Home / Docs / Coding agents · also: Quickstart

Coding agents in the sandbox

The agent-full template ships six coding-agent CLIs, installed with no credentials baked in. Pass your own model key as an environment variable on the command. Versions below were checked with --version inside a live agent-full sandbox on 2026-10-01; model-backed runs were not tested.

Launch from the E2B SDK

import os
from e2b import Sandbox

sbx = Sandbox.create("agent-full", timeout=1800)
try:
    sbx.files.write("/root/work/notes.txt", "hi")
    out = sbx.commands.run(
        'cd /root/work && codex exec --skip-git-repo-check "summarize notes.txt"',
        envs={"OPENAI_API_KEY": os.environ["OPENAI_API_KEY"]},   # key stays in process env
        timeout=600,
    )
    print(out.stdout)
finally:
    sbx.kill()

Swap the command and the env var for any row below. Pass keys through envs, never as a CLI flag (a flag is visible to every process in the sandbox).

Baked CLIs

AgentVerifiedKey env var (from upstream docs, not tested)
Claude Codeclaude --version → 2.1.284ANTHROPIC_API_KEY (ANTHROPIC_BASE_URL for a compatible endpoint)
Codex CLIcodex --version → 0.158.0OPENAI_API_KEY
OpenCodeopencode --version → 1.18.33provider key, e.g. OPENAI_API_KEY or ANTHROPIC_API_KEY
Cline CLIcline --version → 3.0.65no env route: cline auth -p openai -k $KEY takes the key as an argument
Aideraider --version → 0.86.2OPENAI_API_KEY or ANTHROPIC_API_KEY
mini-swe-agentpipx list → mini-swe-agent 2.4.6 (mini has no --version)OPENAI_API_KEY or ANTHROPIC_API_KEY (model via -m)

Headless commands

IS_SANDBOX=1 claude -p "fix the failing tests" --dangerously-skip-permissions
codex exec --dangerously-bypass-approvals-and-sandbox --skip-git-repo-check "fix the failing tests"
opencode run -m openai/gpt-5 "fix the failing tests"
cline "fix the failing tests"
aider --yes-always --no-git --message "fix the failing tests" calc/stats.py
mini -y --exit-immediately -m openai/gpt-5 -t "fix the failing tests"

Flags are taken from our run harness and each CLI's help; they were not re-run against a model for this page. IS_SANDBOX=1 is what that harness sets for Claude Code as root. Codex exec is read-only by default; the bypass flag is safe here because the sandbox itself is the isolation boundary.

Not baked yet: install on demand

These installed and reported a version inside an agent-full sandbox (5 to 16 s each for npm, 7 to 13 s for the curl installers). Run the npm commands as root to put them on PATH.

AgentInstallVerified
Gemini CLInpm install --global @google/gemini-cli@0.62.0gemini --version → 0.62.0
Qwen Codenpm install --global @qwen-code/qwen-code@0.24.7qwen --version → 0.24.7
Kilo Code CLInpm install --global @kilocode/cli@7.8.3kilo --version → 7.8.3
Crushnpm install --global @charmland/crush@0.97.1crush --version → v0.97.1
Ampnpm install --global @sourcegraph/ampamp --version → 0.0.1790871178-g5cbe9b
Cursor CLIcurl -fsSL https://cursor.com/install | bashcursor-agent --version → 2026.10.01-14929f9
Goosecurl -fsSL https://github.com/block/goose/releases/download/stable/download_cli.sh | CONFIGURE=false bashgoose --version → 1.52.0

The curl installers and Amp are unpinned and not checksum-verified.

Next: quickstart · limits and network policy