---
sourceDocument: Brazil API Reference
sourceDocumentLink: https://www.servicenow.com/docs/r/api-reference

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil API Reference

ft:clusterId :

    - crapiref

bundleId :

    - crapiref

workflow :

    - Creator


---

# Sandbox environment

# Script sandbox environment {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Script sandbox environment

The script sandbox environment in ServiceNow Brazil release provides a restricted server-side execution context for untrusted, client-generated scripts.
When scripts are sent to the server, trusted scripts run normally in the JavaScript engine, while untrusted scripts execute within this sandbox to enhance security.
Show full answer Show less  
This sandbox environment applies to scripts sent via filter or query parameters in URLs and the AJAXEvaluate API call. It does not apply to script includes or client-side scripts, which run outside the sandbox.

## Sandbox Restrictions

* Only business rules marked as **Client callable** and script includes marked as **Sandbox enabled** can be executed.
* Direct database modifications (insert, update, delete) are not allowed; calls like `current.update()` are ignored.
* Certain API calls, especially those involving direct database access, are restricted.
* From the Xanadu release onward, only script includes marked as **Sandbox enabled** are accessible; those previously marked as **Client callable** are no longer accessible within the sandbox.
* When upgrading to Brazil from Washington DC or earlier, script includes marked **Client callable** are automatically marked as **Sandbox enabled**.

## Script Sandbox Evaluators

Two evaluators enforce sandbox restrictions with varying levels of script support:

* **Guarded script evaluator:** Supports a restricted domain-specific scripting language allowing only simple expressions or function calls and a limited set of APIs. It provides enhanced security by detecting or rejecting unsupported JavaScript features. Guest transactions are fully enforced, and authenticated user scripts are evaluated depending on instance type.
* **Script sandbox evaluator:** Allows more JavaScript features but restricts certain APIs, especially those that could compromise security by enabling untrusted scripts to access sensitive functionality.

| Characteristic | Guarded script evaluator | Script sandbox evaluator |
|-|-|-|
| Purpose | Enhanced security with a restricted scripting language | Limits APIs to prevent execution of untrusted scripts |
| JavaScript support | Single simple expressions or function calls only; limited APIs | Supports most JavaScript features except restricted APIs/methods |
| When it runs | Evaluates untrusted scripts without guarded-script exemption | Evaluates untrusted scripts with guarded-script exemption or in detection phase |
| Script includes | Not applicable; script includes run outside sandbox | Not applicable; script includes run outside sandbox |
[Comparison of Guarded Script Evaluator and Script Sandbox Evaluator]

## Practical Impact for ServiceNow Customers

Understanding and utilizing the script sandbox environment helps ServiceNow customers safely execute untrusted client-generated scripts on their instances without compromising data integrity or security. By marking business rules and script includes appropriately (Client callable and Sandbox enabled), customers control which scripts can run in the sandbox. Awareness of evaluator differences assists in troubleshooting script execution issues and planning script upgrades or migrations between releases.  
The script sandbox environment is a restricted execution context in which untrusted, client-generated scripts run on the server using one of two evaluators: the guarded script evaluator or the script sandbox
evaluator.

## Script sandbox environment overview {#script-sandbox-environment__section_sandbox_overview}

When a script is sent to the server, a server-side script evaluator determines whether the script is trusted. Trusted scripts run in the JavaScript engine. Untrusted scripts run in the restricted sandbox environment instead.  
Note:  
The sandbox does not apply to script includes, which run in the application scope outside of the sandbox, or to client-side scripts.  
Untrusted scripts are client-generated and sent to the server for evaluation in the following ways:

* Filter or query parameters: Filter and query parameters in URLs can send scripts to the server with HTTP requests, such as when a logged-out user follows a link containing a javascript: filter parameter.
* System APIs: The AJAXEvaluate API call allows the client to run arbitrary scripts on the server and receive a response.
{#script-sandbox-environment__ul_tps_4pn_w3c}  
Within the sandbox, the following restrictions apply to scripts:

* Only business rules marked Client callable can be called.
* Only script includes marked Sandbox enabled can be called.
* Certain API calls, mostly limited to ones dealing with direct database access, aren't allowed.
* Data can't be inserted, updated, or deleted from within the sandbox. For example, any calls to current.update() are ignored.
{#script-sandbox-environment__ul_ncg_skn_g1c}  
Note:  
Beginning with the Xanadu release, script includes marked as Glide AJAX enabled (previously named Client callable) aren't accessible within the sandbox. Only those marked Sandbox enabled are available within the sandbox. When upgrading to the Brazil release from the Washington DC release or earlier, any script includes marked as Client callable are also marked as Sandbox enabled.

## Script sandbox evaluators {#script-sandbox-environment__section_nvd_2tn_w3c}

The sandbox uses two evaluators to enforce different levels of restrictions:

* Guarded script evaluator: Enhances instance security by supporting only a restricted scripting language and rejecting untrusted scripts that are incompatible. Guest transactions are fully enforced immediately. Scripts sent by authenticated users are evaluated differently depending on the instance type.
* Script sandbox evaluator: Helps prevent executing untrusted scripts on an instance by limiting the APIs available to scripts.

{#script-sandbox-environment__ul_evaluators} {#script-sandbox-environment__table_evaluator_comparison__entry__3}

| Characteristic | Guarded script evaluator | Script sandbox evaluator |
|-|-|-|
| Purpose | Provides enhanced security for scripts that run in the sandbox. Uses a domain-specific language (DSL) that permits only a small set of JavaScript features. | Supports additional JavaScript but restricts certain APIs for scripts. |
| JavaScript support | Only a single simple expression or function call and only certain APIs. | Features supported by the JavaScript engine except for certain API and method restrictions. |
| When it runs | Evaluates untrusted scripts that haven't been granted a guarded-script exemption. | Evaluates untrusted scripts under the following conditions: * A script has been granted a guarded-script exemption (manually or automatically). * When guarded script is in Phase 1: Detection, and a script is sent to the server by an authenticated user. {#script-sandbox-environment__ul_itd_xk4_w3c} |
| Script includes | Not applicable: script includes run outside the sandbox in the application scope | Not applicable: script includes run outside the sandbox in the application scope |
[Table 1. Comparison of the guarded script evaluator and script sandbox evaluator]

{#script-sandbox-environment__table_evaluator_comparison}

For details about each evaluator, including JavaScript restrictions, see the following topics and the [Server-Side Sandbox Runtime Replacement \[KB2944435\]](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB2944435) article on the Now Support
Knowledge Base.
* **[Guarded script evaluator](https://www.servicenow.com/docs/IPyYKQ64KgXFtF9SiPWs~w)**   
  The guarded script evaluator enhances instance security by supporting only a restricted scripting language and detecting or rejecting untrusted scripts that use unsupported JavaScript features.
* **[Script sandbox evaluator](https://www.servicenow.com/docs/fi6OceerjxeoDIf7vqxwqQ)**   
  The script sandbox evaluator helps prevent executing untrusted scripts on an instance by limiting the APIs available to scripts.

