Skip to main content
POST
Create box

Authorizations

Authorization
string
header
required

Box bearer token in the form box_.... Service API keys authenticate Box operations.

Headers

Idempotency-Key
string

Optional exactly-once key for creating a box. Send your own opaque, account-unique value (a UUID) to make POST /boxes safe to retry when the response is lost (network timeout, 5xx): the first request creates the box and binds it to the key; every later request with the same account, key, and request body returns that same box instead of creating a second, billable one. Behavior: keys are retained for 24 hours; a concurrent or early retry while the first box is still being minted returns 409 idempotency_in_progress (retry shortly, same key); reusing a key with a different body returns 409 idempotency_key_reused; timeouts and 5xx are safe to retry with the same key; a create that fails before the box exists releases the key within ~2 minutes so a retry can create the box. Omit the header to keep the default (non-idempotent) behavior.

Maximum string length: 255
X-Box-Org
string

Same as the org query parameter. Query wins when both are set.

Query Parameters

org
string

Billing wallet for this request. A team id you belong to reads that team's limits / bills a create to that team. Your own account id is personal. Boxes, snapshots, and environments stay creator-private.

Body

application/json

Options for provisioning a new cloud computer.

type
enum<string>
default:default

Machine size. small consumes machine time at half rate and large at twice the default rate (see the Billing guide). xlarge costs $0.20 per running hour, requires the effective $100 plan or higher, and requires an explicit bare-metal operator allocation. A fork inherits the source box's type unless the fork request passes its own, and resume and fork can move a box between sizes.

Available options:
small,
default,
large,
xlarge
ttlSeconds
integer | null
default:3600

Number of seconds before automatic archival. null disables auto-stop. The backend also accepts the string infinite for legacy compatibility; new clients should send null.

Required range: 1 <= x <= 2592000
env
object

Per-box environment variables injected into the box's tool environment, on top of the account environment's variables (per-box values win on conflicts). Keys must match [A-Za-z_][A-Za-z0-9_]{0,127}; at most 100 variables and 64KB total. Reserved names (ASCII_TOKEN, ASCII_API_URL, AGENT_ID, PRODUCT_MODE, ENVIRONMENT_ID, BOX_ID, SERVICE_PREVIEW_TOKEN, BOX_CLI_TOKEN) are rejected with invalid_env. Forked boxes inherit the source box's env unless the fork request supplies its own env.

environment
string
default:base

Name of the Box environment to attach to this box. Environments are managed in the Box dashboard and bundle the repositories, secrets, and credential toggles a box gets. Omit to use your default environment (base unless you changed it). Unknown names are rejected with unknown_environment. An environment marked "safe for third parties" passes nothing to the box, exactly like noEnv.

Examples:

"base"

"customer-demos"

noEnv
boolean
default:false

Create a box with none of the secrets attached to your account (no environment variables, secret files, or credentials), confined to itself so it cannot act on your account or other boxes. For boxes you give to your own users. SSH, SCP, desktop, snapshots, and public URLs still work; pass env to give the box a secret of its own. A fork of a no-env box is always no-env. Equivalent to attaching an environment marked "safe for third parties".

setupScript
string

Shell script that runs on the box after it is ready. Ready means "ready to accept the user", not "setup done": the script starts in the background once provisioning completes and never blocks the box becoming usable. It runs as the box user via bash, with the box's environment applied, and its output goes to a log file on the box. Observe the outcome as setupStatus (pending/running/done/failed) and setupError on the box. Rejected with a 400 invalid_setup_script error when it is not a string or exceeds 64KB.

Maximum string length: 65536
org
string

Bill this box to a team you belong to (the team's shared wallet). Your own account id means personal billing. Listing, snapshots, and environments stay yours — the org is a wallet, not a shared workspace. Takes precedence over teamId and over the X-Box-Org / ?org= request scope.

teamId
string

Legacy alias for org. Ignored when org is also set.

from
string

Create the box from a named snapshot (saved with POST /named-snapshots, or box snapshot <id> <name> in the CLI). The box starts from that exact frozen state. Omitting type inherits the type the snapshot was saved from; env and no-env inherit from the snapshot's source box unless the request passes its own, with the same rules as forking.

Response

Box accepted for provisioning.

ok
boolean
required
Example:

true

type
string
required

Stable success envelope discriminator added by v1.

Allowed value: "box.created"
status
enum<string>
required
Available options:
provisioning
ttlSeconds
integer | null
required
box
object
required