---
title: Sandboxes
description: Isolated machines for running untrusted code and computer use, granted now and destroyed when the lease ends.
type: tutorial
product: sandboxes
summary: One lease, one machine — what it is, what surrounds it, and how it ends
updated: 2026-09-28
order: 0
---

A Lease is one isolated machine — a shape, a region, an image — for a bounded
time. It is granted immediately, from a warm machine or a cold one, or refused
with a typed reason. Sandboxes is the only writer of a lease: you describe the
machine you want, and the platform hands you one.

## A lease is granted, not queued

There is no queue. `create` answers when the guest is ready, and waits at most
60 seconds for that; with `skip_wait_ready` it answers as soon as the machine
is granted. A request that cannot be served now is refused rather than parked,
and `status.refusal` names which refusal it was: `no_capacity`,
`no_matching_cell`, `shape_not_offered`, `shape_not_entitled`,
`image_not_found` or `abuse_hold`.

The trade is deliberate: nobody waits behind someone else's workload, and the
caller owns the retry. A refusal is an answer, not a delay.

## The objects around a lease

<FeatureGrid
	features={[
		{
			title: 'Shape',
			description: 'One entry of the machine catalog: the operating system, vCPUs, memory, disk, the Cell capability it needs and the bounds on a lease of it. The catalog is read-only.',
			href: '/docs/api/sandbox_shapes',
		},
		{
			title: 'Pool',
			description: 'Never-leased machines of one shape and image, kept warm so a lease starts sooner. An empty pool makes a lease slower, never different.',
			href: '/docs/api/pools',
		},
		{
			title: 'Volume',
			description: 'A persistent disk, scoped to one environment and encrypted at rest, attached by name when a lease is created. It outlives the lease.',
			href: '/docs/api/volumes',
		},
		{
			title: 'Snapshot',
			description: 'A lease’s disk and image captured at one moment; a lease created with `source_snapshot` boots from it.',
			href: '/docs/api/snapshots',
		},
		{
			title: 'Lease event',
			description: 'One immutable fact in a lease’s life — granted, ready, renewed, paused, ended — in the order it happened.',
			href: '/docs/api/lease_events',
		},
	]}
/>

A lease names its shape, its image — a Kernel Artifact by digest, or a
`template:` name — its `kind`, and its `ttl`. `kind` decides what the machine
serves, and defaults to `general`; the other three, `browser`, `desktop` and
`android`, are the ones with a display.

## The lease ends, and the machine is destroyed

`release` ends a lease now. So does its `ttl`, a lease left unused past its
`idle_timeout`, a budget, and a machine the platform loses — and
`status.end_reason` says which of those happened. The end destroys the
machine: it is never leased again, and its disk goes with it.

A [volume](/docs/api/volumes) is the way work survives a lease. It is attached
by name when the lease is created, detached when the lease ends, and destroyed
only by its own Delete. Everything else you leave in a lease belongs to that
lease.

## The scopes

- `sandboxes:read` — the lease, its events, and the shape catalog.
- `sandboxes:write` — everything that changes a lease: create, renew, pause,
  resume, release, its network policy, and the pools, volumes and snapshots
  around it.
- `sandboxes:exec` — the data plane: `exec`, the files, the exposed ports,
  computer actions, the live view, and minting a lease token.

<KeyValue
	items={[
		{ key: 'Name', value: 'orgs/{org}/projects/{project}/envs/{env}/leases/{lease}', mono: true },
		{ key: 'Id', value: 'sbx_<cell><ulid>', mono: true },
	]}
/>

A lease’s name is a path, and the same path works in the API, the CLI and the
console. The id is never reused.

<RelatedDocs
	links={[
		{
			href: '/docs/sandboxes/quickstart',
			label: 'Quickstart',
			description: 'List the shapes, create a lease, run a command, and release it.',
		},
		{
			href: '/docs/sandboxes/leases',
			label: 'Lease lifecycle',
			description: 'The states, the two clocks, the budgets and the event stream.',
		},
		{
			href: '/docs/sandboxes/computer-use',
			label: 'Computer use',
			description: 'Screens, streams, control, screenshots and Android apps.',
		},
		{
			href: '/docs/api/leases',
			label: 'The leases collection',
			description: 'Every method, its scope and its examples.',
		},
	]}
/>
