This release is a pre-release and may not be stable for production use.
claude-sandbox
Run Claude Code, Codex or Pi in a container with a bubblewrap sandbox that isolates host credentials and limits access to internal networks.
On a Linux host with uv and rootless Podman:
uv tool install claude-sandbox
cd ~/src/my-project
claude-sandbox
Log in when prompted. Use claude-sandbox codex or claude-sandbox pi
to choose another agent. The host needs /dev/net/tun and unprivileged user
namespaces; no devcontainer setup is required.
Update with uv tool upgrade claude-sandbox, then
claude-sandbox --recreate in each project. Recreation removes
container-local packages and forge logins, but retains project files and
shared agent settings.
Already inside a Debian/Ubuntu devcontainer? As root, run
uvx claude-sandbox install, then claude. That container must expose
/dev/net/tun.
The package is the sandbox itself: the host launcher, the installer and the in-container wrapper, in Python with no dependencies beyond the standard library. Its version selects the matching container image. Documentation · Source
Metadata
Release files for claude-sandbox 5.0.0b2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| claude_sandbox-5.0.0b2-py3-none-any.whl | Python 3 | none | any | Details |
Release files / claude_sandbox-5.0.0b2-py3-none-any.whl
| Download URL | claude_sandbox-5.0.0b2-py3-none-any.whl |
|---|---|
| Size | 166.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
7f01134d809064d4183d80a8d268c11c402f28e8042191daad922925e98516c7
|
|
BLAKE2b-256 checksum How to use checksums |
fd9d936b7047346a7f2bc84450c5e2fea5e810f2f08a45d734ec9ff8583ac509
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|