intentic
Download the app
Download the app
The sandbox itself

System

The daemon itself: its identity, its event stream, its terminals, its browsers, its helpers

On this page(25 sections)

The group with the widest job. The identity read is what the daemon says it is, including the routes it implements, which is the one call that tells a newer client what this sandbox can do. The event stream is the sandbox-wide live feed. The rest is the machinery an agent leaves running: terminals and their history, browsers, and the records of helpers it delegated to.

25 calls. Pick one to open it, or use the list on the right.

GET/infoWhat this sandbox is

The sandbox's own identity and state: which workspace it holds, which image it runs, what it is called, and the list of calls it actually implements. Start here, because a browser is routinely newer than the sandbox it is talking to and this is how it finds out what is there.

What you send

Nothing. Call it as it is.

What comes back

FieldType
nameWhat this sandbox is calledstring
imageThe image it is runningstring
versionThe version of that imagestring
latestThe newest published version on its…string
updateAvailableWhether those two differboolean
runtimesWhich agent runtimes can serve a…object
channelWhich release channel this sandbox followsstring
previousImageThe image the last update replaced,…string
updateNotesWhat is in the update, in…string[]
moreUpdateNotesHow many further notes there are…number
breakingNotesWhat the update takes away, uncapped,…string[]
stagedAn update already downloaded and built…object
versionWhat the downloaded build says it…string
channelWhich channel it was taken fromstring
atWhen the download finished, in milliseconds,…number
planWhat the downloaded build's first boot…object
planThe format of this line1
versionThe release of the image that…string
engineThe conversion count builds before the…number
digestWhat identifies the planning build's conversion…string
okFalse when a conversion would fail…boolean
downgradeA newer release than the planning…boolean
failuresEach conversion or step that would…object[]
documentThe stored file whose conversion would…string
detailWhy, in the conversion's own wordsstring
stepsWhat the first boot changes on…object[]
documentThe stored file, workspace-relative, or `<volume>:<path>`…string
changeWhat is done to it, in…string
detailWhat was particular about this one:…string
convertsWhat the build's conversions change as…object[]
documentThe stored file, workspace-relative, or `<volume>:<path>`…string
changeWhat is done to it, in…string
detailWhat was particular about this one:…string
filesEvery file the first boot writes,…string[]
preparingA download of the next update…object
channelWhich channel it is being taken…string
startedAtWhen the download began, in millisecondsnumber
atWhen the machine last said it…number
phaseWhat it is doing: download (pulling…string
percentHow far through the download it…number
lastUpdateWhat the machine running this sandbox…object
resultWhat happened"updated" | "kept" | "restored" | "rolled-back"
verbWhat was asked for: update, rollback,…string
atWhen it happened, in millisecondsnumber
fromThe version (or, when it would…string
toThe version (or image) that was…string
reasonWhy the host gave up on…string
logWhere the host kept the full…string
keepUntilUntil when the previous version stays…number
withdrawnSet when the version this sandbox…object
versionThe withdrawn version, which is the…string
reasonWhy it was withdrawn, as the…string
skippedVersionA release the owner chose to…string
autoUpdateWhether and when this sandbox takes…object
enabledWhether this sandbox takes downloaded updates…boolean
phaseWhere it stands: idle (nothing downloaded…string
versionThe downloaded version it will takestring
holdsEverything keeping it waiting right now,…object[]
kindWhat it waits on: agents (an…string
namesWho or what, by name: the…string[]
untilWhen this lifts by itself, in…number
startsAtDuring a countdown, when the restart…number
pausedUntilThe owner's pause: no automatic update…number
failureWhy the last automatic try did…string
lastAppliedThe last update this sandbox took…object
atnumber
tostring
Try itanswered in this tab
curl
curl "$SANDBOX/info" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.info();
POST/system/update/skipStop offering one release

Stops offering the named release as an update, typically one this sandbox already tried and went back from. A newer release is offered as usual. Null offers the newest release again.

What you send

FieldTypeWhere
versionrequiredThe release to stop offering, or…string | nullbody

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/update/skip" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"version":"1.4.0"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.skipUpdate({
  "version": "1.4.0"
});
POST/system/update/autoDecide how updates are taken

Turns taking a downloaded update by itself on or off, pauses it until a moment, or takes the downloaded update right now. A sandbox taking updates by itself waits for a quiet moment: no agent mid-turn, nobody at the editor, terminals quiet. Answers with where it stands afterwards.

What you send

FieldTypeWhere
enabledTurn taking downloaded updates by itself…booleanbody
pausedUntilHold automatic updates until this moment,…numberbody
applyNowTake the downloaded update now, without…truebody

What comes back

FieldType
enabledWhether this sandbox takes downloaded updates…boolean
phaseWhere it stands: idle (nothing downloaded…string
versionThe downloaded version it will takestring
holdsEverything keeping it waiting right now,…object[]
kindWhat it waits on: agents (an…string
namesWho or what, by name: the…string[]
untilWhen this lifts by itself, in…number
startsAtDuring a countdown, when the restart…number
pausedUntilThe owner's pause: no automatic update…number
failureWhy the last automatic try did…string
lastAppliedThe last update this sandbox took…object
atnumber
tostring
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/update/auto" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"enabled":true,"pausedUntil":1,"applyNow":true}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.autoUpdate({
  "enabled": true,
  "pausedUntil": 1,
  "applyNow": true
});
GET/system/manifest-problemsSettings files the sandbox could not read

Anything the daemon tripped over in its own configuration on disk: a file it had to fall back from, a key it did not recognise, an entry it skipped. Separate from the identity call because it goes stale for a different reason, namely a file changing.

What you send

Nothing. Call it as it is.

What comes back

FieldType
pathThe file, as a workspace path,…string
problemsEverything currently wrong with itobject[]
kindWhat to do about it"unreadable" | "unknownKey" | "invalidEntry"
reasonWhy it could not be read:…"io" | "not-json" | "conversion-failed" | "rejected"
detailWhat exactly was wrong, as one…string
suggestionThe name it was probably meant…string
fixWhat to do about it, when…string
Try itanswered in this tab
curl
curl "$SANDBOX/system/manifest-problems" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.manifestProblems();
POST/system/manifest-problems/repairTake a stray setting out of a file

Removes a key the sandbox does not recognise from one of its settings files, or renames it to the one it was probably meant to be, keeping the value. Only the files a person hand-edits can be named, and only a key — never a value — so this can only ever remove something already being ignored. Renaming onto a key the file already has is refused instead of overwriting it.

What you send

FieldTypeWhere
pathrequiredThe file to repair, as the…stringbody
keyrequiredThe stray top-level key, exactly as…stringbody
toRename the key to this instead…stringbody

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/manifest-problems/repair" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"path":"src/app.ts","key":"OPENAI_API_KEY","to":"src/server.ts"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.repairManifest({
  "path": "src/app.ts",
  "key": "OPENAI_API_KEY",
  "to": "src/server.ts"
});
POST/system/sessionTrade a sign-in for a session

Exchanges a verified sign-in, or a session that has not expired yet, for a fresh session the daemon minted. That session is the credential every other call carries, and calling this again with a live one renews it.

What you send

Nothing. Call it as it is.

What comes back

FieldType
tokenThe credential every other call carriesstring
expiresAtWhen it stops working, in milliseconds,…number
emailWho the sandbox verified you asstring
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/session" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.session();
GET/eventsThe live event streamstream

A stream held open for as long as you want it, carrying heartbeats so a caller notices the sandbox dying at once, batches of file changes so a tree or an editor can refresh itself, and the roster of who else is looking. Give it an id for this connection to appear in that roster; leave it out and you watch without being seen.

What you send

FieldTypeWhere
clientIdstringquery

What comes back

FieldType
when event is "message"shape
dataobject
when kind is "hello"shape
workspaceIdstring
routesstring[]
shapesobject
buildstring
bootobject
projectDirstring
surface"sandbox" | "folder"
when kind is "heartbeat"shape
revnumber
when kind is "boot"shape
readyboolean
startedAtnumber
stepsobject[]
when kind is "workspaceChanged"shape
pathsstring[]
when kind is "treeChanged"shape
fromThe generation this applies on top…integer
generationThe generation it leaves the tree…integer
dirsEach folder that changed, parents before…object[]
barrenThe barren folders now, present only…string[]
when kind is "derivedChanged"shape
pathsstring[]
when kind is "reposChanged"shape
reposstring[]
when kind is "refsChanged"shape
reposstring[]
when kind is "runtimeChanged"shape
domainsstring[]
when kind is "presence"shape
usersobject[]
when kind is "agents"shape
agentsobject[]
revnumber
when kind is "accountUsage"shape
providerstring
accountstring
usageobject
when kind is "providerRefusal"shape
providerstring
refusalobject
idstring
retrynumber
when event is "done"shape
dataunknown
idstring
retrynumber
when event is "error"shape
dataunknown
idstring
retrynumber
Try itanswered in this tab
curl
curl -N "$SANDBOX/events" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.events();
POST/system/presenceSay what you are looking at

Reports which view, conversation or file this connection is on, or that it has gone idle. The daemon fans it back out on the event stream so everyone else's roster updates.

What you send

FieldTypeWhere
clientIdrequiredThis connection's own id, the same…stringbody
idlerequiredWhether the person has stopped doing…booleanbody
awayWhether the window is on screen…booleanbody
viewWhich view they are onstringbody
sessionIdWhich conversation they have openstringbody
pathWhich file they are looking atstringbody

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/presence" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"clientId":"a1b2c3d4","idle":true,"away":true,"view":"…","sessionId":"a1b2c3d4","path":"src/app.ts"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.presence({
  "clientId": "a1b2c3d4",
  "idle": true,
  "away": true,
  "view": "…",
  "sessionId": "a1b2c3d4",
  "path": "src/app.ts"
});
GET/system/usageWhat has been spent

Token and cost totals per account, added up from the record of every finished turn.

What you send

Nothing. Call it as it is.

What comes back

FieldType
accountsobject[]
providerstring
accountstring
turnsnumber
inputTokensnumber
outputTokensnumber
cacheReadTokensnumber
cacheCreationTokensnumber
costUsdnumber
Try itanswered in this tab
curl
curl "$SANDBOX/system/usage" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.usage();
GET/system/metricsWhat the sandbox is using right now

CPU and memory for the sandbox as a whole, for the daemon that runs it, for each kind of process, and for each conversation's own processes. Measured when you ask and never in between, so CPU is the use since the previous reading: the first reading after a quiet spell has memory and no CPU, and the next one a few seconds later has both.

What you send

Nothing. Call it as it is.

What comes back

FieldType
atWhen this reading was taken, in…number
windowMsHow long the CPU figures were…number
sandboxThe sandbox as a wholeobject
cpuPercentCPU the whole sandbox used over…number
coresHow many cores the sandbox may…number
memoryBytesMemory counted against the limit, as…number
memoryLimitBytesThe memory limit work is admitted…number
swapBytesWhat was pushed out to swap,…number
swapLimitBytesWhat swap can holdnumber
swapFullSwap is nearly at `swapLimitBytes`: nothing…boolean
memoryRoomWhat admission reads off the same…object
freeBytesThe limit less what is used…number
reservedBytesWhat work admitted in the last…number
personNeedBytesWhat a person's turn needs free…number
stallPercentPercent of the last ten seconds…number
stallLimitPercentThe stall at or past which…number
stallSustainedPercentPercent of the last minute in…number
stallSustainedLimitPercentThe minute's stall at or past…number
diskBytesSpace used on the volume the…number
diskTotalBytesThat volume's sizenumber
loadAverageThe load average over 1, 5…unknown[]
machineCoresCores the machine's load average reads…number
processesHow many processes are running in…number
pressureHow much work waited on CPU,…object
cpuPercent of the last ten seconds…number
memoryPercent of the last ten seconds…number
ioPercent of the last ten seconds…number
daemonThe daemon that runs it, which…object
rssBytesThe daemon's own resident memorynumber
heapUsedBytesOf that, JavaScript objects in usenumber
cpuPercentCPU the daemon itself used over…number
eventLoopPercentHow much of the window the…number
sessionsWhat each conversation's processes use, by…object
rolesEvery process in the sandbox but…object
Try itanswered in this tab
curl
curl "$SANDBOX/system/metrics" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.metrics();
GET/system/storageWhat is filling the disk

The last measurement of the sandbox's disk, by what the space is for: conversations, checkouts, restore points, caches, logs, the trash and the rest, each with its biggest parts and whether it can be cleaned from here. Reading it measures nothing; ask for a scan to measure again.

What you send

Nothing. Call it as it is.

What comes back

FieldType
scanThe last scan that finishedobject
startedAtWhen the scan began, in millisecondsnumber
finishedAtWhen it ended, in milliseconds: the…number
outcome`partial` when the scan hit its…"complete" | "partial"
diskThe volume as a wholeobject
usedBytesSpace used on the volume the…number
totalBytesThat volume's sizenumber
categoriesEvery category that holds anything, largest…object[]
id"workspace" | "conversations" | "checkouts" | "restorePoints" … (22)
cleanabilityWhether this category can be cleaned…"none" | "safe" | "confirm"
bytesIts size in bytesnumber
filesHow many files it holdsnumber
cleanableBytesWhat cleaning it would free right…number
itemsIts biggest parts, largest first, at…object[]
pathWhere it is, as an absolute…string
bytesIts size in bytesnumber
unreadableFiles and folders the scan could…number
scanningWhether a scan is running nowboolean
Try itanswered in this tab
curl
curl "$SANDBOX/system/storage" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.storage();
POST/system/storage/scanMeasure what is filling the disk

Walks the sandbox's volumes and answers with the new measurement once it is done. A scan already running is joined rather than doubled. It stops at a time limit and says so, since a size it could not finish is still worth reading. A cancelled scan answers with the previous measurement.

What you send

Nothing. Call it as it is.

What comes back

FieldType
scanThe last scan that finishedobject
startedAtWhen the scan began, in millisecondsnumber
finishedAtWhen it ended, in milliseconds: the…number
outcome`partial` when the scan hit its…"complete" | "partial"
diskThe volume as a wholeobject
usedBytesSpace used on the volume the…number
totalBytesThat volume's sizenumber
categoriesEvery category that holds anything, largest…object[]
id"workspace" | "conversations" | "checkouts" | "restorePoints" … (22)
cleanabilityWhether this category can be cleaned…"none" | "safe" | "confirm"
bytesIts size in bytesnumber
filesHow many files it holdsnumber
cleanableBytesWhat cleaning it would free right…number
itemsIts biggest parts, largest first, at…object[]
pathWhere it is, as an absolute…string
bytesIts size in bytesnumber
unreadableFiles and folders the scan could…number
scanningWhether a scan is running nowboolean
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/storage/scan" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.scanStorage();
DELETE/system/storage/scanStop measuring the disk

Stops a running scan. Whoever was waiting on it gets the previous measurement back; nothing is lost but the time.

What you send

Nothing. Call it as it is.

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X DELETE "$SANDBOX/system/storage/scan" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.cancelStorageScan();
POST/system/storage/cleanFree the space one category holds

Removes what one cleanable category holds, and says how much space that gave back. Only what is old enough and not in use goes: today's logs, a browser that is open, the weights a running model reads and a pack still being written all stay. Nothing outside the sandbox's own volumes, and nothing a category may not hold, is ever removed. Categories that cannot be cleaned are refused.

What you send

FieldTypeWhere
categoryrequiredThe category to clean; one whose…"workspace" | "conversations" | "checkouts" | "restorePoints" … (22)body

What comes back

FieldType
category"workspace" | "conversations" | "checkouts" | "restorePoints" … (22)
freedBytesSpace the removals gave back, in…number
removedHow many items were removednumber
keptHow many were left in place:…number
failedHow many removals the filesystem refusednumber
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/storage/clean" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"category":"workspace"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.cleanStorage({
  "category": "workspace"
});
GET/system/terminalsOpen terminals

The terminal sessions this sandbox is holding, which is what a terminal panel rebuilds its tabs from after a reload. The live typing and output run over a separate socket; this is the list.

What you send

Nothing. Call it as it is.

What comes back

FieldType
sessionsEvery live surface the sandbox is…object[]
nameIts id, and what the close…string
labelWhat to call it on screenstring
kindWhat sort of thing it is:…"shell" | "panel" | "agent" | "job" … (5)
runningWhether it is aliveboolean
activityAtWhen it last produced output, in…number
exitCodeHow the last thing in it…number
commandWhat is running in it right…string
extensionIdWhich extension declared this process, when…string
processNameWhich of that extension's processes it…string
helpThe agent has stopped at something…object
requestIdWhat to send back when you…string
messageWhat the agent needs, in its…string
requestedAtWhen it asked, in millisecondsnumber
Try itanswered in this tab
curl
curl "$SANDBOX/system/terminals" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.terminals();
DELETE/system/terminals/{name}Close a terminal

Destroys one terminal session and whatever was running inside it.

What you send

FieldTypeWhere
namerequiredWhich terminalstringaddress

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X DELETE "$SANDBOX/system/terminals/nightly%20changelog" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.killTerminal({
  "name": "nightly changelog"
});
GET/system/terminals/{name}/scrollbackA terminal's history as plain text

What has scrolled past in one terminal, as text you can select and copy. The live view is a picture of a screen on the far side of a socket, with nothing in the page to select, so scrolling back and copying is this call rather than a gesture.

What you send

FieldTypeWhere
namerequiredWhich terminalstringaddress
linesHow far back to ask fornumberquery

What comes back

FieldType
nameWhich terminal this is fromstring
textThe history, oldest line first, with…string
linesHow many lines you gotnumber
truncatedIt stopped because you asked for…boolean
Try itanswered in this tab
curl
curl "$SANDBOX/system/terminals/nightly%20changelog/scrollback" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.terminalScrollback({
  "name": "nightly changelog"
});
GET/system/browsersBrowsers the agent has open

Every browser a conversation currently has running and the pages inside each one. The picture of what they are showing comes over a separate socket; this is the roster.

What you send

Nothing. Call it as it is.

What comes back

FieldType
sessionsEvery browser the agents have running,…object[]
nameIts id, and what the close…string
labelWhat to call it on screen:…string
serverWhich browser drives it: the credential-free…string
runningWhether it is still openboolean
activityAtWhen it last did anything, in…number
finishedAtWhen it closed, in millisecondsnumber
helpThe agent has hit something only…object
requestIdWhat to send back when you…string
messageWhat the agent needs, in its…string
requestedAtWhen it asked, in millisecondsnumber
dialogA dialog a page has open…object
pageIdWhich page opened itstring
kindWhat it asks: an alert wants…"alert" | "confirm" | "prompt" | "beforeunload"
messageWhat the page saysstring
defaultValueA prompt's prefilled answerstring
pagesEvery page it has openobject[]
idStable for the life of the…string
titleThe page's titlestring
urlWhere it isstring
activeThe one the agent last touched,…boolean
Try itanswered in this tab
curl
curl "$SANDBOX/system/browsers" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.browsers();
DELETE/system/browsers/{name}Shut a browser down

Closes one of the agent's browsers. Its next attempt to use that browser then fails as though it had crashed, which is the honest account of somebody pulling the plug.

What you send

FieldTypeWhere
namerequiredWhich browserstringaddress

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X DELETE "$SANDBOX/system/browsers/nightly%20changelog" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.closeBrowser({
  "name": "nightly changelog"
});
GET/system/desktopThe sandbox's own desktop

Whether the sandbox's desktop is up, which display it is, and how many windows are open on it. The live picture of it comes over a separate socket; this says whether there is anything to see.

What you send

Nothing. Call it as it is.

What comes back

FieldType
runningWhether the desktop is upboolean
displayThe X display it is, present…string
windowsHow many windows are open on…integer
Try itanswered in this tab
curl
curl "$SANDBOX/system/desktop" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.desktop();
GET/system/subagentsSubagents the agents have started

Every subagent that conversations the caller can see have delegated work to, whichever tool started it, with what each one is doing: all that are still working, and the most recent that have settled.

What you send

Nothing. Call it as it is.

What comes back

FieldType
sessionsThe subagents conversations the caller can…object[]
idThe id of the tool call…string
kindHow it was started: in-process by…"subagent" | "spawned"
conversationIdThe conversation whose turn started it,…string
agentTypeWhat kind of subagent it isstring
descriptionWhat it was asked to do,…string
modelWhich model it runs on: the…string
effortHow hard it was told to…string
providerWhich provider serves it, for a…string
spawnDepthHow deep in the chain it…number
backgroundThe parent carried on working instead…boolean
statusHow it is going"pending" | "running" | "blocked" | "completed" … (7)
startedAtWhen it started, in millisecondsnumber
endedAtWhen it finished, in millisecondsnumber
activityAtWhen it last did anything, in…number
tokensWhat it has spentnumber
toolUsesHow many tools it has usednumber
lastToolThe last one it reached forstring
summaryIts report: what it concluded, without…string
errorWhy it failed, when it didstring
verificationWhether anything proved the work its…object
stateWhether anything proved its work: a…"verified" | "unproven" | "failing" | "no-code"
pathsThe code files it changed, most…string[]
checkThe command that spoke: the one…string
Try itanswered in this tab
curl
curl "$SANDBOX/system/subagents" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.subagents();
GET/system/devicesThe machines you have connected

Every computer this sandbox can see, whether it reached it through desktop sync or through a connected device, in one row per machine: what it says about itself, which sandboxes it holds, and what stopped it answering when nothing came back.

What you send

Nothing. Call it as it is.

What comes back

FieldType
devicesobject[]
keystring
labelstring
syncobject
machinestring
mode"sync" | "mirror"
seenAtnumber
machineIdstring
environmentstring
hostIdstring
cardstring
machineIdstring
onlineboolean
platformstring
factsobject
machineIdstring
osstring
archstring
shellstring
homestring
rootsstring[]
engineobject
memoryBytesnumber
cpusnumber
hostnamestring
wslobject
distrostring
wslDistrosstring[]
linksobject
totalnumber
unreachablenumber
unreachableSincenumber
featuresstring[]
icOutOfDatestring
upkeepobject
atnumber
foundobject
fixedobject
skippedobject[]
agentVersionstring
lastSeennumber
reportobject
machineIdstring
hostnamestring
osstring
wslobject
distrostring
pairingsobject[]
sandboxIdstring
mode"sync" | "mirror"
localDirstring
remoteDirstring
projectsHostboolean
deliver"auto" | "off"
mirroring"on" | "off"
mutagenStatusstring
conflictsinteger
conflictedPathsobject[]
pausedboolean
backupStatusstring
portsobject[]
portinteger
host"127.0.0.1" | "::1"
sandboxIdstring
state"mirrored" | "held-by-sandbox" | "busy" | "ignored"
heldBystring
commandstring
agentobject
runningboolean
pidinteger
installedstring
buildstring
lastTickAtnumber
capturedAtnumber
sandboxesobject[]
slugstring
containerstring
namestring
runningboolean
imagestring
tunnelRunningboolean
resourcesobject
memoryBytesnumber
cpusnumber
privilegedboolean
gpuboolean
hostRuntimestring[]
overlayRuntimestring[]
shapeobject
desiredobject
savedobject
stagedobject
imagestring
versionstring
channelstring
versionstring
parkedboolean
probationUntilnumber
lastUpdateobject
resultWhat happened"updated" | "kept" | "restored" | "rolled-back"
verbWhat was asked for: update, rollback,…string
atWhen it happened, in millisecondsnumber
fromThe version (or, when it would…string
toThe version (or image) that was…string
reasonWhy the host gave up on…string
logWhere the host kept the full…string
keepUntilUntil when the previous version stays…number
rollbackTargetsobject[]
imageThe local image a rollback would…string
versionWhat that image says it isstring
downloadThe local pin is gone (pruned…boolean
keptElsewherestring
keptElsewhereNamestring
adoptedFromstring
keeperSilentSincenumber
gap"offline" | "scope-off" | "unreported"
Try itanswered in this tab
curl
curl "$SANDBOX/system/devices" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.devices();
POST/system/devices/{id}/sandboxes/{slug}Drive a sandbox on one of your own devicesstream

Start, stop, restart, update, rebuild, roll back, reshape (its memory and CPU caps, privileged, GPU) or remove a sandbox running on a machine you own, relayed over the connection that machine holds open. The answer is a stream because the slowest of these takes minutes, and it is the same stream whichever you ask for. The daemon adds no opinion: the machine enforces its own permissions and a refusal arrives as the last line, in the machine's words, naming the switch to flip.

What you send

FieldTypeWhere
idrequiredstringaddress
slugrequiredstringaddress
oprequired"start" | "stop" | "restart" | "prepare" … (17)body
hashstringbody
tostringbody
shapeobjectbody
memoryGibrequiredinteger | nullbody
cpusrequiredinteger | nullbody
privilegedrequiredbooleanbody
gpurequiredbooleanbody
when"now" | "nextRestart"body
resourcesobjectbody
memoryGibinteger | nullbody
cpusinteger | nullbody
privilegedbooleanbody
gpubooleanbody
laterbooleanbody
parentUrlstringbody
pairstringbody
setupCodestringbody
platformUrlstringbody
definitionstringbody
overlaystringbody
overlayHashstringbody
resumeTurnsbooleanbody

What comes back

FieldType
when event is "message"shape
dataobject
when kind is "line"shape
textstring
when kind is "result"shape
messagestring
when kind is "error"shape
messagestring
idstring
retrynumber
when event is "done"shape
dataunknown
idstring
retrynumber
when event is "error"shape
dataunknown
idstring
retrynumber
Try itanswered in this tab
curl
curl -N -X POST "$SANDBOX/system/devices/a1b2c3d4/sandboxes/nightly-changelog" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"op":"start","hash":"…","to":"src/server.ts","shape":{"memoryGib":1,"cpus":1,"privileged":true,"gpu":true},"when":"now","resources":{"memoryGib":1,"cpus":1,"privileged":true,"gpu":true},"later":true,"parentUrl":"https://sandbox-a1b2c3d4e5f6.intentic.dev","pair":"…","setupCode":"…","platformUrl":"https://sandbox-a1b2c3d4e5f6.intentic.dev","definition":"…","overlay":"…","overlayHash":"…","resumeTurns":true}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.manageDeviceSandbox({
  "id": "a1b2c3d4",
  "slug": "nightly-changelog",
  "op": "start",
  "hash": "…",
  "to": "src/server.ts",
  "shape": {
    "memoryGib": 1,
    "cpus": 1,
    "privileged": true,
    "gpu": true
  },
  "when": "now",
  "resources": {
    "memoryGib": 1,
    "cpus": 1,
    "privileged": true,
    "gpu": true
  },
  "later": true,
  "parentUrl": "https://sandbox-a1b2c3d4e5f6.intentic.dev",
  "pair": "…",
  "setupCode": "…",
  "platformUrl": "https://sandbox-a1b2c3d4e5f6.intentic.dev",
  "definition": "…",
  "overlay": "…",
  "overlayHash": "…",
  "resumeTurns": true
});
POST/system/devices/{id}/commands/{command}Run one of your device's own CLI actions

Performs a named action on a machine you own by running its own intentic-machine command there — turning that device's port mirroring off, say — over the connection it holds open. The set of actions is fixed and the command line is built here from the name, never sent by the caller. The machine enforces its own permissions and a refusal comes back as its own sentence, naming the switch to flip.

What you send

FieldTypeWhere
idrequiredstringaddress
commandrequired"mirror-off" | "mirror-on" | "mirror-ignore" | "mirror-unignore" … (12)address
sandboxIdstringbody
mode"sync" | "mirror"body
localDirstringbody
portintegerbody

What comes back

FieldType
okboolean
messagestring
outputstring
refusedboolean
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/system/devices/a1b2c3d4/commands/mirror-off" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"sandboxId":"a1b2c3d4e5f6","mode":"sync","localDir":"…","port":5173}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.runDeviceCommand({
  "id": "a1b2c3d4",
  "command": "mirror-off",
  "sandboxId": "a1b2c3d4e5f6",
  "mode": "sync",
  "localDir": "…",
  "port": 5173
});
POST/system/devices/{id}/agent/{op}Update, restart, or clean up the links of the agent on one of your own devicesstream

Updates a machine you own to the current intentic-machine agent, restarts the loop it is running, or drops the links it holds to sandboxes that have stopped answering — over the connection that machine holds open. The answer is a stream of the run's own output — and it normally stops mid-run, because the agent's loop is what carries this connection: the work is detached from it first, so it finishes regardless, and the device's reported version is what confirms it. Takes the machine's "Run commands" permission, the same one a command typed there would.

What you send

FieldTypeWhere
idrequiredstringaddress
oprequired"upgrade" | "restart" | "forget-unreachable"address

What comes back

FieldType
when event is "message"shape
dataobject
when kind is "line"shape
textstring
when kind is "result"shape
messagestring
when kind is "error"shape
messagestring
idstring
retrynumber
when event is "done"shape
dataunknown
idstring
retrynumber
when event is "error"shape
dataunknown
idstring
retrynumber
Try itanswered in this tab
curl
curl -N -X POST "$SANDBOX/system/devices/a1b2c3d4/agent/upgrade" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.system.runDeviceAgentFlow({
  "id": "a1b2c3d4",
  "op": "upgrade"
});
More in The sandbox itself

Type to search every page, in the docs and the API reference.