Skip to main content
The Kernel kit is a Docker Sandboxes mixin that gives any sbx agent:
  • Kernel CLI (@onkernel/cli) installed at sandbox creation
  • Kernel agent skills from kernel/skills, so Claude Code (and any agent that reads ~/.agents/skills) can drive Kernel without prompting
  • Proxy-managed KERNEL_API_KEY — your real key stays on the host. The sbx proxy injects it as Authorization: Bearer … on requests to api.onkernel.com. The agent inside the sandbox never sees the secret.
The last point is the main reason to use this kit over installing @onkernel/cli yourself inside a custom kit.

Quickstart

Claude calls kernel inside the sandbox → CLI hits api.onkernel.com → the sbx proxy attaches your KERNEL_API_KEY → the request authenticates as you. The kit’s full spec.yaml, install commands, and allowed domains live in the repo README.

Prerequisites

Customizing or extending

For everything not specific to Kernel — loading kits from local paths or OCI registries, stacking multiple mixins, building your own agent kit, debugging the proxy, sbx kit add for running sandboxes — see Docker’s kit reference. The Kernel kit is a standard mixin and composes with anything else you put on top.

Next steps