sandbox.credentials
A Claude Code settings key, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.
What it is
Hide or mask credential files and variables inside the [sandbox](/docs/en/sandboxing#protect-credentials)
Anthropic's own wording. Read off Claude Code settings reference, captured 2026-08-28.
Presence across releases
The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.
Changelog entries naming it
-
v2.1.246Disabled settings files no longer feed rules into the sandbox
Rules from settings files you disabled no longer sneak into the sandbox policy.
named in this entry
-
v2.1.224Invalid sandbox credential settings now fail closed instead of being ignored
A malformed sandbox.credentials block now denies everything instead of quietly disabling protection.
named in this entry
-
v2.1.224Sandbox credential masking gains JWT handling, per-claim masking and AWS SigV4 re-signing
Sandbox credential masking can fake JWTs, mask single claims, and re-sign AWS requests after swapping keys.
named in this entry
Documentation pages
- Claude Code settings reference reference table Claude Code CLI
- Use Claude Code features in the SDK mentions it Claude Code CLI
- Claude Code changelog mentions it Claude Code CLI
- Claude apps gateway for Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry mentions it Claude Code CLI
- Deploy managed settings mentions it Claude Code CLI
- Configure the sandboxed Bash tool mentions it Claude Code CLI
- Claude Code settings mentions it Claude Code CLI
- Week 26 · June 22–26, 2026 mentions it Claude Code CLI
A reference table page is one whose own table defines this name, and it is where the description above came from. A page that mentions it carries the name somewhere in its text and may say nothing about it at all. Every page carrying it.
Names beside it
Every settings key in the inventory starting sandbox, up to twelve of them.
sandbox[Isolate Bash commands](/docs/en/sandboxing) from your filesystem and network on macOS, Linux, and WSL2 2.1.138
sandbox.bwrapPathPoint the [sandbox](/docs/en/sandboxing) at a bubblewrap binary outside PATH never mined
sandbox.credentials.filesBlock or mask reads of a credential file inside the [sandbox](/docs/en/sandboxing#mask-credential-files) never mined
sandbox.excludedCommandsName commands that always run outside the [sandbox](/docs/en/sandboxing) never mined
sandbox.failIfUnavailableRefuse to start when the [sandbox](/docs/en/sandboxing) can't, instead of running unsandboxed never mined
sandbox.filesystemControl which paths [sandboxed](/docs/en/sandboxing#filesystem-isolation) commands can read and write never mined
sandbox.network.allowedDomainsPre-allow domains so [sandboxed](/docs/en/sandboxing) commands don't prompt for them never mined
sandbox.network.strictAllowlistDeny hosts outside the [allowlist](/docs/en/sandboxing#network-isolation) instead of prompting never mined
sandbox.network.tlsTerminateHave the [sandbox](/docs/en/sandboxing#network-isolation) proxy terminate TLS so it can read HTTPS requests never mined
sandbox.ripgrepUse your own ripgrep binary inside the [sandbox](/docs/en/sandboxing) never mined
sandbox.socatPathPoint the [sandbox](/docs/en/sandboxing) proxy at a socat binary outside PATH never mined
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.