Skip to content

REST API

Every /v1 route needs an API key. The OpenAPI spec holds the full request and response schemas.

Method and path What it does
GET /healthz Report whether the server can reach Docker. No key needed.
POST /v1/sandboxes Create and start a sandbox.
GET /v1/sandboxes List live sandboxes.
GET /v1/sandboxes/{id} Get one sandbox.
DELETE /v1/sandboxes/{id} Destroy a sandbox and its workspace. Its snapshots remain.
POST /v1/sandboxes/{id}/timeout Reset the TTL, counted from now.
POST /v1/sandboxes/{id}/exec Run a command and return stdout, stderr, and the exit code.
POST /v1/sandboxes/{id}/exec/stream Run a command and stream NDJSON events as output arrives.
GET /v1/sandboxes/{id}/files?path= Download a file.
PUT /v1/sandboxes/{id}/files?path=&mode= Upload a file into /workspace.
GET /v1/sandboxes/{id}/files/list?path= List a directory.
POST /v1/sandboxes/{id}/snapshots Snapshot /workspace.
POST /v1/sandboxes/{id}/rollback Restore a snapshot into the sandbox.
GET /v1/snapshots List snapshots, optionally for one sandbox.
GET /v1/snapshots/{id} Get one snapshot.
DELETE /v1/snapshots/{id} Delete a snapshot.
POST /v1/snapshots/{id}/fork Start a new sandbox from a snapshot.

Errors share one shape: {"error": {"code": "not_found", "message": "..."}}.