Search the documentation
8 pages for sandbox.credentials.
Titles and paths first, then pages whose text carries it. Each row opens that page as this site last read it.
Use Claude Code features in the SDK
Claude Code CLI · in the page
agent-sdk/claude-code-features
…or `ENABLE_CLAUDEAI_MCP_SERVERS=false` in `env` | | [`sandbox.credentials`](/docs/en/sandboxing#protect-credentials) `deny` entries and file `mask` entries in `~/.claude/settings.json`…
Claude Code changelog
Claude Code CLI · in the page
changelog
…ate> <Update label="2.1.187" description="June 23, 2026"> * Added `sandbox.credentials` setting to block sandboxed commands from reading credential files and secret environment variables * Added…
Claude apps gateway for Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry
Claude Code CLI · in the page
claude-apps-gateway
…missions#manage-permissions). Claude Code forwards parent-supplied [`sandbox.credentials`](/docs/en/settings-reference#sandbox-credentials) entries in stripped form: * **`deny` entries**: forwarded…
Deploy managed settings
Claude Code CLI · in the page
managed-settings
…| | `sandbox.credentials` | A recoverable invalid entry is degraded to `mode: "deny"` with a warning; an unrecoverable one is s…
Configure the sandboxed Bash tool
Claude Code CLI · in the page
sandboxing
…managed settings configure `sandbox.filesystem` at all, or list any `sandbox.credentials.files` entry with `"mode": "deny"`, only managed settings can set the key. This keeps administrator-deployed f…
Claude Code settings
Claude Code CLI · in the page
settings
…| | `sandbox.credentials` | An invalid entry in `files` or `envVars` that still has a valid `path` or `name` and a `mode` of `m…
Claude Code settings reference
Claude Code CLI · in the page
settings-reference
…| Sandbox settings | Managed | | [`sandbox.credentials`](#sandbox-credentials) | Hide or mask credential files and…
Week 26 · June 22–26, 2026
Claude Code CLI · in the page
whats-new/2026-w26
…tion from before <code>/clear</code> was run</div> <div>New <code>sandbox.credentials</code> setting blocks sandboxed commands from reading credential files and secret environment variables</div>…