Skip to main content
Global flags (available on all commands):
  • -t, --token <TOKEN>: require/use bearer auth
  • -n, --no-token: disable auth

server

Run the HTTP server.
sandbox-agent server [OPTIONS]
OptionDefaultDescription
-H, --host <HOST>127.0.0.1Host to bind
-p, --port <PORT>2468Port to bind
-O, --cors-allow-origin <ORIGIN>-Allowed CORS origin (repeatable)
-M, --cors-allow-method <METHOD>allAllowed CORS method (repeatable)
-A, --cors-allow-header <HEADER>allAllowed CORS header (repeatable)
-C, --cors-allow-credentialsfalseEnable CORS credentials
--no-telemetryfalseDisable anonymous telemetry
sandbox-agent server --port 3000
Notes:
  • Server logs are redirected to files by default.
  • Set SANDBOX_AGENT_LOG_STDOUT=1 to force stdout/stderr logging.
  • Use SANDBOX_AGENT_LOG_DIR to override log directory.

install-agent

Install or reinstall a single agent.
sandbox-agent install-agent <AGENT> [OPTIONS]
OptionDescription
-r, --reinstallForce reinstall
--agent-version <VERSION>Override agent package version
--agent-process-version <VERSION>Override agent process version
sandbox-agent install-agent claude --reinstall

opencode (experimental)

Start/reuse daemon and run opencode attach against /opencode.
sandbox-agent opencode [OPTIONS]
OptionDefaultDescription
-H, --host <HOST>127.0.0.1Daemon host
-p, --port <PORT>2468Daemon port
--session-title <TITLE>-Reserved option (currently no-op)
--yolofalseOpenCode attach mode flag
sandbox-agent opencode

daemon

Manage the background daemon.

daemon start

sandbox-agent daemon start [OPTIONS]
OptionDefaultDescription
-H, --host <HOST>127.0.0.1Host
-p, --port <PORT>2468Port
--upgradefalseUse ensure-running + upgrade behavior
sandbox-agent daemon start
sandbox-agent daemon start --upgrade

daemon stop

sandbox-agent daemon stop [OPTIONS]
OptionDefaultDescription
-H, --host <HOST>127.0.0.1Host
-p, --port <PORT>2468Port

daemon status

sandbox-agent daemon status [OPTIONS]
OptionDefaultDescription
-H, --host <HOST>127.0.0.1Host
-p, --port <PORT>2468Port

credentials

credentials extract

sandbox-agent credentials extract [OPTIONS]
OptionDescription
-a, --agent <AGENT>Filter by claude, codex, opencode, or amp
-p, --provider <PROVIDER>Filter by provider
-d, --home-dir <DIR>Override home dir
--no-oauthSkip OAuth sources
-r, --revealShow full credential values
sandbox-agent credentials extract --agent claude --reveal

credentials extract-env

sandbox-agent credentials extract-env [OPTIONS]
OptionDescription
-e, --exportPrefix output with export
-d, --home-dir <DIR>Override home dir
--no-oauthSkip OAuth sources
eval "$(sandbox-agent credentials extract-env --export)"

api

API subcommands for scripting. Shared option:
OptionDefaultDescription
-e, --endpoint <URL>http://127.0.0.1:2468Target server

api agents

sandbox-agent api agents list [--endpoint <URL>]
sandbox-agent api agents install <AGENT> [--reinstall] [--endpoint <URL>]