Get the Tenant's sandbox configuration
managementKeyAuthorizationBearer <token>A management key of the Tenant (role management): it reaches the Management API (/v1/tenant/*) and /v1/me, as itself, never for a subject. Issued only on the Tenant's machine (nylorun-operate keys put <id> --role management) or from NYLORUN_MANAGEMENT_KEY_FILE. Never accepted from a browser (Origin).
Nylorun-Protocol*stringThe protocol version, 8
The backend in use and the configuration in force
application/json- response
preference*|backend*|"virtual""local"nullisolation*|"process""container"nullreason*stringprobes*array<>defaultImage*stringconfig*cluster?|nullimport { createAdmin } from "@nylorun/admin";const admin = createAdmin();const sandbox = await admin.settings.sandbox.get();{ "preference": "auto", "backend": "virtual", "isolation": "process", "reason": "string", "probes": [ { "name": "virtual", "available": true, "isolation": "process", "reason": "string", "version": "string" } ], "defaultImage": "string", "config": { "default": "none", "limits": { "network": [ "string" ], "resources": { "cpus": 0, "memoryMiB": 0 }, "defaultResources": { "cpus": 0, "memoryMiB": 0 }, "idle": "string", "sandboxes": 0, "ttl": "string" }, "lifecycle": { "onExpiry": "retain", "stopGrace": "string" }, "placement": { "property1": { "hosts": [ "harness-container" ] }, "property2": { "hosts": [ "harness-container" ] } } }, "cluster": { "namespace": "string", "context": "string", "ready": true, "controllerVersion": "string", "networkPolicy": { "enforced": true, "probedAt": "string" } }}Finish an MCP OAuth connect GET
Where the authorization server sends the browser back with `code` and `state` (or `error`). Exchanges the code once and stores the credential; answers a small HTML page. Needs no credential and no `Nylorun-Protocol`. A `state` is used once, for ten minutes (`oauth_state_invalid`).
Set the Tenant's sandbox configuration PUT
What a session gets when it names no sandbox, and the limits every session's sandbox must fit.