Skip to main content
POST
Create box

Authorizations

Authorization
string
header
required

Box bearer token in the form box_.... Service API keys authenticate Box operations.

Body

application/json

Options for provisioning a new cloud computer.

ttlSeconds
integer | null
default:3600

Number of seconds before automatic archival. null disables auto-stop. The backend also accepts the string infinite for legacy compatibility; new clients should send null.

Required range: 1 <= x <= 2592000
env
object

Per-box environment variables injected into the box's tool environment, on top of the account environment's variables (per-box values win on conflicts). Keys must match [A-Za-z_][A-Za-z0-9_]{0,127}; at most 100 variables and 64KB total. Reserved names (ASCII_TOKEN, ASCII_API_URL, AGENT_ID, PRODUCT_MODE, ENVIRONMENT_ID, BOX_ID, SERVICE_PREVIEW_TOKEN, BOX_CLI_TOKEN) are rejected with invalid_env. Forked boxes inherit the source box's env unless the fork request supplies its own env.

noEnv
boolean
default:false

Create a box with none of the secrets attached to your account (no environment variables, secret files, or credentials), confined to itself so it cannot act on your account or other boxes. For boxes you give to your own users. SSH, SCP, desktop, snapshots, and public URLs still work; pass env to give the box a secret of its own. A fork of a no-env box is always no-env.

Response

Box accepted for provisioning.

ok
boolean
required
Example:

true

type
string
required

Stable success envelope discriminator added by v1.

Allowed value: "box.created"
status
enum<string>
required
Available options:
provisioning
ttlSeconds
integer | null
required
box
object
required