Skip to main content
Sandboxes support two networking features:
  1. Routing internet traffic into services running inside a sandbox through *.sandbox.tensorlake.ai
  2. Restricting the sandbox’s own outbound internet access

Sandbox Public URL

Every running sandbox is reachable through sandbox-specific ingress.
  • https://<sandbox-id-or-name>.sandbox.tensorlake.ai routes to the sandbox management API on port 9501
  • https://<port>-<sandbox-id-or-name>.sandbox.tensorlake.ai routes to a user service listening on <port> inside the sandbox
The proxy preserves the request path and query string, supports WebSocket upgrades, and forwards gRPC over HTTP/2. The hostname can use either the sandbox ID or a sandbox name. The proxy resolves names to the sandbox’s canonical ID before forwarding the request. These examples use the familiar *.sandbox.tensorlake.ai hostname pattern. The returned sandbox_url is the management URL on port 9501.

Route Traffic Into Sandbox Apps

There are two access modes for internet-facing sandbox traffic:
  1. Authenticated requests: the caller sends TensorLake auth credentials, and the proxy authorizes the request before forwarding it.
  2. Unauthenticated requests: the sandbox owner explicitly makes selected user ports public, and the proxy skips auth for those user ports.

Expose a User Port

Port 9501 is the built-in management API and is always routable through the bare sandbox hostname. For any other port, the proxy only forwards requests if that port is listed in exposed_ports.
allow_unauthenticated_access does not expose a port by itself. User ports still have to be present in exposed_ports.

Authenticated-Only Exposure with the HTTP API

Use this when a port should be routable from the internet but still require TensorLake auth on every request.

Unauthenticated Public Internet Access with the CLI

Use this when you want anyone on the internet to be able to reach a sandbox app without TensorLake credentials. Common cases include webhook receivers, demo apps, public APIs, browser clients, and temporary preview environments.
The CLI port expose workflow sets both:
  • exposed_ports
  • allow_unauthenticated_access=true
So traffic to that user port becomes publicly reachable from the internet without TensorLake auth.

Authenticated Requests

Authenticated routing is the default model for sandbox access.
  • The management URL on port 9501 always requires auth
  • User ports can also require auth when they are exposed but allow_unauthenticated_access=false
Verified against sandbox-proxy, the proxy accepts these auth modes:
  • API key: Authorization: Bearer <api-key>
  • Personal access token: Authorization: Bearer tl_pat... plus X-Forwarded-Organization-Id and X-Forwarded-Project-Id
  • Session cookie: tl.session_token or legacy tl-session, plus the same forwarded organization/project context
For browser WebSocket clients that cannot set custom X-Forwarded-* headers, the proxy also accepts organizationId and projectId in the query string.
You can use the same authenticated routing model for HTTP, gRPC, and WebSocket services:

Unauthenticated Requests

To make a user port public on the internet, both of these conditions must be true:
  • the port is in exposed_ports
  • allow_unauthenticated_access=true
When those are set, the proxy skips TensorLake auth for that user port.
After that, requests to the exposed user port can omit auth entirely:
Unauthenticated access only applies to user ports. The management API on port 9501 never becomes public.
If a named sandbox is suspended, the proxy can auto-resume it when a request arrives for an exposed port.

Outbound Internet Access

By default, sandboxes have outbound internet access enabled. Disable it for untrusted code:
In a verified public-cloud test, a sandbox created with allow_internet_access=False failed DNS resolution for https://example.com, confirming that outbound internet access was disabled.

Allow Specific Destinations

Use allow_out when you want a sandbox to reach only selected destinations.
  • allow_out rules are evaluated before deny_out
  • when allow_internet_access=false, allow_out acts as an explicit outbound allowlist
  • values should be destination IPs or CIDR ranges

Block Specific Destinations

In a verified public-cloud request, deny_out=["example.com"] blocked https://example.com while https://api.openai.com/v1/models still returned 401, confirming outbound connectivity was still available for destinations that were not denied.

Network Configuration Summary