Preview sandbox
Opens a port of a sandbox the caller holds in a browser.
POST /v1/sandbox/{id}/preview
| Address | https://api.hanzo.ai/v1/sandbox/{id}/preview |
| Method | POST |
| Operation | post_sandbox_by_id_preview |
| Auth | Authorization: Bearer $HANZO_API_KEY |
Opens a port of a sandbox the caller holds in a browser.
It answers a URL at an origin of the preview's own — https://sandbox-<id>-preview-<port>.<apex>/ — carrying a single-use ticket. Opening it sets a cookie on that origin and lands on its root, and from then on every request there is carried to the port inside the sandbox: pages, assets, APIs and WebSockets, as the app serves them on localhost. The preview stays open for twelve hours or until the sandbox stops running; a preview answering 401 is opened again by asking for another URL. A sandbox that is not running is 409.
Request
3 fields, body application/json (required).
| Field | In | Type | Required | Description |
|---|---|---|---|---|
id | path | string | yes | ID is the sandbox, from the path. |
id | body | string | — | ID is the sandbox, from the path. |
port | body | integer (int64) | — | Port is the TCP port inside the sandbox to open, 1 to 65535. |
Response
| Status | Body | Meaning |
|---|---|---|
201 | sandbox.previewGrant | created |
default | problem-details | refused |
201 body — 4 fields.
| Field | In | Type | Always | Description |
|---|---|---|---|---|
expiresIn | body | integer (int64) | — | ExpiresIn is how long the ticket in URL is good for, in seconds. |
host | body | string | — | Host is the preview's origin host, the same for every ticket for this port of this sandbox, before and after the sandbox is parked and resumed. |
port | body | integer (int64) | — | Port is the port the preview serves. |
url | body | string | — | URL opens the preview: its own origin, with a single-use ticket that sets the preview's cookie and redirects to its root. |
Failure carries the platform error shape — see Errors.
Examples
hanzo has no subcommand for this operation — the CLI serves only what cloud's live route table confirms. Use HTTP or an SDK.
import { Configuration, SandboxApi } from 'hanzoai';
const api = new SandboxApi(new Configuration({ accessToken: process.env.HANZO_API_KEY }));
const { data } = await api.postSandboxByIdPreview({ id: 'id', id: "<id>", port: 0 });from hanzoai.cloud import ApiClient, Configuration
from hanzoai.cloud.api import SandboxApi
client = ApiClient(Configuration(access_token=os.environ["HANZO_API_KEY"]))
result = SandboxApi(client).post_sandbox_by_id_preview(id='id', id="<id>", port=0)cfg := hanzoai.NewConfiguration()
cfg.AddDefaultHeader("Authorization", "Bearer "+os.Getenv("HANZO_API_KEY"))
client := hanzoai.NewAPIClient(cfg)
resp, _, err := client.SandboxAPI.PostSandboxByIdPreview(context.Background()).Execute()
if err != nil {
return err
}use hanzo_client::apis::{configuration::Configuration, sandbox_api};
let mut cfg = Configuration::new();
cfg.bearer_access_token = std::env::var("HANZO_API_KEY").ok();
let result = sandbox_api::post_sandbox_by_id_preview(&cfg, Default::default()).await?;import ai.hanzo.cloud.ApiClient;
import ai.hanzo.cloud.api.SandboxApi;
ApiClient client = new ApiClient();
client.setBearerToken(System.getenv("HANZO_API_KEY"));
var result = new SandboxApi(client).postSandboxByIdPreview();curl -X POST https://api.hanzo.ai/v1/sandbox/<id>/preview \
-H "Authorization: Bearer $HANZO_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"id": "<id>",
"port": 0
}'MCP reaches sandbox through the sandbox tool, which names its 17 operations with its own verbs — this one among them, under a name only MCP declares. describe explains any of them:
curl -X POST https://api.hanzo.ai/v1/mcp \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "describe",
"arguments": {
"op": "list_sandboxes"
}
}
}'