CoreWeave
Sandboxes

Run code you can’t fully trust next to your models, data, and GPUs. Each sandbox reaches only what you allow. Choose your CKS cluster or CoreWeave-managed capacity through one API.

import { createSandboxClientFromEnv } from "@coreweave/cwsandbox/node";
const client = createSandboxClientFromEnv();
const result = await client.withSandbox(
  async (sandbox) => sandbox.commands.run(["echo", "Hello!"]),
  { resources: { cpu: "1", memory: "1Gi" } },
);
console.log(result.stdout);
Copied

Give agents a controlled place to work

Agents, evaluations, and RL runs need a safe place for model-generated commands, file edits, and tool calls. CoreWeave Sandboxes gives every run its own isolated environment under the boundaries your platform team sets.

Contain what breaks

Agent code can behave unpredictably. Serverless sandboxes run in hardware-isolated microVMs with their own kernel, filesystem, and network. On CKS, administrators set the permitted runtime classes, so every workload stays inside the containment your policy allows.

Keep work close to your AI

Run sandboxes on the same CoreWeave storage, Kubernetes, and network as your training and inference. Your agents reach the models and data they need locally. Sensitive work stays inside your environment, with no public path in.

Set the policy once

Define network access, runtime classes, resource limits, security posture, and lifetime at the cluster level. Every sandbox request must fit that policy, and templates or workload overrides cannot bypass it.

Your cluster or ours, one API

Use the same API, client, control plane, and lifecycle whether a sandbox runs on your CKS capacity or on CoreWeave-managed capacity. Choose the placement that fits the workload without changing how your team builds.

CoreWeave-managed capacity

Start isolated environments in seconds with nothing to provision. CoreWeave operates the capacity and policy. Your teams can run agent and research workloads on demand and pay only for the resources each workload requests while it runs.

Your CKS capacity

Run sandboxes on the CoreWeave compute you already use for training and inference. Put idle CPU to work between training runs, keep code and data inside your environment, and let administrators own the cluster policy.

Burst when your cluster fills

When an evaluation sweep or RL fan-out outgrows your cluster, the CoreWeave Sandboxes SDK can place additional workloads on managed capacity. The work keeps moving without waiting for local capacity.

DEVELOPER EXPERIENCE

Build with Python or TypeScript

Use open-source Python or TypeScript clients to create sandboxes, run commands, and collect results through the same API.

NETWORK CONTROL

Control what each sandbox can reach

Allow each sandbox to reach only the services it needs. Restrict outbound access by IP address, port, and HTTPS hostname without opening a public inbound path.

PERSISTENT WORKSPACES

Pick up where the run stopped

Snapshot a sandbox filesystem, then restore or fork that state into a new sandbox. Stop compute without losing the workspace.

Interface of a web app named Forge showing the Sandboxes section with sidebar options Getting started, Org sandboxes, and Snapshots; main area displays instructions about Sandboxes as isolated compute environments for Python or JavaScript workloads with buttons to create a sandbox or save a sandbox as a snapshot, plus a link to documentation.
SANDBOXES IS PART OF COREWEAVE FORGE

Run every stage of the AI loop in isolation

CoreWeave Sandboxes gives agents, evaluations, and RL rollouts isolated execution next to the models, data, and compute they use. The same environment supports the work from first test through production.

Run

Improve

Evaluate

FAQS

Frequently asked questions

What are CoreWeave Sandboxes?

How are sandbox workloads isolated?

Where can a sandbox run?

Can workloads move between CKS and managed capacity?

How does policy enforcement work?

How do sandboxes connect to services and the internet?

Do CoreWeave Sandboxes support GPUs?

Which languages and workload types are supported?

Can sandbox state persist between sessions?