What
The sandbox is the protection that limits which files and network addresses Claude Code's commands can reach. Before, if anything in the sandbox settings failed validation, the whole block was ignored with "This field was ignored.", and only the credentials part was rescued.
Now each field is checked on its own:
- Invalid fields: each one falls back to its restrictive value, or is ignored by itself.
sandbox.failIfUnavailable: never filled in with a substitute value.sandbox.enabled: not filled in with a restrictive value when invalid.- Warnings: when an invalid field has a restrictive value that was not used, the warning names that value.
- Credentials: damaged credential entries are now marked as substituted.
- Text values: "true" and "false" written as text, and
falsemeaning "disable", are handled the same way everywhere.
Why
One typo in a sandbox setting no longer turns off every other sandbox protection.
Names in the bundlesandbox.enabled
sandbox.enabled
Set up Claude Code for your organization modified, high confidence
| [Sandboxing](/docs/en/sandboxing) | OS-level filesystem and network isolation with domain allowlists | `sandbox.enabled`, `sandbox.network.allowedDomains` |see the edit
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
Confirmed since
Anthropic's documentation has since written up sandbox.enabled, on Set up Claude Code for your organization.
| [Sandboxing](/docs/en/sandboxing) | OS-level filesystem and network isolation with domain allowlists | `sandbox.enabled`, `sandbox.network.allowedDomains` |admin-setup see the edit
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
Which sandbox fields have a restrictive fallback value is not listed.
Anthropic's documentation agrees
sandbox.enabled on Set up Claude Code for your organization