sandbox.desktop gives an agent that
desktop inside a sandbox: screenshots, mouse, keyboard, scroll, a resizable
display, and a live viewer you can open in a browser.
Every call is one request to the sandbox. A click is one round trip, a drag
is one request, a whole model turn can go in one request, and typing has no
per-character delay. A paused sandbox resumes on first use, as
with commands and files.
Create a desktop sandbox
The sandbox must come from a desktop-enabled template.superserve/desktop
ships the xfce desktop, Chrome, and a browser-based viewer, and runs the
session as the non-root desktop user (also the default user for
commands.run). The display starts at 1280x800.
The agent loop
Your code owns the model call and the conversation. The sandbox runs the actions. Each turn is a screenshot in, a list of actions out:step runs the model’s whole turn and captures the frame after it in one
request, so a turn is a single round trip. The sandbox waits settleMs /
settle_ms (up to 2000) before capturing, because input is delivered before
the application has repainted; how long it needs depends on the application.
step does not throw when the batch stops at a failing action or when the
capture fails, since the actions that ran have already landed: check
actionError / action_error (with executed, the index it stopped at) and
screenshotError / screenshot_error. Resizing to the model’s native
resolution first keeps frames small and maps its coordinates 1:1 onto the
screen.
Everything the agent reads from the screen is untrusted input to the model:
page content, file contents, text in dialogs. Keep credentials out of the
desktop, restrict where the sandbox can connect with network
rules, and have the model ask for approval before an
action with an outside effect.
Watch it live
6080, publishing that port
under the sandbox’s preview policy. Under public the
URL is clean. Under private it carries a 60-second signed credential, as
getSignedPreviewUrl / get_signed_preview_url does; mint a fresh URL for
each viewer. viewOnly / view_only is a flag on that viewer only and does
not stop someone else from opening the same URL with control, so use a
private policy when the viewer must not be shared.
Screenshots
Mouse
Keyboard
write types literal text with no per-character pacing, so long strings land
in well under a second. press sends a key or chord. Friendly names (enter,
esc, tab, backspace, delete, up, down, pageup, ctrl, alt,
shift, cmd) are accepted as written; any other key uses its X keysym name,
so F5, Return, and KP_Enter work as written.
Batch actions
Models that emit several actions per turn can send them in one request:step is the same batch followed by a
capture in the same request, for the agent loop above; actions is for input
you do not need to look at afterwards.
Resize the display
Pause and resume
The desktop survives a pause. Open windows, running applications, and the screen come back exactly as they were, and the nextdesktop call on a paused
sandbox resumes it first.
MCP
The MCP server exposes the same surface as thesandbox_computer tool, one
action per call (screenshot, left_click, type, key, scroll,
left_click_drag, …) in the vocabulary computer-use models are trained on.
Input actions return a fresh screenshot of the result by default. See
MCP Sandboxes.
Related
- SDK reference: Sandbox
- Preview URLs — access policy for the viewer port
- Templates — the
superserve/desktoptemplate