sandboxes scope.
Store the key in a server-side environment variable:
1. Create a sandbox
Use an idempotency key so a network retry cannot create a second sandbox:id, which is also the public sandbox identifier:
2. Stream the lifecycle
The stream covers boot, agent output, approvals, tools, and completion in one connection. Use a fetch-based SSE client because browserEventSource cannot set the authorization header.
id. Reconnect with Last-Event-ID, or pass the same value as ?since= when your HTTP client cannot set that header. Delivery is at least once, so apply events idempotently.
3. Send a follow-up
After the first turn settles, the same sandbox can accept another prompt. A stablepromptId makes retries idempotent.