Private pilot — invite only
firebox
Secure code execution for AI agents — every run in its own Firecracker microVM.
One HTTP call spins up an isolated Linux sandbox. Run code, stream the output, tear it down. Metered per second.
$ curl -X POST https://firebox.beamto.io/v1/sandboxes \
-H "X-API-Key: $FB_KEY" -d '{"vcpu":1,"memory_mb":512}'
{"id":"sb_8fa8f125a9cc","status":"running"}
$ curl -X POST .../sb_8fa8f125a9cc/exec \
-d '{"command":"python3 -c \"print(40+2)\""}'
{"stdout":"42\n","exit_code":0,"duration_ms":29,"timed_out":false}
$ curl -X DELETE .../sb_8fa8f125a9cc
{"id":"sb_8fa8f125a9cc","status":"destroyed"}
How it works
Three calls. No servers to manage, no containers to harden.
Create a sandbox
POST /v1/sandboxes boots an isolated Linux microVM — its own kernel, its own private network.
Execute code
Run commands, stream output live, read and write files. Timeouts, CPU and memory caps enforced.
Destroy it
One call tears it down — or pause it to disk and resume later. Billed per second of actual compute.
Quickstart
Create a sandbox, run code, destroy it. Authenticate with an X-API-Key header.
# point at your firebox host and key
export FB_URL="https://firebox.beamto.io"
export FB_KEY="fb_your_api_key"
# 1. create a sandbox
SB=$(curl -s -X POST "$FB_URL/v1/sandboxes" \
-H "X-API-Key: $FB_KEY" -H 'Content-Type: application/json' \
-d '{"vcpu":1,"memory_mb":512}' \
| python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])')
# 2. run code
curl -s -X POST "$FB_URL/v1/sandboxes/$SB/exec" \
-H "X-API-Key: $FB_KEY" -H 'Content-Type: application/json' \
-d '{"command":"python3 -c \"print(40+2)\""}'
# {"stdout":"42\n","stderr":"","exit_code":0,"duration_ms":29,"timed_out":false}
# 3. destroy it
curl -s -X DELETE "$FB_URL/v1/sandboxes/$SB" -H "X-API-Key: $FB_KEY"
# {"id":"sb_...","status":"destroyed"}
# pip install requests
import requests
FB_URL = "https://firebox.beamto.io"
H = {"X-API-Key": "fb_your_api_key", "Content-Type": "application/json"}
# 1. create a sandbox
sb = requests.post(f"{FB_URL}/v1/sandboxes",
json={"vcpu": 1, "memory_mb": 512},
headers=H).json()
box_id = sb["id"]
# 2. run code
r = requests.post(f"{FB_URL}/v1/sandboxes/{box_id}/exec",
json={"command": 'python3 -c "print(40+2)"'},
headers=H).json()
print(r["stdout"]) # 42
# 3. destroy it
requests.delete(f"{FB_URL}/v1/sandboxes/{box_id}", headers=H)
const FB_URL = "https://firebox.beamto.io";
const H = { "X-API-Key": "fb_your_api_key", "Content-Type": "application/json" };
// 1. create a sandbox
const sb = await fetch(`${FB_URL}/v1/sandboxes`, {
method: "POST", headers: H,
body: JSON.stringify({ vcpu: 1, memory_mb: 512 }),
}).then(r => r.json());
// 2. run code
const run = await fetch(`${FB_URL}/v1/sandboxes/${sb.id}/exec`, {
method: "POST", headers: H,
body: JSON.stringify({ command: 'python3 -c "print(40+2)"' }),
}).then(r => r.json());
console.log(run.stdout); // 42
// 3. destroy it
await fetch(`${FB_URL}/v1/sandboxes/${sb.id}`, { method: "DELETE", headers: H });
Built for untrusted code
Agent-generated code is hostile code. firebox treats it that way.
Firecracker microVM isolation
Every sandbox gets its own KVM microVM, kernel, and private /30 network. No shared kernels, no cross-tenant traffic.
Streaming exec output
Watch long-running commands as they happen — stdout and stderr stream over SSE, in order per stream.
Pause / resume snapshots
Snapshot a sandbox to disk and bring it back later. State survives; the compute meter stops while paused.
Filesystem API
Read, write, list, and delete files inside the sandbox. Paths are jailed — traversal is rejected.
Per-second metering
CPU time and memory metered by the second, totaled per API key. The exact events usage-based billing needs.
API key management
Create, rotate, and revoke keys with per-key concurrency caps and rate limits. Secrets shown once, never again.
API reference
Every endpoint takes an X-API-Key header, except GET /healthz. Key management endpoints are admin-only.
| Method | Path | Purpose |
|---|---|---|
| POST | /v1/sandboxes | Create a sandbox |
| POST | /v1/sandboxes/{id}/exec | Run a command, get the output |
| POST | /v1/sandboxes/{id}/exec/stream | Run a command, stream output (SSE) |
| GET | /v1/sandboxes/{id} | Get sandbox status |
| DELETE | /v1/sandboxes/{id} | Destroy a sandbox |
| POST | /v1/sandboxes/{id}/pause | Snapshot to disk and pause |
| POST | /v1/sandboxes/{id}/resume | Resume from snapshot |
| POST | /v1/sandboxes/{id}/files | Write a file (base64 content) |
| GET | /v1/sandboxes/{id}/files?path= | Read a file |
| GET | /v1/sandboxes/{id}/files/list?path= | List a directory |
| DELETE | /v1/sandboxes/{id}/files?path= | Delete a file |
| GET | /v1/usage | Usage totals for your key |
| POST | /v1/keys | Create an API key (admin) |
| GET | /v1/keys | List API keys (admin) |
| POST | /v1/keys/{id}/rotate | Rotate a key (admin) |
| DELETE | /v1/keys/{id} | Revoke a key (admin) |
| GET | /healthz | Health check, no auth |
Status codes: 401 missing/invalid/revoked key · 403 valid key, not admin · 409 state conflict (e.g. exec on a paused sandbox) · 410 sandbox expired · 413 file too large · 422 bad path.
Private pilot
firebox is in private pilot — access is invite-only for now. We’re validating with a small group of agent builders running real workloads.
See how it works