> ## Documentation Index
> Fetch the complete documentation index at: https://docs.e2b.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Update sandbox network

> Update the network configuration for a running sandbox. Replaces the current egress rules with the provided configuration. Omitting field clears it.



## OpenAPI

````yaml /openapi-public.yaml put /sandboxes/{sandboxID}/network
openapi: 3.1.0
info:
  title: E2B API
  version: 0.1.0
  description: >-
    Complete E2B developer API. Platform endpoints are served on api.e2b.app.
    Sandbox endpoints (envd) are served on the shared sandbox host
    (sandbox.e2b.app); target a specific sandbox with the E2b-Sandbox-Id and
    E2b-Sandbox-Port headers.
servers:
  - url: https://api.e2b.app
    description: E2B Platform API
security: []
tags:
  - name: Sandboxes
  - name: Templates
  - name: Tags
  - name: Volumes
  - name: Envd
  - name: Filesystem
  - name: Process
  - name: Teams
  - name: Secrets
  - name: Events
  - name: Webhooks
paths:
  /sandboxes/{sandboxID}/network:
    servers:
      - url: https://api.e2b.app
        description: E2B Platform API
    put:
      tags:
        - Sandboxes
      summary: Update sandbox network
      description: >-
        Update the network configuration for a running sandbox. Replaces the
        current egress rules with the provided configuration. Omitting field
        clears it.
      operationId: putSandboxNetwork
      parameters:
        - $ref: '#/components/parameters/sandboxID'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/SandboxNetworkUpdateConfig'
      responses:
        '204':
          description: Successfully updated the sandbox network configuration
        '400':
          description: Bad request
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 400
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                invalidSandboxId:
                  summary: The sandbox ID is malformed
                  value:
                    code: 400
                    message: Invalid sandbox ID
        '401':
          description: Authentication error
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 401
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                missingAuthentication:
                  summary: No supported authentication header was supplied
                  value:
                    code: 401
                    message: authorization header is missing
        '403':
          description: Forbidden
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 403
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                teamBanned:
                  summary: The team is banned at authentication
                  value:
                    code: 403
                    message: team is banned
                teamBlocked:
                  summary: >-
                    The authenticated team is blocked. The message may append a
                    reason
                  value:
                    code: 403
                    message: team is blocked
        '404':
          description: Not found
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 404
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                sandboxNotFound:
                  summary: No accessible sandbox or saved snapshot was found
                  value:
                    code: 404
                    message: >-
                      Sandbox "sandboxid" doesn't exist or you don't have access
                      to it
        '409':
          description: Conflict
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 409
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                stateConflict:
                  summary: The sandbox is changing state
                  value:
                    code: 409
                    message: Sandbox "sandboxid" is being paused
        '429':
          description: Too many requests
          headers:
            Retry-After:
              description: >-
                When present, the number of seconds to wait before retrying the
                request.
              required: false
              schema:
                type: integer
                minimum: 0
              example: 30
            RateLimit-Limit:
              description: Configured rate-limit burst size.
              schema:
                type: integer
            RateLimit-Remaining:
              description: Requests remaining in the rate-limit window.
              schema:
                type: integer
            RateLimit-Reset:
              description: Seconds until the rate-limit window resets.
              schema:
                type: integer
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 429
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                rateLimitExceeded:
                  summary: A configured API rate limit was exceeded
                  value:
                    code: 429
                    message: Rate limit exceeded
        '500':
          description: Server error
          content:
            application/json:
              schema:
                required:
                  - code
                  - message
                properties:
                  code:
                    type: integer
                    format: int32
                    description: Error code
                    example: 500
                  error_code:
                    type: string
                    description: >-
                      Machine-readable semantic error code. Not a closed set;
                      initial values: sandbox_capacity_unavailable,
                      sandbox_placement_timeout, sandbox_no_compatible_node,
                      sandbox_create_failed, internal_server_error,
                      secret_limit_reached.
                  message:
                    type: string
                    description: Error
                type: object
              examples:
                operationFailed:
                  summary: Looking up the sandbox for network-rule validation fails
                  value:
                    code: 500
                    message: Failed to get sandbox
      security:
        - ApiKeyAuth: []
components:
  parameters:
    sandboxID:
      name: sandboxID
      in: path
      required: true
      schema:
        type: string
  schemas:
    SandboxNetworkUpdateConfig:
      type: object
      description: >-
        Network configuration update for a running sandbox. Replaces the current
        egress rules with the provided configuration. Omitting a field clears
        it.
      properties:
        allowOut:
          type: array
          description: >-
            List of allowed destinations for egress traffic. Each entry can be a
            CIDR block (e.g. "8.8.8.8/32"), a bare IP address (e.g. "8.8.8.8"),
            or a domain name (e.g. "example.com", "*.example.com"). Allowed
            entries always take precedence over denied entries.
          items:
            type: string
        denyOut:
          type: array
          description: >-
            List of denied CIDR blocks or IP addresses for egress traffic.
            Domain names are not supported for deny rules.
          items:
            type: string
        egressProxy:
          $ref: '#/components/schemas/SandboxEgressProxyConfig'
        rules:
          type: object
          description: >
            Per-domain transform rules applied to matching outbound HTTPS
            requests. Replaces all existing rules when provided. Keys may be
            exact DNS names or a single leading wildcard (for example,
            "*.example.com"), and are normalized to lowercase on write.
            Wildcards match subdomains at any depth but not the apex domain; a
            bare "*" is invalid. Exact rules take precedence, followed by the
            longest matching wildcard suffix, and matching rule sets are not
            merged. Broad wildcards such as "*.com" are allowed and may expose
            transformed credentials to every matching destination the sandbox
            contacts. Rules do not grant network access; configure allowOut
            separately to permit the destination.
          additionalProperties:
            type: array
            items:
              $ref: '#/components/schemas/SandboxNetworkRule'
        allow_internet_access:
          type: boolean
          description: >-
            Allow sandbox to access the internet. When set to false, it behaves
            the same as specifying denyOut to 0.0.0.0/0 in the network config.
    SandboxEgressProxyConfig:
      type:
        - object
        - 'null'
      description: >-
        SOCKS5 proxy for sandbox egress. Outbound TCP is tunneled through the
        proxy after allow/deny filtering; the sandbox is unaware. Domain-matched
        flows use remote DNS (ATYP=domain).
      required:
        - address
      properties:
        address:
          type: string
          description: >-
            SOCKS5 proxy address in host:port format (e.g.
            "proxy.example.com:1080").
        username:
          type: string
          maxLength: 255
          description: Optional SOCKS5 username (RFC 1929), max 255 bytes.
        password:
          type: string
          maxLength: 255
          description: Optional SOCKS5 password (RFC 1929), max 255 bytes.
        tls:
          $ref: '#/components/schemas/SandboxEgressProxyTLSConfig'
    SandboxNetworkRule:
      type: object
      description: Transform rule applied to egress requests matching a domain pattern.
      properties:
        transform:
          $ref: '#/components/schemas/SandboxNetworkTransform'
    SandboxEgressProxyTLSConfig:
      type:
        - object
        - 'null'
      description: >-
        TLS for the connection to the SOCKS5 proxy. The SOCKS5 negotiation and
        the tunneled traffic both run inside the TLS session, so the proxy
        credentials are not sent in the clear. This secures only the hop to the
        proxy; what the proxy does onward is its own concern. A half-close from
        the sandbox reaches the proxy as a TLS close_notify, not a TCP FIN, and
        a proxy that treats close_notify as a full close cuts the reply short.
      required:
        - enabled
      properties:
        enabled:
          type: boolean
          description: >-
            Connect to the proxy over TLS. When false, no other field in this
            object may be set.
        serverName:
          type: string
          maxLength: 253
          description: >-
            Name to verify the proxy certificate against, and to send as SNI.
            Defaults to the host part of address. Set this only when the
            certificate does not match the address the proxy is reached at.
        caCert:
          type: string
          maxLength: 8192
          description: >-
            One or more PEM-encoded certificates to verify the proxy against,
            for a proxy fronted by a private CA. These replace the system trust
            store, which is what is used when this is omitted. The system trust
            store depends on the host the orchestrator runs on, so set this to
            get the same verification everywhere.
    SandboxNetworkTransform:
      type: object
      description: Transformations applied to matching egress requests before forwarding.
      properties:
        headers:
          type: object
          description: >
            HTTP headers to inject or override in matching requests. An existing
            header with the same name is replaced. Values are plain strings;
            secret resolution happens client-side before sending to the API.
          additionalProperties:
            type: string
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: X-API-Key

````