opsen
opsen

The sandbox environment

What is set inside the machine, and why none of it is a provider key.

variablewhat it is
ANTHROPIC_BASE_URLthe opsen gateway
ANTHROPIC_API_KEYa session token, not your key
OPENAI_BASE_URLthe opsen gateway
OPENAI_API_KEYa session token
GOOGLE_GENAI_BASE_URLthe opsen gateway
GOOGLE_API_KEYa session token
OPSEN_SESSION_IDthis session
OPSEN_TASK_IDthe task these runs group under
OPSEN_EGRESS_URLwhere lent credentials are attached
OPSEN_INPUTthis run's input, in a batch

The session token

Scoped to one session, capped by that session's budget, dead when the session ends, and useless anywhere else. A provider key inside a machine running generated code is what this replaces.

Nothing else from the host

The sandbox gets an allowlist of ordinary variables — PATH, HOME and the like — and nothing more. Secrets belonging to the opsen deployment are not reachable from customer code.