沙箱
为你的脚本和 AI 代理运行代码而准备的隔离 Linux 微型虚拟机。沙箱大约一秒即可启动,可运行 Python、Node.js 或 bash,并从与服务器相同的余额中按秒计费。
什么是沙箱
一台小型 Linux 机器:通过 API 或 MCP 创建,用几秒或几天,然后删除。出站网络可用(pip install、npm install、git clone)。没有入站端口,也没有 SSH:命令和文件都通过 API 传递。内置:带 pip 的 Python 3.12、带 npm 的 Node.js 22、bash、git 和 curl。
两种模式
套餐
| 套餐 | vCPU | RAM | 磁盘 | 网络 | 每小时 | 持久,每月上限 |
|---|---|---|---|---|---|---|
| micro | 0.25 | 512 MB | 3 GB | 50 Mbit/s | $0.0165 | $9.03 |
| small | 0.5 | 1 GB | 5 GB | 100 Mbit/s | $0.033 | $18.07 |
| standard | 1 | 2 GB | 10 GB | 200 Mbit/s | $0.066 | $36.14 |
| plus | 2 | 4 GB | 15 GB | 300 Mbit/s | $0.132 | $72.27 |
| pro | 4 | 8 GB | 20 GB | 400 Mbit/s | $0.264 | $144.54 |
| max | 8 | 16 GB | 40 GB | 500 Mbit/s | $0.528 | $289.08 |
按所选套餐的 vCPU 和 RAM 付费:每 vCPU 小时 $0.040,每 GiB 小时 $0.013。实时价格无需令牌:GET /sandboxes/tariffs。
需要了解的限制
单条命令最长运行 55 秒;更长的任务以后台任务运行,由你轮询结果。每次请求的文件最大 5 MB,更大的文件(最大 2 GB)通过一次性下载和上传链接传输。一个账户最多同时运行 20 个沙箱和 2 条命令。
环境变量
通过 env 传递密钥和配置。创建时设置的变量适用于沙箱中的每条命令;在 exec 或 run 中设置的变量只对该次调用生效,并覆盖沙箱的值。最多 64 个变量,每个值 32 KB,总计 64 KB。值以加密形式存储,API 从不返回,也不会写入日志:响应中只显示名称(env_keys)。
API=https://api.eqvps.com/api/v1/eqvps
AUTH="Authorization: Bearer $EQVPS_API_KEY"
# env for the whole sandbox (only the names come back, as env_keys)
SB=$(curl -s -X POST $API/sandboxes -H "$AUTH" -H "Content-Type: application/json" \
-d '{"tariff":"small","env":{"DB_URL":"postgres://user:pass@db/app","MODE":"test"}}' | jq -r .id)
# env for one call, merged over the sandbox env
curl -s -X POST $API/sandboxes/$SB/exec -H "$AUTH" -H "Content-Type: application/json" \
-d '{"command":"echo $MODE $RUN_ID","env":{"RUN_ID":"42"}}'消费上限
默认情况下沙箱没有消费上限。你可以在控制台或通过 PUT /sandboxes/budget 设置每日和每月上限。达到上限后,新沙箱会收到 429 budget_exceeded,运行中的临时沙箱会被删除,持久沙箱会暂停并保留磁盘。当你提高上限或进入新的一天或一个月(UTC)后,它们会恢复运行。
# daily cap $5, monthly cap $50 (null = no cap)
curl -s -X PUT $API/sandboxes/budget -H "$AUTH" -H "Content-Type: application/json" \
-d '{"daily_usd":5,"monthly_usd":50}'
# spent today / this month and when the caps reset (UTC)
curl -s $API/sandboxes/budget -H "$AUTH"快速开始:MCP(Claude Code、Cursor 及其他客户端)
只需连接一次 MCP 服务器,之后用日常语言吩咐代理即可。沙箱工具:create_sandbox、run_code、exec_command、get_task、kill_task、get_upload_url、get_download_url、list_sandboxes、get_sandbox、kill_sandbox、sandbox_pricing。
claude mcp add --transport http eqvps https://mcp.eqvps.com/mcp \
--header "Authorization: Bearer $EQVPS_API_KEY"创建一个小沙箱,用 Python 运行 print(2 + 2),把输出给我看,然后删除这个沙箱。快速开始:从 Python 和 Node.js 调用 REST
无需额外安装包。把令牌放入环境变量 EQVPS_API_KEY(获取方法见“连接你的账户”)。
# first_sandbox.py — Python 3.8+, standard library only
import json, os, urllib.request
API = "https://api.eqvps.com/api/v1/eqvps"
KEY = os.environ["EQVPS_API_KEY"]
def call(method, path, body=None):
req = urllib.request.Request(API + path, method=method,
data=json.dumps(body).encode() if body is not None else None,
headers={"Authorization": "Bearer " + KEY,
"Content-Type": "application/json", "Accept": "application/json"})
with urllib.request.urlopen(req, timeout=90) as r: # HTTPError on 401/402/…
return json.loads(r.read() or b"{}")
sb = call("POST", "/sandboxes", {"tariff": "small"})
try:
r = call("POST", f"/sandboxes/{sb['id']}/run",
{"language": "python", "code": "print(2 + 2)"})
print(r["exit_code"], r["stdout"]) # 0 4
finally:
call("DELETE", f"/sandboxes/{sb['id']}")// first_sandbox.mjs — Node.js 18+ (built-in fetch), run: node first_sandbox.mjs
const API = "https://api.eqvps.com/api/v1/eqvps";
const KEY = process.env.EQVPS_API_KEY;
async function call(method, path, body) {
const r = await fetch(API + path, {
method,
headers: { Authorization: `Bearer ${KEY}`, "Content-Type": "application/json", Accept: "application/json" },
body: body ? JSON.stringify(body) : undefined,
});
const data = await r.json();
if (!r.ok) throw new Error(`${r.status} ${data.error ?? ""} ${data.message ?? ""}`);
return data;
}
const sb = await call("POST", "/sandboxes", { tariff: "small" });
try {
const r = await call("POST", `/sandboxes/${sb.id}/run`, { language: "node", code: "console.log(2 + 2)" });
console.log(r.exit_code, r.stdout); // 0 4
} finally {
await call("DELETE", `/sandboxes/${sb.id}`);
}Python 与 TypeScript SDK
更喜欢用库?Python 和 TypeScript 包封装了同样的 REST 调用,会自动重试 429 和 503,并在代码块结束时总会删除沙箱。安装与示例:
# pip install -U eqvps https://pypi.org/project/eqvps/ (0.2.0+ for env)
# "eqvps sandbox create" = Sandbox.create() here · create_sandbox in MCP · POST /sandboxes in REST (no CLI)
from eqvps import Sandbox
# EQVPS_API_KEY from the environment; env = secrets for your code, stored encrypted
with Sandbox.create(tariff="small", env={"DB_URL": "postgres://user:pass@db/app"}) as sb:
r = sb.run("print(2 + 2)")
print(r.stdout, r.exit_code) # "4\n" 0
sb.upload("/root/data.csv", "a,b\n1,2\n")
print(sb.exec("wc -l /root/data.csv").stdout)
print(sb.exec("echo $RUN_ID", env={"RUN_ID": "42"}).stdout) # env for one call
# the sandbox is deleted when the block exits, also on errors// npm i @eqvps/sdk@latest https://www.npmjs.com/package/@eqvps/sdk (0.2.0+ for env)
import { Sandbox } from "@eqvps/sdk";
// EQVPS_API_KEY from the environment; env = secrets for your code, stored encrypted
await Sandbox.with({ tariff: "small", env: { DB_URL: "postgres://user:pass@db/app" } }, async (sb) => {
const r = await sb.run("print(2 + 2)");
console.log(r.stdout, r.exit_code); // "4\n" 0
console.log((await sb.exec("echo $RUN_ID", { env: { RUN_ID: "42" } })).stdout); // env for one call
}); // deleted afterwards, also on errors
评论
暂无评论。来做第一个吧。