createVercelSandboxProvider
Purpose and behavior
Section titled “Purpose and behavior”Create a remote provider on Vercel Sandbox; the optional @vercel/sandbox SDK loads on acquire. Each acquire creates a sandbox, Outpost uploads the repository and synchronizes changes back, and release stops the sandbox.
Complete example and detailed rules.
Parameters and properties
Section titled “Parameters and properties”optionsOptionalVercelOptions | undefinedVercel sandbox creation, workspace root, egress, environment and output retention settings.options.egressOptionalEgressPolicy | undefinedPortable policy translated to Vercel’s firewall when the provider is created: domains match the TLS server name, allowCidrs grant IP access on their own and denyCidrs take priority. Setting create.networkPolicy too fails with code configuration.options.createOptionalNonNullable<(WithPrivate<((BaseCreateSandboxParams & ({ runtime?: RUNTIMES | (string & {}); image?: never; } | { runtime?: never; image?: (string & {}) | "vercel/sandbox/universal" | "vercel/sandbox/node:22" | "vercel/sandbox/node:24" | "vercel/sandbox/node:26" | "vercel/sandbox/python:3.14" | "vercel/sandbox/ubuntu" | "vercel/sandbox/arch"; })) | (Omit<BaseCreateSandboxParams, "source"> & { source: { type: "snapshot"; snapshotId: string; }; runtime?: never; image?: never; })) | (((BaseCreateSandboxParams & ({ runtime?: RUNTIMES | (string & {}); image?: never; } | { runtime?: never; image?: (string & {}) | "vercel/sandbox/universal" | "vercel/sandbox/node:22" | "vercel/sandbox/node:24" | "vercel/sandbox/node:26" | "vercel/sandbox/python:3.14" | "vercel/sandbox/ubuntu" | "vercel/sandbox/arch"; })) | (Omit<BaseCreateSandboxParams, "source"> & { source: { type: "snapshot"; snapshotId: string; }; runtime?: never; image?: never; })) & Credentials)> & WithFetchOptions) | undefined> | undefinedOptions passed to Sandbox.create() from @vercel/sandbox; Outpost adds the sandbox environment to env.options.variablesOptionalReadonly<Record<string, string>> | undefinedEnvironment variables set for every command in the sandbox, as literal values. A key the agent also declares fails with code configuration.options.rootOptionalstring | undefinedRepository directory inside the sandbox, default /vercel/sandbox/outpost.options.retainOptionalnumber | undefinedBytes of output tail kept per stream, default 65536.connectOptional((config: VercelOptions["create"]) => Promise<Sandbox>) | undefinedReplaces the default Sandbox.create() from @vercel/sandbox; receives the creation options with the network policy and env applied.