> ## Documentation Index
> Fetch the complete documentation index at: https://docs.e2b.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Get sandbox

> Get a sandbox by id



## OpenAPI

````yaml /openapi-public.yaml get /sandboxes/{sandboxID}
openapi: 3.1.0
info:
  title: E2B API
  version: 0.1.0
  description: >-
    Complete E2B developer API. Platform endpoints are served on api.e2b.app.
    Sandbox endpoints (envd) are served on the shared sandbox host
    (sandbox.e2b.app); target a specific sandbox with the E2b-Sandbox-Id and
    E2b-Sandbox-Port headers.
servers:
  - url: https://api.e2b.app
    description: E2B Platform API
security: []
tags:
  - name: Sandboxes
  - name: Templates
  - name: Tags
  - name: Volumes
  - name: Envd
  - name: Filesystem
  - name: Process
  - name: Teams
  - name: Secrets
  - name: Events
  - name: Webhooks
paths:
  /sandboxes/{sandboxID}:
    servers:
      - url: https://api.e2b.app
        description: E2B Platform API
    get:
      tags:
        - Sandboxes
      summary: Get sandbox
      description: Get a sandbox by id
      operationId: getSandbox
      parameters:
        - $ref: '#/components/parameters/sandboxID'
      responses:
        '200':
          description: Successfully returned the sandbox
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/SandboxDetail'
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 400
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                invalidSandboxId:
                  summary: The sandbox ID is malformed
                  value:
                    code: 400
                    message: Invalid sandbox ID
        '401':
          description: Authentication error
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 401
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                missingAuthentication:
                  summary: No supported authentication header was supplied
                  value:
                    code: 401
                    message: authorization header is missing
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 403
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                teamBanned:
                  summary: The team is banned at authentication
                  value:
                    code: 403
                    message: team is banned
        '404':
          description: Not found
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 404
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                sandboxNotFound:
                  summary: No accessible sandbox or saved snapshot was found
                  value:
                    code: 404
                    message: >-
                      Sandbox "sandboxid" doesn't exist or you don't have access
                      to it
        '429':
          description: Too many requests
          headers:
            Retry-After:
              description: >-
                When present, the number of seconds to wait before retrying the
                request.
              required: false
              schema:
                type: integer
                minimum: 0
              example: 30
            RateLimit-Limit:
              description: Configured rate-limit burst size.
              schema:
                type: integer
            RateLimit-Remaining:
              description: Requests remaining in the rate-limit window.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the rate-limit window resets.
              schema:
                type: integer
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 429
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                rateLimitExceeded:
                  summary: A configured API rate limit was exceeded
                  value:
                    code: 429
                    message: Rate limit exceeded
        '500':
          description: Server error
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 500
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                operationFailed:
                  summary: The sandbox snapshot lookup fails
                  value:
                    code: 500
                    message: Error getting sandbox
      security:
        - ApiKeyAuth: []
components:
  parameters:
    sandboxID:
      name: sandboxID
      in: path
      required: true
      schema:
        type: string
  schemas:
    SandboxDetail:
      required:
        - templateID
        - sandboxID
        - clientID
        - startedAt
        - cpuCount
        - memoryMB
        - diskSizeMB
        - endAt
        - state
        - envdVersion
      properties:
        templateID:
          type: string
          description: Identifier of the template from which is the sandbox created
        alias:
          type: string
          description: Alias of the template
        sandboxID:
          type: string
          description: Identifier of the sandbox
        clientID:
          type: string
          deprecated: true
          description: Identifier of the client
        startedAt:
          type: string
          format: date-time
          description: Time when the sandbox was started
        endAt:
          type: string
          format: date-time
          description: Time when the sandbox will expire
        envdVersion:
          $ref: '#/components/schemas/EnvdVersion'
        envdAccessToken:
          type: string
          description: Access token used for envd communication
        allowInternetAccess:
          type:
            - boolean
            - 'null'
          description: >-
            Whether internet access was explicitly enabled or disabled for the
            sandbox. Null means it was not explicitly set.
        domain:
          type:
            - string
            - 'null'
          description: Base domain where the sandbox traffic is accessible
        cpuCount:
          $ref: '#/components/schemas/CPUCount'
        memoryMB:
          $ref: '#/components/schemas/MemoryMB'
        diskSizeMB:
          $ref: '#/components/schemas/DiskSizeMB'
        metadata:
          $ref: '#/components/schemas/SandboxMetadata'
        state:
          $ref: '#/components/schemas/SandboxState'
        network:
          $ref: '#/components/schemas/SandboxNetworkConfig'
        lifecycle:
          $ref: '#/components/schemas/SandboxLifecycle'
        volumeMounts:
          type: array
          items:
            $ref: '#/components/schemas/SandboxVolumeMount'
      type: object
    EnvdVersion:
      type: string
      description: Version of the envd running in the sandbox
    CPUCount:
      type: integer
      format: int32
      minimum: 1
      description: CPU cores for the sandbox
    MemoryMB:
      type: integer
      format: int32
      minimum: 128
      description: Memory for the sandbox in MiB
    DiskSizeMB:
      type: integer
      format: int32
      minimum: 0
      description: Disk size for the sandbox in MiB
    SandboxMetadata:
      additionalProperties:
        type: string
        description: Metadata of the sandbox
      type: object
    SandboxState:
      type: string
      description: State of the sandbox
      enum:
        - running
        - paused
    SandboxNetworkConfig:
      type: object
      properties:
        allowPublicTraffic:
          type: boolean
          default: true
          description: >-
            Specify if the sandbox URLs should be accessible only with
            authentication.
        allowOut:
          type: array
          description: >-
            List of allowed destinations for egress traffic. Each entry can be a
            CIDR block (e.g. "8.8.8.8/32"), a bare IP address (e.g. "8.8.8.8"),
            or a domain name (e.g. "example.com", "*.example.com"). Allowed
            entries always take precedence over denied entries.
          items:
            type: string
        denyOut:
          type: array
          description: >-
            List of denied CIDR blocks or IP addresses for egress traffic.
            Domain names are not supported for deny rules.
          items:
            type: string
        egressProxy:
          $ref: '#/components/schemas/SandboxEgressProxyConfig'
        maskRequestHost:
          type: string
          description: Specify host mask which will be used for all sandbox requests
        httpsPorts:
          type: array
          description: >-
            Sandbox ports that serve HTTPS rather than plaintext HTTP. Affects
            how the proxy reaches the service inside the sandbox; the public URL
            is HTTPS either way. Certificates are not verified, so self-signed
            ones work. The envd port (49983) cannot be listed.
          maxItems: 128
          uniqueItems: true
          items:
            type: integer
            format: uint32
            minimum: 1
            maximum: 65535
        rules:
          type: object
          description: >
            Per-domain transform rules applied to matching outbound HTTPS
            requests. Keys may be exact DNS names (for example,
            "api.example.com") or a leading wildcard (for example,
            "*.example.com"), and are normalized to lowercase on write.
            Wildcards match subdomains at any depth but not the apex domain; a
            bare "*" is invalid. Exact rules take precedence, followed by the
            longest matching wildcard suffix, and matching rule sets are not
            merged. Broad wildcards such as "*.com" are allowed and may expose
            transformed credentials to every matching destination the sandbox
            contacts. Rules do not grant network access; configure allowOut
            separately to permit the destination.
          additionalProperties:
            type: array
            items:
              $ref: '#/components/schemas/SandboxNetworkRule'
    SandboxLifecycle:
      type: object
      description: Sandbox lifecycle policy returned by sandbox info.
      required:
        - autoResume
        - onTimeout
      properties:
        autoResume:
          type: boolean
          description: Whether the sandbox can auto-resume.
        onTimeout:
          $ref: '#/components/schemas/SandboxOnTimeout'
    SandboxVolumeMount:
      type: object
      properties:
        name:
          type: string
          description: Name of the volume
        path:
          type: string
          description: Path of the volume
      required:
        - name
        - path
    SandboxEgressProxyConfig:
      type:
        - object
        - 'null'
      description: >-
        SOCKS5 proxy for sandbox egress. Outbound TCP is tunneled through the
        proxy after allow/deny filtering; the sandbox is unaware. Domain-matched
        flows use remote DNS (ATYP=domain).
      required:
        - address
      properties:
        address:
          type: string
          description: >-
            SOCKS5 proxy address in host:port format (e.g.
            "proxy.example.com:1080").
        username:
          type: string
          maxLength: 255
          description: Optional SOCKS5 username (RFC 1929), max 255 bytes.
        password:
          type: string
          maxLength: 255
          description: Optional SOCKS5 password (RFC 1929), max 255 bytes.
        tls:
          $ref: '#/components/schemas/SandboxEgressProxyTLSConfig'
    SandboxNetworkRule:
      type: object
      description: Transform rule applied to egress requests matching a domain pattern.
      properties:
        transform:
          $ref: '#/components/schemas/SandboxNetworkTransform'
    SandboxOnTimeout:
      type: string
      description: Action taken when the sandbox times out.
      enum:
        - kill
        - pause
    SandboxEgressProxyTLSConfig:
      type:
        - object
        - 'null'
      description: >-
        TLS for the connection to the SOCKS5 proxy. The SOCKS5 negotiation and
        the tunneled traffic both run inside the TLS session, so the proxy
        credentials are not sent in the clear. This secures only the hop to the
        proxy; what the proxy does onward is its own concern. A half-close from
        the sandbox reaches the proxy as a TLS close_notify, not a TCP FIN, and
        a proxy that treats close_notify as a full close cuts the reply short.
      required:
        - enabled
      properties:
        enabled:
          type: boolean
          description: >-
            Connect to the proxy over TLS. When false, no other field in this
            object may be set.
        serverName:
          type: string
          maxLength: 253
          description: >-
            Name to verify the proxy certificate against, and to send as SNI.
            Defaults to the host part of address. Set this only when the
            certificate does not match the address the proxy is reached at.
        caCert:
          type: string
          maxLength: 8192
          description: >-
            One or more PEM-encoded certificates to verify the proxy against,
            for a proxy fronted by a private CA. These replace the system trust
            store, which is what is used when this is omitted. The system trust
            store depends on the host the orchestrator runs on, so set this to
            get the same verification everywhere.
    SandboxNetworkTransform:
      type: object
      description: Transformations applied to matching egress requests before forwarding.
      properties:
        headers:
          type: object
          description: >
            HTTP headers to inject or override in matching requests. An existing
            header with the same name is replaced. Values are plain strings;
            secret resolution happens client-side before sending to the API.
          additionalProperties:
            type: string
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key

````