What is SSH?
SSH (Secure Shell) is the protocol for logging in to a remote computer and running commands over an encrypted connection.
runtime sandbox ssh <id> opens a shell in a Runtime sandbox with no port
open to the internet and no key to copy: the CLI makes a key on first use,
sends only its public half, and carries the session over Runtime's
authenticated API. The same sandbox opens in VS Code or a JetBrains IDE as the
host <id>.runtime (SSH and editors).
What the protocol is
RFC 4251, published in January 2006, opens: "The Secure Shell (SSH) Protocol is a protocol for secure remote login and other secure network services over an insecure network." It has three layers:
| Layer | What it does |
|---|---|
| Transport | Authenticates the server, encrypts and checks every byte |
| User authentication | Proves who the client is: a key, a password, a certificate |
| Connection | Splits the one encrypted tunnel into channels: shells, commands, forwarded ports |
The connection layer is why one SSH session can carry a terminal, a file copy and a forwarded port at the same time.
SSH and a sandbox
A server on the internet has to listen on port 22 and defend it. A sandbox does not: Runtime's API authenticates you with your key, then joins your SSH client to the sandbox over one WebSocket, so nothing in the sandbox is reachable from outside. Each login gets a fresh host key, so the entry the CLI writes skips host-key checks on purpose; the connection already goes to the sandbox you named.
runtime sandbox ssh <id> -- make testruns one command and exits with its code.runtime sandbox ssh config --installmakesssh,scpandrsyncwork with<id>.runtime.- A sandbox from a custom image gets
openssh-serverinstalled on first use.
Related
- How to SSH into a sandbox
- How to use VS Code Remote SSH with a sandbox
- What is SSH port forwarding?
- What is a remote development environment?
Sources
Checked 27 September 2026.