Sandbox Agent tools (BETA)
Inside the sandbox, the agent doesn't just reply — it calls tools to act. During a turn, every tool call shows up live in the UI. This page describes the tools available in the Sandbox Agent BETA feature (overview).
Files
write_file / read_file
Write a file into the sandbox workspace, and read it back. This is how the agent produces code, data, or a deliverable to later publish as an artifact.
filesystem
Explore the workspace: list a directory's contents and get file metadata (stat). Useful for the agent to get its bearings before acting.
Execution
run_code
Run a code snippet (in the agent's runtime, Python or Node) and get its output. Ideal for a one-off computation or a quick check.
terminal
Run shell commands in the sandbox. The agent can install an available dependency, manipulate files, run tests, and so on.
python_context
A stateful Python namespace that persists across calls within a single sandbox: variables and imports you define stay available from one call to the next, like a notebook. (Reminder: this state is gone the moment the sandbox expires — and that can be much sooner than the ~10 minutes a turn gets while it's actively running: once the agent stops working, the sandbox is released after only ~2 minutes. Anything you need from this namespace has to be extracted — written to a file and published as an artifact — before the turn ends, not "sometime before the sandbox expires.")
Persistence and deliverables
checkpoint
Create, list, restore, and delete checkpoints of the filesystem state. This is how the agent keeps an intermediate state and returns to it mid-task.
publish_artifact
Publish a workspace file as a downloadable artifact (with an expiry). See workspace and artifacts.
Web
web_search
Status: `web_search` not enabled yet. It is not available to beta accounts while its security, cost and rollback gates remain closed.
Search the public web. Results are normalized (title, URL, snippet) and size-bounded.
At launch, the ceilings remain 1 search per turn, and per account 3 per 5-hour window and 6 per week on Dev, 5 and 12 on Pro. A counted search stays counted even if the provider errors or times out — the ceiling protects your plan, it does not refund attempts.
web_fetch
Status: `web_fetch` not enabled yet. This tool is open on no account. It's documented here because it's part of the feature, not because it's available.
Fetch the contents of an authorized public page. Access is SSRF-guarded (only allowed targets are reachable) and the tool may ask for confirmation before fetching a page.
Next steps
- Conversations and turns — watch tool calls stream in.
- Workspace and artifacts — upload files, publish deliverables.
