E2b Opencode
OpenCode plugin that runs every session in an E2B sandbox whose vendor API calls are answered by a Veris twin, with a receipt of what the vendor received.
0
58
30.9
Multi-signal model
4 days ago
2026-09-30
Install and configure
opencode.jsonWrites to this project's opencode.json — applies to this repository only.
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@veris-ai/e2b-opencode@0.2.0"]
}Writes to ~/.config/opencode/opencode.json — applies to every project.
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@veris-ai/e2b-opencode@0.2.0"]
}If you want to modify the plugin locally, install it into the project and reference the local path.
shell
pnpm add -D @veris-ai/e2b-opencodeOpenCode loads npm dependencies through its embedded runtime on startup and caches them locally — no manual global install needed.
Veris interception for E2B: vendor API calls made inside an E2B sandbox are answered by a stateful Veris twin, and every run ends with a receipt of what the vendor actually received.
Three packages, one repo, because they move together.
| package | what it is |
|---|---|
@veris-ai/e2b |
The SDK. A drop-in subclass of E2B's Sandbox whose create() also provisions the twin, points the sandbox's egress at the Veris gateway and installs the interception CA — and whose kill() deletes the twin with it. |
@veris-ai/e2b-opencode |
An OpenCode plugin. One line in opencode.json and every session in that repo runs in a Veris-intercepted sandbox. |
veris-e2b |
The same SDK in Python — Sandbox and AsyncSandbox subclassing e2b's, with the same options in snake_case. Gateway mode only; what differs. |
@veris-ai/e2b@0.1.1 is SDK-only. This PR adds no CLI;
CLI draft #22 is separate and
requires a future npm release before its commands can be used.
Shared skills in OpenCode
Use the canonical @veris-ai/veris-opencode skills package plus one sandbox
plugin after the pending skills 0.7.3 and provider 0.2.0 releases are published:
{
"plugin": [
"@veris-ai/veris-opencode@latest",
"@veris-ai/e2b-opencode@latest"
]
}
The commands are /veris:setup, /veris:build <request> and /veris:fix <request>.
verisSkill reads installed skill resources on the host; application file/bash
tools remain remote. verisTwin identifies the plugin-owned session and controls,
and verisReceipt takes an explicit pre-execution baseline. Skills reuse this
session automatically. Record and pin the resolved published npm versions.
See e2b-opencode/README.md for the capability
contract, separate network/TLS/persistence/sync behavior and release prerequisites.
The SDK
import { Sandbox } from '@veris-ai/e2b' // was: 'e2b'
const sbx = await Sandbox.create()
await sbx.commands.run('curl -sS https://api.stripe.com/v1/customers -u sk_test_veris:')
await sbx.veris.assertTouched('stripe')
await sbx.kill()
Every E2B option still works — it is a real subclass — so an existing template
or workflow keeps working with the import changed. Details in
e2b/README.md and e2b/docs/reference.md.
The OpenCode plugin
// opencode.json
{ "plugin": ["@veris-ai/e2b-opencode"] }
The agent's bash, read, write and the rest execute in the sandbox while the
reasoning loop stays on your machine — so the sandbox never holds your model
key. Adds a verisReceipt tool, because an agent that fabricated an API response
and one that really called it produce identical transcripts. They produce
different receipts. See e2b-opencode/README.md.
The Python SDK
from veris_e2b import Sandbox, VerisOpts
sbx = Sandbox.create(veris=VerisOpts(environment_id="env_…", snapshot_id="snap_…"))
sbx.commands.run("curl -sS https://api.stripe.com/v1/customers -u sk_test_veris:")
sbx.veris.assert_touched("stripe")
sbx.kill()
AsyncSandbox is the same thing for callers already inside an event loop. Details
in python/README.md.
Install
npm i @veris-ai/e2b # the SDK
npm i @veris-ai/e2b-opencode # the OpenCode plugin (pulls the SDK with it)
uv add veris-e2b # the Python SDK
Both packages version together, so a given plugin version always resolves the SDK it was built against.
Working in this repo
npm install # links both node workspaces
npm run build # must come first, see CONTRIBUTING.md
npm run typecheck
npm test # unit tests for both node packages
npm run test:live # SDK only; needs E2B_API_KEY, VERIS_API_KEY, VERIS_ENVIRONMENT_ID
cd python && uv sync && uv run pytest # the Python package, independently
The Python package is its own uv project rather than a workspace member: it shares the control-plane contract with the TypeScript SDK, not a toolchain.
Releases are cut from the Actions tab — see CONTRIBUTING.md.
Similar plugins
Atelier
@konfeature/opencode-atelier
OpenCode plugin that dispatches coding tasks to Atelier sandboxes (self-hosted Kata Containers dev environments).
Daytona Opencode
@veris-ai/daytona-opencode
Run every OpenCode session in a Daytona sandbox whose vendor API calls are answered by a Veris twin. One line in opencode.json: unmodified code, real hostnames, and a receipt of what the vendor actually received.
Seatbelt
opencode-seatbelt
macOS Seatbelt (kernel sandbox) for OpenCode. Stops coding agents from reading secrets, enforced by the OS, not by command matching.