Skip to main content
Sandbox API access is available to every Sparkles user. Open the API access page while signed in to create a key for your active WorkOS organization, and include the sandboxes scope. Store the key in a server-side environment variable:

1. Create a sandbox

Use an idempotency key so a network retry cannot create a second sandbox:
The response is queued immediately. Save its id, which is also the public sandbox identifier:

2. Stream the lifecycle

The stream covers boot, agent output, approvals, tools, and completion in one connection. Use a fetch-based SSE client because browser EventSource cannot set the authorization header.
Durable events include an SSE id. Reconnect with Last-Event-ID, or pass the same value as ?since= when your HTTP client cannot set that header. Delivery is at least once, so apply events idempotently.

3. Send a follow-up

After the first turn settles, the same sandbox can accept another prompt. A stable promptId makes retries idempotent.

4. Terminate the sandbox

Termination is idempotent: