sandbox_environments

Lists the account's environments (its own dev or staging): the private addresses a box reaches through their connectors, whether each connection is online, the services whose settings a box gets, and the boxes already using each one.

Input Output
none for each environment: name, externalBaseUrl, reachable (the host:port a box can reach), connectorOnline (at least one connection up), connections[{name, online, sessions, lastSeenAt, connectorVersion, rttMs, reachable}], services[{name, envFile, shellFile, keysCount, keys, notable, notableMore, source, deployedImage, syncedAt}], activeBoxes[{id, name, goal, status, agent, lastUsedAt, background}]
sandbox_environments {}
  • An environment is the account's own dev or staging. This tool only reads, and no MCP tool creates or changes one: do that over REST with your token (Environments): POST /v1/environments, POST /v1/environments/{env}/connections, PUT /v1/environments/{env}/connections/{id}/endpoints, and PUT /v1/environments/{env}/services/{name} with a .env body (or POST .../services/import from AWS ECS). Pass its name to sandbox_start as environment to run only the services you changed in the box, against the rest of that environment.
  • reachable: the private host:port addresses a box started with the environment reaches through the connector in the person's network, by their usual host names.
  • connectorOnline is true when at least one connection is up. connections[] shows each network's connector on its own (online, sessions, lastSeenAt, connectorVersion), with the addresses that go through it (reachable). rttMs is the round trip between ParallelSandbox and that connector, measured at each heartbeat (about every 15 seconds) while it is online: every connection a box makes through it pays at least that, so timings measured through the connector compare with each other as ratios, not with timings inside the person's network.
  • services[]: the services whose settings a box gets, as /work/.sbx/env/<service>.env (envFile) and .sh (shellFile). keys names every setting (keysCount counts them); notable picks out the ones to check first, at most 15 (notableMore counts the rest):
    • connection: the value points at the environment itself (one of its addresses or externalBaseUrl's host, given as host), such as a database URL: writing through it changes the environment's real data. This is how to find which variable holds a service's database when it is not DATABASE_URL.
    • mode: settings that switch how the service behaves (SERVER_MODE, NODE_ENV, STAGE, *_BYPASS, SKIP_AUTH, DEBUG), with the value when it is a plain word that the box shows unmasked anyway. Dev's value can turn authentication or checks off, so a test of that path may pass for the wrong reason: override it (-e SERVER_MODE=production) when that matters.
    • permission: admin lists, allowlists and allowed origins. Dev has its own list, not production's, which is why an admin call can get 403 in a box; read the value in the env file.
    • source is aws-ecs or dotenv. For a service imported from AWS ECS, deployedImage is the container image the ECS service ran when it was imported (syncedAt), and its tag is often the commit dev runs: build your changes on that commit when dev lags behind or runs ahead of the branch. POST /v1/environments/{env}/services/{name}/sync reads the task definition again.
  • activeBoxes[]: the account's live boxes started with this environment, with name, goal, status, agent (whether their conversation is still at it) and background, the last few commands they started with background: true (which may have finished). Dev is shared real data: when results do not add up, check whether another box is changing the same data. Programs outside ParallelSandbox that write to dev do not show here.
  • externalBaseUrl: where unchanged HTTP services live; a box started with the environment uses it unless you pass your own.
  • For tests, do not point them at the environment's database: psbx-testdb up <name> starts a clean Postgres of your own in the box (--redis a Redis; Team setup). To read dev's data, psbx-ro-psql <service> in the box connects with that service's database setting in read-only transactions (Environments).
  • An address may also be a public host. A box reaching it goes out through the connector, from the person's own network, which is how to check whether their services can reach an outside site: a box's own traffic leaves from another address (Other facts).
  • It only reads, and needs no box. How to set environments up, and what each field means, is in Environments.

Every tool and topic is listed in the tool reference.