Durable sandbox orchestration for AI agents built on Durable Workflow. The package provides a reusable Laravel workflow for provisioning a sandbox, dispatching tool calls, checkpointing state, recovering from sandbox loss, and cleaning up resources. Provider-specific APIs stay behind versioned contracts.
The package is currently published on the 2.0 release-candidate channel. The Durable Workflow runtime it uses is stable 2.x.
composer require durable-workflow/ai:^2.0@RC
php artisan vendor:publish --tag=durable-workflow-ai-configLaravel discovers DurableWorkflow\AI\Laravel\SandboxServiceProvider
automatically. The package requires PHP 8.2 or newer, Laravel 12 or newer, and
the embedded Durable Workflow runtime.
use DurableWorkflow\AI\Workflows\SandboxAgentWorkflow;
use Workflow\V2\WorkflowStub;
$workflow = WorkflowStub::make(SandboxAgentWorkflow::class);
$workflow->start(
toolCalls: [
[
'type' => 'write_file',
'args' => [
'path' => 'README.md',
'contents' => "# Agent workspace\n",
],
],
['type' => 'shell', 'args' => ['command' => 'ls -la']],
],
provider: 'e2b',
snapshotEveryNCalls: 10,
);Configure E2B before starting the application worker:
DURABLE_AI_SANDBOX_DRIVER=e2b
E2B_API_KEY=
E2B_TEMPLATE_ID=basephp artisan queue:workEvery tool call receives a stable operation ID. The workflow can restore its latest snapshot after sandbox loss and replay every completed later call before continuing. Success, cancellation, and failure all enter the cleanup path; provider leases remain the final cleanup bound when deletion cannot complete.
| Provider | Intended use | Snapshot recovery | Suspend and resume |
|---|---|---|---|
e2b |
Remote agent sandboxes | Yes | No |
local |
Development and deterministic tests | Yes | Yes |
| Custom | Any adapter implementing the versioned provider contract | Capability-dependent | Capability-dependent |
The local provider runs subprocesses with the application worker's privileges. It is not a security boundary and must not execute untrusted code.
See the provider-author guide to register E2B, Modal, Daytona, Kubernetes, or another sandbox backend without changing workflow code.
The package makes effect delivery, snapshot ownership, recovery, leases, and cleanup behavior explicit. Built-in providers currently advertise at-least-once effects because neither remote HTTP execution nor a local process can atomically commit an arbitrary tool effect with a Durable Workflow acknowledgement.
Read the delivery and recovery guarantees for the full contract, including operation deduplication, checkpoint replacement, post-snapshot reconstruction, and retained-snapshot ownership.
composer install
composer format
composer stan
composer testShared contribution, security, and release guidance lives in the Durable Workflow organization guide.
Durable Workflow AI is open-source software licensed under the MIT license.