Skip to content

Credentials and network access

Last updated View as MarkdownAgent setup

Any process in a sandbox can read a token that the sandbox holds. Keep the token in your Worker instead, and give the sandbox only the access it needs. A Container sends requests to a hostname that you choose, and your Worker intercepts each request and adds the token. A Dynamic Worker calls a method that your Worker passes it, and the method adds the token.

A Container that starts with enableInternet: false reaches only the hostnames you intercept. A Dynamic Worker loaded with globalOutbound: null cannot make its own requests, and reaches your application only through the methods you pass.

For every outbound option in each environment, refer to Handle outbound traffic for Containers and Egress control for Dynamic Workers.

Was this helpful?