Skip to main content
A session is an isolated cloud sandbox where coding agents (Claude Code, Codex, Cursor CLI, and others) run, edit files, execute commands, and ship code with live preview URLs. The endpoints on this page cover the full lifecycle of a session resource. For pause/resume/start, see Lifecycle. For long-running prompts, see Prompts. For real-time streaming, see WebSockets.
Required scopes per operation:
  • sessions:read - list, get
  • sessions:write - create
  • sessions:delete - destroy
See Scopes & Permissions for the full catalog.
All session endpoints honor X-Organization-Id. Personal keys may omit the header to operate on personal sessions; org keys must use the header that matches the key’s organization.

List Sessions

GET /api/sessions Returns a paginated list of sessions visible to the caller. Personal keys see only organization_id = NULL sessions; org keys see sessions in the active organization. Pass team_mode=true with an org key to see sessions other org members have explicitly shared with the team (visibility = "team").

Query Parameters

boolean
default:"false"
Include sessions in destroyed or error states.
integer
default:"20"
Page size (1-100).
integer
default:"0"
Pagination offset.
boolean
default:"false"
When true and an org context is set, return sessions other members shared with the team. Your own private sessions appear under the default “you” view, not here.
string
Comma-separated list of source values to exclude (e.g. agents,api).
string
Comma-separated session states to exclude (e.g. destroyed,destroying).

Response

array
Paginated session objects.
integer
Total sessions matching the filters.
integer
Echo of the request limit.
integer
Echo of the request offset.
boolean
true when offset + limit < total.

Create Session

POST /api/sessions Provisions a new sandbox. The response returns immediately with state creating; poll GET /api/sessions/{id} (or call POST /api/sessions/{id}/start) until state = "running".
Background-agent sessions (e.g. source = "api") require a stored Anthropic API key. Configure one in the dashboard under Settings → Integrations → Anthropic, or set it via Provider Keys. Without a stored key, this endpoint returns 400.

Body Parameters

string
Project scaffold to use (web-app, backend-service, static-site). Optional - sessions can also start blank or attach to a GitHub repo.
string
default:"claude-code"
One of: claude-code, codex, opencode, github-copilot, cursor-cli, devin-cli, gemini-cli.
string
default:"autopilot"
autopilot (auto-approve actions) or interactive (allows the agent to ask for confirmation).
object
Single GitHub repo metadata for tier selection and auto-clone.
array
Up to 5 repos for multi-repo sessions. Takes precedence over github_repo. First entry is treated as the primary repo. Each entry mirrors the github_repo schema.
string
Free-form attribution string. Customers calling from automation typically use api. Internal source values (used by Slack/Linear bots and the dashboard) are not part of the public contract and must not be relied on.
string
Lifecycle action after a prompt finishes: pause, destroy, or keep_alive. Defaults to keep_alive for interactive sessions.
integer
Hard maximum lifetime in minutes (1-1440). Sessions exceeding this are destroyed regardless of activity. Recommended for unattended agent runs.

Response

string
Session UUID.
string
Initial state, usually creating.
string
Agent identifier.
string
Resolved template name.
string
ISO 8601 timestamp.
string
When the session will expire.
string
Working directory inside the sandbox. Non-/home/user values indicate an org template with code already baked into the image.
array
Additional repos to clone after the session starts (when not baked into a template image).

Get Session

GET /api/sessions/{session_id} Returns the full session object. By default (refresh=true), the backend reconciles the cached state with the actual sandbox before responding, which catches sandboxes that were destroyed externally.

Path Parameters

string
required
Session UUID.

Query Parameters

boolean
default:"true"
When true, verify the sandbox exists in the provider before responding. Pass false for snappier reads when staleness is acceptable.

Response

Same shape as the items in List Sessions.

Destroy Session

DELETE /api/sessions/{session_id} Marks the session as destroying and returns immediately. The sandbox teardown and any session-scoped key revocation finish in the background, so the session may briefly remain visible in destroying state before flipping to destroyed. This action is permanent - destroyed sessions cannot be resumed. To preserve filesystem and memory state, use Pause instead.

Path Parameters

string
required
Session UUID.

Response

string
Session UUID.
string
ISO 8601 timestamp of when destruction was initiated.
string
Human-readable confirmation.