The sandbox limits which websites and files commands run by Claude can reach. Its sandbox.network and sandbox.filesystem settings now fail safe when a single deny entry is invalid and gets dropped:
- An invalid entry in
deniedDomainswithholdsallowedDomains. - An invalid entry in
denyWritewithholdsallowWrite. - An invalid entry in
denyReadwithholdsallowRead.
Before, this happened only when a whole deny setting could not be read. autoMode already worked this way.
A typo in one deny rule can no longer leave your allow rules fully in force while part of the restriction silently goes missing. If some access you allowed stops working, check your deny lists for an invalid entry.
| [Sandboxing](/docs/en/sandboxing) | OS-level filesystem and network isolation with domain allowlists | `sandbox.enabled`, `sandbox.network.allowedDomains` |see the edit
| [`sandbox.network.allowManagedDomainsOnly`](/docs/en/settings-reference#sandbox-network-allowmanageddomainsonly) | Honor only managed `allowedDomains` and `WebFetch(domain:...)` allow rules; block other domains without prompting |see the edit
| [`sandbox.filesystem.allowManagedReadPathsOnly`](/docs/en/settings-reference#sandbox-filesystem-allowmanagedreadpathsonly) | When `true`, only `filesystem.allowRead` paths from managed settings are respected. `denyRead` still merges from…see the edit
Protect credential files or directories from sandboxed commands. With `"mode": "deny"`, Claude Code blocks reads of the path inside the sandbox, the same read block as [`sandbox.filesystem.denyRead`](#sandbox-filesystem-denyread). With `"m…see the edit
Configuring a mirror removes the public package hosts from the sandbox's network allowlist and admits the mirror host in their place, so a misconfigured mirror fails with an error that names the mirror rather than falling back to the publi…see the edit
When Claude runs code, its network access passes through a local filtering proxy that allows only the domains on the sandbox's built-in allowlist, grouped by purpose below. By default, each member manages the list on their own computer. Me…see the edit
The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.
| [Sandboxing](/docs/en/sandboxing) | OS-level filesystem and network isolation with domain allowlists | `sandbox.enabled`, `sandbox.network.allowedDomains` |admin-setup see the edit
Which settings sources this applies to, such as managed or personal settings, is not clear.
sandbox.network on Set up Claude Code for your organization