Home / Docs / Coding agents · also: Quickstart
Coding agents in the sandbox
The agent-full template ships six coding-agent CLIs, installed with no credentials baked in. Pass your own model key as an environment variable on the command. Versions below were checked with --version inside a live agent-full sandbox on 2026-10-01; model-backed runs were not tested.
Launch from the E2B SDK
import os
from e2b import Sandbox
sbx = Sandbox.create("agent-full", timeout=1800)
try:
sbx.files.write("/root/work/notes.txt", "hi")
out = sbx.commands.run(
'cd /root/work && codex exec --skip-git-repo-check "summarize notes.txt"',
envs={"OPENAI_API_KEY": os.environ["OPENAI_API_KEY"]}, # key stays in process env
timeout=600,
)
print(out.stdout)
finally:
sbx.kill()
Swap the command and the env var for any row below. Pass keys through envs, never as a CLI flag (a flag is visible to every process in the sandbox).
Baked CLIs
| Agent | Verified | Key env var (from upstream docs, not tested) |
|---|---|---|
| Claude Code | claude --version → 2.1.284 | ANTHROPIC_API_KEY (ANTHROPIC_BASE_URL for a compatible endpoint) |
| Codex CLI | codex --version → 0.158.0 | OPENAI_API_KEY |
| OpenCode | opencode --version → 1.18.33 | provider key, e.g. OPENAI_API_KEY or ANTHROPIC_API_KEY |
| Cline CLI | cline --version → 3.0.65 | no env route: cline auth -p openai -k $KEY takes the key as an argument |
| Aider | aider --version → 0.86.2 | OPENAI_API_KEY or ANTHROPIC_API_KEY |
| mini-swe-agent | pipx list → mini-swe-agent 2.4.6 (mini has no --version) | OPENAI_API_KEY or ANTHROPIC_API_KEY (model via -m) |
Headless commands
IS_SANDBOX=1 claude -p "fix the failing tests" --dangerously-skip-permissions
codex exec --dangerously-bypass-approvals-and-sandbox --skip-git-repo-check "fix the failing tests"
opencode run -m openai/gpt-5 "fix the failing tests"
cline "fix the failing tests"
aider --yes-always --no-git --message "fix the failing tests" calc/stats.py
mini -y --exit-immediately -m openai/gpt-5 -t "fix the failing tests"
Flags are taken from our run harness and each CLI's help; they were not re-run against a model for this page. IS_SANDBOX=1 is what that harness sets for Claude Code as root. Codex exec is read-only by default; the bypass flag is safe here because the sandbox itself is the isolation boundary.
Not baked yet: install on demand
These installed and reported a version inside an agent-full sandbox (5 to 16 s each for npm, 7 to 13 s for the curl installers). Run the npm commands as root to put them on PATH.
| Agent | Install | Verified |
|---|---|---|
| Gemini CLI | npm install --global @google/gemini-cli@0.62.0 | gemini --version → 0.62.0 |
| Qwen Code | npm install --global @qwen-code/qwen-code@0.24.7 | qwen --version → 0.24.7 |
| Kilo Code CLI | npm install --global @kilocode/cli@7.8.3 | kilo --version → 7.8.3 |
| Crush | npm install --global @charmland/crush@0.97.1 | crush --version → v0.97.1 |
| Amp | npm install --global @sourcegraph/amp | amp --version → 0.0.1790871178-g5cbe9b |
| Cursor CLI | curl -fsSL https://cursor.com/install | bash | cursor-agent --version → 2026.10.01-14929f9 |
| Goose | curl -fsSL https://github.com/block/goose/releases/download/stable/download_cli.sh | CONFIGURE=false bash | goose --version → 1.52.0 |
The curl installers and Amp are unpinned and not checksum-verified.
Next: quickstart · limits and network policy