sha256:3b94a4649fc325bad16e6813657e644ac8eb274e79fc5eedad110e7b6ede6249
Last pushed
9 days by cdupuis
Type
Sandbox Kit
Manifest digest
sha256:3b94a4649fc325bad16e6813657e644ac8eb274e79fc5eedad110e7b6ede6249
schemaVersion: "3"
displayName: OpenHands (mixin)
description: OpenHands as a mixin — the `uv`-installed CLI and its managed CPython in an overlay, with the Anthropic, Google and OpenAI credentials and the hook that resolves which Anthropic auth the host actually holds. Layer it onto a shell base and run `openhands`.
version: 1.16.0
kind: mixin
provides:
- [email protected]
capabilities:
- type: com.docker.sandbox/network-policy@1
config:
runtime:
allow:
- api.anthropic.com
- platform.claude.com
- api.openai.com
- generativelanguage.googleapis.com
- github.com
- api.github.com
- raw.githubusercontent.com
- pypi.org
- registry.npmjs.org
- api.tavily.com
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.anthropic.com
format: '%s'
header: x-api-key
name: ANTHROPIC_API_KEY
proxyManaged: true
oauth:
credentialFile:
path: ~/.claude/.credentials.json
structure:
claudeAiOauth:
accessToken: '{{.AccessToken}}'
expiresAt: '{{.ExpiresAt}}'
refreshToken: '{{.RefreshToken}}'
scopes: '{{.Scopes}}'
resourceHosts:
- api.anthropic.com
sentinels:
accessToken: sk-ant-oat01-proxy-managed
refreshToken: sk-ant-ort01-proxy-managed
tokenEndpoint:
host: platform.claude.com
path: /v1/oauth/token
phase: runtime
service: anthropic
description: Anthropic API access (API key or claude.ai OAuth)
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: generativelanguage.googleapis.com
format: '%s'
header: x-goog-api-key
name: GEMINI_API_KEY
proxyManaged: true
phase: runtime
service: google
description: Google Gemini API access
- type: com.docker.sandbox/credential@1
optional: true
config:
apiKey:
inject:
- domain: api.openai.com
format: Bearer %s
header: Authorization
name: OPENAI_API_KEY
proxyManaged: true
phase: runtime
service: openai
description: OpenAI API access
- type: com.docker.sandbox/lifecycle@1
config:
startup:
- command:
- sh
- /home/agent/.local/bin/openhands-anthropic-auth.sh
description: Resolve whether Anthropic auth is an API key, an OAuth login, or absent, and record it for `openhands-start` and `sbx exec` shells
env:
- SBX_CRED_ANTHROPIC_MODE
user: "1000"
- type: com.docker.sandbox/agent-context@1
config:
contentFile: /usr/share/sandbox/kit/openhands-mixin/openhands-mixin-context.md
args:
version:
default: 1.16.0
description: OpenHands release to install
pattern: ^[0-9]+\.[0-9]+\.[0-9]+$
buildArg: OPENHANDS_VERSION