Start a sandbox and run untrusted or generated code
A sandbox is an isolated place to run code. The code cannot directly read the memory or data of your application. Your Worker decides which application APIs and data the code receives, and whether the code can reach the public Internet.
You can use a sandbox for agent-written code, user-uploaded applications, data analysis, development previews, build pipelines, or any other work that should not share a process with your application.
Cloudflare provides two sandbox environments. Both are accessible through a Worker, the application that already handles your traffic.
If your application uses @cloudflare/sandbox 0.x, refer to Sandbox SDK 0.x, or move it to the current version with Migrate from Sandbox SDK 0.x.
Containers run an image you provide. The instance is a full Linux environment, so you can run any language and keep processes running. Your Worker starts the instance and sends it work. HTTP from the Internet reaches the instance only through your Worker.
Each instance is a microVM with its own kernel and network, so no other workload shares it.
A sandbox container uses the Durable Object scheduling policy, which is in public beta.
A Durable Object in your Worker starts the instance from an image and runs a command in it:
container.start({
image: "cloudflare/debian-trixie",
entrypoint: ["sleep", "infinity"],
enableInternet: false,
});
const process = await container.exec(["uname", "-a"]);
const output = await process.output();Run a Linux command
Build a coding agent runner
Dynamic Workers create a new Worker at runtime. The untrusted code can be JavaScript, Python, or WebAssembly. Compile TypeScript to JavaScript before loading it.
The Workers runtime runs each Dynamic Worker apart from your Worker and from other Dynamic Workers. A Dynamic Worker reaches your application only through the methods and data you pass to it.
Your Worker loads the untrusted module as a new Worker, blocks its outbound requests, and calls it:
const sandbox = env.LOADER.load({
compatibilityDate: "$today",
mainModule: "code.js",
modules: { "code.js": untrustedModule },
globalOutbound: null,
});
const entrypoint = sandbox.getEntrypoint<CodeEntrypoint>("Code");
const result = await entrypoint.evaluate();Run JavaScript
Build an AI code interpreter
Choose a sandbox environment
Decide whether a job needs Linux or only calls methods that your Worker provides.
Sandbox lifetime
Understand what keeps a Linux sandbox running, what stops it, and which files a snapshot brings back.
Sandbox security
Decide what each sandbox holds, because its code can use everything you place inside it.
Run commands
Run Python code and tests, stream output, keep processes running, and open a terminal.
Work with files
Move files, keep a workspace between instances, and mount an R2 bucket.
Preview applications
From your browser, open a web server that runs in a sandbox.
Credentials and network
Keep credentials in your Worker, and decide which services a sandbox reaches.
Manage sandboxes
List a user's sandboxes, and record when and why each one stops.
Coding agents
Run coding agents such as Claude Code, Codex, and Devin in a sandbox that belongs to one task.
The serverless platform these sandbox environments run on.
Identity and coordination for an attached container.
Run models on Cloudflare, then execute the code they generate in a sandbox.
| Topic | Links |
|---|---|
| Deploy and debug | Deploy Containers, Local development, Logs |
| Reference | @cloudflare/sandbox, Durable Object container API, Dynamic Workers API |
| Pricing and limits | Containers pricing, Container limits, Dynamic Workers pricing |
| Related | Code Mode, Workers security model |