Can agents reach the internet from a sandbox?

Only as your deployment allows: open, a domain allow-list, or workspace-only. The posture is stated to the agent, and connectors go through the broker either way.

Sandbox egress is a deployment setting with three postures: open, a domain allow-list, or workspace-only (the sandbox can reach the platform and nothing else). Whatever the posture, connector calls are brokered through the Context server with credentials issued per action. Air-gapped deployments run closed; VPC deployments commonly allow-list the model endpoint and the systems a workflow needs.

Written for it and security, deployment engineers. Last reviewed 2026-09-15.

Still need an answer?

Tell us what you were looking for and we reply within one business day.

Contact the team →

Running a security review?

Documents, controls, and the request form live in the Trust Center.

Open the Trust Center →

Something to report?

Security findings go straight to the people who fix them.

security@context.ai