{"name":"sandbox.network","slug":"sandbox-network","family":"setting","title":"Settings keys","noun":"settings key","description":"Control which hosts, ports, and sockets [sandboxed](\/docs\/en\/sandboxing#network-isolation) commands reach","description_source":"docs","described_by":{"doc":"claude-code\/settings-reference","title":"All settings"},"presence":{"first_seen":null,"removed_in":null,"in_current_build":false,"newest_mined":"2.1.283","builds":0,"mined_builds":126,"first_cited":{"version":"2.1.224","released_at":"2026-08-07 01:36:32","spans":1}},"aliases":[],"entries":[{"version":"2.1.283","anchor":"sandbox-network-and-filesystem-grants-are-withheld-when-a-re","heading":"One invalid sandbox deny entry now withholds the matching allow rules","line":"If one entry in deniedDomains, denyWrite or denyRead is invalid, Claude Code now withholds the matching allow list instead of applying it","released_at":"2026-09-25 18:46:11","reason":"named in this entry, found in this entry's text"},{"version":"2.1.281","anchor":"sandbox-prompt-new-macos-guidance-for-local-port-binding-an","heading":"Sandbox prompt: new macOS guidance for local port binding and open\/osascript","line":"On macOS, Claude is now told how to recognise sandbox blocks on local ports and on open\/osascript, and what to offer the user instead","released_at":"2026-09-23 17:01:17","reason":"found in this entry's text"},{"version":"2.1.224","anchor":"sandbox-network-rules-can-specify-a-port","heading":"Sandbox network rules can specify a port","line":"Sandbox allow and deny rules can now target a specific port instead of the whole host.","released_at":"2026-08-07 01:36:32","reason":"found in this entry's text"},{"version":"1.0.124","anchor":"sandboxed-bash-mode-sb-sandboxed-bash","heading":"Sandboxed Bash Mode ( -sb\/--sandboxed-bash )","line":null,"released_at":"2025-09-25 01:37:53","reason":"found in this entry's text"}],"entries_total":4,"docs":[{"source":"claude-code","path":"settings-reference","title":"All settings","documented":true},{"source":"claude-code","path":"admin-setup","title":"Set up Claude Code for your organization","documented":false},{"source":"claude-code","path":"changelog","title":"Claude Code changelog","documented":false},{"source":"claude-code","path":"claude-apps-gateway-config","title":"Claude apps gateway configuration","documented":false},{"source":"claude-code","path":"cross-session-messaging","title":"Message your other Claude Code sessions","documented":false},{"source":"claude-code","path":"managed-settings","title":"Deploy managed settings","documented":false},{"source":"claude-code","path":"monitoring-usage","title":"Monitoring","documented":false},{"source":"claude-code","path":"server-managed-settings","title":"Configure server-managed settings","documented":false},{"source":"claude-code","path":"tools-reference","title":"Tools reference","documented":false},{"source":"claude-code","path":"whats-new\/2026-w16","title":"Week 16 \u00b7 April 13\u201317, 2026","documented":false}],"docs_total":13,"gates":[],"related":[{"name":"sandbox","slug":"sandbox","description":"[Isolate Bash commands](\/docs\/en\/sandboxing) from your filesystem and network on macOS, Linux, and WSL2"},{"name":"sandbox.bwrapPath","slug":"sandbox-bwrappath","description":"Point the [sandbox](\/docs\/en\/sandboxing) at a bubblewrap binary outside `PATH`"},{"name":"sandbox.credentials","slug":"sandbox-credentials","description":"Hide or mask credential files and variables inside the [sandbox](\/docs\/en\/sandboxing#protect-credentials)"},{"name":"sandbox.credentials.awsPairs","slug":"sandbox-credentials-awspairs","description":"Link custom-named AWS key variables into one credential for [re-signing](\/docs\/en\/sandboxing#re-sign-aws-requests)"},{"name":"sandbox.credentials.files","slug":"sandbox-credentials-files","description":"Block or mask reads of a credential file inside the [sandbox](\/docs\/en\/sandboxing#mask-credential-files)"},{"name":"sandbox.enabled","slug":"sandbox-enabled","description":"Turn on [Bash sandboxing](\/docs\/en\/sandboxing#get-started) on macOS, Linux, and WSL2"},{"name":"sandbox.excludedCommands","slug":"sandbox-excludedcommands","description":"Name commands Claude Code can run outside the [sandbox](\/docs\/en\/sandboxing)"},{"name":"sandbox.failIfUnavailable","slug":"sandbox-failifunavailable","description":"Refuse to start when the [sandbox](\/docs\/en\/sandboxing) can't, instead of running unsandboxed"},{"name":"sandbox.filesystem","slug":"sandbox-filesystem","description":"Control which paths [sandboxed](\/docs\/en\/sandboxing#filesystem-isolation) commands can read and write"},{"name":"sandbox.network.allowedDomains","slug":"sandbox-network-alloweddomains","description":"Pre-allow domains so [sandboxed](\/docs\/en\/sandboxing) commands don't prompt for them"}],"url":"https:\/\/changelogs.core-directive.com\/reference\/setting\/sandbox-network","family_url":"https:\/\/changelogs.core-directive.com\/reference\/setting.json"}