diff --git a/docs.json b/docs.json
index 7922cd0a..e59f4a1a 100644
--- a/docs.json
+++ b/docs.json
@@ -145,7 +145,8 @@
"docs/sandbox/connect",
"docs/sandbox/pty",
"docs/sandbox/ssh-access",
- "docs/sandbox/secured-access"
+ "docs/sandbox/secured-access",
+ "docs/sandbox/workload-identity"
]
},
{
diff --git a/docs/sandbox/workload-identity.mdx b/docs/sandbox/workload-identity.mdx
new file mode 100644
index 00000000..df453193
--- /dev/null
+++ b/docs/sandbox/workload-identity.mdx
@@ -0,0 +1,64 @@
+---
+title: "Workload identity"
+sidebarTitle: Workload identity
+description: "Give sandbox workloads short-lived identity tokens instead of long-lived secrets."
+---
+
+Workload identity lets code running in a sandbox prove who it is with short-lived identity tokens instead of long-lived credentials.
+Rather than baking cloud API keys into a template or passing them as environment variables, you define named workload tokens when creating the sandbox.
+Each token is scoped to an audience — the external service that will verify it, such as AWS STS — and the service can exchange the token for its own temporary credentials.
+
+
+Workload identity is currently available for selected teams. If it's not enabled for your team, sandbox creation with the `iam` option fails with `Sandbox IAM workload tokens are not available for your team.` — [contact us](/docs/support) to get access.
+
+
+## Configure
+
+Pass the `iam` option when creating a sandbox. A non-empty `tokens` map enables workload identity for the sandbox.
+Each entry maps a token name you choose to a token definition, which you can create with the `Secret` helper.
+
+
+```js JavaScript & TypeScript
+import { Sandbox, Secret } from 'e2b'
+
+const sandbox = await Sandbox.create({
+ iam: {
+ tokens: {
+ aws: Secret.iamToken({
+ audience: 'sts.amazonaws.com',
+ tokenType: 'JWT-SVID',
+ }),
+ },
+ },
+})
+```
+```python Python
+from e2b import Sandbox, Secret
+
+sandbox = Sandbox.create(
+ iam={
+ "tokens": {
+ "aws": Secret.iam_token(
+ audience="sts.amazonaws.com",
+ token_type="JWT-SVID",
+ ),
+ },
+ },
+)
+```
+
+
+You can also pass plain token definitions instead of using the `Secret` helper — `{ audience, tokenType }` objects in JavaScript, `{"audience": ..., "token_type": ...}` dicts in Python.
+
+## Token definitions
+
+Each token definition has two fields:
+
+| Field | Description |
+|-------|-------------|
+| `audience` | Required. The audience of the workload token — the identifier of the service that will verify it. Stored exactly as provided. |
+| `tokenType` (JavaScript) / `token_type` (Python) | Required. The workload token type. `"JWT-SVID"` is the only type supported today; more types may be added later. |
+
+Token names (the keys of the `tokens` map) are yours to choose and must not be empty. A sandbox can define up to **5** workload tokens.
+
+Creating a sandbox without the `iam` option, or with an empty `tokens` map, leaves workload identity disabled.