DocsAI / Agents

Deno Sandbox

Isolate agents, plugins, and untrusted code in ephemeral Linux microVMs on Deno Deploy

Deno Sandbox creates on-demand Linux microVMs through @deno/sandbox for agent code execution, plugins, and user builds. This is a different layer from Deno runtime permissions: a sandbox supplies a separate VM and resource boundary.

Create and clean up automatically

import { Sandbox } from "@deno/sandbox";

await using sandbox = await Sandbox.create({
  memoryMb: 2048,
  timeout: "10m",
  allowNet: ["jsr.io", "registry.npmjs.org"],
  labels: { workload: "agent-build" },
});

const result = await sandbox.sh`deno --version`;
console.log(result.stdout);

Use await using or finally to guarantee cleanup. close() disconnects; use kill() when the VM must terminate early. Do not conflate those lifecycle operations.

Secure defaults

As of 2026-08-03, official pages disagree about omitted allowNet: the creation guide says no outbound network, while the security guide says all outbound requests are allowed. Do not rely on that default; always pass the smallest explicit allowNet. Default memory is roughly 1280 MB, while memory, regions, lifetime, and prerelease quotas require a current check.

  • Allowlist network hosts and bind each secret to hosts that need it.
  • Validate upload paths; cap download size and type.
  • Use parameterized APIs or tagged templates, never concatenate user text into a shell.
  • Bound wall-clock time, output, concurrency, and disk.
  • Put sandbox ID, agent ID, tenant, and request ID in labels and audit logs.
  • Promote stable long-running services to a Deploy app instead of using a temporary sandbox as a server.

Official sources: Deno Sandbox, Create a sandbox, and Security.

Type to search all documentation.