Skip to main content
boxd.sh and TanStack AI, the TanStack AI card on a boxd frame TanStack AI is the type-safe, provider-agnostic AI SDK for TypeScript, from the team behind TanStack Query and Router. Its sandbox layer gives a coding agent a real computer to work in. A provider decides where the agent runs, a workspace decides what it sees, and a harness adapter decides which agent runs. With @tanstack/ai-sandbox-boxd as the provider, that computer is an isolated boxd KVM microVM:

One chat() run. The provider creates the machine, Codex runs inside it, and the machine shows up in the org like any other.

withSandbox resumes or creates the machine before the run, bootstraps the workspace, and tears the machine down according to the sandbox lifecycle. The harness adapter spawns codex inside the machine over boxd’s exec stream and turns its events into the same stream chunks every other chat() call produces. Swap codexText for claudeCodeText or grokBuildText and the provider stays the same. Every machine the provider creates is isolated. Isolation strips the in-VM boxd CLI, the metadata endpoint, and org integrations, and keeps the machine off the org network. The API key stays on your side of the boundary, and workspace secrets arrive as environment variables at create time. The /workspace root the framework talks about maps to /home/boxd/workspace inside the machine. Where boxd goes beyond the container providers is in what the SandboxHandle can do: Pick the machine size with vcpu (1, 2, or 4, which boxd pairs with 4, 8, or 16 GiB), boot from a prepared snapshot with fromSnapshot, and set autoDestroyTimeout as a safety net for sandboxes nobody tears down.
Every boxd API key is fenced to one org. Pass that org as org or BOXD_ORG, next to the key in BOXD_API_KEY.
The microVM is the isolation boundary, so Codex runs with sandboxMode: 'danger-full-access'. The adapter applies the same setting on Daytona and Cloudflare, whose VMs also cannot nest Codex’s own bubblewrap sandbox. The provider ships in TanStack AI as @tanstack/ai-sandbox-boxd. TanStack’s own providers page covers configuration and the full capability matrix, and the sandbox overview explains the provider, workspace, and harness split.