DocsConfigure
Sandbox
On a Mac and Linux, agents run inside Anthropic's sandbox-runtime: they write only to their folders and reach only the hosts they need.
On a Mac and on Linux the agents can run inside Anthropic’s sandbox-runtime (srt). It is on by default. Each tool then:
- writes only to its folders, its own state and temp;
- can’t read your keychains, mail or other apps’ data;
- opens no windows;
- reaches the network only through srt’s proxy, to the hosts it needs.
It works alongside tool access: access decides what an agent may ask for, the sandbox limits what it can touch.
Setting it up
Switch it off or on in Settings. If srt isn’t installed the agents start unsandboxed, and Settings says what is missing (on a Mac it does not list the missing pieces, so check for both).
| Needs | |
|---|---|
| macOS | srt and rg: npm install -g @anthropic-ai/sandbox-runtime@0.0.78 and brew install ripgrep |
| Linux | srt and bubblewrap |
| Windows | Not available; the switch is off and says why |