| name | opencomputer |
| description | Manage OpenComputer cloud sandboxes. Use when the user wants to create, run commands in, checkpoint, or manage sandbox environments. Auto-invokes when sandboxes, remote environments, or the oc CLI are mentioned. |
| allowed-tools | Bash(oc *), Bash(which oc), Bash(curl *), Bash(open *), Bash(xdg-open *), Bash(chmod *), Read, Grep, Glob |
You have access to the oc CLI for managing OpenComputer cloud sandboxes. Use it to create sandboxes, execute commands, manage checkpoints, and more.
First-time setup (run this BEFORE any other oc command)
Before running any sandbox command, make sure the user is set up. Do these checks in order, only fixing what's broken:
1. Is the oc CLI installed?
which oc
If it returns a path → installed, skip to step 2.
If it returns nothing / non-zero exit → install it with the official one-liner:
curl -fsSL https://raw.githubusercontent.com/diggerhq/opencomputer/main/scripts/install.sh | bash
This installs oc to ~/.local/bin/oc. If ~/.local/bin is not on the user's PATH, tell them to add export PATH="$HOME/.local/bin:$PATH" to their shell rc file, and use the full path ~/.local/bin/oc for the rest of this session.
2. Is the user logged in?
oc whoami
If it succeeds → logged in, you're done.
If it fails because no credential is configured, OR a sandbox command fails
with an auth error (401, "unauthorized", "missing API key"):
- Run:
oc login
- Relay the complete browser URL and short confirmation code printed by the
command to the user.
- Leave the command running while the user approves it in their browser. It
resumes automatically after approval.
Do not ask for an API key in chat. For CI or service automation, the user
may instead configure OPENCOMPUTER_API_KEY themselves.
CLI Reference
Sandbox Lifecycle
oc sandbox create --timeout 300 --cpu 1 --memory 512
oc sandbox create --env KEY=VALUE --env KEY2=VALUE2
oc sandbox create --secret-store my-secrets --metadata project=demo
oc create
oc sandbox list
oc ls
oc sandbox get <sandbox-id>
oc sandbox kill <sandbox-id>
oc sandbox hibernate <sandbox-id>
oc sandbox wake <sandbox-id> --timeout 300
oc sandbox set-timeout <sandbox-id> <seconds>
Execute Commands
oc exec streams stdout/stderr live by default and exits with the remote process's exit code. Use --wait for buffered/synchronous execution (needed for --json), or --detach to fire-and-forget.
oc exec <sandbox-id> -- echo hello
oc exec <sandbox-id> --cwd /app -- npm install
oc exec <sandbox-id> --timeout 120 -- make build
oc exec <sandbox-id> --env NODE_ENV=production -- node server.js
oc exec <sandbox-id> --wait --json -- whoami
oc exec <sandbox-id> --detach -- long-running-job
oc exec list <sandbox-id>
oc exec attach <sandbox-id> <session-id>
oc exec kill <sandbox-id> <session-id>
Checkpoints
Checkpoints snapshot a running sandbox. You can restore to a checkpoint (in-place revert) or spawn new sandboxes from one (fork).
oc checkpoint create <sandbox-id> --name "after-setup"
oc checkpoint list <sandbox-id>
oc checkpoint restore <sandbox-id> <checkpoint-id>
oc checkpoint spawn <checkpoint-id> --timeout 300
oc checkpoint delete <sandbox-id> <checkpoint-id>
Checkpoint Patches
Patches are scripts applied when sandboxes are spawned from a checkpoint. Use them to customize forked environments.
oc patch create <checkpoint-id> --script ./setup.sh --description "Install deps"
echo "apt install -y curl" | oc patch create <checkpoint-id> --script -
oc patch list <checkpoint-id>
oc patch delete <checkpoint-id> <patch-id>
Preview URLs
Expose a sandbox port via a public URL.
oc preview create <sandbox-id> --port 3000
oc preview create <sandbox-id> --port 8080 --domain myapp.example.com
oc preview list <sandbox-id>
oc preview delete <sandbox-id> <port>
Interactive Shell
oc shell <sandbox-id>
oc shell <sandbox-id> --shell /bin/zsh
Global Flags
All commands support:
--json — output as JSON instead of tables
--api-key <key> — override API key
--api-url <url> — override API URL
Workflow Patterns
Create and use a sandbox
ID=$(oc create --json | jq -r '.sandboxID')
oc exec $ID --wait -- apt update
oc exec $ID --wait -- apt install -y nodejs
oc exec $ID -- node -e "console.log('hello')"
oc sandbox kill $ID
Checkpoint workflow (setup once, fork many)
ID=$(oc create --json | jq -r '.sandboxID')
oc exec $ID --wait -- apt update
oc exec $ID --wait -- apt install -y python3 pip
oc exec $ID --wait -- pip install flask
CP=$(oc checkpoint create $ID --name "python-flask" --json | jq -r '.id')
oc checkpoint list $ID
FORK1=$(oc checkpoint spawn $CP --json | jq -r '.sandboxID')
FORK2=$(oc checkpoint spawn $CP --json | jq -r '.sandboxID')
Add a patch to customize forks
oc patch create $CP --script ./inject-config.sh --description "Add app config"
Important Notes
- Always use
--json and parse with jq when you need to extract IDs or fields programmatically.
- Sandbox IDs look like
sb-xxxxxxxx. Checkpoint IDs are UUIDs.
- Checkpoints take a few seconds to become
ready. Poll with oc checkpoint list if needed.
- Use
oc sandbox kill to clean up sandboxes when done.
- The
oc exec command exits with the remote process exit code.