sha256:b5bf163024d7eabaa8a273012f69d14178e643c20917beca972fbbc5a1b4facf
Last pushed
about 22 hours by sbx
Type
Sandbox Kit
Manifest digest
sha256:b5bf163024d7eabaa8a273012f69d14178e643c20917beca972fbbc5a1b4facf
schemaVersion: "3"
displayName: OpenHands (mixin)
description: OpenHands as a mixin — the `uv`-installed CLI and its managed CPython in an overlay, with the Anthropic, Google and OpenAI credentials and the hook that resolves which Anthropic auth the host actually holds. Layer it onto a shell base and run `openhands`.
version: 1.16.0
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- api.anthropic.com
- platform.claude.com
- api.openai.com
- generativelanguage.googleapis.com
- github.com
- api.github.com
- raw.githubusercontent.com
- pypi.org
- registry.npmjs.org
- api.tavily.com
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.anthropic.com
format: '%s'
header: x-api-key
name: ANTHROPIC_API_KEY
proxyManaged: true
oauth:
credentialFile:
path: ~/.claude/.credentials.json
structure:
claudeAiOauth:
accessToken: '{{.AccessToken}}'
expiresAt: '{{.ExpiresAt}}'
refreshToken: '{{.RefreshToken}}'
scopes: '{{.Scopes}}'
resourceHosts:
- api.anthropic.com
sentinels:
accessToken: sk-ant-oat01-proxy-managed
refreshToken: sk-ant-ort01-proxy-managed
tokenEndpoint:
host: platform.claude.com
path: /v1/oauth/token
phase: runtime
service: anthropic
description: Anthropic API access (API key or claude.ai OAuth)
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: generativelanguage.googleapis.com
format: '%s'
header: x-goog-api-key
name: GEMINI_API_KEY
proxyManaged: true
phase: runtime
service: google
description: Google Gemini API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.openai.com
format: Bearer %s
header: Authorization
name: OPENAI_API_KEY
proxyManaged: true
phase: runtime
service: openai
description: OpenAI API access
- type: com.docker.sandbox/lifecycle@1
config:
startup:
- command:
- sh
- /home/agent/.local/bin/openhands-anthropic-auth.sh
description: Resolve whether Anthropic auth is an API key, an OAuth login, or absent, and record it for `openhands-start` and `sbx exec` shells
env:
- SBX_CRED_ANTHROPIC_MODE
user: "1000"
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/openhands-mixin/openhands-mixin-context.md
args:
version:
default: 1.16.0
description: OpenHands release to install
pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
buildArg: OPENHANDS_VERSION