Sandbox quickstart
Install the CLI, log in, and run a command in a sandbox.
This guide adapts the sandbox workflow into the Tachyonic CLI and account. Sandbox commands require Tachyonic 0.18.0 or later. The installer serves the latest published release; check the version before continuing.
Install
curl -fsSL https://tachyonic.sh/install | bash
tachyonic --versionOn macOS or Linux with Homebrew:
brew install tachyonic-sh/tap/tachyonicThe release installer checks a SHA-256 checksum. Follow the installer's output for the destination and any permissions it needs.
Log in
Create an account at platform.tachyonic.co, then authorize the CLI in the browser:
tachyonic login
tachyonic whoamiThe login creates a workspace-bound device key and stores it locally. Device keys cannot change budgets. For a key you created in Settings > API Keys, use the hidden prompt:
tachyonic login --with-keyIn CI, supply TACHYONIC_API_KEY through the job's secret environment. The CLI
reads it in-process. Do not put a key in a command argument, URL, shell history,
or output. See Authentication.
Check the account and capacity
tachyonic whoami
tachyonic regions
tachyonic budget getHosted Free credit requires a verified card. Check your plan and available credit in Settings > Billing before starting. Available regions and pools can change; the commands report current account and capacity information.
Run a first command
tachyonic sandbox create --budget 30mCopy the returned sandbox ID and use it below in place of sb_example:
tachyonic sandbox exec sb_example -- python3 --version
tachyonic sandbox cp ./test_app.py sb_example:/workspace/test_app.py
tachyonic sandbox exec sb_example -- python3 /workspace/test_app.py
tachyonic sandbox usage sb_example
tachyonic sandbox rm sb_examplecreate waits for readiness, up to its configured wait. Capacity that needs to
start can take longer than a warm pool. exec streams stdout and stderr and
returns the remote command's exit code. rm stops the sandbox; its record and
lifecycle events remain available through the API.
Container isolation shares the host kernel. Inspect the image, commands, files, and allowed hosts before running untrusted code. An explicit isolation requirement fails when matching capacity is unavailable.
Next
- Sandboxes: isolation, egress, budgets, files, and lifecycle.
- Sandbox CLI: commands, flags, and exit codes.
- Sandbox API: workspace authentication and routes.
- Runtime quickstart: test an authorized agent endpoint.