# Get sandbox (/docs/api-reference/sandboxes/get-sandbox)

<!-- agent-signals: reading_time_min: 4 · est_tokens: 2850 · updated: 2026-07-30 -->
Related: [List sandboxes](/docs/api-reference/sandboxes/list-sandboxes.md), [Create sandbox](/docs/api-reference/sandboxes/create-sandbox.md), [List sandboxes (v2)](/docs/api-reference/sandboxes/list-sandboxes-v2.md), [List sandbox metrics](/docs/api-reference/sandboxes/list-sandbox-metrics.md), [Get sandbox logs](/docs/api-reference/sandboxes/get-sandbox-logs.md), [Get sandbox logs (v2)](/docs/api-reference/sandboxes/get-sandbox-logs-v2.md)

# Get sandbox

`GET /sandboxes/{sandboxID}`

Get a sandbox by id

## OpenAPI

```json
{
  "security": [
    {
      "ApiKeyAuth": []
    }
  ],
  "parameters": [
    {
      "name": "sandboxID",
      "in": "path",
      "required": true,
      "schema": {
        "type": "string"
      }
    }
  ],
  "responses": {
    "200": {
      "description": "Successfully returned the sandbox",
      "content": {
        "application/json": {
          "schema": {
            "required": [
              "templateID",
              "sandboxID",
              "clientID",
              "startedAt",
              "cpuCount",
              "memoryMB",
              "diskSizeMB",
              "endAt",
              "state",
              "envdVersion"
            ],
            "properties": {
              "templateID": {
                "type": "string",
                "description": "Identifier of the template from which is the sandbox created"
              },
              "alias": {
                "type": "string",
                "description": "Alias of the template"
              },
              "sandboxID": {
                "type": "string",
                "description": "Identifier of the sandbox"
              },
              "clientID": {
                "type": "string",
                "deprecated": true,
                "description": "Identifier of the client"
              },
              "startedAt": {
                "type": "string",
                "format": "date-time",
                "description": "Time when the sandbox was started"
              },
              "endAt": {
                "type": "string",
                "format": "date-time",
                "description": "Time when the sandbox will expire"
              },
              "envdVersion": {
                "type": "string",
                "description": "Version of the envd running in the sandbox"
              },
              "envdAccessToken": {
                "type": [
                  "string",
                  "null"
                ],
                "description": "Access token for authenticating envd requests to this sandbox. Only returned when the sandbox is created with `secure: true`. Null for non-secure sandboxes (envd endpoints work without auth)."
              },
              "allowInternetAccess": {
                "type": [
                  "boolean",
                  "null"
                ],
                "description": "Whether internet access was explicitly enabled or disabled for the sandbox. Null means it was not explicitly set."
              },
              "domain": {
                "type": [
                  "string",
                  "null"
                ],
                "description": "Deprecated: always null. Construct sandbox URLs as `https://{port}-{sandboxID}.e2b.app`.",
                "deprecated": true
              },
              "cpuCount": {
                "type": "integer",
                "format": "int32",
                "minimum": 1,
                "description": "CPU cores for the sandbox"
              },
              "memoryMB": {
                "type": "integer",
                "format": "int32",
                "minimum": 128,
                "description": "Memory for the sandbox in MiB"
              },
              "diskSizeMB": {
                "type": "integer",
                "format": "int32",
                "minimum": 0,
                "description": "Disk size for the sandbox in MiB"
              },
              "metadata": {
                "additionalProperties": {
                  "type": "string",
                  "description": "Metadata of the sandbox"
                },
                "type": "object"
              },
              "state": {
                "type": "string",
                "description": "State of the sandbox",
                "enum": [
                  "running",
                  "paused"
                ]
              },
              "network": {
                "type": "object",
                "properties": {
                  "allowPublicTraffic": {
                    "type": "boolean",
                    "default": true,
                    "description": "Specify if the sandbox URLs should be accessible only with authentication."
                  },
                  "allowOut": {
                    "type": "array",
                    "description": "List of allowed destinations for egress traffic. Each entry can be a CIDR block (e.g. \"8.8.8.8/32\"), a bare IP address (e.g. \"8.8.8.8\"), or a domain name (e.g. \"example.com\", \"*.example.com\"). Allowed entries always take precedence over denied entries.",
                    "items": {
                      "type": "string"
                    }
                  },
                  "denyOut": {
                    "type": "array",
                    "description": "List of denied CIDR blocks or IP addresses for egress traffic. Domain names are not supported for deny rules.",
                    "items": {
                      "type": "string"
                    }
                  },
                  "egressProxy": {
                    "type": "object",
                    "nullable": true,
                    "description": "SOCKS5 proxy for sandbox egress. Outbound TCP is tunneled through the proxy after allow/deny filtering; the sandbox is unaware. Domain-matched flows use remote DNS (ATYP=domain).",
                    "required": [
                      "address"
                    ],
                    "properties": {
                      "address": {
                        "type": "string",
                        "description": "SOCKS5 proxy address in host:port format (e.g. \"proxy.example.com:1080\")."
                      },
                      "username": {
                        "type": "string",
                        "maxLength": 255,
                        "description": "Optional SOCKS5 username (RFC 1929), max 255 bytes."
                      },
                      "password": {
                        "type": "string",
                        "maxLength": 255,
                        "description": "Optional SOCKS5 password (RFC 1929), max 255 bytes."
                      }
                    }
                  },
                  "maskRequestHost": {
                    "type": "string",
                    "description": "Specify host mask which will be used for all sandbox requests"
                  },
                  "rules": {
                    "type": "object",
                    "description": "Per-domain transform rules applied to matching egress HTTP/HTTPS requests. Keys are domains (e.g. \"api.example.com\", \"example.com\"). A domain listed here is not automatically allowed - use allowOut to permit the traffic.\n",
                    "additionalProperties": {
                      "type": "array",
                      "items": {
                        "type": "object",
                        "description": "Transform rule applied to egress requests matching a domain pattern.",
                        "properties": {
                          "transform": {
                            "type": "object",
                            "description": "Transformations applied to matching egress requests before forwarding.",
                            "properties": {
                              "headers": {
                                "type": "object",
                                "description": "HTTP headers to inject or override in matching requests. An existing header with the same name is replaced. Values are plain strings; secret resolution happens client-side before sending to the API.\n",
                                "additionalProperties": {
                                  "type": "string"
                                }
                              }
                            }
                          }
                        }
                      }
                    }
                  }
                }
              },
              "lifecycle": {
                "type": "object",
                "description": "Sandbox lifecycle policy returned by sandbox info.",
                "required": [
                  "autoResume",
                  "onTimeout"
                ],
                "properties": {
                  "autoResume": {
                    "type": "boolean",
                    "description": "Whether the sandbox can auto-resume."
                  },
                  "onTimeout": {
                    "type": "string",
                    "description": "Action taken when the sandbox times out.",
                    "enum": [
                      "kill",
                      "pause"
                    ]
                  }
                }
              },
              "volumeMounts": {
                "type": "array",
                "items": {
                  "type": "object",
                  "properties": {
                    "name": {
                      "type": "string",
                      "description": "Name of the volume"
                    },
                    "path": {
                      "type": "string",
                      "description": "Path of the volume"
                    }
                  },
                  "required": [
                    "name",
                    "path"
                  ]
                }
              }
            },
            "type": "object"
          }
        }
      }
    },
    "401": {
      "description": "Authentication error",
      "content": {
        "application/json": {
          "schema": {
            "required": [
              "code",
              "message"
            ],
            "properties": {
              "code": {
                "type": "integer",
                "format": "int32",
                "description": "Error code"
              },
              "message": {
                "type": "string",
                "description": "Error"
              }
            },
            "type": "object"
          }
        }
      }
    },
    "404": {
      "description": "Not found",
      "content": {
        "application/json": {
          "schema": {
            "required": [
              "code",
              "message"
            ],
            "properties": {
              "code": {
                "type": "integer",
                "format": "int32",
                "description": "Error code"
              },
              "message": {
                "type": "string",
                "description": "Error"
              }
            },
            "type": "object"
          }
        }
      }
    },
    "500": {
      "description": "Server error",
      "content": {
        "application/json": {
          "schema": {
            "required": [
              "code",
              "message"
            ],
            "properties": {
              "code": {
                "type": "integer",
                "format": "int32",
                "description": "Error code"
              },
              "message": {
                "type": "string",
                "description": "Error"
              }
            },
            "type": "object"
          }
        }
      }
    }
  }
}
```
