Private pilot — invite only

firebox

Let AI write the code. We’ll make sure it’s safe to run.

Every run executes inside its own Firecracker microVM — isolated kernel, locked-down network, DNS that can’t exfiltrate. One HTTP call, metered per second.

How it works

Three calls. No servers to manage, no containers to harden.

1

Create a sandbox

POST /v1/sandboxes boots an isolated Linux microVM — its own kernel, its own private network.

2

Execute code

Run commands, stream output live, read and write files. Timeouts, CPU and memory caps enforced.

3

Destroy it

One call tears it down — or pause it to disk and resume later. Billed per second of actual compute.

Quickstart

Create a sandbox, run code, destroy it. Authenticate with an X-API-Key header.

# point at your firebox host and key
export FB_URL="https://getfirebox.dev"
export FB_API_KEY="fb_your_api_key"

# 1. create a sandbox
SB=$(curl -s -X POST "$FB_URL/v1/sandboxes" \
  -H "X-API-Key: $FB_API_KEY" -H 'Content-Type: application/json' \
  -d '{"vcpu":1,"memory_mb":512}' \
  | python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])')

# 2. run code
curl -s -X POST "$FB_URL/v1/sandboxes/$SB/exec" \
  -H "X-API-Key: $FB_API_KEY" -H 'Content-Type: application/json' \
  -d '{"command":"python3 -c \"print(40+2)\""}'
# {"stdout":"42\n","stderr":"","exit_code":0,"duration_ms":29,"timed_out":false}

# 3. destroy it
curl -s -X DELETE "$FB_URL/v1/sandboxes/$SB" -H "X-API-Key: $FB_API_KEY"
# {"id":"sb_...","status":"destroyed"}
# pip install requests
import requests

FB_URL = "https://getfirebox.dev"
H = {"X-API-Key": "fb_your_api_key", "Content-Type": "application/json"}

# 1. create a sandbox
sb = requests.post(f"{FB_URL}/v1/sandboxes",
                   json={"vcpu": 1, "memory_mb": 512},
                   headers=H).json()
box_id = sb["id"]

# 2. run code
r = requests.post(f"{FB_URL}/v1/sandboxes/{box_id}/exec",
                  json={"command": 'python3 -c "print(40+2)"'},
                  headers=H).json()
print(r["stdout"])  # 42

# 3. destroy it
requests.delete(f"{FB_URL}/v1/sandboxes/{box_id}", headers=H)
const FB_URL = "https://getfirebox.dev";
const H = { "X-API-Key": "fb_your_api_key", "Content-Type": "application/json" };

// 1. create a sandbox
const sb = await fetch(`${FB_URL}/v1/sandboxes`, {
  method: "POST", headers: H,
  body: JSON.stringify({ vcpu: 1, memory_mb: 512 }),
}).then(r => r.json());

// 2. run code
const run = await fetch(`${FB_URL}/v1/sandboxes/${sb.id}/exec`, {
  method: "POST", headers: H,
  body: JSON.stringify({ command: 'python3 -c "print(40+2)"' }),
}).then(r => r.json());
console.log(run.stdout); // 42

// 3. destroy it
await fetch(`${FB_URL}/v1/sandboxes/${sb.id}`, { method: "DELETE", headers: H });

Built for untrusted code

Agent-generated code is hostile code. firebox treats it that way.

Firecracker microVM isolation

Every sandbox gets its own KVM microVM, kernel, and private /30 network. No shared kernels, no cross-tenant traffic.

Streaming exec output

Watch long-running commands as they happen — stdout and stderr stream over SSE, in order per stream.

Pause / resume snapshots

Snapshot a sandbox to disk and bring it back later. State survives; the compute meter stops while paused.

Filesystem API

Read, write, list, and delete files inside the sandbox. Paths are jailed — traversal is rejected.

Per-second metering

CPU time and memory metered by the second, totaled per API key. The exact events usage-based billing needs.

API key management

Create, rotate, and revoke keys with per-key concurrency caps and rate limits. Secrets shown once, never again.

MCP server for AI agents

Ten tools over stdio — create, exec, files, pause, resume, delete, usage. Point Claude Code or Claude Desktop at firebox and agents run code in microVMs instead of on your machine. See it in action.

API reference

Every endpoint takes an X-API-Key header, except GET /healthz. Click any endpoint for request/response examples.

MethodPathPurpose

Status codes: 401 missing/invalid/revoked key · 403 valid key, not admin · 409 state conflict (e.g. exec on a paused sandbox) · 410 sandbox expired · 413 file too large · 422 bad path.

Private pilot — invite only

Express interest

Tell us what you’d run in a sandbox. We’re onboarding a small group of teams with real workloads, and we’ll reach out when a spot opens.

  • Run AI-generated code without having to trust it
  • Every execution isolated in its own Firecracker microVM
  • Locked-down network — DNS can’t exfiltrate

We’ll only email about pilot access. No spam, no list.