Sandbox
Create, refresh, and login to sandboxes
sfp sandbox createsfp sandbox deletesfp sandbox delete-with-cleanupsfp sandbox listsfp sandbox loginsfp sandbox reset-passwordssfp sandbox updatesfp sandbox validate
sfp sandbox create
Create a sandbox.
USAGE
$ sfp sandbox create -v <value> [--json] [-s <value> [-n <value> | -f <value>]] [--activation-user-group <value>]
[-d <value>] [--loglevel trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-d, --description=<value> Description for the sandbox being created
-f, --definition-file=<value> Sandbox definition file. Multiple inputs possible by comma seperated list.
-n, --name=<value> Sandbox name(s). Multiple inputs possible by comma seperated list.
-s, --sourcesandbox=<value> Provide the name of the source sandbox where the sandbox should be cloned from
-v, --targetdevhubusername=<value> (required) Username or alias of the Dev Hub org.
--activation-user-group=<value> Name of the Public Group whose members are activated (able to log in) on create;
everyone else is frozen. Required by Salesforce for Developer and Developer Pro
sandboxes.
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
GLOBAL FLAGS
--json Format output as json.
DESCRIPTION
Create a sandbox.
Start a sandbox create process for all specified names from the input flag.
ALIASES
$ sfp org create sandbox
EXAMPLES
$ sfp sandbox:create -v MyDevHub -n MySandbox1 -s SourceSandboxsfp sandbox delete
Delete a sandbox.
USAGE
$ sfp sandbox delete -n <value> -v <value> [--json] [--loglevel
trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-n, --name=<value> (required) Sandbox name(s). Multiple inputs possible by comma seperated list.
-v, --targetdevhubusername=<value> (required) Username or alias of the Dev Hub org.
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
GLOBAL FLAGS
--json Format output as json.
DESCRIPTION
Delete a sandbox.
Start a sandbox deletion process for all specified names from the input flag. The process includes only sandboxes with
status "Completed"
ALIASES
$ sfp org delete sandbox
EXAMPLES
$ sfp sandbox:delete -n SIT -v my-sandbox-orgsfp sandbox delete-with-cleanup
Delete a sandbox with full cleanup of associated resources.
USAGE
$ sfp sandbox delete-with-cleanup -n <value> -v <value> [--json] [-r <value>] [-e <value>] [-t <value>] [--sfp-server-url
<value>] [--delete-environments] [--unregister-org] [-f] [--loglevel
trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-e, --email=<value> Email address for authenticated user. Ignored if --application-token is provided.
Can be set via SFP_SERVER_USER env var.
-f, --force Skip confirmation prompts.
-n, --name=<value> (required) Name of the sandbox to delete.
-r, --repository=<value> Repository identifier for environment operations. Required when using
--delete-environments.
-t, --application-token=<value> Application token for CI/CD authentication. Can be set via SFP_SERVER_TOKEN env
var (CLI flags take precedence over env vars).
-v, --targetdevhubusername=<value> (required) Username or alias of the Dev Hub org.
--delete-environments Delete all environments associated with this sandbox.
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
--sfp-server-url=<value> URL of the SFP server. Can be set via SFP_SERVER_URL env var or config: sfp
config:set server-url
--unregister-org Unregister the sandbox org from sfp server after deletion.
GLOBAL FLAGS
--json Format output as json.
DESCRIPTION
Delete a sandbox with full cleanup of associated resources.
Deletes a sandbox from Salesforce and optionally cleans up all associated resources:
- Deletes all environments in sfp server that use this sandbox
- Unregisters the sandbox org from sfp server
This is a compound command that performs multiple operations in sequence, providing a single command for complete
sandbox cleanup.
EXAMPLES
$ sfp sandbox delete-with-cleanup -n mySandbox -v myProdOrg
$ sfp sandbox delete-with-cleanup -n mySandbox -v myProdOrg --delete-environments --repository myorg/myrepo
$ sfp sandbox delete-with-cleanup -n mySandbox -v myProdOrg --delete-environments --repository myorg/myrepo --unregister-org
$ sfp sandbox delete-with-cleanup -n mySandbox -v myProdOrg --force --jsonsfp sandbox list
This command displays the sandbox status from the given devhub.
USAGE
$ sfp sandbox list -v <value> [--json] [-n <value>] [-s
Pending|Processing|Completed|Deleted|Deleting|Discarding|Locked|Locking|Sampling|Stopped|Suspended|Activating]
[--loglevel trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-n, --name=<value> Name of the sandbox.
-s, --status=<option> [default: Completed] Status of the sandbox to be filtered on
<options: Pending|Processing|Completed|Deleted|Deleting|Discarding|Locked|Locking|
Sampling|Stopped|Suspended|Activating>
-v, --targetdevhubusername=<value> (required) Username or alias of the Dev Hub org.
--json output in json format
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
DESCRIPTION
This command displays the sandbox status from the given devhub.
ALIASES
$ sfp sandbox status
EXAMPLES
$ sfops sandbox:status --name mySandbox1 -v myDevHubsfp sandbox login
This command performs a login using the sandbox name.
USAGE
$ sfp sandbox login -n <value> [--json] [--repository <value>] [-e <value>] [-t <value>] [--sfp-server-url
<value>] [-p <value>] [-a <value>] [-s] [-w] [-v <value>] [--loglevel
trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-a, --alias=<value> Alias for the org.
-e, --email=<value> Email address for authenticated user. Ignored if --application-token is provided.
Can be set via SFP_SERVER_USER env var.
-n, --name=<value> (required) Name of the sandbox required for login.
-p, --production-username=<value> Username of the production org that owns the sandbox (for server-based auth)
-s, --set-default Set this org as the default org
-t, --application-token=<value> Application token for CI/CD authentication. Can be set via SFP_SERVER_TOKEN env
var (CLI flags take precedence over env vars).
-v, --targetdevhubusername=<value> Username or alias of the Dev Hub org.
-w, --write-file Write the results of the org into org_details.json, Please note this is sensitive
and contains access token, so please
ensure it is deleted
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
--repository=<value> The repository identifier. E.g `owner/repo` for GitHub/GitLab or
`org/project/repo` for Azure DevOps
--sfp-server-url=<value> URL of the SFP server. Can be set via SFP_SERVER_URL env var or config: sfp
config:set server-url
GLOBAL FLAGS
--json Format output as json.
DESCRIPTION
This command performs a login using the sandbox name.
ALIASES
$ sfp org login sandbox
EXAMPLES
$ sfp sandbox login --name mySandbox1 -v myDevHub
$ sfp sandbox login --name mySandbox1 --production-username admin@prod.com
$ sfp sandbox login -n dev1 -a dev1 # Auto-detects production org via serversfp sandbox reset-passwords
Reset the passwords of an activation user group's members inside a created/refreshed sandbox so each receives a "set your password" email and can log in.
USAGE
$ sfp sandbox reset-passwords -n <value> --activation-user-group <value> [--json] [--cap <value>] [-v <value>] [--loglevel
trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-n, --name=<value> (required) Name of the sandbox whose activation-group members get their passwords
reset.
-v, --targetdevhubusername=<value> Username or alias of the Dev Hub org.
--activation-user-group=<value> (required) Name of the Public Group (Selective Sandbox Access activation group)
whose members' passwords are reset.
--cap=<value> [default: 150] Maximum number of members to reset (activation groups should stay
under 150). Defaults to 150.
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
GLOBAL FLAGS
--json Format output as json.
DESCRIPTION
Reset the passwords of an activation user group's members inside a created/refreshed sandbox so each receives a "set
your password" email and can log in.
EXAMPLES
$ sfp sandbox reset-passwords -n dev1 --activation-user-group "Sandbox Access" -v myDevHubsfp sandbox update
Update/Refresh a sandbox.
USAGE
$ sfp sandbox update -v <value> [--json] [-n <value> | -f <value>] [--auto-activate] [--source-sandbox <value>]
[--activation-user-group <value>] [--apex-class-id <value>] [--template-id <value>] [--history-days <value>]
[--loglevel trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-f, --definition-file=<value> [default: config/sandbox-def.json] Sandbox definition file. Multiple inputs
possible by comma seperated list.
-n, --name=<value> Sandbox name(s). Multiple inputs possible by comma seperated list.
-v, --targetdevhubusername=<value> (required) Username or alias of the Dev Hub org.
--activation-user-group=<value> Name of the Public Group whose members are activated on refresh (Selective
Sandbox Access). Resolved to its Id and set as ActivationUserGroupId. When
omitted, the definition file value, then the existing SandboxInfo value, is
preserved.
--apex-class-id=<value> Id of the Apex class Salesforce runs after the refresh completes
(SandboxInfo.ApexClassId). When omitted, the definition file value, then the
existing SandboxInfo value, is preserved.
--[no-]auto-activate Set AutoActivate on the sandbox before submitting the refresh. Use
--no-auto-activate to disable. When omitted, the definition file value, then the
existing SandboxInfo value, is preserved.
--history-days=<value> Days of object history to copy (SandboxInfo.HistoryDays). When omitted, the
definition file value, then the existing SandboxInfo value, is preserved.
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
--source-sandbox=<value> Name of the sandbox to refresh from. Resolved to its SandboxInfoId and set as
SourceId. When omitted, the existing source is preserved (production if none).
--template-id=<value> Id of the sandbox template for Partial/Full copies (SandboxInfo.TemplateId). When
omitted, the definition file value, then the existing SandboxInfo value, is
preserved.
GLOBAL FLAGS
--json Format output as json.
DESCRIPTION
Update/Refresh a sandbox.
Start a sandbox refresh process for all specified names from the input flag.
ALIASES
$ sfp org update sandbox
EXAMPLES
$ sfp sandbox:update -o MyDevHub -n my-sandboxsfp sandbox validate
Validate a sandbox for create, delete, or refresh operations.
USAGE
$ sfp sandbox validate -o create|delete|refresh -v <value> [--json] [-n <value>] [-l
DEVELOPER|DEVELOPER_PRO|PARTIAL|FULL] [--loglevel
trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL]
FLAGS
-l, --licensetype=<option> License type for create validation (DEVELOPER, DEVELOPER_PRO, PARTIAL, FULL).
<options: DEVELOPER|DEVELOPER_PRO|PARTIAL|FULL>
-n, --name=<value> Name of the sandbox to validate (required for delete/refresh operations).
-o, --operation=<option> (required) The operation to validate for: create, delete, or refresh.
<options: create|delete|refresh>
-v, --targetdevhubusername=<value> (required) Username or alias of the Dev Hub org.
--loglevel=<option> [default: info] logging level for this command invocation
<options: trace|debug|info|warn|error|fatal|TRACE|DEBUG|INFO|WARN|ERROR|FATAL>
GLOBAL FLAGS
--json Format output as json.
DESCRIPTION
Validate a sandbox for create, delete, or refresh operations.
Validates that a sandbox is in the correct state for the specified operation and returns eligibility information
including any required wait time before the operation can proceed.
For create operations: Checks if sufficient sandbox licenses are available.
For delete/refresh operations: Checks if sandbox exists, is in a valid state, and calculates the eligibility wait time
based on license type.
Minimum age requirements for delete/refresh:
- Developer / Developer Pro: 1 day (24 hours)
- Partial Copy: 5 days
- Full: 29 days
EXAMPLES
$ sfp sandbox validate --operation delete --name mySandbox -v myProdOrg
$ sfp sandbox validate --operation refresh --name mySandbox -v myProdOrg --json
$ sfp sandbox validate --operation create --licensetype DEVELOPER -v myProdOrg