PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchConnect the assistant’s harness to an isolated execution environment through a supported executor or tool interface. The harness runs the model and manages the tool loop; the sandbox runs code and holds its working files; your application starts tasks and handles events, approvals, and lifecycle. In OpenAI’s documented Agents API pattern, you can use an OpenAI-hosted environment or connect a self-hosted one. Keep application credentials and control logic outside agent-accessible compute wherever possible.
Choose the right execution pattern
A sandbox is useful when a task needs to run commands, install or use packages, edit files, create artifacts, expose services, or preserve resumable state. If the assistant only answers questions or calls remote services, a shell and workspace may be unnecessary. OpenAI describes the harness, environment, and application server as distinct parts of the Agents API architecture; the application can supply function tools or connect remote MCP servers without adding a code execution environment. OpenAI Agents API architecture and Agents SDK sandbox agents explain the split and use cases.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Executive Mini-Sandbox - Big Dig | $13.99 | Buy on Amazon |
| Pattern | Who operates compute | When it fits | Important distinction |
|---|---|---|---|
| No execution environment | No sandbox compute is provisioned. | Question answering or remote service calls that do not need a mutable workspace. | Function tools and remote MCP connections may still be available through the application or harness. OpenAI Agents API architecture |
| OpenAI-hosted environment | OpenAI provisions and manages the environment. | You need code execution or a workspace and prefer managed sandbox compute. | Your application still submits tasks, receives progress and results, and handles any function tools. OpenAI Agents API architecture |
| Self-hosted Agents API environment | Your application provisions and manages the compute lifecycle. | The workload needs your private infrastructure, private-network reachability, trusted compute, or custom software. | Your application must connect the executor, manage reconnection and shutdown, and preserve files it needs. Architecture and self-hosted sandbox setup |
| Agents SDK sandbox pattern | Your application runs the harness and arranges execution compute. | You need workspaces, commands, generated files, exposed services, or resumable state in an application-run harness. | The harness remains the control plane and compute is the execution plane; it may be unnecessary for a short response. OpenAI Agents SDK sandbox agents |
| Local Docker sandbox for Codex | Docker runs the local sandbox workflow. | You want to run Codex from a project directory in Docker’s documented setup. | Docker documents sbx run codex; its documented authentication flow runs on the host before the sandbox starts. This is a local workflow, not a universal connector for coding assistants. Docker’s Codex sandbox guide |
The cited documentation does not establish comparable prices or performance figures for these patterns. Select based on who must operate compute, whether the environment needs private-network access or custom software, what data must persist, how network egress and credentials are controlled, where MCP connections originate, and what approval and audit controls your application requires.
Connect a self-hosted environment to the OpenAI Agents API
The following sequence applies to the documented OpenAI-managed harness plus self-hosted environment arrangement. It is not a general-purpose protocol for every AI coding assistant. Check the current self-hosted sandbox guide before deployment because API fields and connection endpoints can change.
#1 Best Overall
- 5" x 5" sandbox comes with everything needed for some a moment, or two, of relaxation.
- Provision an isolated workspace. Prepare the compute for the user or workload, including the workspace directory, required files, dependencies, and software. Avoid sharing an environment across users or workloads when they must not share files, credentials, or other resources. OpenAI’s self-hosted setup and sandbox security guide.
- Start the executor inside that environment. Install and run
codex exec-server. In this documented pattern, the executor runs shell commands, reads and writes files, and can use local MCP servers at the harness’s request. It is a specific executor for this integration, not a universal sandbox connector. OpenAI self-hosted sandbox guide. - Create the session with the self-hosted environment configuration. Supply the workspace directory and arrange for the executor to register with the API using an environment ID and a restricted environment key. Follow the current guide’s required configuration fields rather than assuming names or formats not documented here. OpenAI self-hosted sandbox guide.
- Allow the executor’s required outbound connections. The guide names
https://api.openai.comfor registration andwss://codex-cloud-environments.chatgpt.comfor commands and results. Verify the current required-host list before deployment; endpoints can change. OpenAI self-hosted sandbox guide. - Pass only the environment key to the executor. The documented key is supplied as
CODEX_API_KEY. It permits environment connection rather than other API actions, but code running in the environment can still read it. Keep the application API key outside the sandbox. OpenAI self-hosted sandbox guide and sandbox security guide. - Handle reconnects and shutdown in application lifecycle code. Coordinate incoming work and confirm no execution is pending before stopping compute. The application owns provisioning and lifecycle management for this self-hosted pattern. OpenAI Agents API architecture and self-hosted sandbox guide.
Connect MCP tools from the right network origin
An MCP server publishes tool definitions and handles tool calls. Choose the connection origin according to where the server can be reached: use an OpenAI service-origin connection when the server is reachable from that service, and an environment-origin connection for a private-network server or software installed in the sandbox. For a private MCP service behind a firewall, OpenAI documents Secure MCP Tunnel as an option that avoids exposing the server publicly. MCP connections and MCP servers.
- Limit tool exposure. Set
allowed_toolsto the tools the agent needs, and decide whether MCP server initialization must succeed for the task to proceed. OpenAI MCP connections guide. - Match authentication to origin and trust. The guide describes session HTTP credentials and vault-backed credentials for service-origin connections. Environment-origin connections may require inline authentication or a trusted proxy. Any credential placed inside an agent-accessible environment can be read by code running there. MCP connections and sandbox security.
- Review what the server receives. MCP services are third parties: their data policies apply to information sent to them, and their behavior can change. Trust the server operator and assess what data and tools are shared. OpenAI MCP servers guide.
Keep the execution boundary secure
Treat agent-generated code as untrusted workload code. It can access files, credentials, and network resources made available to its environment. Security therefore depends not just on the sandbox product, but on what you mount, expose, and permit it to reach. OpenAI’s sandbox security guide.
- Isolate by user or workload wherever files, credentials, or resources must not be shared.
- Restrict outbound network access to approved destinations rather than granting unrestricted egress.
- Keep application and third-party credentials out of the sandbox. A restricted environment key still remains readable by generated code if exposed there.
- Broker third-party access. Use a trusted proxy or server where possible. For OpenAI-hosted sandboxes, the security guide describes vault secrets as placeholders replaced by a network proxy for approved hosts.
- Require approval for sensitive tool actions and expose only the tools required for the task.
- Account for prompt injection in user-provided content and tool outputs; review the data shared with MCP servers and use providers you trust.
- Log and review activity and data sharing according to your organization’s retention and residency requirements.
These controls are described across the sandbox security and MCP servers guides.
Troubleshoot a connection that does not work
Check the boundary where the failure occurs rather than treating every error as an API-key problem. For MCP setup, OpenAI’s guide specifically calls out connection origin, executor availability, reachability, credentials, and the environment’s installed commands and dependencies. MCP connections troubleshooting.
- Executor does not register: Confirm it is running in the intended environment, has the environment ID and restricted environment key, and can make the required outbound registration connection.
- Commands or results do not flow: Check outbound access to the documented WebSocket endpoint and confirm the executor remains connected.
- A private MCP server is unreachable: Confirm the chosen origin can reach the server. A service-origin connection cannot reach a private service merely because the sandbox can; use an appropriate environment-origin connection or Secure MCP Tunnel where applicable.
- MCP authentication fails: Confirm the credential mechanism matches the origin and that the supplied credentials are valid for that server.
- A tool cannot find a command, package, or file: Check that the software and dependencies are installed in the execution environment and that the task uses the intended working directory.
- Shutdown interrupts work: Have the application coordinate incoming requests and verify no execution remains pending before stopping the environment.
For current setup details, consult the self-hosted environment guide and MCP connection guide. The API fields, authentication scopes, transports, endpoints, and product availability may change.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




