get_session_sandbox
const url = 'https://app.everruns.com/api/v1/sessions/example/sandbox';const options = {method: 'GET'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url https://app.everruns.com/api/v1/sessions/example/sandboxGet the primary Sandbox a Session runs in: template, target, containment, and capabilities.
Parameters
Section titled “ Parameters ”Path Parameters
Section titled “Path Parameters”Session ID
Responses
Section titled “ Responses ”Resolved primary Session Sandbox
The primary Sandbox a Session is running in.
object
What the Sandbox target can actually do.
Read this before assuming a shell behaves like Linux. Bashkit reports
native_processes: false, which is why a build fails there; the answer is
available before the first turn rather than after a confusing tool error.
object
Whether commands can spawn operating-system processes.
Whether the target enforces the declared outbound network policy.
Whether the runtime can install operating-system packages.
Whether filesystem state has a portable checkpoint representation.
Whether workloads can bind and expose network ports.
Whether interactive pseudo-terminals are supported.
What commands may touch, and who enforces it.
object
none, native, or isolated.
Outbound network policy: deny, allowlist, or allow.
Most recent checkpoint used to recover this logical Sandbox.
Control-plane lifecycle intent and latest observed physical state.
checkpointed, provider_snapshot, or none. Declared per target, so a
session on somebody else’s machine is never reported as recoverable.
Physical incarnation fence. Increments whenever compute is replaced.
Last recorded runtime activity used by lifecycle policy.
Agent template binding selected for this Session (inline for one-offs).
Latest lifecycle state observed from the physical provider resource.
How this view was produced. capabilities means it was derived from the
Session’s effective capability set rather than a stored Sandbox spec.
primary for the implicit shell/files binding.
Durable logical primary Sandbox id. Absent for legacy capability-derived sessions.
Reusable Sandbox Template revision pinned into this Sandbox.
Capability that supplied the compute, for operators tracing a surprise.
Immutable resolved specification pinned when the Session was created.
object
Pinned initialization commands.
object
Ordered commands replayed when creating or recovering physical compute.
Fully resolved containment contract.
object
Whether the runtime may widen containment after Session creation.
Filesystem mutation boundary for command execution.
object
Absolute roots the runtime may mutate; empty means provider default.
Isolation mechanism the provider must supply.
Fully resolved recovery guarantee.
Pinned lifecycle policy.
object
Action Everruns requests after the idle interval.
Inactivity interval before applying idle_action.
Exact target pinned for the Session.
object
Credential/transport binding for a registered machine target.
Provider-neutral target class.
Provider-owned, non-secret configuration. Credentials are references, never values in this object.
object
Concrete adapter for target kinds with more than one implementation.
Reusable revision from which this complete snapshot was copied.
Target, absent when the session has no compute at all and only reads and writes files. That is a real configuration, not a misconfiguration.
object
Registered connection used by a machine target.
Shape of the target: host, machine, vfs, container, managed.
Concrete provider, when the kind has one (bashkit, daytona, …).
Example
{ "capabilities": { "native_processes": false, "network_enforced": true, "packages": false, "portable_checkpoint": true, "ports": false, "pty": false }, "containment": { "level": "isolated", "network": "deny" }, "durability": "checkpointed", "resolved_from": "capabilities", "source_capability": "bashkit_shell", "target": { "kind": "vfs", "provider": "bashkit" }}Session not found