Private pilot — invite only
firebox
Let AI write the code. We’ll make sure it’s safe to run.
Every run executes inside its own Firecracker microVM — isolated kernel, locked-down network, DNS that can’t exfiltrate. One HTTP call, metered per second.
$ curl -X POST https://getfirebox.dev/v1/sandboxes \
-H "X-API-Key: $FB_API_KEY" -d '{"vcpu":1,"memory_mb":512}'
{"id":"sb_8fa8f125a9cc","status":"running"}
$ curl -X POST .../sb_8fa8f125a9cc/exec \
-d '{"command":"python3 -c \"print(40+2)\""}'
{"stdout":"42\n","exit_code":0,"duration_ms":29,"timed_out":false}
$ curl -X DELETE .../sb_8fa8f125a9cc
{"id":"sb_8fa8f125a9cc","status":"destroyed"}
How it works
Three calls. No servers to manage, no containers to harden.
Create a sandbox
POST /v1/sandboxes boots an isolated Linux microVM — its own kernel, its own private network.
Execute code
Run commands, stream output live, read and write files. Timeouts, CPU and memory caps enforced.
Destroy it
One call tears it down — or pause it to disk and resume later. Billed per second of actual compute.
Quickstart
Create a sandbox, run code, destroy it. Authenticate with an X-API-Key header.
# point at your firebox host and key
export FB_URL="https://getfirebox.dev"
export FB_API_KEY="fb_your_api_key"
# 1. create a sandbox
SB=$(curl -s -X POST "$FB_URL/v1/sandboxes" \
-H "X-API-Key: $FB_API_KEY" -H 'Content-Type: application/json' \
-d '{"vcpu":1,"memory_mb":512}' \
| python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])')
# 2. run code
curl -s -X POST "$FB_URL/v1/sandboxes/$SB/exec" \
-H "X-API-Key: $FB_API_KEY" -H 'Content-Type: application/json' \
-d '{"command":"python3 -c \"print(40+2)\""}'
# {"stdout":"42\n","stderr":"","exit_code":0,"duration_ms":29,"timed_out":false}
# 3. destroy it
curl -s -X DELETE "$FB_URL/v1/sandboxes/$SB" -H "X-API-Key: $FB_API_KEY"
# {"id":"sb_...","status":"destroyed"}
# pip install requests
import requests
FB_URL = "https://getfirebox.dev"
H = {"X-API-Key": "fb_your_api_key", "Content-Type": "application/json"}
# 1. create a sandbox
sb = requests.post(f"{FB_URL}/v1/sandboxes",
json={"vcpu": 1, "memory_mb": 512},
headers=H).json()
box_id = sb["id"]
# 2. run code
r = requests.post(f"{FB_URL}/v1/sandboxes/{box_id}/exec",
json={"command": 'python3 -c "print(40+2)"'},
headers=H).json()
print(r["stdout"]) # 42
# 3. destroy it
requests.delete(f"{FB_URL}/v1/sandboxes/{box_id}", headers=H)
const FB_URL = "https://getfirebox.dev";
const H = { "X-API-Key": "fb_your_api_key", "Content-Type": "application/json" };
// 1. create a sandbox
const sb = await fetch(`${FB_URL}/v1/sandboxes`, {
method: "POST", headers: H,
body: JSON.stringify({ vcpu: 1, memory_mb: 512 }),
}).then(r => r.json());
// 2. run code
const run = await fetch(`${FB_URL}/v1/sandboxes/${sb.id}/exec`, {
method: "POST", headers: H,
body: JSON.stringify({ command: 'python3 -c "print(40+2)"' }),
}).then(r => r.json());
console.log(run.stdout); // 42
// 3. destroy it
await fetch(`${FB_URL}/v1/sandboxes/${sb.id}`, { method: "DELETE", headers: H });
Built for untrusted code
Agent-generated code is hostile code. firebox treats it that way.
Firecracker microVM isolation
Every sandbox gets its own KVM microVM, kernel, and private /30 network. No shared kernels, no cross-tenant traffic.
Streaming exec output
Watch long-running commands as they happen — stdout and stderr stream over SSE, in order per stream.
Pause / resume snapshots
Snapshot a sandbox to disk and bring it back later. State survives; the compute meter stops while paused.
Filesystem API
Read, write, list, and delete files inside the sandbox. Paths are jailed — traversal is rejected.
Per-second metering
CPU time and memory metered by the second, totaled per API key. The exact events usage-based billing needs.
API key management
Create, rotate, and revoke keys with per-key concurrency caps and rate limits. Secrets shown once, never again.
MCP server for AI agents
Ten tools over stdio — create, exec, files, pause, resume, delete, usage. Point Claude Code or Claude Desktop at firebox and agents run code in microVMs instead of on your machine. See it in action.
API reference
Every endpoint takes an X-API-Key header, except GET /healthz. Click any endpoint for request/response examples.
| Method | Path | Purpose |
|---|
Status codes: 401 missing/invalid/revoked key · 403 valid key, not admin · 409 state conflict (e.g. exec on a paused sandbox) · 410 sandbox expired · 413 file too large · 422 bad path.
Private pilot — invite only
Express interest
Tell us what you’d run in a sandbox. We’re onboarding a small group of teams with real workloads, and we’ll reach out when a spot opens.
- Run AI-generated code without having to trust it
- Every execution isolated in its own Firecracker microVM
- Locked-down network — DNS can’t exfiltrate