Skip to main content
Use Agent37 Cloud as the sandbox for an OpenAI Agents API session. OpenAI runs the agent; your Agent37 instance runs its shell commands and file operations through codex exec-server. You choose the image and keep the workspace on the instance’s disk. This guide follows OpenAI’s self-hosted sandbox setup. To run the whole Codex agent on Agent37 and call the Agent37 chat API, use Host Codex.
Paste this into your coding agent

Before you begin

  • An Agent37 API key in AGENT37_API_KEY and a funded workspace wallet. Create a key in the dashboard.
  • An OpenAI application key in OPENAI_API_KEY, with Agents API access and the api.agents.read, api.agents.write, and api.responses.write permissions.
  • A separate environment key, created on the OpenAI Platform Agents tab, exported as OPENAI_EXECUTOR_API_KEY. Use the same organization, project, and user or service account as the application key, with other permissions set to None.
  • Node.js, curl, and jq on your computer. The cloud build needs no local Docker.
Run the commands below from your computer. Keep both platform API keys there. Only the restricted environment key goes into the sandbox, where agent-generated code can read it.

1. Build the sandbox image

Put this Dockerfile in an empty folder:
Dockerfile
The image includes OpenAI’s executor and common command-line tools. Add dependencies your workload needs here, outside /home/node: that directory is the instance’s persistent home, mounted over the image at runtime. The main process keeps the instance available; you start the executor separately after creating a session. Build it as a workspace template:
Omit --default-port: the executor only makes outbound connections to api.openai.com and codex-cloud-environments.chatgpt.com, so this sandbox needs no listening port or public URL.

2. Create the OpenAI session

Keep the returned remote URL unchanged. Save the session id with your application’s conversation state.

3. Create the Agent37 instance

Save the mapping from OPENAI_SESSION_ID to INSTANCE_ID. Each OpenAI session needs its own executor; use a dedicated instance per session to keep files and credentials separate. Leave auto-sleep off because the executor’s outbound connection does not keep an instance awake.

4. Connect the executor

In a second terminal, export the same OPENAI_API_KEY and OPENAI_SESSION_ID, then keep the OpenAI event stream open:
Back in the first terminal, start the executor through Agent37 exec:
The command creates the agent’s working directory in the persistent home, then starts the executor in the background. Wait for agent.session.environment.connected in the OpenAI stream. A successful exec response only means the launch command ran. If the connection fails, read /tmp/openai-executor.log with exec and check the environment key and session values.

5. Run a task and read its file

Send input through the OpenAI session API:
Follow the stream until the root turn completes or fails. After a successful task, read the file directly from your instance:
Check exit_code is 0 and stdout contains the hostname. That verifies the OpenAI agent wrote a file on your Agent37 instance. You can also use SSH to inspect the workspace or stage files before a task.

Lifecycle and cleanup

Reuse the OpenAI session for follow-up messages while its executor stays connected. If you stop, restart, or update the instance, run the launch command from step 4 again before sending more work; the next turn waits for the executor to reconnect. Files in /home/node/workspace survive those operations. Your application owns both resources. Ending or deleting an OpenAI session does not delete the Agent37 instance. When you no longer need the sandbox, copy out any files you want and delete it:
Manage or delete the OpenAI session separately through OpenAI’s session management API. Agent37 bills compute and storage through your wallet; OpenAI bills model usage through your OpenAI account.

Provider listing

OpenAI lists sandbox providers on its self-hosted sandboxes page, each with a short setup page. Everything needed to add Agent37 is below.
Provider description
Provider table row
Provider setup page