Skip to content

Replace the Chat sandbox when its pasted key entries change - #820

Merged
czpython merged 1 commit into
mainfrom
fix/chat-sandbox-key-entries
Oct 3, 2026
Merged

czpython merged 1 commit into
mainfrom
fix/chat-sandbox-key-entries

Conversation

@czpython

@czpython czpython commented Oct 3, 2026 •

Copy link
Copy Markdown
Owner

Drukbox binds the entries of a pasted API key when it creates a box. Chat matched the account's sandbox only by the secrets the box fetches, so a new key, or a harness that reads the key from another variable, kept the old sandbox. For example, after a switch from OpenCode to Codex on one OpenAI key, Codex failed with "The sandbox environment lacks CODEX_API_KEY."

AgentConfig.secrets_id becomes secrets_hash, a SHA-256 digest in both billing modes: of the pasted key's version and its entries without the value, or of the subscriptions the box fetches. A sandbox identity now records the hash of the agent config that created its box. Chat replaces the sandbox when the hash changes, as docs/chat.md already describes for a change of the Chat credentials. Workflow boxes record the hash too.

@czpython
czpython force-pushed the fix/chat-sandbox-key-entries branch from b713fd1 to c475733 Compare October 3, 2026 16:18
@czpython
czpython merged commit c42edb0 into main Oct 3, 2026
4 checks passed
@czpython
czpython deleted the fix/chat-sandbox-key-entries branch October 3, 2026 16:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant