Skip to main content
wandb.sandbox is deprecated and will be removed in a future release of the W&B Python SDK. Use the cwsandbox package instead, documented in the CoreWeave sandbox docs.Migrating changes two things:
  • The import. Install cwsandbox with the W&B extra (pip install "cwsandbox[wandb]") and import from cwsandbox instead of wandb.sandbox.
  • The credential. cwsandbox authenticates with a CoreWeave API access token in CWSANDBOX_API_KEY by default, so pass auth=AuthStrategy.WANDB to keep using your W&B API key. See Choose a credential.
The examples on this page still use wandb.sandbox. For the equivalent cwsandbox code, see Migrate to cwsandbox.
Serverless Sandboxes is in public preview. Access is enabled per organization. To request access for your organization, contact support.
Serverless Sandboxes gives you on-demand, isolated compute environments that you can create, use, and discard using Python. Serverless Sandboxes is built using the CoreWeave Sandbox library. For the underlying API reference and library docs, see the CoreWeave Sandbox documentation.

How it works

A sandbox is a single isolated compute environment. You create it, run commands inside it, and stop it when it is done. Each sandbox runs in its own container with its own filesystem, network, and process space. W&B authenticates your identity when you create and manage sandboxes. To use W&B or Weave inside a sandbox, pass your API key using the W&B Secrets Manager or environment variables. See Secrets for more information about using secrets in sandboxes. A sandbox goes through several states in its lifecycle. When a container is running, you can execute commands inside it. Read, write, and mount read-only files to and from the sandbox. Common examples include reading in a Python script to execute, writing out logs or results, or mounting a directory of data read-only for the sandbox to access. Use a session to manage multiple sandboxes that share configuration. When a session closes, all of its sandboxes are stopped automatically. See Manage multiple sandboxes for more details.

Basic usage

Follow these steps to create a sandbox and run a command inside it:
  1. Install the W&B Python SDK (wandb) and the serverless sandbox dependencies with the following command:
  2. Log in to W&B with the wandb login CLI command. When prompted, provide your API key to authenticate your identity and access your W&B account:
  3. Copy and paste the following code snippet into a Python file and run it. The code snippet accomplishes the following:
    1. Create a sandbox with Sandbox.run().
    2. Run the command echo "Hello from Serverless Sandboxes!" inside the sandbox using the Sandbox.exec() method.
    3. Print the output to the console using the Process object returned by Sandbox.exec().
    hello_sandbox.py
    You should see the output Hello from Serverless Sandboxes! printed to the console. The sandbox automatically stops when the context manager (the with block) exits. For more information on sandbox lifecycle and states, see Lifecycle of sandboxes.

Migrate to cwsandbox

wandb.sandbox is deprecated and will be removed in a future release of the W&B Python SDK. The cwsandbox package replaces it and accepts either a W&B API key or a CoreWeave API access token. Its reference documentation lives in the CoreWeave sandbox docs. To migrate, change how you install the package, how you import it, and how you select your credential:
  1. Install cwsandbox with the W&B extra. The extra pulls in the wandb library, which cwsandbox uses to resolve W&B credentials:
  2. Import from cwsandbox instead of wandb.sandbox, and pass auth=AuthStrategy.WANDB when you create a sandbox or a session. cwsandbox reads a CoreWeave API access token from CWSANDBOX_API_KEY by default, so W&B authentication must be selected explicitly:
    Before: wandb.sandbox
    After: cwsandbox
Your W&B credentials resolve the same way they do today: from an active wandb login session, the WANDB_API_KEY environment variable, or the api.wandb.ai entry in ~/.netrc. To bill sandboxes to a CoreWeave account instead, omit auth and set CWSANDBOX_API_KEY to a CoreWeave API access token. For a comparison of the two credentials, see Choose a credential.

Behavior that changes after you migrate

wandb.sandbox wraps cwsandbox and applies W&B Serverless defaults that the cwsandbox package doesn’t apply on its own. Account for these differences when you migrate:

Serverless Sandboxes tutorials

For more in-depth examples, see:

Integrations

The following third-party frameworks support Serverless Sandboxes as a sandbox provider.