Sandbox lifecycle
Create, attach to, and tear down sandboxes.Archive Sandbox
Delete conversations to release their Persistent Volume Claims (PVCs) and free storage resources.
Clone and Attach
Clone a repository and run its setup script in a sandbox, then attach a conversation to the prepared environment.
Start Sandbox
Start a sandbox without a conversation and run commands via the agent-server REST API.
Conversation monitoring & reacting
Observe conversations and react to their state.Conversation Tags
Attach key-value metadata to a conversation with tags and read it back from AppConversation.tags.
Secrets & authentication
Inject credentials and manage identity.GPG Commit Signing
Configure GPG commit signing on every conversation with a SessionStart hook that imports a key from a custom secret.
Per-Conversation Secrets
Inject per-conversation secrets via REST API as bash env vars and to template an MCP server config bundled in a plugin.
Service Account GitHub PAT
Use one OpenHands account as a service account, overriding the managed GITHUB_TOKEN with each user’s PAT per conversation.
Guardrails
Constrain what the agent can do with hooks.Command Blacklist
Block known-dangerous shell commands with a PreToolUse hook bundled in a plugin. Everything not on the blocklist runs normally.

