Skip to content

Run coding agents in a sandbox

Last updated View as MarkdownAgent setup

Coding agents such as Claude Code, Codex, and OpenCode can run a task on their own: they read a repository, edit files, and run commands until the task is done. Run the agent in a Linux sandbox so its commands stay inside a Container that belongs to one task.

The agent runs in your sandbox

Your Worker starts the sandbox, holds the credentials, and decides which hostnames the sandbox can reach. The agent calls its model over HTTP, for example through AI Gateway. Your Worker adds the API token to each request, so the sandbox never receives it.

Each guide in this section changes only the agent-specific parts of one runner. Build the runner first:

Then switch the runner to another agent:

Claude Code

Edit a GitHub repository with Claude Code, which calls Anthropic models through AI Gateway.

Codex

Edit a GitHub repository with the Codex CLI, which calls OpenAI models through AI Gateway.

OpenCode

Edit a GitHub repository with OpenCode, which calls models through AI Gateway.

Pi

Edit a GitHub repository with Pi, which calls models through its built-in AI Gateway provider.

The vendor runs the agent loop

Devin, Cursor, Claude Managed Agents, and the OpenAI Agents API run their agent loop in their own service. The loop sends commands and file edits to sandboxes in your Cloudflare account. Each vendor template gives every session its own sandbox. In the Devin, Cursor, and OpenAI Agents API templates, the vendor worker process runs inside the sandbox, so the sandbox also holds a vendor credential.

Devin

Deploy a Devin Outpost that runs each Devin session in its own sandbox on Containers.

Cursor Cloud Agents

Deploy self-hosted machines that run each Cursor session in its own sandbox on Containers.

OpenAI Agents API

Deploy a self-hosted environment that runs each Codex session in its own sandbox on Containers.

Build your own agent

To give an agent that runs in a Durable Object a container to run commands in, refer to Sandbox in the Agents SDK documentation.

Was this helpful?