Pick a type
openai_hosted is the name the Agents API uses for a managed sandbox. On Orca it means “managed by Orca”. Nothing runs at OpenAI.400 with “Self-hosted environments are coming soon to Orca”; use openai_hosted. They work today with an Orca server you run on the same machine as the executor.
Managed sandbox
A managed sandbox is a private Linux machine created for one session, with 1 vCPU, 2 GiB of memory, and 5 GiB of disk. The agent works in/workspace. Anything it writes to /workspace/outputs is saved as a downloadable artifact when a turn completes.
A managed sandbox uses machine time from your plan while it runs, and it needs at least $0.50 of Orca credit in your wallet, even within your included hours.
Create one
Examples on this page assumeclient is an OpenAI client configured as in the quickstart.
Pass environment with type: "openai_hosted". You can copy files in at the start, either inline (base64) or from an uploaded file.
Choose network access
The sandbox’s internet access is set bynetwork.access. If you do not set it, it is enabled. Start with the least access that works.
On hosted Orca, choose
disabled or enabled. This setting only controls commands the agent runs inside the sandbox. Model calls and MCP tool calls are made by the Orca server and are not affected.
Configure the sandbox
Besidesfiles and network, a managed environment accepts:
Add files later
You can add a file to a running sandbox and list what is there:Reuse a setup with a template
If many sessions need the same setup, save it once as an environment template and passenvironment_template_id when creating a session. A template accepts the same fields as above. Fields you also set on the session override the template’s, with one exception: a session can tighten the template’s network policy but not loosen it. See skills and templates.
Idle sandboxes are paused
A sandbox that has not been used for 5 minutes is paused to free resources. Until then it counts as machine time; while paused, it does not. Its status becomesdisconnected. The next time the session needs it, Orca restores it automatically, with all files in /workspace intact. Programs that were running inside it, such as a server the agent started, do not survive the pause. Declared packages, environment variables, and network policy come back, and setup_commands run again during the restore, so keep setup commands safe to repeat.
Self-hosted environment
Coming soon on hosted Orca. The stock executor connects with an API key only to OpenAI hosts or to
localhost, so today this section applies to an Orca server you run on the same machine, as in the examples.codex exec-server), which connects out to Orca and carries out the agent’s commands.
Steps
1
Create the session
Give the folder the agent should work in. The path must be absolute and must not go through a symbolic link. On macOS, The environment starts as
/tmp is a symlink, so use the real path (for example from realpath).pending and the session as requires_action (environment_connection). Any input you send is held until the executor connects.2
Start the executor
On the machine, run the stock Codex executor with the values from the previous step and an Orca API key for the same account:
3
Wait for it to connect
Poll
agents.environments.retrieve(environment_id).status until it is connected. Then use the session as normal.<workspace_directory>/outputs are captured when a turn completes.
What you must know about trust
- If the executor disconnects, the environment becomes
disconnected, any running turn stops, and the session showsrequires_actionuntil an executor connects again. The interrupted turn is not re-run. - Deleting the session cuts the executor off, but does not stop the process or delete files on your machine. Clean those up yourself.
capability_directoriesmust be empty for self-hosted environments. Put any files the agent needs inside the workspace folder.
Common mistakes
- Choosing
noneand asking the agent to run code. It has no machine. Create a new session with an environment. - Expecting files outside
/workspace/outputsto become artifacts. Only that folder is captured. - Leaving network access at its default. The default is
enabled. Setdisabledunless the task needs the internet. - A relative or symlinked
workspace_directory. It is rejected when the first turn runs, so the turn fails rather than the create call.