sandbox.socatPath
A Claude Code settings key, read out of the shipped bundle. No mined inventory carries it: everything below comes from what this site has written about it.
What it is
Point the [sandbox](/docs/en/sandboxing) proxy at a socat binary outside PATH
Anthropic's own wording. Read off Claude Code settings reference, captured 2026-08-28.
Presence across releases
The miner has never read a build containing this name. It is here because a changelog entry of ours names it, which is evidence that it existed and not evidence of which releases carried it. The inventory starts at v2.1.138 and everything older than that was never mined.
Changelog entries naming it
-
v2.1.232Sandbox binary paths in project settings are surfaced at the trust prompt
Sandbox binary paths set by a project now show up in the folder trust prompt before you accept.
named in this entry
Documentation pages
- Claude Code settings reference reference table Claude Code CLI
- Claude Code changelog mentions it Claude Code CLI
- Claude apps gateway configuration mentions it Claude Code CLI
- Deploy managed settings mentions it Claude Code CLI
- Configure server-managed settings mentions it Claude Code CLI
A reference table page is one whose own table defines this name, and it is where the description above came from. A page that mentions it carries the name somewhere in its text and may say nothing about it at all. Every page carrying it.
Names beside it
Every settings key in the inventory starting sandbox, up to twelve of them.
sandbox[Isolate Bash commands](/docs/en/sandboxing) from your filesystem and network on macOS, Linux, and WSL2 2.1.138
sandbox.bwrapPathPoint the [sandbox](/docs/en/sandboxing) at a bubblewrap binary outside PATH never mined
sandbox.credentialsHide or mask credential files and variables inside the [sandbox](/docs/en/sandboxing#protect-credentials) never mined
sandbox.credentials.filesBlock or mask reads of a credential file inside the [sandbox](/docs/en/sandboxing#mask-credential-files) never mined
sandbox.excludedCommandsName commands that always run outside the [sandbox](/docs/en/sandboxing) never mined
sandbox.failIfUnavailableRefuse to start when the [sandbox](/docs/en/sandboxing) can't, instead of running unsandboxed never mined
sandbox.filesystemControl which paths [sandboxed](/docs/en/sandboxing#filesystem-isolation) commands can read and write never mined
sandbox.network.allowedDomainsPre-allow domains so [sandboxed](/docs/en/sandboxing) commands don't prompt for them never mined
sandbox.network.strictAllowlistDeny hosts outside the [allowlist](/docs/en/sandboxing#network-isolation) instead of prompting never mined
sandbox.network.tlsTerminateHave the [sandbox](/docs/en/sandboxing#network-isolation) proxy terminate TLS so it can read HTTPS requests never mined
sandbox.ripgrepUse your own ripgrep binary inside the [sandbox](/docs/en/sandboxing) never mined
Read out of the published npm bundle release by release, and out of Anthropic's own documentation as this site captured it. Nothing on this page is a description anybody here wrote about what the settings key does. All settings keys.