{"name":"sandbox.enabled","slug":"sandbox-enabled","family":"setting","title":"Settings keys","noun":"settings key","description":"Turn on [Bash sandboxing](\/docs\/en\/sandboxing#get-started) on macOS, Linux, and WSL2","description_source":"docs","described_by":{"doc":"claude-code\/settings-reference","title":"All settings"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.283","builds":0,"mined_builds":126,"first_cited":null},"aliases":[],"entries":[{"version":"2.1.283","anchor":"invalid-sandbox-settings-now-validated-per-field-keeping-re","heading":"A bad sandbox setting no longer switches off the whole sandbox block","line":"Invalid sandbox settings are now handled one field at a time, falling back to the restrictive value instead of the whole block being ignored","released_at":"2026-09-25 18:46:11","reason":"named in this entry, found in this entry's text"},{"version":"2.1.251","anchor":"eval-runs-that-grant-a-shell-tool-now-refuse-to-run-without-","heading":"Eval runs that grant a shell tool now refuse to run without a sandbox","line":"Eval runs with a shell tool refuse to start without a sandbox, and hide your credential files.","released_at":"2026-08-28 15:34:26","reason":"found in this entry's text"},{"version":"2.1.83","anchor":"sandbox-failifunavailable-setting","heading":"sandbox.failIfUnavailable Setting","line":null,"released_at":"2026-03-24 22:16:47","reason":"found in this entry's text"}],"entries_total":3,"docs":[{"source":"claude-code","path":"settings-reference","title":"All settings","documented":true},{"source":"claude-code","path":"admin-setup","title":"Set up Claude Code for your organization","documented":false},{"source":"claude-code","path":"memory","title":"How Claude remembers your project","documented":false},{"source":"claude-code","path":"permission-modes","title":"Choose a permission mode","documented":false},{"source":"claude-code","path":"sandboxing","title":"Configure the sandboxed Bash tool","documented":false},{"source":"claude-code","path":"self-hosted-environments-deploy","title":"Deploy self-hosted environments to production","documented":false},{"source":"claude-code","path":"self-hosted-environments-reference","title":"Self-hosted environments reference","documented":false},{"source":"claude-code","path":"settings","title":"Claude Code settings","documented":false},{"source":"claude-docs","path":"government\/security\/security-and-data-handling","title":"Security and data handling","documented":false}],"docs_total":9,"gates":[],"related":[{"name":"sandbox","slug":"sandbox","description":"[Isolate Bash commands](\/docs\/en\/sandboxing) from your filesystem and network on macOS, Linux, and WSL2"},{"name":"sandbox.bwrapPath","slug":"sandbox-bwrappath","description":"Point the [sandbox](\/docs\/en\/sandboxing) at a bubblewrap binary outside `PATH`"},{"name":"sandbox.credentials","slug":"sandbox-credentials","description":"Hide or mask credential files and variables inside the [sandbox](\/docs\/en\/sandboxing#protect-credentials)"},{"name":"sandbox.credentials.awsPairs","slug":"sandbox-credentials-awspairs","description":"Link custom-named AWS key variables into one credential for [re-signing](\/docs\/en\/sandboxing#re-sign-aws-requests)"},{"name":"sandbox.credentials.files","slug":"sandbox-credentials-files","description":"Block or mask reads of a credential file inside the [sandbox](\/docs\/en\/sandboxing#mask-credential-files)"},{"name":"sandbox.excludedCommands","slug":"sandbox-excludedcommands","description":"Name commands Claude Code can run outside the [sandbox](\/docs\/en\/sandboxing)"},{"name":"sandbox.failIfUnavailable","slug":"sandbox-failifunavailable","description":"Refuse to start when the [sandbox](\/docs\/en\/sandboxing) can't, instead of running unsandboxed"},{"name":"sandbox.filesystem","slug":"sandbox-filesystem","description":"Control which paths [sandboxed](\/docs\/en\/sandboxing#filesystem-isolation) commands can read and write"},{"name":"sandbox.network","slug":"sandbox-network","description":"Control which hosts, ports, and sockets [sandboxed](\/docs\/en\/sandboxing#network-isolation) commands reach"},{"name":"sandbox.network.allowedDomains","slug":"sandbox-network-alloweddomains","description":"Pre-allow domains so [sandboxed](\/docs\/en\/sandboxing) commands don't prompt for them"}],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/sandbox-enabled","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}