opensandbox-groupOps & cloud

OpenSandbox

An open-source sandbox platform for AI agents and code execution with Docker/Kubernetes runtimes, SDKs, CLI, and MCP integration.

  • Backend
  • DevOps
  • Security
  • Automation
  • CLI
  • API/SDK
  • Library/framework
  • Linux
  • Self-hostable
  • Runs locally
  • Docker supported
OpenSandbox screenshot
Popularity
15.6k Stars
GitHub stars
Recent activity
10/1/2026
Updated in the last 30 days
License
APACHE-2.0
Permissive

Why it matters

We look beyond stars: what problem it solves, whether it creates real utility, and what makes its approach worth noticing.

Last 90 days

Problem

AI agents need to run partially trusted code, shells, browsers, and tools, but executing them directly on hosts or shared clusters creates permission, credential, network, and resource-isolation risks.

Practical value

Unified sandbox APIs, SDKs, CLI, and MCP combine Docker/Kubernetes runtimes with command/file operations, network policy, and credential boundaries, reducing the need for teams to build agent execution infrastructure from scratch.

Innovation / differentiation

It elevates a code-execution sandbox from a container wrapper into a general control plane for AI workloads, keeping a consistent developer interface across different runtimes and isolation technologies.

Leverage potential

The sandbox is an infrastructure primitive reusable by coding agents, GUI agents, evaluations, code interpreters, and training systems, giving it leverage far beyond a single end-user feature.

Why now

Agents are rapidly moving from calling APIs to executing code and manipulating environments, making secure execution infrastructure a core product layer rather than a background engineering detail.

Community activity

In the last 90 days there were 251 new issues and 665 pull requests; the bounded issue/PR samples include 35 issue authors and 19 PR contributors, with at least 30 releases.

Maintainer responsiveness

The 100-issue window sample had a 81% close rate, and the 100-pull-request sample had a 67% merge rate. Maintainer-response observations covered 59% of that issue sample, with a 2% response rate and median first response of 6 days.

19 contributors in PR sampleAt least 30 releasesIssue response rate 2% · sample 59 (59% coverage)Median first response 6dPR merge rate 67% · 100 sampled in window

Key highlights

  • Unified sandbox lifecycle, command execution, and file-operation APIs
  • Multi-language SDKs, the osb CLI, and an MCP server
  • Local Docker and Kubernetes runtimes

Quick start

How it is installed, how hard it is, and where to start.

Where it runs

Self-hosted (your own server)

Difficulty

Medium — some setup needed

Docker supportedSelf-hostableRuns locally
  1. 01Prepare Docker; the local examples also require Python 3.10 or newer.
  2. 02Run uvx opensandbox-server init-config ~/.sandbox.toml --example docker to create a local Docker-based configuration.
  3. 03Start the sandbox service with uvx opensandbox-server, then connect through an SDK, the osb CLI, or an MCP client.
  4. 04For production workloads that execute untrusted code, configure gVisor, Kata, Firecracker, or another supported secure runtime following the official guide.

Best for

  • Teams that want data on their own servers
  • Developers who want to try it on their machine
  • People who prefer Docker deploys

More about it

OpenSandbox is a general-purpose sandbox platform for AI applications and code execution. It defines lifecycle and execution APIs and ships Python, Java/Kotlin, JavaScript/TypeScript, C#, and Go SDKs together with the osb CLI and an MCP server.

The runtime supports local Docker and Kubernetes scheduling. Sandboxes can expose command execution, filesystem operations, code interpreters, Chrome/Playwright environments, and full desktop environments. Networking components include ingress, per-sandbox egress controls, and a Credential Vault that can inject credentials without exposing the underlying secrets directly to workloads.

Isolation depends on deployment configuration. The project supports gVisor, Kata Containers, and Firecracker microVM runtimes, but these require explicit setup and should not be assumed from a default Docker deployment.

Sources

Each field shows its status and source — expand to review.

12 · Expand
  • capability tags

    Verified

    automation, security

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

  • Latest release

    Verified

    release-1.1.0

    Source: GitHub API · latest_release=release-1.1.0 · 10/2/2026

  • License

    Verified

    Apache-2.0

    Source: GitHub API · license.spdx_id=Apache-2.0 · 10/2/2026

  • needs api key

    Verified

    No

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

  • One-liner

    Verified

    {"en":"An open-source sandbox platform for AI agents and code execution with Docker/Kubernetes runtimes, SDKs, CLI, and MCP integration.","zh":"为 AI Agent 和代码执行场景提供 Docker/Kubernetes 隔离运行环境、SDK、CLI 与 MCP 接口的开源沙箱平台。"}

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

  • Platforms

    Verified

    linux

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

  • Category hint

    Inferred from materials

    ai-apps

    Source: Project README · hint=ai-apps · 8/14/2026

  • product forms

    Verified

    cli, api_sdk, library_framework

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

  • role tags

    Verified

    backend, devops, security

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

  • supports docker

    Verified

    Yes

    Source: Repository file · dockerfile=true; compose=false · 10/2/2026

  • supports local

    Verified

    Yes

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

  • supports self host

    Verified

    Yes

    Source: manual_curated · Manually curated from the verified project README; no AI draft. · 8/17/2026

Other verified projects matched by category, capabilities, and intended roles.