Private pilot — invite only

firebox

Secure code execution for AI agents — every run in its own Firecracker microVM.

One HTTP call spins up an isolated Linux sandbox. Run code, stream the output, tear it down. Metered per second.

How it works

Three calls. No servers to manage, no containers to harden.

1

Create a sandbox

POST /v1/sandboxes boots an isolated Linux microVM — its own kernel, its own private network.

2

Execute code

Run commands, stream output live, read and write files. Timeouts, CPU and memory caps enforced.

3

Destroy it

One call tears it down — or pause it to disk and resume later. Billed per second of actual compute.

Quickstart

Create a sandbox, run code, destroy it. Authenticate with an X-API-Key header.

# point at your firebox host and key
export FB_URL="https://firebox.beamto.io"
export FB_KEY="fb_your_api_key"

# 1. create a sandbox
SB=$(curl -s -X POST "$FB_URL/v1/sandboxes" \
  -H "X-API-Key: $FB_KEY" -H 'Content-Type: application/json' \
  -d '{"vcpu":1,"memory_mb":512}' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])')

# 2. run code
curl -s -X POST "$FB_URL/v1/sandboxes/$SB/exec" \
  -H "X-API-Key: $FB_KEY" -H 'Content-Type: application/json' \
  -d '{"command":"python3 -c \"print(40+2)\""}'
# {"stdout":"42\n","stderr":"","exit_code":0,"duration_ms":29,"timed_out":false}

# 3. destroy it
curl -s -X DELETE "$FB_URL/v1/sandboxes/$SB" -H "X-API-Key: $FB_KEY"
# {"id":"sb_...","status":"destroyed"}
# pip install requests
import requests

FB_URL = "https://firebox.beamto.io"
H = {"X-API-Key": "fb_your_api_key", "Content-Type": "application/json"}

# 1. create a sandbox
sb = requests.post(f"{FB_URL}/v1/sandboxes",
                   json={"vcpu": 1, "memory_mb": 512},
                   headers=H).json()
box_id = sb["id"]

# 2. run code
r = requests.post(f"{FB_URL}/v1/sandboxes/{box_id}/exec",
                  json={"command": 'python3 -c "print(40+2)"'},
                  headers=H).json()
print(r["stdout"])  # 42

# 3. destroy it
requests.delete(f"{FB_URL}/v1/sandboxes/{box_id}", headers=H)
const FB_URL = "https://firebox.beamto.io";
const H = { "X-API-Key": "fb_your_api_key", "Content-Type": "application/json" };

// 1. create a sandbox
const sb = await fetch(`${FB_URL}/v1/sandboxes`, {
  method: "POST", headers: H,
  body: JSON.stringify({ vcpu: 1, memory_mb: 512 }),
}).then(r => r.json());

// 2. run code
const run = await fetch(`${FB_URL}/v1/sandboxes/${sb.id}/exec`, {
  method: "POST", headers: H,
  body: JSON.stringify({ command: 'python3 -c "print(40+2)"' }),
}).then(r => r.json());
console.log(run.stdout); // 42

// 3. destroy it
await fetch(`${FB_URL}/v1/sandboxes/${sb.id}`, { method: "DELETE", headers: H });

Built for untrusted code

Agent-generated code is hostile code. firebox treats it that way.

Firecracker microVM isolation

Every sandbox gets its own KVM microVM, kernel, and private /30 network. No shared kernels, no cross-tenant traffic.

Streaming exec output

Watch long-running commands as they happen — stdout and stderr stream over SSE, in order per stream.

Pause / resume snapshots

Snapshot a sandbox to disk and bring it back later. State survives; the compute meter stops while paused.

Filesystem API

Read, write, list, and delete files inside the sandbox. Paths are jailed — traversal is rejected.

Per-second metering

CPU time and memory metered by the second, totaled per API key. The exact events usage-based billing needs.

API key management

Create, rotate, and revoke keys with per-key concurrency caps and rate limits. Secrets shown once, never again.

API reference

Every endpoint takes an X-API-Key header, except GET /healthz. Key management endpoints are admin-only.

MethodPathPurpose
POST/v1/sandboxesCreate a sandbox
POST/v1/sandboxes/{id}/execRun a command, get the output
POST/v1/sandboxes/{id}/exec/streamRun a command, stream output (SSE)
GET/v1/sandboxes/{id}Get sandbox status
DELETE/v1/sandboxes/{id}Destroy a sandbox
POST/v1/sandboxes/{id}/pauseSnapshot to disk and pause
POST/v1/sandboxes/{id}/resumeResume from snapshot
POST/v1/sandboxes/{id}/filesWrite a file (base64 content)
GET/v1/sandboxes/{id}/files?path=Read a file
GET/v1/sandboxes/{id}/files/list?path=List a directory
DELETE/v1/sandboxes/{id}/files?path=Delete a file
GET/v1/usageUsage totals for your key
POST/v1/keysCreate an API key (admin)
GET/v1/keysList API keys (admin)
POST/v1/keys/{id}/rotateRotate a key (admin)
DELETE/v1/keys/{id}Revoke a key (admin)
GET/healthzHealth check, no auth

Status codes: 401 missing/invalid/revoked key · 403 valid key, not admin · 409 state conflict (e.g. exec on a paused sandbox) · 410 sandbox expired · 413 file too large · 422 bad path.

Private pilot

firebox is in private pilot — access is invite-only for now. We’re validating with a small group of agent builders running real workloads.

See how it works