openapi: 3.0.3 info: title: PostHog actions sandbox-environments API version: 1.0.0 description: '' tags: - name: sandbox-environments paths: /api/projects/{project_id}/sandbox_environments/: get: operationId: sandbox_list description: API for managing sandbox environments that control network access for task runs. parameters: - name: limit required: false in: query description: Number of results to return per page. schema: type: integer - name: offset required: false in: query description: The initial index from which to return the results. schema: type: integer - $ref: '#/components/parameters/ProjectIdPath' tags: - sandbox-environments security: - PersonalAPIKeyAuth: - task:read - PersonalAPIKeyAuth: - task:read responses: '200': content: application/json: schema: $ref: '#/components/schemas/PaginatedSandboxEnvironmentListList' description: '' x-explicit-tags: - sandbox-environments - tasks post: operationId: sandbox_create description: API for managing sandbox environments that control network access for task runs. parameters: - $ref: '#/components/parameters/ProjectIdPath' tags: - sandbox-environments requestBody: content: application/json: schema: $ref: '#/components/schemas/SandboxEnvironment' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/SandboxEnvironment' multipart/form-data: schema: $ref: '#/components/schemas/SandboxEnvironment' required: true security: - PersonalAPIKeyAuth: - task:write - PersonalAPIKeyAuth: - task:write responses: '201': content: application/json: schema: $ref: '#/components/schemas/SandboxEnvironment' description: '' x-explicit-tags: - sandbox-environments - tasks /api/projects/{project_id}/sandbox_environments/{id}/: get: operationId: sandbox_retrieve description: API for managing sandbox environments that control network access for task runs. parameters: - in: path name: id schema: type: string format: uuid description: A UUID string identifying this sandbox environment. required: true - $ref: '#/components/parameters/ProjectIdPath' tags: - sandbox-environments security: - PersonalAPIKeyAuth: - task:read - PersonalAPIKeyAuth: - task:read responses: '200': content: application/json: schema: $ref: '#/components/schemas/SandboxEnvironment' description: '' x-explicit-tags: - sandbox-environments patch: operationId: sandbox_partial_update description: API for managing sandbox environments that control network access for task runs. parameters: - in: path name: id schema: type: string format: uuid description: A UUID string identifying this sandbox environment. required: true - $ref: '#/components/parameters/ProjectIdPath' tags: - sandbox-environments requestBody: content: application/json: schema: $ref: '#/components/schemas/PatchedSandboxEnvironment' application/x-www-form-urlencoded: schema: $ref: '#/components/schemas/PatchedSandboxEnvironment' multipart/form-data: schema: $ref: '#/components/schemas/PatchedSandboxEnvironment' security: - PersonalAPIKeyAuth: - task:write - PersonalAPIKeyAuth: - task:write responses: '200': content: application/json: schema: $ref: '#/components/schemas/SandboxEnvironment' description: '' x-explicit-tags: - sandbox-environments delete: operationId: sandbox_destroy description: API for managing sandbox environments that control network access for task runs. parameters: - in: path name: id schema: type: string format: uuid description: A UUID string identifying this sandbox environment. required: true - $ref: '#/components/parameters/ProjectIdPath' tags: - sandbox-environments security: - PersonalAPIKeyAuth: - task:write - PersonalAPIKeyAuth: - task:write responses: '204': description: No response body x-explicit-tags: - sandbox-environments components: schemas: PaginatedSandboxEnvironmentListList: type: object required: - count - results properties: count: type: integer example: 123 next: type: string nullable: true format: uri example: http://api.example.org/accounts/?offset=400&limit=100 previous: type: string nullable: true format: uri example: http://api.example.org/accounts/?offset=200&limit=100 results: type: array items: $ref: '#/components/schemas/SandboxEnvironmentList' BlankEnum: enum: - '' UserBasic: type: object properties: id: type: integer readOnly: true uuid: type: string format: uuid readOnly: true distinct_id: type: string nullable: true maxLength: 200 first_name: type: string maxLength: 150 last_name: type: string maxLength: 150 email: type: string format: email title: Email address maxLength: 254 is_email_verified: type: boolean nullable: true hedgehog_config: type: object additionalProperties: true nullable: true readOnly: true role_at_organization: nullable: true oneOf: - $ref: '#/components/schemas/RoleAtOrganizationEnum' - $ref: '#/components/schemas/BlankEnum' - $ref: '#/components/schemas/NullEnum' required: - email - hedgehog_config - id - uuid SandboxEnvironment: type: object properties: id: type: string format: uuid readOnly: true name: type: string maxLength: 255 network_access_level: $ref: '#/components/schemas/NetworkAccessLevelEnum' allowed_domains: type: array items: type: string maxLength: 255 description: List of allowed domains for custom network access include_default_domains: type: boolean description: Whether to include default trusted domains (GitHub, npm, PyPI) repositories: type: array items: type: string maxLength: 255 description: 'List of repositories this environment applies to (format: org/repo)' environment_variables: writeOnly: true description: Encrypted environment variables (write-only, never returned in responses) has_environment_variables: type: boolean readOnly: true description: Whether this environment has any environment variables set private: type: boolean description: If true, only the creator can see this environment. Otherwise visible to whole team. internal: type: boolean readOnly: true description: If true, this environment is for internal use (e.g. signals pipeline) and should not be exposed to end users. effective_domains: type: array items: type: string readOnly: true description: Computed domain allowlist based on network_access_level and allowed_domains created_by: allOf: - $ref: '#/components/schemas/UserBasic' readOnly: true created_at: type: string format: date-time readOnly: true updated_at: type: string format: date-time readOnly: true required: - created_at - created_by - effective_domains - has_environment_variables - id - internal - name - updated_at SandboxEnvironmentList: type: object properties: id: type: string format: uuid readOnly: true name: type: string maxLength: 255 network_access_level: $ref: '#/components/schemas/NetworkAccessLevelEnum' allowed_domains: type: array items: type: string maxLength: 255 description: List of allowed domains for custom network access repositories: type: array items: type: string maxLength: 255 description: 'List of repositories this environment applies to (format: org/repo)' private: type: boolean description: If true, only the creator can see this environment. Otherwise visible to whole team. internal: type: boolean description: If true, this environment is for internal use (e.g. signals pipeline) and should not be exposed to end users. created_by: allOf: - $ref: '#/components/schemas/UserBasic' readOnly: true created_at: type: string format: date-time readOnly: true updated_at: type: string format: date-time readOnly: true required: - created_at - created_by - id - name - updated_at PatchedSandboxEnvironment: type: object properties: id: type: string format: uuid readOnly: true name: type: string maxLength: 255 network_access_level: $ref: '#/components/schemas/NetworkAccessLevelEnum' allowed_domains: type: array items: type: string maxLength: 255 description: List of allowed domains for custom network access include_default_domains: type: boolean description: Whether to include default trusted domains (GitHub, npm, PyPI) repositories: type: array items: type: string maxLength: 255 description: 'List of repositories this environment applies to (format: org/repo)' environment_variables: writeOnly: true description: Encrypted environment variables (write-only, never returned in responses) has_environment_variables: type: boolean readOnly: true description: Whether this environment has any environment variables set private: type: boolean description: If true, only the creator can see this environment. Otherwise visible to whole team. internal: type: boolean readOnly: true description: If true, this environment is for internal use (e.g. signals pipeline) and should not be exposed to end users. effective_domains: type: array items: type: string readOnly: true description: Computed domain allowlist based on network_access_level and allowed_domains created_by: allOf: - $ref: '#/components/schemas/UserBasic' readOnly: true created_at: type: string format: date-time readOnly: true updated_at: type: string format: date-time readOnly: true RoleAtOrganizationEnum: enum: - engineering - data - product - founder - leadership - marketing - sales - other type: string description: '* `engineering` - Engineering * `data` - Data * `product` - Product Management * `founder` - Founder * `leadership` - Leadership * `marketing` - Marketing * `sales` - Sales / Success * `other` - Other' NetworkAccessLevelEnum: enum: - trusted - full - custom type: string description: '* `trusted` - Trusted * `full` - Full * `custom` - Custom' NullEnum: enum: - null parameters: ProjectIdPath: in: path name: project_id required: true schema: type: string description: Project ID of the project you're trying to access. To find the ID of the project, make a call to /api/projects/. securitySchemes: PersonalAPIKeyAuth: type: http scheme: bearer x-tagGroups: - name: All endpoints tags: - LLM Analytics - actions - activity_log - activity_logs - advanced_activity_logs - alerts - annotations - approval_policies - batch_exports - cdp - change_requests - code - code-invites - cohorts - comments - conversations - core - customer_analytics - customer_journeys - customer_profile_configs - dashboard_templates - dashboards - data_color_themes - data_modeling_jobs - data_warehouse - dataset_items - datasets - desktop_recordings - domains - early_access_feature - early_access_features - elements - endpoints - environments - error_tracking - evaluation_runs - evaluations - event_definitions - event_filter - event_schemas - events - experiment_holdouts - experiment_saved_metrics - experiments - exports - external_data_schemas - external_data_sources - feature_flags - file_system - file_system_shortcut - flag_value - groups - groups_types - health_issues - heatmap_screenshots - heatmaps - hog_flows - hog_function_templates - hog_functions - insight_variables - insights - integrations - invites - js-snippet - legal_documents - lineage - live_debugger_breakpoints - llm_analytics - llm_prompts - llm_skills - logs - managed_viewsets - max - max_tools - mcp_server_installations - mcp_servers - mcp_store - mcp_tools - members - notebooks - oauth_applications - object_media_previews - organizations - persisted_folder - persons - platform_features - plugin_configs - product_analytics - product_tours - project_secret_api_keys - projects - property_definitions - proxy_records - public_hog_function_templates - query - replay - reverse_proxy - role_external_references - roles - sandbox-environments - sandbox_environments - saved - schema_property_groups - sdk_doctor - session_group_summaries - session_recording_playlists - session_recordings - session_summaries - sessions - signals - subscriptions - surveys - taggers - task-automations - task-runs - task_automations - tasks - uploaded_media - user_home_settings - user_interviews - users - visual_review - warehouse_dag - warehouse_model_paths - warehouse_saved_queries - warehouse_saved_query_folders - warehouse_tables - warehouse_view_link - warehouse_view_links - web_analytics - web_experiments - web_vitals - welcome - workflows