> ## Documentation Index
> Fetch the complete documentation index at: https://docs.devic.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Start a sandbox session

> Boots from the environment snapshot when it has one, otherwise creates a fresh machine and runs the init script — whose output comes back, which is the way to verify a script works. One session per environment (per tenant, where snapshots are per-tenant): a second concurrent start returns 409 SESSION_ACTIVE unless `force` is set.



## OpenAPI

````yaml POST /v1/environments/{environmentId}/sandbox/start
openapi: 3.0.0
info:
  title: Devic.ai Public API
  description: >-
    Devic.ai is an AI platform that allows you to create, manage, and use AI
    agents for various tasks.
  version: 1.0.0
  contact:
    name: Devic.ai Support
    url: https://devic.ai
  x-logo:
    url: https://devic.ai/logo.png
    altText: Devic.ai Logo
  x-summary: Public API for interacting with Devic.ai platform
servers:
  - url: https://api.devic.ai
    description: Production server
  - url: https://staging-api.devic.ai
    description: Staging server
security:
  - bearerAuth: []
tags:
  - name: Environments
    description: >-
      The machine an agent works on and everything it may reach: sandbox,
      snapshot, knowledge, tools and encrypted variables
  - name: Sandboxes
    description: >-
      Start a real Linux machine on an environment, run commands and files on
      it, and save its snapshot
  - name: Projects
    description: Group agents, assistants, documents and costs into projects
  - name: Documents
    description: >-
      Knowledge base documents: create, version, attach and index markdown
      content for RAG
  - name: Document Folders
    description: Organise knowledge base documents into folders and attach them in bulk
  - name: Files
    description: Upload files and obtain shareable download URLs to attach to messages
  - name: Agents
    description: Endpoints related to AI agents and their operations
  - name: Assistants
    description: Endpoints for interacting with assistants and their specializations
  - name: Tool Servers
    description: Endpoints for managing tool servers and their tool definitions
  - name: Health
    description: API health check endpoints
  - name: Documentation
    description: Endpoints for retrieving markdown documentation
  - name: Integrations
    description: Connect third-party apps and turn them into tools
  - name: Triggers
    description: Start an agent or an assistant from an app event
  - name: Tenant Integrations
    description: Apps that each end user connects for themselves
  - name: Memory
    description: What an assistant remembers between conversations
  - name: Skills
    description: Reusable instruction packs for agents and assistants
  - name: Speech to Text
    description: Audio transcription
  - name: Tenants
    description: Tenants, subtenants and their usage
  - name: MCP Gateway
    description: One MCP endpoint over many servers, with visibility per user
  - name: Tenant Sessions
    description: Tokens that prove which end user is calling
paths:
  /v1/environments/{environmentId}/sandbox/start:
    post:
      tags:
        - Sandboxes
      summary: Start a sandbox session
      description: >-
        Boots from the environment snapshot when it has one, otherwise creates a
        fresh machine and runs the init script — whose output comes back, which
        is the way to verify a script works. One session per environment (per
        tenant, where snapshots are per-tenant): a second concurrent start
        returns 409 SESSION_ACTIVE unless `force` is set.
      operationId: start
      parameters:
        - name: environmentId
          required: true
          in: path
          description: Environment id
          schema:
            type: string
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/StartSandboxSessionDto'
      responses:
        '201':
          description: Session started. Returns sandboxId, runtime and expiresAt.
        '400':
          description: Bad request — invalid or inconsistent payload
        '401':
          description: Unauthorized — missing or invalid API key
        '403':
          description: Forbidden — not reachable with this credential
        '404':
          description: Not found
        '409':
          description: >-
            SESSION_ACTIVE (another session is live) or
            SNAPSHOT_SAVE_IN_PROGRESS (the snapshot is still being written).
      security:
        - bearerAuth: []
components:
  schemas:
    StartSandboxSessionDto:
      type: object
      properties:
        timeoutMinutes:
          type: number
          description: >-
            Session length in minutes (1-30, default 10). `autoExtend` on the
            environment renews it while the session is in use.
          example: 10
        tenantId:
          type: string
          description: >-
            Start from THIS tenant's snapshot. Only meaningful when the
            environment has per-tenant snapshots enabled.
        force:
          type: boolean
          description: >-
            Take over an already-active session, discarding its unsaved state.
            Without it a second concurrent session returns 409 SESSION_ACTIVE.
        forceUnsavedSnapshot:
          type: boolean
          description: >-
            Start from the last saved version even though a snapshot save is
            still running. The session may be missing what that save commits.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: Use JWT token for authentication

````