The sandbox environment
What is set inside the machine, and why none of it is a provider key.
| variable | what it is |
|---|---|
| ANTHROPIC_BASE_URL | the opsen gateway |
| ANTHROPIC_API_KEY | a session token, not your key |
| OPENAI_BASE_URL | the opsen gateway |
| OPENAI_API_KEY | a session token |
| GOOGLE_GENAI_BASE_URL | the opsen gateway |
| GOOGLE_API_KEY | a session token |
| OPSEN_SESSION_ID | this session |
| OPSEN_TASK_ID | the task these runs group under |
| OPSEN_EGRESS_URL | where lent credentials are attached |
| OPSEN_INPUT | this run's input, in a batch |
The session token
Scoped to one session, capped by that session's budget, dead when the session ends, and useless anywhere else. A provider key inside a machine running generated code is what this replaces.
Nothing else from the host
The sandbox gets an allowlist of ordinary variables —
PATH, HOME and the like — and nothing more.
Secrets belonging to the opsen deployment are not reachable from customer
code.