OpenInspect
Configure repositories and environments

Sandbox settings

Configure ports, resources, timeouts, child-session limits, and cost limits for sandboxes globally, per repository, or per environment.

Last reviewed View as MarkdownEdit on GitHubGive feedback

Sandbox settings control what each sandbox exposes (terminal, editor, desktop, tunnel ports), how much it can use (CPU, memory, lifetime, cost), and how many child sessions an agent can spawn.

Settings, Sandbox: repository scope picker, Web Terminal toggle, service ports, tunnel ports, session cost limit, child session limits, and resources
Settings › Sandbox with the global scope selected. Per-repository and per-environment values override these.

Where settings live

Settings are layered. Each layer only stores the fields you set; everything else inherits from the layer beneath it.

LayerWhere to editInherits from
Global defaultsSettings › Sandbox with "All Repositories (Global)" selectedNothing (provider defaults apply for blank fields)
Repository overridesSettings › Sandbox with a repository selectedGlobal defaults
Environment overridesSettings › Environments › the environment › SandboxGlobal defaults merged with the environment's primary repository overrides

Leaving a field blank at an override scope inherits the value from the layer beneath. The exceptions are CPU cores and memory: clearing them at a repository or environment scope explicitly uses the provider default instead of inheriting a global value.

Editing global defaults requires the integrations.manage permission; repository overrides require repositories.settings.manage, and environment overrides require environments.settings.manage. Without the permission for that scope the form is read-only.

Settings

SettingWhat it controlsNotes and limits
Web TerminalEnables a browser-based terminal in sandbox sessionsToggle. See sandbox tools for how the terminal is used in a session.
Code server portPort code-server binds to inside the sandboxDefault 8080. Code-server itself is enabled under Settings › Integrations; see Sandbox tools.
VNC portPort noVNC binds to inside the sandboxDefault 6080. The VNC desktop is enabled under Settings › Integrations; see Sandbox tools.
Terminal portPort the web terminal proxy is exposed onDefault 7680
Tunnel PortsExtra ports exposed from the sandbox as public tunnel URLs, such as dev server portsUp to 10 ports. Whole numbers from 1 to 65535.
Cost limit (USD)Stops additional model work once the reported session cost reaches the limitPositive amount. Blank means "No limit" at global scope and "Inherit" at override scopes. Unreported model cost cannot be limited.
Max concurrent child sessionsActive agent-spawned child sessions per parent sessionDefault 5. Must be less than or equal to the total limit.
Max total child sessionsAgent-spawned child sessions per parent session over its lifetimeDefault 15
CPU coresCPU reserved for each sandboxPlaceholder "provider default". Positive number. Shown only on providers that support resource settings.
Memory (MiB)Memory reserved for each sandboxPlaceholder "provider default". Positive whole number. Shown only on providers that support resource settings.
Session Timeout (minutes)Requested lifetime of each sandboxThe sandbox lifetime, in minutes. Internally stored in whole seconds with a minimum of 1 second. Blank inherits a parent setting. Blank at every layer means 2 hours on Modal and E2B (E2B uses the operator's TTL, 2 hours by default), 45 minutes on Vercel (its maximum), and OpenComputer's own default. Shown only on providers that support timeout settings.
Final snapshot buffer (minutes)Time reserved before provider expiry to stop work, preserve the filesystem, and retire the sandboxDefault 10 minutes, minimum 5 minutes. Must be shorter than the session timeout.
Image Build TimeoutHow long a prebuilt image may take to build (clone plus setup), in secondsDefault 1800, maximum 3600. Applies to builds only; sessions are unaffected.

Port rules apply across the whole form: the code server, VNC, terminal, and tunnel ports must all be different, and the ports reserved for internal sandbox services (5900 and 7681) cannot be used. Change a service port to free its default for your own service on a tunnel.

Click Save Settings to apply. The form reports the first validation error it finds, for example "Code server, VNC, terminal, and tunnel ports must all be different."

Provider capabilities

Resource and timeout fields are honored only by providers that support them. On other providers the form hides the field and notes that the value is configured by the deployment. Stored values for a hidden field are preserved, not deleted.

ProviderCPU and memorySession timeout
ModalYesYes
VercelYesYes
OpenComputerNoYes
E2BNoYes
DaytonaNoNo

See sandbox providers for what each provider offers.

When changes apply

Sandbox settings are resolved when a sandbox is created and when an image build starts. A sandbox that is already running keeps the settings it was created with; the next sandbox for the same target, and the next build, use the new values.

The session cost limit can also be adjusted for one session from the Budget section of the session sidebar. That change applies only to that session. See spend limits.

Troubleshooting

Next steps

On this page