Register the workspace
The handler registers a sandbox with a checkpoint policy:VercelResource
implements three operations:
create(checkpoint_ref=None)creates a sandbox from the selected snapshot or a fresh checkout, and configures its Git branch.open(binding)resumes the sandbox name recorded for this execution.checkpoint(handle)creates a snapshot and resumes the sandbox, since taking a snapshot stops its session.
open resumes it. Missing sandboxes or selected snapshots fail the
execution.
Wrap the tools
shell and write_file declare workspace changes. read_file uses the default
of none:
shell to commit and push the branch. These tools use
safe_to_retry, so an interrupted command can run again. See
idempotency when adding commands with effects
that must not repeat.
Keep credentials out of the sandbox
Cloning and pushing need a GitHub token. The driver creates the sandbox with a network policy that sets theAuthorization header on requests to github.com and allows
other domains unchanged:
github.com, so the sandbox can push a branch but cannot
use that token to call the API. Protect the default branch with a GitHub ruleset
that requires a pull request.
Stop while waiting
The handler stops the workspace when the model loop finishes or waits for approval:pause() stops the sandbox. Files persist and running processes end. The check
reads execution().suspension because a framework can catch Blocked inside
its loop. After approval, the next dispatch replays up to the held call and the
driver resumes the same sandbox. A completion checkpoint briefly resumes a
stopped sandbox and stops it again after capture.
Sessions
The handler reads the previous completed turn withprevious() and returns its
conversation in Result.state:
Fork the workspace
Write the policy
Run it
examples/integrations/sandbox/vercel
has the full agent, resource driver, policy, and dev kernel config.
Set VERCEL_TOKEN, VERCEL_TEAM_ID, VERCEL_PROJECT_ID, REPO (the
repository as owner/name), GITHUB_TOKEN, LLM_MODEL, LLM_BASE_URL, and
LLM_API_KEY. The token needs read and write access to the repository’s
contents and pull requests. Start the kernel and agent from that directory:
open_pr call appears in rebuno exec watch. See
Approvals to approve it. Continue the same session with:
lease_timeout_seconds sets a shorter lease for the agent.