Coding agents such as Claude Code, Codex, and OpenCode can run a task on their own: they read a repository, edit files, and run commands until the task is done. Run the agent in a Linux sandbox so its commands stay inside a Container that belongs to one task.
Your Worker starts the sandbox, holds the credentials, and decides which hostnames the sandbox can reach. The agent calls its model over HTTP, for example through AI Gateway. Your Worker adds the API token to each request, so the sandbox never receives it.
Each guide in this section changes only the agent-specific parts of one runner. Build the runner first:
Build a coding agent runner
Then switch the runner to another agent:
Claude Code
Codex
OpenCode
Pi
Devin, Cursor, Claude Managed Agents, and the OpenAI Agents API run their agent loop in their own service. The loop sends commands and file edits to sandboxes in your Cloudflare account. Each vendor template gives every session its own sandbox. In the Devin, Cursor, and OpenAI Agents API templates, the vendor worker process runs inside the sandbox, so the sandbox also holds a vendor credential.
Devin
Cursor Cloud Agents
Claude Managed Agents
OpenAI Agents API
To give an agent that runs in a Durable Object a container to run commands in, refer to Sandbox in the Agents SDK documentation.