> ## Documentation Index
> Fetch the complete documentation index at: https://paper.brimble.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Run a code snippet

> Writes `code` to a temp file and runs it with the chosen interpreter.
Cleaner than `/exec` for multi-line scripts because you don't have to
deal with shell escaping. Response shape matches `/exec`.

Supports the same `stream: true` opt-in as `/exec`; see that endpoint's
description for the SSE event shape.




## OpenAPI

````yaml POST /sandboxes/{id}/code
openapi: 3.0.3
info:
  title: Brimble Sandbox API
  description: >
    REST API for managing Brimble sandboxes, ephemeral compute environments with

    optional persistent storage. Covers lifecycle (create / pause / resume /
    destroy),

    egress policy, runtime operations (exec, runCode, file upload/download),

    observability (logs, stats), and snapshots.


    ## Conventions


    - **Response envelope:** non-`204` JSON responses use `{ "message": string,
    "data"?: <payload> }`.
      The schemas below describe the **`data`** payload only.
    - **Errors:** every non-2xx response uses `{ "message": string }`. The
    message is
      user-facing.
    - **Async transitions:** pause / resume / destroy return immediately;
      the status change is visible on the next `GET` or in the dashboard.
      **Create is synchronous** — `POST /sandboxes` blocks until `status` is `ready`.
    - **IDs:** every `id` is a 24-char hex string.
  version: 1.0.0
  contact:
    name: Brimble Engineering
    url: https://brimble.io
servers:
  - url: https://sandbox.brimble.io
    description: Production
security:
  - brimbleKey: []
tags:
  - name: Sandboxes
    description: Lifecycle and metadata
  - name: Runtime
    description: Exec, code, files
  - name: Observability
    description: Logs and stats
  - name: Snapshots
    description: Manual & automatic snapshots
  - name: Volumes
    description: >-
      Persistent disks, pre-provisioned independently of sandbox lifecycle, then
      attached to a sandbox or project
paths:
  /sandboxes/{id}/code:
    post:
      tags:
        - Runtime
      summary: Run a code snippet
      description: |
        Writes `code` to a temp file and runs it with the chosen interpreter.
        Cleaner than `/exec` for multi-line scripts because you don't have to
        deal with shell escaping. Response shape matches `/exec`.

        Supports the same `stream: true` opt-in as `/exec`; see that endpoint's
        description for the SSE event shape.
      operationId: runCode
      parameters:
        - $ref: '#/components/parameters/SandboxIdParam'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/CodeInput'
      responses:
        '200':
          description: |
            Code completed.

            When the request body has `stream: true`, the response is
            `text/event-stream`, one `ExecStreamFrame` per `data:` event.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ExecResultEnvelope'
            text/event-stream:
              schema:
                type: string
                description: SSE stream of `ExecStreamFrame` JSON objects.
        '400':
          $ref: '#/components/responses/BadRequest'
        '404':
          $ref: '#/components/responses/NotFound'
components:
  parameters:
    SandboxIdParam:
      in: path
      name: id
      required: true
      schema:
        type: string
        pattern: ^[a-f0-9]{24}$
      description: 24-char hex id of the sandbox.
  schemas:
    CodeInput:
      type: object
      required:
        - language
        - code
      properties:
        language:
          type: string
          enum:
            - python
            - node
        code:
          type: string
          description: Snippet source. Multi-line via `\n` in the JSON string.
        timeout_seconds:
          type: integer
          minimum: 1
          maximum: 300
        cwd:
          type: string
        env:
          type: object
          additionalProperties:
            type: string
          description: |
            Extra environment variables for this snippet only. Same semantics as
            `env` on `/exec`, per-call override on top of the sandbox's default
            environment.
          example:
            OPENAI_API_KEY: sk-...
        stream:
          type: boolean
          description: |
            When true, the response is SSE (`text/event-stream`) as the snippet
            runs, same behaviour as `/exec` with `stream: true`.
    ExecResultEnvelope:
      type: object
      required:
        - message
        - data
      properties:
        message:
          type: string
          example: Exec completed
        data:
          $ref: '#/components/schemas/ExecResult'
    ExecResult:
      type: object
      required:
        - stdout
        - stderr
        - exit_code
        - duration_ms
      properties:
        stdout:
          type: string
        stderr:
          type: string
        exit_code:
          type: integer
        duration_ms:
          type: integer
    ErrorResponse:
      type: object
      required:
        - message
      properties:
        message:
          type: string
          description: Human-readable, user-facing error reason.
  responses:
    BadRequest:
      description: Validation error / invalid state transition
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            invalidId:
              summary: Invalid sandbox id
              value:
                message: Invalid sandbox id
            statusTransition:
              summary: Wrong status
              value:
                message: Sandbox is paused; only ready sandboxes can be paused
            fileNotDir:
              summary: Parent dir missing on upload
              value:
                message: 'Destination directory does not exist: /work'
            duplicateVolumeName:
              summary: Duplicate volume name
              value:
                message: A volume named "node-cache" already exists
            volumeAttached:
              summary: Delete attempted on attached volume
              value:
                message: Volume is attached; detach it before deleting
    NotFound:
      description: >-
        Sandbox or related resource not found (also returned when owned by
        another user)
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            sandboxNotFound:
              value:
                message: Sandbox not found
            snapshotNotFound:
              value:
                message: Snapshot not found
            volumeNotFound:
              value:
                message: Volume not found
  securitySchemes:
    brimbleKey:
      type: apiKey
      in: header
      name: x-brimble-key
      description: |
        Your account-level Brimble API key. Find it in the dashboard under
        your profile drawer → **API key** (click the avatar in the sidebar).
        Available on paid plans only.

````