DocsConfigure

Sandbox

On a Mac and Linux, agents run inside Anthropic's sandbox-runtime: they write only to their folders and reach only the hosts they need.

On a Mac and on Linux the agents can run inside Anthropic’s sandbox-runtime (srt). It is on by default. Each tool then:

  • writes only to its folders, its own state and temp;
  • can’t read your keychains, mail or other apps’ data;
  • opens no windows;
  • reaches the network only through srt’s proxy, to the hosts it needs.

It works alongside tool access: access decides what an agent may ask for, the sandbox limits what it can touch.

Setting it up

Switch it off or on in Settings. If srt isn’t installed the agents start unsandboxed, and Settings says what is missing (on a Mac it does not list the missing pieces, so check for both).

Needs
macOSsrt and rg: npm install -g @anthropic-ai/sandbox-runtime@0.0.78 and brew install ripgrep
Linuxsrt and bubblewrap
WindowsNot available; the switch is off and says why