Private pilot — invite only
Real-world examples
Four examples of firebox in action.
Each one is a problem, the exact API calls that solve it, and why the isolation model matters. Every call below is against the documented API — create a sandbox, do the work, destroy it.
Example 01
The AI data analyst
A user uploads sales_q3.csv and asks in plain English: “which region grew fastest?” The agent writes analysis code — but nobody vetted it, and the dataset can’t leak. So the code runs sealed.
Boot a sandbox
POST /v1/sandboxes. The dataset is about to live only inside this VM.
Upload the data
POST /v1/sandboxes/{id}/files with the CSV, base64-encoded. Files up to 10 MiB.
Ship unvetted code
The LLM generates analyze.py. Same files API. At this point the code could contain anything — it goes straight into the sealed box.
Run it, watch it fail safely
POST /v1/sandboxes/{id}/exec → KeyError: 'Region' — the model guessed a column name. A wrong guess, contained. If it had been malicious instead of merely wrong, the outcome is identical: one dead VM.
Fix, re-run, stream the long pass
Corrected script, same warm sandbox. For the full-dataset run, POST /v1/sandboxes/{id}/exec/stream delivers stdout over SSE as it happens.
Collect and destroy
GET /v1/sandboxes/{id}/files?path=summary.json returns the answer; then DELETE the sandbox. Metering logged the CPU-seconds.
$ curl -X POST https://firebox.beamto.io/v1/sandboxes \
-H "X-API-Key: $FB_API_KEY" -d '{"vcpu":1,"memory_mb":512}'
{"id":"sb_51bd88c2e7f1","status":"running"}
$ curl -X POST .../sb_51bd88c2e7f1/files \
-d '{"path":"sales_q3.csv","content":"cmVnaW9uLHNhbGVzCkVNRUEsMTIwCk5BLDk1Cg=="}'
{"path":"sales_q3.csv","size":26}
$ curl -X POST .../sb_51bd88c2e7f1/exec -d '{"command":"python3 analyze.py"}'
{"stdout":"","stderr":"KeyError: 'Region'\n","exit_code":1,"timed_out":false}
# fixed script, long run — stream it live
$ curl -N -X POST .../sb_51bd88c2e7f1/exec/stream -d '{"command":"python3 analyze.py"}'
event: stdout
data: {"data":"cHJvY2Vzc2VkIDEwMDAgcm93cwo="}
event: exit
data: {"exit_code":0,"timed_out":false}
$ curl -s .../sb_51bd88c2e7f1/files?path=summary.json
{"path":"summary.json","content":"eyJmYXN0ZXN0X2dyb3dpbmciOiJFTUVBIiwiZ3Jvd3RoX3BjdCI6MTguNH0=","size":44}
$ curl -X DELETE .../sb_51bd88c2e7f1
{"id":"sb_51bd88c2e7f1","status":"destroyed"}
Try it yourself
# pip install firebox
from firebox import Firebox
fb = Firebox(api_key="fb_...")
sb = fb.create_sandbox(
template="python",
secrets=["ANTHROPIC_API_KEY"], # injected, never in code
egress=["api.anthropic.com:443"], # locked down
)
sb.write("sales_q3.csv", csv_data)
code = llm.generate("which region grew fastest?", columns)
sb.write("analyze.py", code)
result = sb.exec("python3 analyze.py")
print(result.stdout) # "West, +23% QoQ"
sb.destroy()
Example 02
The coding agent that proves its work
An AI engineer is fixing a checkout bug. Its code is untrusted by construction — written by a language model, reviewed by no one — and “trust me, it works” isn’t proof. So it tests itself, inside a box that gets thrown away.
Boot a clean room
POST /v1/sandboxes returns sb_9c2e…. The agent is about to run code it wrote itself. That runs here — not on your infrastructure.
Drop in the suspect code
POST /v1/sandboxes/{id}/files uploads the checkout module and its test file. Kilobytes, not megabytes.
Reproduce the bug
POST /v1/sandboxes/{id}/exec runs pytest. It fails: assert 95.0 == 90.0. The agent finally has a failing test it can see — the feedback loop that makes agents work.
Iterate warm
Fix via the files API, re-run. Still red — a rounding error this time. Fix again, re-run. Green. Same sandbox, no reboot; a runaway iteration hits timeout_s and gets killed.
Ship with proof
The agent shows the user the diff plus the passing test output it captured. Fixed — and here’s the run proving it.
Destroy it
DELETE /v1/sandboxes/{id}. Nothing persists — no stale state poisoning the next task.
$ curl -X POST https://firebox.beamto.io/v1/sandboxes \
-H "X-API-Key: $FB_API_KEY" -d '{"vcpu":1,"memory_mb":512}'
{"id":"sb_9c2e71b4f0aa","status":"running"}
$ curl -X POST .../sb_9c2e71b4f0aa/files \
-d '{"path":"checkout.py","content":"ZGVmIHRvdGFsKGl0ZW1zKTouLi4="}'
{"path":"checkout.py","size":214}
$ curl -X POST .../sb_9c2e71b4f0aa/exec \
-d '{"command":"python3 -m pytest test_checkout.py -x"}'
{"stdout":"FAILED test_checkout.py::test_total - assert 95.0 == 90.0\n","exit_code":1,...}
# agent fixes the code, re-runs — same sandbox
$ curl -X POST .../sb_9c2e71b4f0aa/exec \
-d '{"command":"python3 -m pytest test_checkout.py"}'
{"stdout":"2 passed in 0.41s\n","exit_code":0,"timed_out":false}
$ curl -X DELETE .../sb_9c2e71b4f0aa
{"id":"sb_9c2e71b4f0aa","status":"destroyed"}
Try it yourself
# pip install firebox
from firebox import Firebox
fb = Firebox(api_key="fb_...")
sb = fb.create_sandbox(template="python")
for attempt in range(5):
code = llm.generate(task) # your LLM call
for path, content in code.files.items():
sb.write(path, content) # upload to microVM
result = sb.exec("pytest -x -q")
if result.exit_code == 0:
break # tests pass
task = fix_prompt(result.stdout) # feed failure back
sb.exec("zip -qr /tmp/app.zip .")
artifact = sb.files.read("/tmp/app.zip")
sb.destroy()
Example 03
Team scripts, without the shared Jenkins
Forty product teams, hundreds of automation scripts, one shared cluster. Noisy neighbors, credential sprawl, zero isolation. The platform team replaces it with an execution API: every team gets its own key, its own VMs, its own bill.
One key per team
POST /v1/keys (admin) mints team-a’s key. The secret is shown once. Per-key concurrency caps and rate limits apply.
Submit and isolate
Team A’s nightly sync runs POST /v1/sandboxes with their key. Their jobs land in their own microVMs — invisible to every other team.
Run with the blast radius contained
POST /v1/sandboxes/{id}/exec with a timeout_s. A script that loops forever gets killed; a script that tries to wander the network hits the egress allowlist.
Meter per team
GET /v1/usage per key gives the platform team chargeback numbers: executions, CPU-seconds, memory-seconds, active sandboxes.
Revoke when someone leaves
DELETE /v1/keys/{id}. The key dies immediately; in-flight sandboxes are reaped. No shared credentials to rotate.
$ curl -X POST https://firebox.beamto.io/v1/keys \
-H "X-API-Key: $FB_ADMIN" -d '{"name":"team-a"}'
{"id":"key_7d21c9","name":"team-a","api_key":"fb_9f2e...","is_admin":false}
$ curl -X POST https://firebox.beamto.io/v1/sandboxes \
-H "X-API-Key: fb_9f2e..." -d '{"vcpu":1,"memory_mb":512}'
{"id":"sb_a1c04dd2e8b2","status":"running"}
$ curl -X POST .../sb_a1c04dd2e8b2/exec \
-d '{"command":"./nightly_sync.sh","timeout_s":600}'
{"stdout":"synced 12,400 rows\n","exit_code":0,"timed_out":false}
$ curl -s .../v1/usage -H "X-API-Key: fb_9f2e..."
{"executions":18,"cpu_seconds":412.5,"gb_seconds":206.2,"active_sandboxes":0}
Example 04
The agent that brings its own sandbox
Your coding assistant already writes code — but it runs that code on your laptop. Give it firebox tools over MCP and the untrusted code runs in a microVM instead. The agent never touches your filesystem.
Register the tools
One command — claude mcp add firebox — gives your agent ten tools: create, exec, files, pause, resume, delete, usage.
Ask in plain English
“Clone this repo, run the test suite, and tell me what fails.” The agent calls firebox_sandbox_create — the work is about to happen in a microVM, not on your machine.
Run it sealed
firebox_exec runs git clone and pytest inside the sandbox. stdout/stderr come back as text, capped at 64 KB so a runaway cat can’t flood the agent’s context.
Iterate warm
12 failures, 9 from a rounding bug. The agent patches the file with firebox_files_write and re-runs in the same sandbox — the feedback loop that makes agents work.
Pause between turns
firebox_sandbox_pause snapshots the VM when the user walks away; firebox_sandbox_resume restores it exactly. Metering stops while paused.
Check spend, clean up
firebox_usage reports the key’s totals any time. When the task is done, firebox_sandbox_delete — or let it expire.
agent → firebox_sandbox_create()
{"id":"sb_41af09c2d7e1","status":"running"}
agent → firebox_exec(sb_41af09c2d7e1,
"git clone https://github.com/acme/shop.git /tmp/shop \
&& cd /tmp/shop && python3 -m pytest -q")
{"stdout":"12 failed, 84 passed in 4.2s\n…","exit_code":0}
agent → "12 failures — 9 are the rounding bug in cart.py. Fixing…"
agent → firebox_files_write(sb_41af09c2d7e1, "/tmp/shop/cart.py", …)
agent → firebox_exec(sb_41af09c2d7e1, "cd /tmp/shop && python3 -m pytest -q")
{"stdout":"96 passed in 3.8s","exit_code":0}
agent → firebox_sandbox_delete(sb_41af09c2d7e1)
See your workload here
firebox is in private pilot — access is invite-only for now. If you’re building agents that run code, we’d like to hear what you’re running.
Try the quickstart