> ## Documentation Index
> Fetch the complete documentation index at: https://docs.boxd.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# TanStack AI

> The type-safe AI SDK for TypeScript. Its sandbox layer runs coding agents like Codex and Claude Code inside isolated boxd microVMs through the boxd provider.

<img src="https://mintcdn.com/azin/6869m0421Agt0IFu/images/boxd-x-tanstack-ai.png?fit=max&auto=format&n=6869m0421Agt0IFu&q=85&s=f59ce3d645aa651c7f7279c5bae647dc" alt="boxd.sh and TanStack AI, the TanStack AI card on a boxd frame" width="2400" height="1640" data-path="images/boxd-x-tanstack-ai.png" />

[TanStack AI](https://tanstack.com/ai) is the type-safe, provider-agnostic AI SDK for TypeScript, from the team behind TanStack Query and Router. Its sandbox layer gives a coding agent a real computer to work in. A provider decides where the agent runs, a workspace decides what it sees, and a harness adapter decides which agent runs. With `@tanstack/ai-sandbox-boxd` as the provider, that computer is an isolated boxd KVM microVM:

```bash theme={"theme":"github-dark"}
npm install @tanstack/ai @tanstack/ai-sandbox @tanstack/ai-sandbox-boxd @tanstack/ai-codex
```

```typescript theme={"theme":"github-dark"}
import { chat } from '@tanstack/ai'
import { codexText } from '@tanstack/ai-codex'
import {
  createSecrets,
  defineSandbox,
  defineWorkspace,
  withSandbox,
} from '@tanstack/ai-sandbox'
import { boxdSandbox } from '@tanstack/ai-sandbox-boxd'

const sandbox = defineSandbox({
  id: 'codex',
  provider: boxdSandbox({ vcpu: 2 }), // reads BOXD_API_KEY and BOXD_ORG
  workspace: defineWorkspace({
    source: { type: 'none' },
    secrets: createSecrets({ CODEX_API_KEY: process.env.CODEX_API_KEY ?? '' }),
  }),
})

const stream = chat({
  adapter: codexText('gpt-5.5', { sandboxMode: 'danger-full-access' }),
  messages: [
    { role: 'user', content: 'in bash, write the hostname to where.txt, reply with it only' },
  ],
  middleware: [withSandbox(sandbox)],
})
```

<Frame caption="One chat() run. The provider creates the machine, Codex runs inside it, and the machine shows up in the org like any other.">
  <video autoPlay muted loop playsInline src="https://mintcdn.com/azin/1bGluqItaOaNwrA1/videos/tanstack-ai-on-boxd.mp4?fit=max&auto=format&n=1bGluqItaOaNwrA1&q=85&s=189abf5edcb49050c56842f9b15e5260" data-path="videos/tanstack-ai-on-boxd.mp4" />
</Frame>

`withSandbox` resumes or creates the machine before the run, bootstraps the workspace, and tears the machine down according to the sandbox lifecycle. The harness adapter spawns `codex` inside the machine over boxd's exec stream and turns its events into the same stream chunks every other `chat()` call produces. Swap `codexText` for `claudeCodeText` or `grokBuildText` and the provider stays the same.

Every machine the provider creates is isolated. Isolation strips the in-VM `boxd` CLI, the metadata endpoint, and org integrations, and keeps the machine off the org network. The API key stays on your side of the boundary, and workspace secrets arrive as environment variables at create time. The `/workspace` root the framework talks about maps to `/home/boxd/workspace` inside the machine.

Where boxd goes beyond the container providers is in what the `SandboxHandle` can do:

| Capability            | On boxd                                                                                                         |
| --------------------- | --------------------------------------------------------------------------------------------------------------- |
| `fork()`              | A live copy of the machine: disk, memory, and running processes, ready in under a second.                       |
| `snapshot()`          | Memory and disk. `restoreSnapshot()` boots a new machine with the captured processes still running.             |
| Durable filesystem    | The disk persists across stop, suspend, and hibernate until `destroy()`. `resume()` picks the machine up by id. |
| `ports.connect(port)` | Pins the machine's public `https://<name>.boxd.sh` route to that port.                                          |
| Background processes  | `spawn()` outlives a closed stream. `kill()` signals the process group and checks it is gone.                   |

Pick the machine size with `vcpu` (`1`, `2`, or `4`, which boxd pairs with 4, 8, or 16 GiB), boot from a prepared snapshot with `fromSnapshot`, and set `autoDestroyTimeout` as a safety net for sandboxes nobody tears down.

<Note>
  Every boxd API key is fenced to one org. Pass that org as `org` or `BOXD_ORG`, next to the key in `BOXD_API_KEY`.
</Note>

The microVM is the isolation boundary, so Codex runs with `sandboxMode: 'danger-full-access'`. The adapter applies the same setting on Daytona and Cloudflare, whose VMs also cannot nest Codex's own bubblewrap sandbox.

The provider ships in TanStack AI as [`@tanstack/ai-sandbox-boxd`](https://www.npmjs.com/package/@tanstack/ai-sandbox-boxd). TanStack's own [providers page](https://tanstack.com/ai/latest/docs/sandbox/providers#boxd) covers configuration and the full capability matrix, and the [sandbox overview](https://tanstack.com/ai/latest/docs/sandbox/overview) explains the provider, workspace, and harness split.
