commands are in pre-release. Arguments, flags, and output may change.

Create a sandbox

Creating a sandbox starts an isolated environment from an image. The new sandbox gets a name, an image, memory (which also sets its CPU allocation), and a region. Name, image, memory, and region can’t change after creation.
To create a sandbox:
  1. Sign in to your workspace at app.baseten.co and choose Sandboxes in the sidebar.
  2. Choose Create sandbox.
  3. Choose Base Image, or another image with the software your task needs.
  4. Enter a Name, for example, hello-world.
  5. For Memory (MiB), keep the default or enter the memory the workload needs. More memory also means more CPU.
  6. Choose a Region.
  7. Optionally, for Time to live, choose how long the sandbox can run before Baseten deletes it.
  8. If the form shows Team, choose the team that should own the sandbox.
  9. Optionally, add environment variables.
  10. Choose Create sandbox.
If the form reports an error, check the validation message next to each field. For common causes, see Handle a failed command.

Get a sandbox

A sandbox’s record shows its configuration, URL, and current status.
In Sandboxes, choose the sandbox. Its detail page shows the same status.
If the status is FAILED, inspect the sandbox’s logs before retrying. For the deployment and deletion statuses, see Lifecycle and expiration.

Run commands in a sandbox

Run a single command in a deployed sandbox. Its output streams to your terminal, and its exit code becomes the command’s exit code.
Put the command after --:
To set extra environment variables for one command, add --env KEY=VALUE before --:
To open an interactive terminal in the sandbox, like SSH, run:
Press Ctrl+D to disconnect.

Set environment variables

Environment variables pass configuration, such as an output format or log level, to the processes in a sandbox, so one image can serve different tasks. Set them at creation. Names begin with a letter or underscore and contain only letters, digits, and underscores. Don’t put your Baseten API key in a sandbox’s environment.
To set environment variables:
  1. In Sandboxes, choose Create sandbox, then choose an image.
  2. Under Environment variables, choose Add variable.
  3. Type a name and value, such as OUTPUT_FORMAT and json.
  4. Repeat steps 2 and 3 for each additional variable.

List sandboxes

The output lists every sandbox in the team, except terminated ones. Narrow it with --status or search names and labels with --query:

Manage a sandbox’s labels

Labels help you find and group sandboxes, such as marking every sandbox an agent creates with purpose=agent. This example changes the purpose label from hello-world to hello-universe:
To change a sandbox’s labels:
  1. In Sandboxes, choose the sandbox.
  2. Choose Sandbox settings.
  3. Under Labels, add, change, or remove labels.
  4. Choose Save changes.
Sandbox settings is unavailable while a sandbox is deleting or archived.
A supplied set of labels replaces all previous labels, so include every one you want to keep. Omitted fields leave their values unchanged. You can also update environment variables with envs. The name, image, memory, and region can’t change after creation. To use a different image, create a new sandbox.

Delete a sandbox

Deletion stops the sandbox’s processes and permanently removes its files, so save the files you need first.
To delete a sandbox:
  1. In Sandboxes, choose the sandbox.
  2. Choose Delete sandbox.
  3. Type the sandbox’s name to confirm, then choose Delete sandbox.
Deletion continues after the call returns. Stop sending work to the sandbox, then describe the sandbox until its status is TERMINATED. The sandbox reports TERMINATED for a few minutes, and then it’s no longer found. Don’t reuse the name until deletion completes.

Work in a team

Sandbox commands act in your team. If you belong to more than one, name the team on each call:
Run baseten org team list to see your teams, and use the same team throughout a workflow.

Handle a failed command

Use the error message to choose the next action:

Next steps

Sandbox lifecycle and expiration

Track deployment status and set an expiration policy.

Manage sandbox images

Choose a built-in image, or create and version your own.