> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mutagent.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Sandbox providers

> A sandbox provider runs cloud sandboxes. What it decides, what it does not, and how a run picks one.

<Note>
  **Early access.** Cloud sessions and managed agent runs are not open to every account yet: we are
  letting accounts in gradually while we test. They run in a cloud sandbox operated by Mutagent, so
  there is nothing to host. A sandbox with nothing to do for 15 minutes stops; send the session a
  message and it wakes up, delivers your message and carries on in the same conversation.
</Note>

A sandbox provider runs cloud sandboxes. Every Helix Cloud session and managed agent run starts its
sandbox on one sandbox provider.

The platform runs its own sandboxes by default, on the sandbox provider `mutagent-cloud` (Mutagent
Cloud), so there is nothing to set up. The platform can have
more than one sandbox provider configured. A run uses the default one unless it names another with
`--sandbox-provider <name>`. An unknown name is refused, and the error lists the configured names.
`mutagent sandbox providers` lists the names and the default. See
[mutagent sandbox](/cli/commands/sandbox).

```bash theme={null}
mutagent sandbox providers --json
```

It needs a [sign-in](/cli/commands/login) (exit 3 without one). The result is
`{ providers: [...], default: <name|null>, count: N }`. Pass only a name from `providers` to
`--sandbox-provider`; the server refuses any other.

Mutagent Cloud is the only sandbox provider available now. More sandbox providers (E2B, Daytona,
Cloudflare, Fly.io, Docker Cloud and others) are coming soon; the web app lists them
under **Configuration → Sandbox Providers** as **Coming soon**. Connecting a sandbox provider account
of your own is not available yet.

## What a sandbox provider decides

| Decides | Does not decide |
| - | - |
| Where and how the machine runs. | The model. It comes from the run, the workspace default model, or a managed agent's package. |
| Whether it can receive a managed agent package. | The LLM provider keys. Every active LLM provider in the workspace is added to the sandbox. |
| | The Environment. It comes from `--env`. |
| | The agent. It comes from the command: the orchestrator, your definition, or a managed agent. |

Changing the sandbox provider does not change the model, the Environment or the agent. The same
15-minute idle stop, checkpoints and restore apply on every sandbox provider. See
[Cloud sandboxes](/platform/sandbox/overview).

## Managed agents

A managed agent run needs a sandbox provider that can receive its package. Not every sandbox provider
can yet.

* `mutagent agent deploy` and `mutagent agent activate` refuse when no configured sandbox provider can
  receive a package.
* A run refuses a sandbox provider that cannot receive a package, before any sandbox starts. The error
  names the sandbox provider.
* A slot does not record a sandbox provider. Each run picks one.

See [Managed agents](/platform/managed-agents/overview).

## Choosing one for a run

The run-time flags and examples are in
[Helix Cloud: sandbox providers](/helix/cloud/sandbox-providers).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.