Home / Docs / Personal agents · also: Quickstart · Limits

Run a personal agent (OpenClaw)

Tested 2026-10-01 on the agent-full template with OpenClaw 2026.9.7 (sbx.agent-next.com, e2b Python 2.40.0). Everything below was run as written, without a model key: it covers install, gateway, public URL and pause/resume. Model keys and chat channels are not covered.

Summary

StepResultEvidence
InstallWorksOfficial installer, about 65 s. It installs Node 24 itself (the template ships Node 22; OpenClaw needs 24.16+ or 26.1+).
Expose the portWorkshttps://18789-<id>.sbx.agent-next.com/health returned 204 with the gateway token.
Pause, then resume with Sandbox.connectWorksGateway process, files and ~/.openclaw were intact. Resume took 3-5 s as seen from outside.
Auto-resume on an HTTP requestWorks (fixed 2026-10-02)On 2026-10-01 the first request to a paused sandbox's URL returned 502 failed to resume sandbox. After the 2026-10-02 gateway fix, a paused python -m http.server sandbox answered its first request with 200 in 0.5-0.6 s. Not yet re-run with OpenClaw.
Schedules during pauseDo not runExpected, and confirmed: see the gaps below.

1. Create the sandbox

Set auto_resume so the data plane is allowed to resume the sandbox on a request (without it the URL returns 409 sandbox is paused and autoResume is disabled). Idle auto-pause is separate: see limits.

export E2B_DOMAIN=sbx.agent-next.com   # plus E2B_API_KEY
python3 - <<'PY'
from e2b import Sandbox
sbx = Sandbox.create(template="agent-full", timeout=3600,
                     lifecycle={"on_timeout": "pause", "auto_resume": True})
print(sbx.sandbox_id)
PY

2. Install OpenClaw (inside the sandbox)

Source: the OpenClaw README. --no-onboard --no-prompt keeps the installer non-interactive.

curl -fsSL --proto '=https' --tlsv1.2 https://openclaw.ai/install.sh \
  | bash -s -- --no-onboard --no-prompt
openclaw --version      # OpenClaw 2026.9.7

3. Start the gateway in the background

The gateway listens on 18789 by default (docs/gateway/index.md). It must bind beyond loopback for the sandbox URL to reach it, which requires a token. State lives in ~/.openclaw (OPENCLAW_STATE_DIR).

echo "OPENCLAW_GATEWAY_TOKEN=$(head -c 32 /dev/urandom | od -An -tx1 | tr -d ' \n')" > /root/gw.env
set -a; . /root/gw.env; set +a
nohup setsid openclaw gateway --port 18789 --bind lan --allow-unconfigured \
  > /root/gateway.log 2>&1 &
sleep 30                                      # give it time to start; step 4 checks it

4. Reach it from outside

curl -H "Authorization: Bearer $OPENCLAW_GATEWAY_TOKEN" \
  -i https://18789-<sandboxId>.sbx.agent-next.com/health     # HTTP 204

Requests without the token (for example the Control UI page at /) get 403 proxy_attribution_required. OpenClaw sees the data plane as an unlisted proxy and asks for gateway.trustedProxies. We did not configure it, so the browser Control UI was not exercised (not tested). Authenticated API routes work as shown.

5. Pause and resume

sbx.pause()                               # ~2.6 s
sbx = Sandbox.connect(sandbox_id)         # resumes; 3.2-4.6 s measured

After connect, in the same sandbox: the openclaw-gateway process kept its PID, /root/marker.txt and ~/.openclaw were intact, and /health returned 204 again.

What survives pause

ItemAfter resume
Processes (gateway, background loops)Alive, same PIDs
Files, ~/.openclaw stateIntact
Guest clockJumps forward to real time. The gateway logged process was frozen ~223300ms and deferred a channel restart.
Open TCP connectionsTreat as dropped; clients reconnect (not tested)
Scheduled work (cron, OpenClaw heartbeat, loops)Does not run while paused. Nothing is queued or replayed by the platform.

Measured gaps. A loop writing date +%s every 5 s: last tick before pause 1790887123, next tick 1790887378, a 255 s gap that matches the pause. A * * * * * cron entry (note: % must be written \% in a crontab): ticks every 60 s until 1790888074, then none until 1790888254 (180 s gap, the pause); on resume cron wrote three lines at the same second, 1790888254. The template does not ship cron: apt-get install -y cron, then start it with service cron start.

Consequence: an always-on agent that must act at fixed times (reminders, a heartbeat that checks mail) will miss them while the sandbox is paused, and an idle sandbox pauses after 300 s. Until a platform-side scheduler exists, keep the sandbox running, or wake it yourself from an external timer with Sandbox.connect.

Back to Quickstart · Limits