---
title: "Sandbox API · intentic"
description: "Every HTTP call an intentic sandbox answers, generated from the wire contract itself, with a playground that responds in your own browser. No sign-in, no setup."
url: "https://intentic.dev/api/"
updated: "2026-10-06"
---

Start here

# Sandbox API

Every call an intentic sandbox answers (363 of them), generated from the wire contract the daemon and its own browser client both import. Each one has a playground on its page that answers you back.

**On this page (4 sections)**

- [Whose API this is](#whose-api)
- [In one minute](#in-one-minute)
- [The whole surface](#the-map)
- [How this is made](#how-this-page-is-made)

## Whose API this is

There is no intentic API in the cloud that reaches your code. The platform holds your identity and your sandbox's address and nothing else. Everything documented here is served by **your** daemon, inside **your** container, on hardware you own, and the only way in is a credential you minted yourself.

That is also why the playgrounds on these pages answer from a simulation in your own tab rather than by calling anything. There is no shared server to point a demo at, and a demo that needed you to have a sandbox, sign in to it and open its door first would be a demo almost nobody reached. What the playground gives you instead is every one of the 363 calls, including the destructive ones, with the real address, the real fields and the real shapes, and beside each one, the `curl` that does it for real.

## In one minute

The call most people are here for, and the one that shows the API's whole personality: start work, then watch it.

Drive an agent from a script

```bash
SANDBOX=https://sandbox-a1b2c3d4e5f6.intentic.dev

# Say something to an agent. It answers as soon as the run exists; the work is detached.
curl -X POST "$SANDBOX/agent" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"prompt":"Update the changelog for the last five commits.",
 "conversationId":"nightly-changelog",
 "isolated":true}'

{ "run": "run_8c2f41d9" }

# Watch it happen, from the start or from wherever you got to.
curl -N -X POST "$SANDBOX/agent/attach" \
 -H "x-intentic-control: $INTENTIC_TOKEN" \
 -H "content-type: application/json" \
 -d '{"conversationId":"nightly-changelog","after":0}'
```

Starting a turn hands back a run id and nothing else, because the work runs inside the sandbox whether or not you stay connected. Any number of watchers can attach to the same run from any number of devices; a reload loses nothing. Read [Authorising a call](https://intentic.dev/api/auth/) for where that token comes from, and [The shape of a call](https://intentic.dev/api/calls/) for the two conventions that cover all 363.

## The whole surface

Thirty-seven groups on seven shelves. Nothing below was typed by hand: the groups, their routes and every field in them come from the contract, and only the sentence under each name is written by a person.

### Agents

Say something to an agent, watch it work, and decide what happens to what it wrote.

[One agent 15 Run a turn in one conversation, then attach to it, answer it, steer it or stop it](https://intentic.dev/api/agent/)[The fleet 32 Every registered conversation, its accumulated diff, and landing or discarding its work](https://intentic.dev/api/agents/)[Past sessions 2 Conversations that have finished, and their transcripts](https://intentic.dev/api/sessions/)[Workflows 9 Several agents in a fixed order, the designs and the runs](https://intentic.dev/api/workflows/)[Loops 6 One conversation run again until it gets there, and the saved designs behind them](https://intentic.dev/api/loops/)[Automations 11 Work the sandbox starts on its own, and the approvals it parks waiting for you](https://intentic.dev/api/automations/)

### The workspace

The files and repos the agents work on, and the history of both.

[Workspace 31 The file tree the agents work on: read it, search it, change it, and run what is in it](https://intentic.dev/api/workspace/)[Git 45 Version control, one repository at a time](https://intentic.dev/api/git/)[Diffs 1 Both sides of a changed document as text, for the files a line diff cannot show](https://intentic.dev/api/diff/)[History 4 Saved states of the whole workspace, and putting one back](https://intentic.dev/api/history/)[Chores 3 What every repository currently measures, and what has been done about it](https://intentic.dev/api/chores/)[Panels 3 Each repository's dev server: what it is and whether it is running](https://intentic.dev/api/panels/)[Ports 3 What is listening inside the sandbox, and forwarding one out](https://intentic.dev/api/ports/)[Areas 3 The named parts of the workspace a teammate's reach is granted in](https://intentic.dev/api/areas/)

### Agent setup

The instructions, characters and add-ons that decide how an agent behaves.

[Personas 8 Named characters an agent can wear: the accounts it speaks for and what it is told](https://intentic.dev/api/personas/)[Skills 5 The instruction packs an agent can be handed](https://intentic.dev/api/skills/)[Extensions 22 Installed extensions: their settings, their readiness, their updates and their processes](https://intentic.dev/api/extensions/)[Settings 11 The sandbox's own configuration, plus what it has saved you and which rules fired](https://intentic.dev/api/settings/)[Safety policy 3 The document deciding when an agent stops to ask, and the record of what it decided](https://intentic.dev/api/safety/)[Privacy shield 8 What personal data is kept from model providers, and the record of what was masked](https://intentic.dev/api/privacy/)

### Connected systems

The outside world: accounts, credentials, tunnels and the infrastructure you declared.

[Capabilities 14 The outside systems this sandbox is wired into, and connecting a new one](https://intentic.dev/api/capabilities/)[Needs 8 What an agent asked you to connect or provide before it can go on](https://intentic.dev/api/needs/)[Secrets 12 Stored values the agent can use without ever reading them](https://intentic.dev/api/secrets/)[VPN 4 Corporate tunnels the sandbox can hold open](https://intentic.dev/api/vpn/)[Network disks 3 Shares on a file server the sandbox can hold mounted](https://intentic.dev/api/netdisk/)[Exit locations 7 Sending the sandbox's outbound traffic out of a chosen country](https://intentic.dev/api/exit/)[Inventory 3 What this sandbox has and what it wants, as declared deployment intent](https://intentic.dev/api/inventory/)[Platform CLI 3 Run the in-sandbox platform tool and follow its output as it arrives](https://intentic.dev/api/intentic/)

### Models and accounts

Which models are available, whose subscription pays for them, and what has been spent.

[Accounts 7 Subscriptions this sandbox holds itself, for any provider, with the provider in the address](https://intentic.dev/api/accounts/)[Routed providers 5 Subscriptions that run another vendor's model under the Claude Code harness](https://intentic.dev/api/translator/)[Endpoints 4 A model server you configured, and the free trial's allowance](https://intentic.dev/api/endpoints/)[Providers 2 A built-in provider's model catalogue](https://intentic.dev/api/providers/)[Usage 4 What has been spent, grouped](https://intentic.dev/api/usage/)

### Ship and share

Checks before code leaves the machine, and the ways work reaches other people.

[Pipelines 5 Continuous integration runs, and asking an agent to fix a failed one](https://intentic.dev/api/ci/)[Offloaded work 5 Send heavy commands such as tests and typechecks to a runner on one of your machines](https://intentic.dev/api/offload/)[Outbox 3 Files published to a public address, with no sign-in](https://intentic.dev/api/public/)[Sharing 4 Conversations published as read-only pages](https://intentic.dev/api/share/)[Approvals 6 Things the agent has prepared, waiting for you to say yes](https://intentic.dev/api/approvals/)[Issues 5 Bugs your own users hit, grouped, and putting an agent on one](https://intentic.dev/api/issues/)

### The sandbox itself

The daemon's own identity, its live event stream, and the record it keeps.

[System 25 The daemon itself: its identity, its event stream, its terminals, its browsers, its helpers](https://intentic.dev/api/system/)[Activity 2 The audit feed of what the agent did out in the world](https://intentic.dev/api/activity/)[Logs 3 The sandbox's durable debug record](https://intentic.dev/api/logs/)[Push notifications 4 So a finished turn can reach you when the tab is closed](https://intentic.dev/api/push/)

## How this is made

The daemon and the app share one typed contract: it declares every route's method, path, input shape and output shape, and both sides import it rather than agreeing to match. These pages are that contract rendered, so they cannot describe a route the daemon does not serve, and a route added to the contract is documented the day it lands.

The same thing is served as a machine-readable document at [openapi.json](https://intentic.dev/api/openapi.json): OpenAPI 3.1, for a client generator, an editor's HTTP plugin, or a model that needs to be told what a sandbox can do.

More in Start here

[Next Authorising a call →](https://intentic.dev/api/auth/)
