curl --request POST \
--url https://api.checkfu.com/v1/sandbox-profiles \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"key": "<string>",
"base_image": {
"reference": "<string>",
"digest": "<string>"
},
"packages": [
{
"name": "<string>",
"version": "<string>"
}
],
"network_policy": {
"mode": "none",
"allowed_hosts": [
"<string>"
]
},
"resource_limits": {
"cpu_millis": 1,
"memory_mib": 1,
"disk_mib": 1,
"max_duration_seconds": 1
}
}
'import requests
url = "https://api.checkfu.com/v1/sandbox-profiles"
payload = {
"key": "<string>",
"base_image": {
"reference": "<string>",
"digest": "<string>"
},
"packages": [
{
"name": "<string>",
"version": "<string>"
}
],
"network_policy": {
"mode": "none",
"allowed_hosts": ["<string>"]
},
"resource_limits": {
"cpu_millis": 1,
"memory_mib": 1,
"disk_mib": 1,
"max_duration_seconds": 1
}
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
key: '<string>',
base_image: {reference: '<string>', digest: '<string>'},
packages: [{name: '<string>', version: '<string>'}],
network_policy: {mode: 'none', allowed_hosts: ['<string>']},
resource_limits: {cpu_millis: 1, memory_mib: 1, disk_mib: 1, max_duration_seconds: 1}
})
};
fetch('https://api.checkfu.com/v1/sandbox-profiles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/sandbox-profiles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'key' => '<string>',
'base_image' => [
'reference' => '<string>',
'digest' => '<string>'
],
'packages' => [
[
'name' => '<string>',
'version' => '<string>'
]
],
'network_policy' => [
'mode' => 'none',
'allowed_hosts' => [
'<string>'
]
],
'resource_limits' => [
'cpu_millis' => 1,
'memory_mib' => 1,
'disk_mib' => 1,
'max_duration_seconds' => 1
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/sandbox-profiles"
payload := strings.NewReader("{\n \"key\": \"<string>\",\n \"base_image\": {\n \"reference\": \"<string>\",\n \"digest\": \"<string>\"\n },\n \"packages\": [\n {\n \"name\": \"<string>\",\n \"version\": \"<string>\"\n }\n ],\n \"network_policy\": {\n \"mode\": \"none\",\n \"allowed_hosts\": [\n \"<string>\"\n ]\n },\n \"resource_limits\": {\n \"cpu_millis\": 1,\n \"memory_mib\": 1,\n \"disk_mib\": 1,\n \"max_duration_seconds\": 1\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/sandbox-profiles")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"key\": \"<string>\",\n \"base_image\": {\n \"reference\": \"<string>\",\n \"digest\": \"<string>\"\n },\n \"packages\": [\n {\n \"name\": \"<string>\",\n \"version\": \"<string>\"\n }\n ],\n \"network_policy\": {\n \"mode\": \"none\",\n \"allowed_hosts\": [\n \"<string>\"\n ]\n },\n \"resource_limits\": {\n \"cpu_millis\": 1,\n \"memory_mib\": 1,\n \"disk_mib\": 1,\n \"max_duration_seconds\": 1\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/sandbox-profiles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"key\": \"<string>\",\n \"base_image\": {\n \"reference\": \"<string>\",\n \"digest\": \"<string>\"\n },\n \"packages\": [\n {\n \"name\": \"<string>\",\n \"version\": \"<string>\"\n }\n ],\n \"network_policy\": {\n \"mode\": \"none\",\n \"allowed_hosts\": [\n \"<string>\"\n ]\n },\n \"resource_limits\": {\n \"cpu_millis\": 1,\n \"memory_mib\": 1,\n \"disk_mib\": 1,\n \"max_duration_seconds\": 1\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"key": "<string>",
"tier": "container",
"base_image": {
"reference": "<string>",
"digest": "<string>"
},
"packages": [
{
"manager": "apt",
"name": "<string>",
"version": "<string>"
}
],
"network_policy": {
"mode": "none",
"allowed_hosts": [
"<string>"
],
"required_egress_certification": "advisory_filter",
"egress_presets": {
"version": 1,
"presets": [
"package_managers"
]
}
},
"resource_limits": {
"cpu_millis": 1,
"memory_mib": 1,
"disk_mib": 1,
"max_duration_seconds": 1
},
"retention_mode": "durable",
"derived_image_digest": "<string>",
"current_revision_number": 1,
"resource_version": 1,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Create a SandboxProfile
Creates a workspace-scoped SandboxProfile under a logical key and publishes immutable revision 1 from the supplied tier, base image, packages, network policy, resource limits, and retention mode (durable or ephemeral_zdr). A package may pin a package version or omit it to install the latest; either way it resolves once, into this revision’s derived image. Allowed hosts must be lower-case public DNS names; a host selector is not itself an enforced egress boundary. On an allowlist policy, allow_package_managers and allow_mcp_servers are conveniences that COMPILE into allowed_hosts at admission — the published revision stores the expanded hosts and records which presets produced them, so the expansion is readable and enforcement sees exact hosts only. The compiled list, not the submitted one, is what the 256-host limit applies to. Returns the SandboxProfile with 201, including the content-hashed derived image digest used for cold-start reuse. Send Idempotency-Key to make retries safe.
Checkfu support posture: alpha; hosted. Required evidence journey: sandbox-conformance. Deployment-specific readiness and the latest proven release are available from GET /v1/support/capabilities.
curl --request POST \
--url https://api.checkfu.com/v1/sandbox-profiles \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--header 'checkfu-version: <checkfu-version>' \
--data '
{
"key": "<string>",
"base_image": {
"reference": "<string>",
"digest": "<string>"
},
"packages": [
{
"name": "<string>",
"version": "<string>"
}
],
"network_policy": {
"mode": "none",
"allowed_hosts": [
"<string>"
]
},
"resource_limits": {
"cpu_millis": 1,
"memory_mib": 1,
"disk_mib": 1,
"max_duration_seconds": 1
}
}
'import requests
url = "https://api.checkfu.com/v1/sandbox-profiles"
payload = {
"key": "<string>",
"base_image": {
"reference": "<string>",
"digest": "<string>"
},
"packages": [
{
"name": "<string>",
"version": "<string>"
}
],
"network_policy": {
"mode": "none",
"allowed_hosts": ["<string>"]
},
"resource_limits": {
"cpu_millis": 1,
"memory_mib": 1,
"disk_mib": 1,
"max_duration_seconds": 1
}
}
headers = {
"checkfu-version": "<checkfu-version>",
"Authorization": "Bearer <token>",
"Content-Type": "application/json"
}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {
'checkfu-version': '<checkfu-version>',
Authorization: 'Bearer <token>',
'Content-Type': 'application/json'
},
body: JSON.stringify({
key: '<string>',
base_image: {reference: '<string>', digest: '<string>'},
packages: [{name: '<string>', version: '<string>'}],
network_policy: {mode: 'none', allowed_hosts: ['<string>']},
resource_limits: {cpu_millis: 1, memory_mib: 1, disk_mib: 1, max_duration_seconds: 1}
})
};
fetch('https://api.checkfu.com/v1/sandbox-profiles', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.checkfu.com/v1/sandbox-profiles",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'key' => '<string>',
'base_image' => [
'reference' => '<string>',
'digest' => '<string>'
],
'packages' => [
[
'name' => '<string>',
'version' => '<string>'
]
],
'network_policy' => [
'mode' => 'none',
'allowed_hosts' => [
'<string>'
]
],
'resource_limits' => [
'cpu_millis' => 1,
'memory_mib' => 1,
'disk_mib' => 1,
'max_duration_seconds' => 1
]
]),
CURLOPT_HTTPHEADER => [
"Authorization: Bearer <token>",
"Content-Type: application/json",
"checkfu-version: <checkfu-version>"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.checkfu.com/v1/sandbox-profiles"
payload := strings.NewReader("{\n \"key\": \"<string>\",\n \"base_image\": {\n \"reference\": \"<string>\",\n \"digest\": \"<string>\"\n },\n \"packages\": [\n {\n \"name\": \"<string>\",\n \"version\": \"<string>\"\n }\n ],\n \"network_policy\": {\n \"mode\": \"none\",\n \"allowed_hosts\": [\n \"<string>\"\n ]\n },\n \"resource_limits\": {\n \"cpu_millis\": 1,\n \"memory_mib\": 1,\n \"disk_mib\": 1,\n \"max_duration_seconds\": 1\n }\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("checkfu-version", "<checkfu-version>")
req.Header.Add("Authorization", "Bearer <token>")
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.checkfu.com/v1/sandbox-profiles")
.header("checkfu-version", "<checkfu-version>")
.header("Authorization", "Bearer <token>")
.header("Content-Type", "application/json")
.body("{\n \"key\": \"<string>\",\n \"base_image\": {\n \"reference\": \"<string>\",\n \"digest\": \"<string>\"\n },\n \"packages\": [\n {\n \"name\": \"<string>\",\n \"version\": \"<string>\"\n }\n ],\n \"network_policy\": {\n \"mode\": \"none\",\n \"allowed_hosts\": [\n \"<string>\"\n ]\n },\n \"resource_limits\": {\n \"cpu_millis\": 1,\n \"memory_mib\": 1,\n \"disk_mib\": 1,\n \"max_duration_seconds\": 1\n }\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.checkfu.com/v1/sandbox-profiles")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["checkfu-version"] = '<checkfu-version>'
request["Authorization"] = 'Bearer <token>'
request["Content-Type"] = 'application/json'
request.body = "{\n \"key\": \"<string>\",\n \"base_image\": {\n \"reference\": \"<string>\",\n \"digest\": \"<string>\"\n },\n \"packages\": [\n {\n \"name\": \"<string>\",\n \"version\": \"<string>\"\n }\n ],\n \"network_policy\": {\n \"mode\": \"none\",\n \"allowed_hosts\": [\n \"<string>\"\n ]\n },\n \"resource_limits\": {\n \"cpu_millis\": 1,\n \"memory_mib\": 1,\n \"disk_mib\": 1,\n \"max_duration_seconds\": 1\n }\n}"
response = http.request(request)
puts response.read_body{
"id": "<string>",
"workspace_id": "<string>",
"key": "<string>",
"tier": "container",
"base_image": {
"reference": "<string>",
"digest": "<string>"
},
"packages": [
{
"manager": "apt",
"name": "<string>",
"version": "<string>"
}
],
"network_policy": {
"mode": "none",
"allowed_hosts": [
"<string>"
],
"required_egress_certification": "advisory_filter",
"egress_presets": {
"version": 1,
"presets": [
"package_managers"
]
}
},
"resource_limits": {
"cpu_millis": 1,
"memory_mib": 1,
"disk_mib": 1,
"max_duration_seconds": 1
},
"retention_mode": "durable",
"derived_image_digest": "<string>",
"current_revision_number": 1,
"resource_version": 1,
"created_at": "<string>",
"updated_at": "<string>"
}{
"error": {
"type": "validation.malformed",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-malformed"
}
}{
"error": {
"type": "auth.invalid_key",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-invalid-key"
}
}{
"error": {
"type": "auth.disabled_tenancy",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#auth-disabled-tenancy"
}
}{
"error": {
"type": "validation.conflict",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#validation-conflict"
}
}{
"error": {
"type": "budget.exceeded",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#budget-exceeded"
}
}{
"error": {
"type": "runtime.internal",
"message": "<string>",
"more": "https://docs.checkfu.com/reference/errors#runtime-internal"
}
}Authorizations
Bearer authentication header of the form Bearer <token>, where <token> is your auth token.
Headers
2026-08-27 255Body
^[a-z0-9](?:[a-z0-9._-]{0,93})$container, microvm Show child attributes
Show child attributes
256Show child attributes
Show child attributes
- Option 1
- Option 2
- Option 3
Show child attributes
Show child attributes
Show child attributes
Show child attributes
durable, ephemeral_zdr Response
Success
^sprof_[0-9a-f]{32}$^wrkspc_[0-9a-f]{32}$^[a-z0-9](?:[a-z0-9._-]{0,93})$container, microvm Show child attributes
Show child attributes
256Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
Show child attributes
durable, ephemeral_zdr ^sha256:[0-9a-f]{64}$x > 0x > 0