Skip to main content
PATCH
Update a sandbox
Update settings of a running sandbox. This endpoint controls the sandbox proxy allowlist (exposed_ports and allow_unauthenticated_access), the sandbox name, and the egress network policy. The network field is tri-state: omit it to leave the policy unchanged, send an object to replace it, or send null to clear it. See Networking for details.

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

sandbox_id
string
required

The ID of the sandbox.

Body

application/json
allow_unauthenticated_access
boolean

Set or clear unauthenticated ingress routing for this sandbox.

exposed_ports
integer<int32>[]

Replace the exposed port allowlist. Pass an empty array to clear it and revert to the default management port only.

Required range: 1 <= x <= 65535
network
object

Update the egress network policy of the running sandbox. This field is tri-state: omit it to leave the current policy unchanged, send an object to replace the whole policy, or send an explicit null to clear it (unrestricted egress). The change is applied to the live sandbox firewall as one atomic swap with no enforcement gap; already-established connections are not revoked. If a hostname in the new policy fails to resolve, the update is rejected and the previous policy stays enforced.

Response

Sandbox updated successfully

id
string
required
namespace
string
required
status
enum<string>
required
Available options:
pending,
running,
snapshotting,
suspending,
suspended,
terminated
created_at
integer<int64>
required

Milliseconds since Unix epoch.

resources
object
required
timeout_secs
integer<int64>
required
allow_unauthenticated_access
boolean
required

Whether sandbox ingress may route requests without auth validation.

image
string
pending_reason
string | null

Present when status is pending.

outcome
string | null

Platform-specific termination outcome string returned for completed sandboxes.

container_id
string | null
executor_id
string | null
ingress_endpoint
string | null

Canonical server-provided base for sandbox-specific ingress.

sandbox_url
string | null

Sandbox-specific management URL derived from ingress_endpoint.

pool_id
string | null
network_policy
null | object
exposed_ports
integer<int32>[] | null

Additional routable ingress ports. When null, only the management port 9501 is routable.

Required range: 1 <= x <= 65535
template_id
string | null
name
string | null