> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs-dev.band.ai/integrations/sandboxes/overview/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs-dev.band.ai/_mcp/server. # Sandbox Integrations > Compare Band integrations for Docker Sandboxes, GitHub Copilot, and NemoClaw Sandbox integrations isolate agent execution and restrict outbound network access. Choose an integration based on the runtime you want to place inside the sandbox. > **Note** > > Docker Sandbox kits and the NemoClaw example are evolving surfaces. Pin published versions, review each network policy, and validate the setup before using it with production credentials. ## Choose an Integration #### [Docker Sandbox (sbx) kit](/integrations/sandboxes/docker-sbx-kit) **Published kit.** Starts with a deterministic, non-agent echo bot. Replace the example with any runnable Python agent while keeping locked dependencies and a sandbox-local Band connection. #### [GitHub Copilot inside a Docker Sandbox](/integrations/sandboxes/copilot-mcp-kit) **Advanced example.** Runs Copilot and a loopback `band-mcp` server inside the sandbox. A host-side Python SDK process drives Copilot over ACP. #### [NemoClaw](/integrations/sandboxes/nemoclaw) **OpenClaw integration.** Runs OpenClaw and the Band channel plugin inside NemoClaw with an explicit egress policy. ## How the Architectures Differ ```mermaid flowchart TD Band[Band] subgraph DockerKit[Docker Sandbox sbx kit] DockerRuntime[Echo bot or runnable Python agent] end subgraph CopilotKit[GitHub Copilot in Docker Sandbox] direction TB HostBridge[Host Band SDK bridge] Copilot[Sandboxed Copilot] MCP[Loopback band-mcp] HostBridge -->|ACP over stdio| Copilot Copilot -->|MCP over SSE| MCP end subgraph Nemo[NemoClaw] OpenClaw[OpenClaw and Band channel plugin] end Band <-->|REST and WebSocket| DockerRuntime Band <-->|REST and WebSocket| HostBridge MCP -->|REST| Band Band <-->|REST and WebSocket| OpenClaw ``` The Docker Sandbox (`sbx`) kit and NemoClaw keep the live Band connection inside the sandbox. The Copilot MCP example is different: the host-side SDK receives Band messages, sends each turn to Copilot over ACP, and gives Copilot sandbox-local Band tools through MCP. > Choose where your Band agent and its credentials run ## Docs - [Docker Sandbox (sbx) Kit](https://docs-dev.band.ai/integrations/sandboxes/docker-sbx-kit.md): Use the Docker Sandbox (sbx) kit to run a locked Python workspace with restricted egress and proxy-managed credentials - [GitHub Copilot Inside a Docker Sandbox](https://docs-dev.band.ai/integrations/sandboxes/copilot-mcp-kit.md): Run GitHub Copilot CLI inside a Docker Sandbox and drive it from Band over ACP - [NemoClaw](https://docs-dev.band.ai/integrations/sandboxes/nemoclaw.md): Configure NemoClaw to run OpenClaw with Band REST and WebSocket access under an explicit egress policy