AI Sandboxes: Secure Runtime for Agent Code | LangSmith

LangSmith Sandboxes

Give agents a secure computer

Ephemeral, isolated sandboxes designed for agent-generated code.

Helping top teams ship great agents

Three ways to build, from full harness to full control

Each package solves a different problem. Choose where you want to start, then compose the rest of the stack around it.

Secure

Run untrusted code safely

Spin up ephemeral microVMs for agent-generated code. Agents get full root inside the sandbox, so they can install packages, run Docker, and do anything else you'd do on a Linux box. Your core infrastructure and other workloads stay untouched.

MicroVM isolation

Agent code runs in a dedicated VM, isolated from your infrastructure and from other sandboxes.

Auth Proxy for credentials

Inject credentials into outbound API requests from the sandbox, so your agent can call external services without secrets ever touching the runtime.

Framework-agnostic SDK

Use the Python or JS SDK with Deep Agents, another framework, or no framework at all.

Scalable

Sub-second starts

Spin up hundreds of sandboxes in parallel with one SDK call. Prewarming keeps p50 latency under 0.98s, so agents get an environment the moment they need one.

Burst to thousands on demand

Launch fleets of sandboxes for evals, parallel agent runs, or RL training without rate limits or queueing.

Bring your own image

Define dependencies, CPU, and memory in a Docker image, then reuse it across sandboxes.

Stateful

Built for long-running, stateful work

Sessions run over WebSockets with streamed output, and state persists across threads. Sandboxes stay alive only as long as you need.

Configurable TTLs

Set inactive TTLs so idle sandboxes shut down automatically, and set hard TTLs to cap total runtime.

Snapshot and fork

Snapshot a running sandbox to capture its full state, then restore later to resume where you left off, or fork the snapshot into multiple sandboxes so an agent can branch and explore alternatives in parallel.

Port tunneling

Open any port inside the sandbox and tunnel it to your local machine to preview a running app, hit an HTTP endpoint, or connect to a service the agent spun up.

FAQs for LangSmith Sandboxes

Ready to ship agents that execute code?

Give your agents an isolated runtime without exposing your infrastructure. Spin one up in a single SDK call.

Start building Get a demo