> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tensorlake.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List Sandboxes

> List sandboxes.

List sandboxes for the current project.

Use `status=running` to query only sandboxes that are currently live in memory. Omitting the filter returns full sandbox history, including terminated sandboxes.


## OpenAPI

````yaml get /sandboxes
openapi: 3.1.0
info:
  title: Tensorlake API
  description: >-
    Tensorlake Cloud APIs for Sandboxes, Document Ingestion, and Serverless
    Workflows
  license:
    name: ''
  version: 0.1.0
servers:
  - url: https://api.tensorlake.ai/
security:
  - bearerAuth: []
tags:
  - name: Tensorlake Cloud API
    description: >-
      Tensorlake Cloud APIs for Sandboxes, Document Ingestion, and Serverless
      Workflows
paths:
  /sandboxes:
    get:
      tags:
        - sandboxes
      summary: List sandboxes
      description: List sandboxes.
      operationId: list_sandboxes
      parameters:
        - name: limit
          in: query
          description: Maximum number of sandboxes to return. Defaults to 100.
          required: false
          schema:
            type: integer
            minimum: 1
        - name: cursor
          in: query
          description: Base64-encoded pagination cursor returned by a previous list call.
          required: false
          schema:
            $ref: '#/components/schemas/Cursor'
        - name: direction
          in: query
          description: Pagination direction for the provided cursor.
          required: false
          schema:
            $ref: '#/components/schemas/SandboxCursorDirection'
        - name: status
          in: query
          description: >-
            Optional sandbox status filter. `running` returns the live running
            set only.
          required: false
          schema:
            $ref: '#/components/schemas/SandboxListStatusFilter'
      responses:
        '200':
          description: List of sandboxes retrieved successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListSandboxesResponse'
        '400':
          description: Invalid query parameters
          content:
            text/plain: {}
        '401':
          description: Unauthorized. Invalid or missing credentials
        '403':
          description: Forbidden. You do not have permission to access this resource
        '500':
          description: Internal server error
          content:
            text/plain: {}
components:
  schemas:
    Cursor:
      type: string
    SandboxCursorDirection:
      type: string
      enum:
        - forward
        - backward
    SandboxListStatusFilter:
      type: string
      enum:
        - running
    ListSandboxesResponse:
      type: object
      required:
        - sandboxes
      properties:
        sandboxes:
          type: array
          items:
            $ref: '#/components/schemas/SandboxInfo'
        prev_cursor:
          type:
            - string
            - 'null'
        next_cursor:
          type:
            - string
            - 'null'
    SandboxInfo:
      type: object
      required:
        - id
        - namespace
        - status
        - created_at
        - resources
        - timeout_secs
        - allow_unauthenticated_access
      properties:
        id:
          type: string
        namespace:
          type: string
        image:
          type: string
        status:
          $ref: '#/components/schemas/SandboxStatus'
        pending_reason:
          type:
            - string
            - 'null'
          description: Present when `status` is `pending`.
        outcome:
          type:
            - string
            - 'null'
          description: >-
            Platform-specific termination outcome string returned for completed
            sandboxes.
        termination_reason:
          type:
            - string
            - 'null'
          description: >-
            Typed reason the sandbox terminated (e.g. `FileSystemNotFound`,
            `FileSystemSnapshotNotFound`, `ImageNotFound`). Present on failed
            terminations.
        error_details:
          type:
            - string
            - 'null'
          description: Human-readable detail accompanying `termination_reason`.
        created_at:
          type: integer
          format: int64
          description: Milliseconds since Unix epoch.
        container_id:
          type:
            - string
            - 'null'
        executor_id:
          type:
            - string
            - 'null'
        resources:
          $ref: '#/components/schemas/ContainerResourcesInfo'
        timeout_secs:
          type: integer
          format: int64
        ingress_endpoint:
          type:
            - string
            - 'null'
          description: Canonical server-provided base for sandbox-specific ingress.
        sandbox_url:
          type:
            - string
            - 'null'
          description: Sandbox-specific management URL derived from `ingress_endpoint`.
        pool_id:
          type:
            - string
            - 'null'
        network_policy:
          oneOf:
            - type: 'null'
            - $ref: '#/components/schemas/SandboxNetworkAccessControl'
        allow_unauthenticated_access:
          type: boolean
          description: Whether sandbox ingress may route requests without auth validation.
        exposed_ports:
          type:
            - array
            - 'null'
          items:
            type: integer
            format: int32
            minimum: 1
            maximum: 65535
          description: >-
            Additional routable ingress ports. When `null`, only the management
            port `9501` is routable.
        template_id:
          type:
            - string
            - 'null'
        name:
          type:
            - string
            - 'null'
        file_systems:
          type: array
          description: Filesystems currently mounted into the sandbox.
          items:
            $ref: '#/components/schemas/FileSystemMount'
    SandboxStatus:
      type: string
      enum:
        - pending
        - running
        - snapshotting
        - suspending
        - suspended
        - terminated
    ContainerResourcesInfo:
      type: object
      required:
        - cpus
        - memory_mb
        - disk_mb
      properties:
        cpus:
          type: number
          format: double
          description: CPU allocation in cores.
        memory_mb:
          type: integer
          format: int64
          description: Memory allocation in MiB.
        disk_mb:
          type: integer
          format: int64
          description: Ephemeral root filesystem size in MiB.
    SandboxNetworkAccessControl:
      type: object
      properties:
        allow_internet_access:
          type: boolean
          default: true
          description: >-
            Allows internet access, including DNS requests. If false, all
            outbound traffic except destinations in allow_out is blocked,
            including DNS requests. If allow_out is non-empty and this is true,
            only the listed destinations and DNS requests are allowed.
        allow_out:
          type: array
          description: >-
            Allowed domains, IPv4 addresses, or IPv4 CIDRs. A non-empty list
            allows the listed destinations and DNS requests when
            allow_internet_access is true. Hostname rules are followed across
            DNS changes. A destination also matched by deny_out is blocked.
          items:
            type: string
        deny_out:
          type: array
          description: >-
            Denied domains, IPv4 addresses, or IPv4 CIDRs. Takes precedence over
            allow_out; a destination matched by both is blocked.
          items:
            type: string
    FileSystemMount:
      type: object
      required:
        - file_system_id
        - mount_path
      properties:
        file_system_id:
          type: string
          description: >-
            Filesystem name within the project — the name created with `tl fs
            create <name>`. ASCII letters, digits, `_`, and `-` only.
        mount_path:
          type: string
          description: >-
            Absolute guest mount path (e.g. `/mnt/skills`). Must not be `/` or
            contain `..`; paths are normalized, and mount paths must be unique
            and non-nested within the sandbox.
        read_only:
          type: boolean
          default: false
          description: >-
            Mount the filesystem read-only. Writes inside the guest fail with
            `EROFS`; the mount's storage credential carries no write scope.
            Fail-closed — sandboxes requesting read-only mounts are only placed
            on fleets that can enforce them.
        prefetch:
          type: boolean
          default: false
          description: >-
            Download the filesystem's full tree in the background after the
            mount is ready. The mount is usable immediately with lazy reads
            meanwhile. Best-effort — never blocks or fails the sandbox, and
            older fleets skip it silently.
        snapshot_id:
          type: string
          description: >-
            Pin the mount to a permanent snapshot of the filesystem (created
            with `tl fs snapshot` or a message-bearing `tl fs push`; ids listed
            by `tl fs history`). A pinned mount serves exactly that snapshot and
            never follows the live filesystem head. Requires `read_only` to be
            `true` — a `snapshot_id` without `read_only` is rejected with `400`.
            Pinning an id that is not a permanent snapshot of the filesystem
            fails the sandbox with `termination_reason`
            `FileSystemSnapshotNotFound`. Omit for an unpinned mount that
            follows the live filesystem; responses omit the field for unpinned
            mounts.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer

````