sandbox.filesystem
A Claude Code settings key, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.
What it is
Control which paths [sandboxed](/docs/en/sandboxing#filesystem-isolation) commands can read and write
Anthropic's own wording. Read off Claude Code settings reference, captured 2026-08-28.
Presence across releases
The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.
Changelog entries naming it
-
v2.1.246Disabled settings files no longer feed rules into the sandbox
Rules from settings files you disabled no longer sneak into the sandbox policy.
named in this entry
Documentation pages
- Claude Code settings reference reference table Claude Code CLI
- Claude Code changelog mentions it Claude Code CLI
- Deploy managed settings mentions it Claude Code CLI
- Configure permissions mentions it Claude Code CLI
- Configure the sandboxed Bash tool mentions it Claude Code CLI
- Deploy self-hosted environments to production mentions it Claude Code CLI
- Week 30 · July 20–24, 2026 mentions it Claude Code CLI
- Code in Claude Desktop on 3P mentions it Claude Documentation
A reference table page is one whose own table defines this name, and it is where the description above came from. A page that mentions it carries the name somewhere in its text and may say nothing about it at all. Every page carrying it.
Names beside it
Every settings key in the inventory starting sandbox, up to twelve of them.
sandbox[Isolate Bash commands](/docs/en/sandboxing) from your filesystem and network on macOS, Linux, and WSL2 2.1.138
sandbox.bwrapPathPoint the [sandbox](/docs/en/sandboxing) at a bubblewrap binary outside PATH never mined
sandbox.credentialsHide or mask credential files and variables inside the [sandbox](/docs/en/sandboxing#protect-credentials) never mined
sandbox.credentials.filesBlock or mask reads of a credential file inside the [sandbox](/docs/en/sandboxing#mask-credential-files) never mined
sandbox.excludedCommandsName commands that always run outside the [sandbox](/docs/en/sandboxing) never mined
sandbox.failIfUnavailableRefuse to start when the [sandbox](/docs/en/sandboxing) can't, instead of running unsandboxed never mined
sandbox.network.allowedDomainsPre-allow domains so [sandboxed](/docs/en/sandboxing) commands don't prompt for them never mined
sandbox.network.strictAllowlistDeny hosts outside the [allowlist](/docs/en/sandboxing#network-isolation) instead of prompting never mined
sandbox.network.tlsTerminateHave the [sandbox](/docs/en/sandboxing#network-isolation) proxy terminate TLS so it can read HTTPS requests never mined
sandbox.ripgrepUse your own ripgrep binary inside the [sandbox](/docs/en/sandboxing) never mined
sandbox.socatPathPoint the [sandbox](/docs/en/sandboxing) proxy at a socat binary outside PATH never mined
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.