python:3.13-slim image and TypeScript on node:24-slim.
Docker marks the Sandboxes API as experimental. Its interfaces and behavior may change.
Requirements
- An active Docker Agentic Platform subscription.
- A personal access token with the
sandbox:usepermission. Registry permissions alone don’t grant sandbox access.
Configure
- Create a personal access token with the
sandbox:usepermission in your Docker account settings. - Add your Docker ID as
DOCKER_IDand the token asDOCKER_PATfrom Settings → Sandboxes, or set them as environment variables on the Phoenix server. - In Sandbox Configurations, click New Sandbox, pick Docker Sandboxes, and choose Python or TypeScript.
Behavior
- Internet access: Deny blocks all outbound traffic. Phoenix creates a network policy named
phoenix-deny-all-egresson your Docker account the first time it’s needed, and it applies only to the sandboxes Phoenix attaches it to. Allow adds no policy, so your Docker account’s default network policy applies. - Dependencies install with
pipornpmwhen the sandbox is created, and need internet access. - Environment variables are passed to each run, not set on the sandbox when it’s created.
- Phoenix deletes each sandbox when it’s done with it. Every sandbox also expires after 10 minutes.

