Guide

Building AI Apps with CodeSandbox Cloud Environments

CodeSandbox was once known as a browser IDE for prototyping web apps. Together AI bought it in December 2024, and today it is infrastructure for running AI-generated code in isolated microVMs, not a general-purpose coding playground.

Quick Answer

CodeSandbox is now part of Together AI, which acquired it in December 2024. What used to be a browser-based IDE for prototyping React and Node apps has turned into the CodeSandbox SDK, a way to spin up isolated microVM sandboxes by API call so an AI agent can run generated code without touching your machine. The SDK reached general availability in May 2025, and Together AI has been migrating it onto its own platform under the name Together Sandbox since. If you are building an AI app for developers and want a cloud place to execute untrusted, model-generated code, the SDK is the current product to look at, not the old standalone web editor.

What CodeSandbox actually is today

If you remember CodeSandbox as a place to fork a React template and share a link with a colleague, that product still exists, but it is no longer the headline. Together AI bought CodeSandbox to get its sandboxing technology, and the company's own site now leads with 'Sandboxes built for scale' rather than a browser editor. The target customer shifted from a developer prototyping a frontend to a team running an AI agent that needs somewhere safe to execute code.

The current product is the CodeSandbox SDK, the `@codesandbox/sdk` npm package, which provisions a microVM by API call. Each sandbox gets its own guest kernel, its own git-versioned filesystem, and a network boundary separate from your infrastructure. Together AI's docs list cold starts around 2.7 seconds at the 95th percentile, snapshot resumes around 500 milliseconds, and VM cloning in under a second, numbers aimed squarely at agent workloads that need to spin environments up and down constantly.

This matters for search intent as much as for architecture. If you are looking for 'codesandbox ai cloud for developers' expecting a multiplayer web IDE with an AI chat sidebar, that is the older product. The thing actively being built and marketed in 2026 is sandbox infrastructure for running AI-generated code, in the same category as E2B or Modal.

  • Together AI acquired CodeSandbox in December 2024 for its sandboxing technology.
  • The CodeSandbox SDK reached general availability in May 2025 and is being folded into Together AI's platform as Together Sandbox.
  • Each sandbox gets a dedicated guest kernel, a git-versioned filesystem, and resource limits of 2 to 64 vCPUs and 1 to 128 GB of RAM.
  • The product now competes with E2B and Modal for running AI-generated code, not with Replit or StackBlitz for prototyping.

Provisioning a sandbox for your AI app

Working with the SDK starts with a template, not a blank editor. You call `Sandbox.create()` (or the equivalent in the JavaScript SDK) with a template id, and the service hands you a running microVM with its own filesystem and a shell you can send commands to. CodeSandbox's own docs describe using Dev Containers to configure the environment, so you can point at a `devcontainer.json` with a custom Dockerfile if your agent needs specific system libraries rather than a generic Node or Python image.

Once the sandbox is running, you install whatever your AI app depends on the same way you would on a normal Linux box: `npm install openai @anthropic-ai/sdk` for the model SDKs, or `apt-get install ffmpeg poppler-utils` for system tools your agent's generated code might call. Because the sandbox is disposable, a mistake here costs you a restart, not a rebuild of your laptop.

The filesystem is git-versioned, so you can snapshot a sandbox mid-session and fork it into several copies. That is the feature worth building workflows around: instead of one long-lived environment you nurse along, you clone a known-good state in under a second and let several agent runs branch off it in parallel.

  • Provision a sandbox from a template with `Sandbox.create()`, not by opening a blank project.
  • Dev Containers let you pin a custom Dockerfile for system libraries an agent's code needs.
  • The filesystem is git-versioned, so you can snapshot and fork a sandbox instead of starting over.

Managing API keys in the cloud

AI applications rely heavily on API keys from providers like OpenAI, Anthropic, or specialized vector databases like Pinecone. Hardcoding these keys in your source code is a major security risk. If you commit the code to a public GitHub repository, those keys will be scraped and exploited within minutes.

Instead of hardcoding a key, pass it as an environment variable when you create or configure the sandbox, mapped to a name like `OPENAI_API_KEY`. The value lands in the running microVM's environment, not in a file in your repository, so it does not get committed and does not show up if someone forks or reads your sandbox's source.

However, you must remain vigilant about what you log. If your AI application encounters an error and you instruct it to `console.log(process.env)` to debug, the API keys will be printed to the terminal. Anyone with read access to your CodeSandbox workspace might see that scrollback. Always scope your debug outputs to specific, non-sensitive variables.

  • Never hardcode API keys or secrets in your source files.
  • Pass secrets as environment variables at sandbox creation, not inside a committed file.
  • Avoid logging entire environment objects to prevent exposing keys in the terminal.
  • Regularly rotate your keys if you suspect they might have been leaked in logs.

Executing untrusted AI code

A common pattern in modern AI development is the 'code interpreter' model, where the AI generates a script to solve a problem and then executes it to verify the result. Building this on your own machine is risky. CodeSandbox is frequently used as the backend infrastructure for this exact use case.

By utilizing the CodeSandbox SDK, developers can programmatically spin up sandboxes from their main application. When the AI generates a Python script to analyze a CSV file, your app can send that script and data to a newly provisioned CodeSandbox microVM via the SDK. The script runs in total isolation in the cloud.

Once the execution finishes, you can retrieve the standard output, errors, and any generated artifact files through the SDK and present them back to the user or feed them into the next step of your AI pipeline. When the task is complete, the sandbox is destroyed, leaving no persistent state or security vulnerabilities behind.

  • Use the CodeSandbox SDK to programmatically provision environments.
  • Send AI-generated scripts to the cloud microVM for isolated execution.
  • Retrieve logs, outputs, and files safely back to your main application.
  • Destroy the sandbox immediately after execution to maintain a clean slate.

Comparing agent runs instead of debugging one at a time

Testing an AI application is rarely a single run. You change a prompt, swap a model, or tweak a tool definition, and you want to know which version actually did better, not just whether the latest one worked. Because a CodeSandbox sandbox snapshots its filesystem and clones in under a second, you can fork the same starting state into several sandboxes and run a different agent configuration in each one.

That turns debugging a flaky AI output into a side-by-side comparison. Instead of re-running the same prompt five times on one machine and hoping you remember what changed, you fork the known-good state five times, change one variable per fork, and compare the transcripts and generated files afterward. The baseline state is identical across every fork, so a difference in the output is a difference you actually caused.

This is also how teams split AI work without stepping on each other. A prompt engineer forks the sandbox to try new wording while a developer forks the same state to change the tool-calling code, and neither one has to wait for the other or maintain a separate local environment.

  • Fork a snapshot of a sandbox to test a prompt or model change without losing the original state.
  • Sub-second VM cloning makes side-by-side comparisons of agent runs practical.
  • A shared starting snapshot means a difference in output is a difference you actually caused.

How Forkbench approaches local AI boundaries

While CodeSandbox excels at cloud-based isolation, many developers prefer to build AI apps on their own local machines using desktop tools. Forkbench is a desktop app designed to run coding agents in a terminal on your Mac, offering a different set of boundaries for vibe coding.

Forkbench uses a Vault that keeps your secrets in your macOS Keychain. An agent can run a command that uses an API key by name, so the value is applied when the command starts but does not appear in the conversation transcript. However, this has a specific limit: an unpinned Vault key can still be read by the program that was run, so the protection focuses on keeping the secret out of the logs rather than preventing the command from using it.

Additionally, a Forkbench Thread can be locked to its specific folders by the macOS kernel sandbox. This stops the agent from wandering into your `~/.ssh` directory or other projects. This folder lock is opt-in and does not restrict the network, so your agent can still make external API calls to OpenAI or install npm packages, but it cannot read local files outside the designated workspace.

  • Forkbench runs coding agents in a dedicated macOS desktop terminal.
  • The Vault injects Keychain secrets into commands so they stay out of transcripts.
  • An unpinned Vault key can still be read by the executed program.
  • The opt-in folder lock restricts local file access but does not block network traffic.

Related: Forkbench as an E2B alternative, How Forkbench handles your data, Download Forkbench for Mac

Frequently asked

  • Can I still use CodeSandbox as a plain web IDE, or is it all AI infrastructure now?

    The browser editor for forking a React or Node template still works, but it is no longer where CodeSandbox is investing. Together AI bought the company for its sandboxing technology, and new development goes into the SDK and Together Sandbox, not the old editor.

  • Can I use CodeSandbox to run code generated by an AI?

    Yes. The CodeSandbox SDK allows you to programmatically spin up isolated microVMs, making it a safe place to execute untrusted, AI-generated code.

  • Is it safe to store OpenAI API keys in CodeSandbox?

    Yes, as long as you pass the key as an environment variable when the sandbox is created rather than hardcoding it in a source file. A hardcoded key gets committed the moment someone pushes the repository.

  • Does Forkbench replace CodeSandbox?

    No, they serve different needs. CodeSandbox and its SDK give you disposable cloud microVMs for executing AI-generated code. Forkbench is a macOS desktop app for running and supervising local coding agents with specific folder and Vault boundaries.

Keep reading