> ## Documentation Index
> Fetch the complete documentation index at: https://docs.e2b.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Create sandbox

> Create a sandbox from the template. Use POST /v2/sandboxes instead.



## OpenAPI

````yaml /openapi-public.yaml post /sandboxes
openapi: 3.1.0
info:
  title: E2B API
  version: 0.1.0
  description: >-
    Complete E2B developer API. Platform endpoints are served on api.e2b.app.
    Sandbox endpoints (envd) are served on the shared sandbox host
    (sandbox.e2b.app); target a specific sandbox with the E2b-Sandbox-Id and
    E2b-Sandbox-Port headers.
servers:
  - url: https://api.e2b.app
    description: E2B Platform API
security: []
tags:
  - name: Sandboxes
  - name: Templates
  - name: Tags
  - name: Volumes
  - name: Envd
  - name: Filesystem
  - name: Process
  - name: Teams
  - name: Secrets
  - name: Events
  - name: Webhooks
paths:
  /sandboxes:
    servers:
      - url: https://api.e2b.app
        description: E2B Platform API
    post:
      tags:
        - Sandboxes
      summary: Create sandbox
      description: Create a sandbox from the template. Use POST /v2/sandboxes instead.
      operationId: postSandboxes
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/NewSandbox'
      responses:
        '201':
          description: The sandbox was created successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Sandbox'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 400
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                invalidAutoPausePolicy:
                  summary: >-
                    Filesystem-only auto-pause was requested without enabling
                    auto-pause
                  value:
                    code: 400
                    message: autoPauseMemory=false only applies when autoPause is true.
        '401':
          description: Authentication error
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 401
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                missingAuthentication:
                  summary: No supported authentication header was supplied
                  value:
                    code: 401
                    message: authorization header is missing
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 403
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                teamBanned:
                  summary: The team is banned at authentication
                  value:
                    code: 403
                    message: team is banned
                teamBlocked:
                  summary: >-
                    The authenticated team is blocked. The message may append a
                    reason
                  value:
                    code: 403
                    message: team is blocked
                egressProxyDisabled:
                  summary: >-
                    Egress proxy configuration was supplied without feature
                    access
                  value:
                    code: 403
                    message: >-
                      Egress proxy (network.egressProxy) is not enabled for this
                      team.
        '404':
          description: Not found
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 404
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                templateNotFound:
                  summary: The template reference cannot be resolved
                  value:
                    code: 404
                    message: template 'my-template' not found
        '429':
          description: Too many requests
          headers:
            Retry-After:
              description: >-
                When present, the number of seconds to wait before retrying the
                request.
              required: false
              schema:
                type: integer
                minimum: 0
              example: 30
            RateLimit-Limit:
              description: Configured rate-limit burst size.
              schema:
                type: integer
            RateLimit-Remaining:
              description: Requests remaining in the rate-limit window.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the rate-limit window resets.
              schema:
                type: integer
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 429
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                rateLimitExceeded:
                  summary: A configured API rate limit was exceeded
                  value:
                    code: 429
                    message: Rate limit exceeded
        '500':
          description: Server error
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 500
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                volumeConversionFailed:
                  summary: Resolving requested volume mounts fails
                  value:
                    code: 500
                    message: failed to convert volume mounts
        '503':
          description: Service unavailable
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 503
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                capacityUnavailable:
                  summary: No node has capacity for the requested sandbox
                  value:
                    code: 503
                    message: >-
                      Failed to place sandbox: not enough capacity for the
                      requested resources right now, please retry shortly
                    error_code: sandbox_capacity_unavailable
        '504':
          description: Backend timeout
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 504
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                placementTimeout:
                  summary: Placement times out before its first attempt
                  value:
                    code: 504
                    message: 'Failed to place sandbox: placement timed out, please retry'
                    error_code: sandbox_placement_timeout
      deprecated: true
      security:
        - ApiKeyAuth: []
components:
  schemas:
    NewSandbox:
      required:
        - templateID
      properties:
        templateID:
          type: string
          description: Identifier of the required template
        timeout:
          type: integer
          format: int32
          minimum: 0
          default: 15
          description: Time to live for the sandbox in seconds.
        autoPause:
          type: boolean
          default: false
          description: Automatically pauses the sandbox after the timeout
        autoPauseMemory:
          type: boolean
          default: true
          description: >-
            Controls the snapshot kind taken when the sandbox auto-pauses on
            timeout (only relevant when autoPause is true). When false, the
            auto-pause drops the in-memory state and persists only the
            filesystem (a filesystem-only snapshot); resuming it cold-boots
            (reboots) the sandbox from disk. Such a snapshot cannot be
            auto-resumed by traffic and must be resumed explicitly, so it cannot
            be combined with autoResume. Defaults to true (full memory
            snapshot).
        autoResume:
          $ref: '#/components/schemas/SandboxAutoResumeConfig'
        secure:
          type: boolean
          description: Secure all system communication with sandbox
        allow_internet_access:
          type: boolean
          description: >-
            Allow sandbox to access the internet. When set to false, it behaves
            the same as specifying denyOut to 0.0.0.0/0 in the network config.
        network:
          $ref: '#/components/schemas/SandboxNetworkConfig'
        metadata:
          $ref: '#/components/schemas/SandboxMetadata'
        envVars:
          $ref: '#/components/schemas/EnvVars'
        mcp:
          $ref: '#/components/schemas/Mcp'
        iam:
          $ref: '#/components/schemas/SandboxIam'
        volumeMounts:
          type: array
          items:
            $ref: '#/components/schemas/SandboxVolumeMount'
      type: object
    Sandbox:
      required:
        - templateID
        - sandboxID
        - clientID
        - envdVersion
      properties:
        templateID:
          type: string
          description: Identifier of the template from which is the sandbox created
        sandboxID:
          type: string
          description: Identifier of the sandbox
        alias:
          type: string
          description: Alias of the template
        clientID:
          type: string
          deprecated: true
          description: Identifier of the client
        envdVersion:
          $ref: '#/components/schemas/EnvdVersion'
        envdAccessToken:
          type: string
          description: Access token used for envd communication
        trafficAccessToken:
          type:
            - string
            - 'null'
          description: Token required for accessing sandbox via proxy.
        domain:
          type:
            - string
            - 'null'
          description: Base domain where the sandbox traffic is accessible
      type: object
    SandboxAutoResumeConfig:
      type: object
      description: Auto-resume configuration for paused sandboxes.
      required:
        - enabled
      properties:
        enabled:
          $ref: '#/components/schemas/SandboxAutoResumeEnabled'
    SandboxNetworkConfig:
      type: object
      properties:
        allowPublicTraffic:
          type: boolean
          default: true
          description: >-
            Specify if the sandbox URLs should be accessible only with
            authentication.
        allowOut:
          type: array
          description: >-
            List of allowed destinations for egress traffic. Each entry can be a
            CIDR block (e.g. "8.8.8.8/32"), a bare IP address (e.g. "8.8.8.8"),
            or a domain name (e.g. "example.com", "*.example.com"). Allowed
            entries always take precedence over denied entries.
          items:
            type: string
        denyOut:
          type: array
          description: >-
            List of denied CIDR blocks or IP addresses for egress traffic.
            Domain names are not supported for deny rules.
          items:
            type: string
        egressProxy:
          $ref: '#/components/schemas/SandboxEgressProxyConfig'
        maskRequestHost:
          type: string
          description: Specify host mask which will be used for all sandbox requests
        httpsPorts:
          type: array
          description: >-
            Sandbox ports that serve HTTPS rather than plaintext HTTP. Affects
            how the proxy reaches the service inside the sandbox; the public URL
            is HTTPS either way. Certificates are not verified, so self-signed
            ones work. The envd port (49983) cannot be listed.
          maxItems: 128
          uniqueItems: true
          items:
            type: integer
            format: uint32
            minimum: 1
            maximum: 65535
        rules:
          type: object
          description: >
            Per-domain transform rules applied to matching outbound HTTPS
            requests. Keys may be exact DNS names (for example,
            "api.example.com") or a leading wildcard (for example,
            "*.example.com"), and are normalized to lowercase on write.
            Wildcards match subdomains at any depth but not the apex domain; a
            bare "*" is invalid. Exact rules take precedence, followed by the
            longest matching wildcard suffix, and matching rule sets are not
            merged. Broad wildcards such as "*.com" are allowed and may expose
            transformed credentials to every matching destination the sandbox
            contacts. Rules do not grant network access; configure allowOut
            separately to permit the destination.
          additionalProperties:
            type: array
            items:
              $ref: '#/components/schemas/SandboxNetworkRule'
    SandboxMetadata:
      additionalProperties:
        type: string
        description: Metadata of the sandbox
      type: object
    EnvVars:
      additionalProperties:
        type: string
        description: Environment variables for the sandbox
      type: object
    Mcp:
      type: object
      description: MCP configuration for the sandbox
      additionalProperties: {}
      nullable: true
    SandboxIam:
      type: object
      description: >-
        Sandbox workload identity configuration. A non-empty, valid tokens map
        enables workload identity for the sandbox.
      properties:
        tokens:
          $ref: '#/components/schemas/SandboxIamTokens'
    SandboxVolumeMount:
      type: object
      properties:
        name:
          type: string
          description: Name of the volume
        path:
          type: string
          description: Path of the volume
      required:
        - name
        - path
    EnvdVersion:
      type: string
      description: Version of the envd running in the sandbox
    SandboxAutoResumeEnabled:
      type: boolean
      description: Auto-resume enabled flag for paused sandboxes. Default false.
      default: false
    SandboxEgressProxyConfig:
      type: object
      nullable: true
      description: >-
        SOCKS5 proxy for sandbox egress. Outbound TCP is tunneled through the
        proxy after allow/deny filtering; the sandbox is unaware. Domain-matched
        flows use remote DNS (ATYP=domain).
      required:
        - address
      properties:
        address:
          type: string
          description: >-
            SOCKS5 proxy address in host:port format (e.g.
            "proxy.example.com:1080").
        username:
          type: string
          maxLength: 255
          description: Optional SOCKS5 username (RFC 1929), max 255 bytes.
        password:
          type: string
          maxLength: 255
          description: Optional SOCKS5 password (RFC 1929), max 255 bytes.
    SandboxNetworkRule:
      type: object
      description: Transform rule applied to egress requests matching a domain pattern.
      properties:
        transform:
          $ref: '#/components/schemas/SandboxNetworkTransform'
    SandboxIamTokens:
      type: object
      description: Named workload-token definitions, keyed by a caller-chosen token name.
      additionalProperties:
        $ref: '#/components/schemas/SandboxIamToken'
    SandboxNetworkTransform:
      type: object
      description: Transformations applied to matching egress requests before forwarding.
      properties:
        headers:
          type: object
          description: >
            HTTP headers to inject or override in matching requests. An existing
            header with the same name is replaced. Values are plain strings;
            secret resolution happens client-side before sending to the API.
          additionalProperties:
            type: string
    SandboxIamToken:
      type: object
      required:
        - audience
        - tokenType
      properties:
        audience:
          type: string
          description: Audience of the workload token, stored exactly as provided.
        tokenType:
          type: string
          description: Workload token type.
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key

````