#88th of 8 in Sandboxes

Open Terminal

REST-driven shell and file sandbox for AI agents, from Open WebUI

Stars
3.3k
License
MIT
Last commit
Oct 2026
Last release
Sep 2026

Overview

Container or pip package exposing a shell and file management over a REST API with an API key on port 8000, so agents can run commands and code. The latest image (about 4 GB) bundles Python, Node.js, gcc, ffmpeg, LibreOffice, LaTeX and the Docker CLI behind an egress firewall; slim (430 MB) and alpine (230 MB) variants keep git, curl and jq. Integrates with Open WebUI as a terminal with a file sidebar.

Who it is for: Open WebUI users and agent builders needing a command sandbox

Strengths

  • API key auto-generated if unset; interactive API docs at /docs
  • Extra apt, pip and npm packages installed at startup via env vars
  • Four image variants from 230 MB alpine to a 4 GB full toolkit
  • Office previews: DOCX and PPTX rendered to PDF when LibreOffice is present

Weaknesses

  • Multi-user mode shares one container and is explicitly not a security boundary
  • Per-user isolation requires Terminals, which needs an Open WebUI Enterprise license
  • Mounting the Docker socket gives the container root-equivalent host access
  • Bare-metal mode runs commands directly as your user with no sandbox

What it needs

  • no GPU
  • Docker
  • port 8000

Also in Sandboxes

See all 8
Also in Sandboxes
RankProjectScore
1LightpandaHeadless browser written in Zig for AI agents and scraping36.2k stars, AGPL-3.078 out of 100
2ObscuraRust headless browser with CDP, native rendering and stealth mode28.7k stars, Apache-2.072 out of 100
3NemoClawNVIDIA reference stack running OpenClaw and Hermes inside OpenShell sandboxes22.7k stars, Apache-2.071 out of 100
#4OpenShellPolicy-enforced sandbox runtime for autonomous agents with credential brokering15.7k stars, Apache-2.069 out of 100
#5microsandboxLocal microVMs for untrusted code with fork, snapshot and SDKs8.6k stars, Apache-2.061 out of 100