Sessionboxer

Self-hosted · Linux or macOS · Claude Code, Codex, Cursor and Devin

Run coding agents in boxes.

Each session gets its own Docker container with a full Linux desktop, and the agent works in it like a person would: terminal, editor, browser, mouse and keyboard. You watch the screen live, browse and edit the files, open terminals, and step in when you want to.

Install
curl -fsSL https://sessionboxer.talayolabs.com/install.sh | sh

Needs Docker (how to install it on macOS, Windows or Linux). Or brew install talayolabs/tap/sessionboxer, npx sessionboxer serve, docker compose up or a desktop app — see Install.

Sessionboxer in 49 seconds: five agents at work at the same time, each in its own virtual, isolated machine, then six features on real screenshots. Device photos from Wikimedia Commons: Linux PC by Syced (CC0), Pixel 6a by Nisiguti (CC BY-SA 4.0), MacBook Air by KKPCW (CC BY-SA 4.0), Dell OptiPlex 745 by Ace_Combat_769 (CC BY-SA 4.0), server rack by Edmondo (CC BY-SA 3.0). MP4
Seven minutes through the UI (v1.1.0, before Cursor): a new session with a repository and a first prompt; the box boots with a Linux desktop; the agent's turn folded into one line, opened to see every step; taking control of the desktop; enqueuing the next request while it works; usage meters, terminal, context and LLM calls; VS Code in the UI's theme; a pull request with checks, comments and auto-merge; forks that continue, start a new chat or hand off to another agent; several repositories with their own accounts; scheduled tasks; themes; dictation; pairing a phone. GIF · MP4

What you get

The container is the safety boundary. Everything the agent does happens in there, and everything you need to follow it is in one browser tab.

Each card opens a page with screenshots, things you can do with the feature and how other products compare. All features →

How it works

One process listens on your machine. Each session is a container it talks to over a private Docker network; nothing in a box is published to the host.

The agents it runs

All four run inside the box over ACP, with the same desktop tools. You bring your own account; tokens are handed only to the containers of sessions that use that agent and are never stored in snapshots. A fork can switch agent mid-way through a handoff.

Claude Code

Through claude-agent-acp, with your Claude subscription: run claude setup-token and paste the result in Global settings.

  • Model, Effort and Fast mode pickers; changes apply when the current turn ends.
  • Standing instructions appended to its system prompt on every start.
  • Branches keep its memory exact: the session is forked at that turn.
  • Exact model API calls recorded in the box and shown per bubble as LLM #n.
  • Context breakdown by system prompt, tools, MCP servers, memory files, skills and messages.
  • Usage bars for the session, weekly and Opus windows; 1M-context models keep their full window.

Codex

Through codex-acp, with your ChatGPT subscription: run codex login on your machine and paste ~/.codex/auth.json in Global settings. It lives on tmpfs in the box; refreshed tokens are stored back.

  • Model and reasoning-effort pickers; changes apply when the current turn ends.
  • Standing instructions prepended to the first message of each conversation.
  • Usage bars for the 5-hour and weekly limits, read after each turn.
  • Same desktop, VS Code, terminals, snapshots, PRs and verification as the others.

Cursor

Through the Cursor CLI's own agent acp, with your Cursor subscription: run agent login on your machine and paste or import the auth.json it writes in Global settings (an API key from the Cursor dashboard works too). It lives on tmpfs in the box; refreshed tokens are stored back.

  • Model picker with the models your plan has, as its CLI lists them; changes apply when the current turn ends.
  • Standing instructions prepended to the first message of each conversation.
  • Its questions and plans are answered so a turn never waits on a dialog.
  • Same desktop, VS Code, terminals, snapshots, PRs and verification as the others.

Devin

Through the Devin CLI's devin acp, with your Devin account: run devin auth login and paste the token from its credentials file in Global settings.

  • The model catalog your account has, grouped by family; pick an effort level by model.
  • Standing instructions prepended to the first message of each conversation.
  • Branches hand it a transcript of the conversation up to that point.
  • Compaction details read from its own session database in the box.
  • Context breakdown by system prompt, tools, messages and free space, estimated.

Compared with

Hosted agents give you a machine in their cloud on their account. Sessionboxer gives the same kind of machine on yours, with the agent and subscription you already have.

Sessionboxer Devin Cursor Cloud Agents Codex cloud Claude Code on the web OpenHands T3 Code
Runs on your machine or your server✓✗✗✗✗✓✓
Your existing subscription, no new account✓✗✗✗✗API key✓
Agents Claude Code Codex Cursor DevinDevinCursorCodexClaude Codeown agent, any modelClaude Code, Codex, Cursor, others
Isolated sandbox per session Docker, / VMVMVMcontainerVMDocker✗ (your machine)
Desktop the agent drives with mouse and keyboard✓browser✓——browser✗
Watch the screen live and take over✓✓✓———✗
VS Code and terminals inside the sandbox✓✓————your own
Several repositories in one session✓✓✓————
Snapshot and fork the whole machine✓—————✗
Revert the conversation, branches✓——————
Pull requests: follow, address, auto-merge✓follow, addressaddressaddressaddressaddress✗
See the exact model API calls✓——————
Offline dictation✓——————
PhonePWA + pushwebiOS appChatGPT appClaude appwebiOS, Android
Open sourceMIT✗✗✗✗MITMIT

From each product's public documentation, September 2026; ✓ = offered, ✗ = not offered, — = not found in the docs. Corrections welcome as an issue.

Remote access from a phone or another machine

Sessionboxer listens on 127.0.0.1:4000 and every browser logs in once with the access token or a pairing code. Pair another device in Global settings shows a QR code and picks how the phone reaches this machine: the local network, a Cloudflare quick tunnel, the Sessionboxer tunnel (a stable https://<name>.tunnel-sessionboxer.talayolabs.com address) or your own server over SSH.

The phone gets the same session in a one-column layout with a touch desktop, and push notifications when the agent finishes or a pull request gets a comment. Paired devices are listed in Global settings and can be revoked there.

Install Docker first

Every session is a Docker container, so the machine that runs Sessionboxer needs a Docker engine with the docker compose plugin. All three installs below include it. When docker compose version answers, come back to Get started.

macOS Apple silicon or Intel

OrbStack, with Homebrew
brew install --cask orbstack
open -a OrbStack           # finish its setup once
docker compose version

OrbStack is lighter and reaches the boxes by their own address, like Linux does; on Apple silicon it may ask to install Rosetta, say yes. Docker Desktop for Mac (brew install --cask docker) works too. Either one needs a Mac that can run virtual machines, so not a Mac that is itself a VM. Open the app once and wait until it says it is running, then install Sessionboxer.

Windows 10 or 11, with WSL2

PowerShell as administrator
wsl --install              # reboot when it asks
winget install -e --id Docker.DockerDesktop
wsl -e docker compose version

WSL2 gives Windows a Linux kernel; Docker Desktop for Windows runs the engine on it. In Docker Desktop, keep Use the WSL 2 based engine on and turn on WSL integration for your distribution. Then open a WSL terminal (wsl) and run the Sessionboxer commands from Get started in it: the one-liner is a shell script and Sessionboxer itself runs on Linux, so on Windows it lives inside WSL.

Linux Debian, Ubuntu, Fedora, Raspberry Pi OS…

Docker Engine, Docker's script
curl -fsSL https://get.docker.com | sh
sudo usermod -aG docker $USER   # then log out and in
docker compose version

get.docker.com installs Docker Engine, the docker compose plugin and Buildx from Docker's repositories on every common distribution; the per-distribution instructions do the same by hand. The usermod line lets your user talk to the daemon without sudo, which Sessionboxer needs (post-install steps).

Already have Docker? docker info has to work as your user, and docker compose version has to print a 2.x version: the old standalone docker-compose (1.x, with a dash) is not enough. Colima works with DOCKER_HOST=unix://$HOME/.colima/default/docker.sock; the macOS notes in the guide have the details.

Get started

1

Requirements

  • Linux with Docker Engine, or macOS with OrbStack or Docker Desktop (Windows: WSL2) — install Docker
  • Node.js 22+ for the npm install; Docker Compose is enough otherwise
  • A Claude Code subscription, a ChatGPT subscription (Codex), a Cursor subscription and/or a Devin account
  • Optional: Sysbox, for Docker inside sessions without a privileged container
2

Install and start

Run the one-liner above (it picks npm or Docker Compose), or one of the commands below. Start the server and open the login link it prints: http://127.0.0.1:4000/#pair=… logs your browser in once. Sessionboxer only listens on localhost.

The Sandbox image (ghcr.io/talayolabs/sessionboxer-sandbox, a few GB, amd64 and arm64) is pulled the first time the server starts.

3

Connect your agent

On the first screen, click the logo of the agent you subscribe to: Claude Code, Codex, Cursor or Devin. The dialog shows the three steps for your OS (install the CLI, run claude setup-token or codex login or the like, paste the result). Add GitHub or Bitbucket if the code is private, type the first prompt, Start. How the first screen works →

Homebrew macOS or Linux laptop

Homebrew and Docker
brew install talayolabs/tap/sessionboxer
sessionboxer serve

Installs the release with Homebrew's Node, no npm to think about; brew upgrade updates it. The same package has the sessionboxer new . command line. Port 4000 taken? SESSIONBOXER_PORT=4001 sessionboxer serve. the tap

npm any machine with Node

Node 22+ and Docker
npx sessionboxer serve

Or npm i -g sessionboxer once and sessionboxer serve. Port 4000 taken? SESSIONBOXER_PORT=4001 sessionboxer serve. sessionboxer on npm

Docker Compose home server, VPS, Pi, Coolify

Docker only
curl -fsSLO https://raw.githubusercontent.com/talayolabs/sessionboxer/v1.4.0/docker-compose.yml
docker compose up -d
docker compose logs control-plane   # the login link (-d hid it)
docker compose exec control-plane sessionboxer token   # the token, for other browsers

The Control Plane runs from ghcr.io/talayolabs/sessionboxer with the Docker socket mounted, so sessions are sibling containers. That socket is root on the host: run it on a machine you would trust the agent's boxes with anyway. .env sets the port, bind address, public URL and a fixed token.

Desktop app no Node, no terminal

An app that starts the Control Plane and stays in the tray. Needs Docker like the others. Version 1.4.0:

Not code-signed yet: macOS says the download is “damaged” until you clear its quarantine flag (command under Remote access), Windows needs More info → Run anyway. All files of the release

From source to hack on it

git, Node 22+ and Docker
git clone https://github.com/talayolabs/sessionboxer.git
cd sessionboxer && npm install && npm run build
npm start                # pulls the Sandbox image…
npm run build:image      # …or build it here (~5 GB)

Every version is a GitHub Release with notes and the npm tarball; images on GHCR: sessionboxer and sessionboxer-sandbox (linux/amd64, linux/arm64). MIT licence.

Installed? The first run takes you through connecting Claude, Codex, Cursor or Devin; the user guide covers the rest, one page per topic.