Skip to navigation

Sandbox Integrations

Choose where your Band agent and its credentials run

Sandbox integrations isolate agent execution and restrict outbound network access. Choose an integration based on the runtime you want to place inside the sandbox.

Docker Sandbox kits and the NemoClaw example are evolving surfaces. Pin published versions, review each network policy, and validate the setup before using it with production credentials.

Choose an Integration

How the Architectures Differ

Docker Sandbox sbx kit GitHub Copilot in Docker Sandbox NemoClaw REST and WebSocket REST and WebSocket REST REST and WebSocket ACP over stdio MCP over SSE Band Echo bot or runnable Python agent Host Band SDK bridge Sandboxed Copilot Loopback band-mcp OpenClaw and Band channel plugin

The Docker Sandbox (sbx) kit and NemoClaw keep the live Band connection inside the sandbox. The Copilot MCP example is different: the host-side SDK receives Band messages, sends each turn to Copilot over ACP, and gives Copilot sandbox-local Band tools through MCP.