This site is not affiliated with or endorsed by Cloudflare, Inc. It simply showcases experiments built using Cloudflare services.
Cloudflare Experiments
Compute & Isolation

Code Sandbox

Run a JavaScript snippet in an isolated Sandbox SDK container

Run a JavaScript snippet in an isolated environment using the Cloudflare Sandbox SDK (@cloudflare/sandbox) backed by Containers and a Durable Object.

API Reference

POST /exec

Execute code and return stdout, stderr, and exit code.

language string (required)

Currently only javascript is supported.

code string (required)

Snippet to run. Max length 5,000 characters.

Example Request

curl -X POST "https://your-worker.workers.dev/exec" \
  -H "Content-Type: application/json" \
  -d '{"language":"javascript","code":"console.log(2 + 2)"}'

Success Response

{
  "stdout": "4\n",
  "stderr": "",
  "exitCode": 0
}

Error Codes

  • 400 - Invalid body, language, or code (INVALID_BODY, INVALID_LANGUAGE, INVALID_CODE)
  • 502 - Sandbox execution failure (EXEC_ERROR)

Use Cases

  • Learn Sandbox SDK getSandbox + exec patterns
  • Safely evaluate untrusted JavaScript snippets at the edge
  • Prototype coding tutors or REPL APIs
  • Compare Sandbox containers vs Dynamic Workers isolation

Limitations

  • Only javascript is supported in this demo
  • Code max length 5,000 characters
  • Docker required for local wrangler dev / deploy
  • Container max_instances is 1 (lite instance type)

Use in your project

Copy these files into an existing Worker. Prefer Deployment to try the full experiment first. Source: apps/experiments/code-sandbox.

DependenciesNoneBindingsDurable Objects, ContainersPlatformDurable Objects
import { SANDBOX_ID, SNIPPET_PATH } from "../constants/defaults";import type { Env } from "../types/env";import type { ExecResult } from "../types/exec";export type SandboxClient = {  writeFile(path: string, content: string): Promise<unknown>;  exec(command: string): Promise<{    stdout: string;    stderr: string;    exitCode: number;  }>;};export type GetSandboxFn = (namespace: Env["Sandbox"], id: string) => SandboxClient;let getSandboxImpl: GetSandboxFn | null = null;/** Test hook to inject a mock sandbox without Docker / cloudflare: imports. */export function setGetSandboxForTests(fn: GetSandboxFn | null): void {  getSandboxImpl = fn;}async function resolveSandbox(env: Env): Promise<SandboxClient> {  if (getSandboxImpl) {    return getSandboxImpl(env.Sandbox, SANDBOX_ID);  }  const { getSandbox } = await import("@cloudflare/sandbox");  // Env uses untyped DO namespace for Node/vitest; cast for Sandbox SDK.  return getSandbox(    env.Sandbox as unknown as Parameters<typeof getSandbox>[0],    SANDBOX_ID  ) as unknown as SandboxClient;}export async function execJavascript(env: Env, code: string): Promise<ExecResult> {  const sandbox = await resolveSandbox(env);  await sandbox.writeFile(SNIPPET_PATH, code);  const result = await sandbox.exec(`node ${SNIPPET_PATH}`);  return {    stdout: result.stdout ?? "",    stderr: result.stderr ?? "",    exitCode: result.exitCode ?? 1,  };}

Deployment

Click the deploy button

Deploy to Cloudflare Workers

Deploy

Wrangler builds the sandbox image, registers the Sandbox Durable Object, and enables nodejs_compat.

Test your deployment

curl -X POST "https://your-worker.workers.dev/exec" \
  -H "Content-Type: application/json" \
  -d '{"language":"javascript","code":"console.log(2 + 2)"}'

Local Development

Docker must be running for container image builds.

cd apps/experiments/code-sandbox
npm install
npm run dev
curl -X POST "http://localhost:8787/exec" \
  -H "Content-Type: application/json" \
  -d '{"language":"javascript","code":"console.log(2 + 2)"}'

Unit tests mock the sandbox client so Docker is not required for npm run test.

Configuration

wrangler.json declares:

  • Container Sandbox from ./Dockerfile (instance_type: lite)
  • Durable Object binding Sandbox → class Sandbox
  • Compatibility flag nodejs_compat

Cloudflare Features Used

On this page