codex exec-server. You choose the image and keep the workspace on the instance’s disk.
This guide follows OpenAI’s self-hosted sandbox setup. To run the whole Codex agent on Agent37 and call the Agent37 chat API, use Host Codex.
Paste this into your coding agent
Before you begin
- An Agent37 API key in
AGENT37_API_KEYand a funded workspace wallet. Create a key in the dashboard. - An OpenAI application key in
OPENAI_API_KEY, with Agents API access and theapi.agents.read,api.agents.write, andapi.responses.writepermissions. - A separate environment key, created on the OpenAI Platform Agents tab, exported as
OPENAI_EXECUTOR_API_KEY. Use the same organization, project, and user or service account as the application key, with other permissions set to None. - Node.js,
curl, andjqon your computer. The cloud build needs no local Docker.
1. Build the sandbox image
Put thisDockerfile in an empty folder:
Dockerfile
/home/node: that directory is the instance’s persistent home, mounted over the image at runtime. The main process keeps the instance available; you start the executor separately after creating a session.
Build it as a workspace template:
--default-port: the executor only makes outbound connections to api.openai.com and codex-cloud-environments.chatgpt.com, so this sandbox needs no listening port or public URL.
2. Create the OpenAI session
3. Create the Agent37 instance
OPENAI_SESSION_ID to INSTANCE_ID. Each OpenAI session needs its own executor; use a dedicated instance per session to keep files and credentials separate. Leave auto-sleep off because the executor’s outbound connection does not keep an instance awake.
4. Connect the executor
In a second terminal, export the sameOPENAI_API_KEY and OPENAI_SESSION_ID, then keep the OpenAI event stream open:
agent.session.environment.connected in the OpenAI stream. A successful exec response only means the launch command ran. If the connection fails, read /tmp/openai-executor.log with exec and check the environment key and session values.
5. Run a task and read its file
Send input through the OpenAI session API:exit_code is 0 and stdout contains the hostname. That verifies the OpenAI agent wrote a file on your Agent37 instance. You can also use SSH to inspect the workspace or stage files before a task.
Lifecycle and cleanup
Reuse the OpenAI session for follow-up messages while its executor stays connected. If you stop, restart, or update the instance, run the launch command from step 4 again before sending more work; the next turn waits for the executor to reconnect. Files in/home/node/workspace survive those operations.
Your application owns both resources. Ending or deleting an OpenAI session does not delete the Agent37 instance. When you no longer need the sandbox, copy out any files you want and delete it:
Provider listing
OpenAI lists sandbox providers on its self-hosted sandboxes page, each with a short setup page. Everything needed to add Agent37 is below.Provider description
Provider table row
Provider setup page