spawnd gives an AI agent a secure Firecracker microVM over a REST call. Create a sandbox, run untrusted code inside it, expose a port, snapshot and fork it — and pay only for the resource-seconds you allocate.
The primary consumer of spawnd is a machine — an agent or app driving sandboxes at scale, not a human clicking around. A sandbox is one Firecracker microVM running a generic Ubuntu rootfs with common toolchains preinstalled (Node, Python, Go, Rust, and the usual build utilities). Guest code is hostile by default and isolated by construction; it cannot reach the host, the control plane, or another sandbox.
REST / SDK API
The primary surface. Create, exec, files, ports, and the full lifecycle.
SSH & terminal
A browser terminal or SSH into the VM for human sessions.
Preview URLs
Expose a guest port at <id>--<workspace>.spawnd.online via reverse proxy.
MCP server
Sandbox control as MCP tools, so LLM clients drive VMs directly.
Quickstart
From zero to a running sandbox with curl. Base URL is https://api.spawnd.sh.
Request a magic link
In dev mode the sign-in link is returned inline as devLink.
Two disjoint auth surfaces share one port. A session JWT cannot drive the sandbox SDK, and an API key cannot manage keys.
Org API key
All sandbox and usage calls. Sent as a bearer token:
Authorization: Bearer e2b_...
Stored as a sha256 hash + 20-char prefix; the secret is shown once at creation.
Session JWT
Dashboard and key-management calls (/auth/*, /v1/keys):
Authorization: Bearer <jwt>
Issued by the passwordless magic-link flow. No passwords anywhere.
Magic link, dev mode. With no email provider configured the sign-in link is returned in the response (devLink) and logged — never dropped. The console auto-provisions your default API key on first authenticated load.
Sandboxes & sizes
template accepts a named size preset. Allocation (vCPU + memory) is fixed at create time and is the basis for resource-seconds billing. Unknown names fall back to the base size.
Name
vCPU
Memory
Use for
smallbox / base
1
2048 MiB
Light scripts, quick execs — cheapest.
box / default
2
4096 MiB
The default. General-purpose agent work.
bigbox
4
8192 MiB
Heavy compilation, parallel workloads.
megabox
8
16384 MiB
The largest box — big builds, many parallel jobs.
Lifecycle
Every sandbox supports the full lifecycle, and every verb is idempotent: kill on a dead sandbox succeeds, pause on a paused VM is a no-op, and create with the same idempotency key returns the same sandbox.
Verb
Meaning
create
Allocate a sandbox from a template; resumes from the warm pool when it can.
start
Bring a created sandbox to running.
exec
Run a command inside the guest and get its stdout, stderr, and exit code.
snapshot
Capture full VM state (memory + disk) as a restorable artifact.
fork
Copy-on-write clone from a snapshot — cheap children from one parent state.
pause
Snapshot memory + state and freeze CPU; billing drops to the paused rate.
resume
Un-freeze a paused VM back to running.
stop
Graceful shutdown.
kill
Hard teardown; release every host resource immediately. Terminal.
Legal states: creating, running, paused, stopping, stopped, killed, plus transient snapshotting and forking. killed is terminal. Cold starts use snapshot-restore from a warm pool, so create and resume are sub-second.
Guest code is treated as hostile. Each VM boots under jailer (chroot + dropped privileges) in its own network namespace, with a per-VM tap device and double-NAT'd outbound internet. From inside a sandbox there is no route to the host, no route to the control plane, and no route to another sandbox; /dev/kvm and host files are unreachable. Isolation is enforced by construction, not by trusting the guest.
Billing — resource-seconds
spawnd bills allocated resource-seconds, not flat wall-clock, so cost scales with size. Both dimensions derive from the create-time allocation × time:
vCPU-secondsvcpu × seconds
GiB-seconds(memMib / 1024) × seconds
Allocation is fixed at create, so billing is deterministic and unforgeable — the guest cannot change its own vcpu/memMib.
State
Billed
Rate class
running
vCPU-s + GiB-s, live
active
snapshotting, forking
live (still running)
active
paused
vCPU-s + GiB-s, paused rate
paused
creating
not billed until guest ping ok
—
stopped, killed
not billed
—
API · Auth
The passwordless sign-in flow. No auth required to start it; the token is the credential.
POST/auth/magic-linknone
Find-or-create the org + user, mint a single-use token, and send the sign-in link. devLink is present only in dev mode.
Every API error is { code, message, retryable }. Only capacity is generally worth retrying.
Code
Meaning
HTTP
unauthorized
Missing, invalid, or wrong-surface credential
401
not_found
No such sandbox or resource for this org
404
invalid_state
The verb is illegal for the sandbox's current state
409
quota_exceeded
Org quota reached
429
capacity
No host slot right now (retryable)
503
guest_timeout
The guest did not respond in time
504
internal
Unexpected server error
500
CLI
The spawn CLI wraps the same REST API. Authenticate once with your org API key, then drive sandboxes from the terminal.
Command
Does
spawn smallbox
Create and enter a smallbox (1 vCPU / 2048 MiB).
spawn bigbox
Create and enter a bigbox (4 vCPU / 8192 MiB).
spawn ls
List your org's sandboxes.
spawn exec <id> -- <cmd>
Run a command inside a sandbox and stream the result.
spawn ssh <id>
A real SSH session — scp, rsync and Remote-SSH work against it.
spawn cp <src> <dst>
Copy files in or out; one side is <id>:<path>.
spawn fork <id>
Copy-on-write clone a sandbox from its latest snapshot.
spawn snapshots
List your org's durable snapshots; -fork, -rename, -rm act on one.
spawn rm <id>
Kill a sandbox and reap its resources.
# create a bigbox, run a build, then tear it downspawn bigboxspawn exec sbx_123 -- cargo build --releasespawn rm sbx_123
MCP server
The orchestrator exposes sandbox control as an MCP server, so any MCP client — an IDE, an agent framework, an LLM app — can drive sandboxes as tools. Register it with your org API key as the bearer credential.
Copy-on-write clone from live state or a snapshot.
list_snapshots
The org's durable snapshots — they outlive their sandbox.
fork_snapshot
Boot a new sandbox from a snapshot, no live parent needed.
rename_snapshot / delete_snapshot
Relabel or remove one.
pause / resume
Pause or resume a sandbox.
kill
Kill a sandbox and reap resources.
Preview URLs
Expose a guest port to the public internet with POST /v1/sandboxes/:id/ports. The response url is http://<sandbox-id>--<workspace>.spawnd.online — a single DNS label (double-dash separator) so one *.spawnd.online wildcard covers every preview — routed by the HTTP Host header. Previews are org-scoped by construction and never outlive their VM — stopping or killing the sandbox deregisters the mapping.
# start a dev server in the sandbox, expose it, share the URLspawn exec sbx_123 -- python3 -m http.server 8000&curl-s-X POST https://api.spawnd.sh/v1/sandboxes/sbx_123/ports \-H'Authorization: Bearer e2b_...'\-H'Content-Type: application/json'-d'{"port":8000}'# → { "url": "http://sbx_123--acme.spawnd.online" }# routed by Host header, so it is testable locally:curl-H'Host: sbx_123--acme.spawnd.online' http://127.0.0.1:8080/
SSH available
Add your public key first. Until an SSH key is authorized for your org, a sandbox reports sshReason: "no_org_key" instead of an endpoint — see Settings → SSH keys. That page is the only way in: it is session-authed on purpose, so an API key cannot authorize a permanent shell into every sandbox you own.
SSH is the human interface to a sandbox. Everything an agent needs is in the REST API; SSH exists so a person can work in a sandbox with the tools they already use — scp, rsync, git, and editor Remote-SSH — none of which speak our API. Each sandbox is single-tenant, so you log in as root.
1 · Add your public key, once
Paste ~/.ssh/id_ed25519.pub into Settings → SSH keys. The key is stored on your organization and authorizes every sandbox the org creates — there is nothing to configure per sandbox. No private key ever leaves your machine, and if you do not have a key yet:
ssh-keygen -t ed25519 -C"$(whoami)@$(hostname)"
2 · Connect
A sandbox with SSH wired reports an ssh object on GET /v1/sandboxes/:id, and the console shows the same command. The host is the sandbox's preview name; the port is allocated per sandbox and is stable for its lifetime, so it is safe to put in ~/.ssh/config.
ssh-p34211 root@sbx_123--acme.spawnd.online# file transfer, sync, and Remote-SSH all work — it is a real sshdscp-P34211 app.tar.gz root@sbx_123--acme.spawnd.online:/root/rsync-e'ssh -p 34211'-a ./src/ root@sbx_123--acme.spawnd.online:/root/src/code --remote ssh-remote+sbx_123--acme.spawnd.online:34211 /root# or let the CLI find the port for you (and resume the sandbox if it is paused)spawn ssh sbx_123spawn ssh-config sbx_123 >> ~/.ssh/config
Host keys
Every sandbox generates its own ed25519 host key on first boot, so two sandboxes are never the same host to your SSH client. The fingerprint is published on the sandbox — compare it on first connect, or let spawn ssh-config write the known_hosts entry for you. You should never need StrictHostKeyChecking=no; if a fingerprint changes on a sandbox you did not recreate, stop and tell us.
Behaviour worth knowing
Situation
What happens
Org has no SSH key
No public port is opened at all — the right default for orgs that only ever drive sandboxes from code
Session open past the idle timeout
Sandbox stays running — a live SSH connection counts as activity, so a long build never freezes under you
Connecting to a paused sandbox
Connection refused; nothing is listening to wake it. Resume first — spawn ssh does that for you
You revoke a key
Immediate for new sandboxes, and on next start for sandboxes already running
You fork a sandbox
The child gets its own port, but inherits its parent's host key from the snapshot — expect a matching fingerprint
Everything on this page is also available as one self-contained markdown file for agents to ingest.