@inis-run/openai-agents
v0.2.0
Published
inis.run sandbox provider for the OpenAI Agents SDK (beta)
Maintainers
Readme
@inis-run/openai-agents
Native inis.run sandbox provider for the OpenAI Agents SDK SandboxAgent path (@openai/agents-core/sandbox).
Beta, upstream and here. The Agents SDK documents its sandbox surface as beta. Verified against @openai/agents-core==0.14.1/@openai/agents==0.14.1.
Install
npm install @inis-run/openai-agentsQuickstart: attached (recommended)
One inis.run session for the whole conversation, owned by your app:
import { Client } from "@inis-run/sdk";
import { run } from "@openai/agents";
import { SandboxAgent } from "@openai/agents-core/sandbox";
import { InisSandboxSession } from "@inis-run/openai-agents";
const client = new Client();
const inisSession = await client.sessions.create({ egress: { mode: "deny" } });
const sandboxSession = InisSandboxSession.wrap(inisSession);
const agent = new SandboxAgent({ name: "assistant", model: "gpt-5.1" });
try {
const result = await run(agent, "list files in /workspace", {
sandbox: { session: sandboxSession },
});
} finally {
await inisSession.destroy(); // this app owns the session; the SDK never will
}The Agents SDK never destroys a session passed via sandbox.session —
that lifecycle stays entirely host-controlled: one persistent session
across a whole conversation, not one sandbox per model turn.
Owned: one run() call at a time
import { InisSandboxClient, InisSandboxClientOptions } from "@inis-run/openai-agents";
const result = await run(agent, "...", {
sandbox: {
client: new InisSandboxClient(),
options: { egressDefault: "deny" } satisfies InisSandboxClientOptions,
},
});The SDK creates a fresh inis.run session for that call and destroys it when the call ends. Prefer the attached path above for a real multi-turn agent.
InisSandboxClientOptions also accepts connections — inline Connections
(scoped credential leases bound to a specific external API origin) to
create alongside the session; see ConnectionCreate in @inis-run/sdk.
What it does
exec/execCommand(shell), with a real interactive PTY (tty: true) andwriteStdinfor a running sessionreadFilematerializeEntryfor plainfile/dirmanifest entries- Exposed ports, via
session.expose() - Persist/hydrate workspace (owned
resume()path) — tar+base64 overexec()
Notes
Nested Dir children and local_file/local_dir/git_repo manifest entries are not implemented — a thrown error, not silently ignored. True remote cancellation of an in-flight command is not implemented: the upstream contract has no abort handle for this adapter to route through.
Truncated output
InisSandboxSession.exec() returns InisSandboxExecResult, a structural
superset of upstream's SandboxExecResult adding one field:
const result = await session.exec!({ cmd: "some-command-that-produces-a-lot-of-output" });
result.truncated; // boolean — set when inis.run's own per-stream capture limit cut a streamstdout/stderr are returned exactly as inis.run produced them — no
marker text, nothing to parse out. truncated is copied straight from
inis.run's own trusted signal (never derived from stream content), so it
can't be spoofed by anything the sandboxed command prints. An earlier
version of this adapter appended a marker with a random per-call nonce to
stderr instead, implying a caller could tell a real marker from a guest
printing a fake one by checking the nonce; nothing ever checked it, so
that implication was false.
Development
npm install
npm test # vitest
npm run buildLinks
- Docs: docs.inis.run
- Source: github.com/inis-run/sdk/tree/main/openai-agents-js
- Homepage: inis.run
Built and run in the EU. Your code and data never leave Europe.
License
MIT — see LICENSE.
