Skip to content
Metamynd
Developers · Sandbox

The Developer Sandbox

Your first allow / observe / block / escalate in minutes — no account, no KYB, nothing to provision. A public endpoint hands you a ready, governed sandbox agent.

01

What you get

  • A shared, pre-issued sandbox agent
  • A real mandate, Standards and a spend-cap SOP
  • Live allow / observe / block / escalate against the gate
  • Zero provisioning — one command or one HTTP call
02

Step 1 — scaffold (about 10 seconds)

The one command calls a public endpoint that hands back a ready governed identity, then writes a small project into ./metamynd-sandbox. Expect a line confirming a did:hedera:testnet:… agent. Nothing is installed globally and no account is created.

03

What the scaffold contains

  • agent.metamynd.json — the agent's DID, signing key and the API base the guard calls (freshly generated for this sandbox agent at scaffold time — a LATER "Redownload config" from the dashboard for this same agent never re-issues the key into the file)
  • index.mjs — one tool wrapped in guard.guardTool(), so it only runs when the gate allows
  • package.json — a single dependency, @metamynd/agentsafe-guard
04

Step 2 — install and run

npm install pulls the guard, which has no dependencies of its own. npm start then runs four attempts, each signed locally. The guard first checks every attempt against the agent's signed policy bundle: what that bundle already refuses stops right there, with no network call, and is reported to the gate for audit. Everything else is sent to the gate, which decides against the sandbox agent's mandate and SOP and records the decision as anchored evidence. Neither path is a mock: the local check runs the same evaluator over the same signed rules the gate uses.

05

Step 3 — read the four verdicts

  • ✅ ALLOW $250 — decided by the gate: inside the mandate and under the SOP's spend cap
  • ⛔ BLOCK $600 (SOP_SPEND_CAP) — decided locally from the signed rules, then reported; the tool never runs
  • ⚠ ESCALATE $250 high risk (RISK_REVIEW) — decided by the gate and held for a human. Nobody can approve it on the shared sandbox; provision your own agent to try approval.
  • ⛔ BLOCK permissions.update (NO_PERMISSION_FOR_ACTION) — the agent asks to raise its own limit; decided locally, because the mandate never granted that action
06

Which verdicts are evidence

Gate decisions are signed, Merkle-batched and anchored, and appear in the Activity Log as decided by the Gate. A refusal the guard made locally is an agent-reported receipt: it is recorded, labelled “Agent-reported · local, not anchored”, and is not anchored evidence. For a boundary a compromised agent cannot skip, scaffold without --sandbox: the default shape adds a separate gateway process that re-verifies every request itself.

07

If every line comes back BLOCK

A verdict of GATE_UNREACHABLE (no connection at all), GATE_HTTP_404 or any other GATE_HTTP code means the guard could not get a decision from the gate and failed closed — the safe default, not a policy decision. Check that apiBase in agent.metamynd.json starts with https: an http base gets redirected, and a redirected POST is retried as a GET, which no gate route answers. Re-run the scaffold for a fresh config.

08

From sandbox to production

The sandbox runs the identical governance engine as production — same gate, same code path, same enforcement. What actually changes: your principal needs KYC/KYB verification to issue a real mandate, and you supply your own spend limits and merchants instead of the fixed demo ones. The guard code itself doesn't change.

Example

See it in code

try-the-sandbox.sh
# 1. Scaffold a governed agent (no account, no KYB)
npx create-metamynd-agent --sandbox

# 2. Install the guard and run the example.
#    One command per line — PowerShell 5 rejects '&&' as a separator.
cd metamynd-sandbox
npm install
npm start

# 3. Four verdicts. The gate decides what the signed rules allow;
#    what they already refuse is decided locally, then reported:
#      ✅ ALLOW    $250 low risk        → AUTHORIZED          (gate)
#      ⛔ BLOCK    $600 over cap        → SOP_SPEND_CAP       (local, reported)
#      ⚠  ESCALATE $250 high risk       → RISK_REVIEW         (gate)
#      ⛔ BLOCK    raise its own limit  → NO_PERMISSION_FOR_ACTION (local, reported)
#
#    Every line BLOCK with GATE_UNREACHABLE or GATE_HTTP_404? The guard could
#    not reach the gate and failed closed. Check apiBase in agent.metamynd.json is https.

# …or skip the scaffold — one HTTP call returns a ready agent config
curl -X POST https://metamynd.ai/api/v1/onboarding/sandbox

# PowerShell: 'curl' is an alias for Invoke-WebRequest and rejects -X.
# Use the native cmdlet instead:
#   Invoke-RestMethod -Method Post -Uri https://metamynd.ai/api/v1/onboarding/sandbox

Prepare your organisation for the Agentic Economy