Sessionboxer

What you get

The container is the safety boundary. Everything the agent does happens in there, and everything you need to follow it is in one browser tab. Each feature has its own page with screenshots, things you can do with it and how other products compare.

Sessionboxer's first screen: the question What should the Agent work on?, four logos for Claude Code, Devin, Codex and Cursor marked not connected, the prompt box with the Provider, Connect, Repository and Advanced controls under it, and a To set up checklist in the sidebar

Set up from the first screen

The first screen is a prompt box with the agent, the repositories and Start under it. Click your agent's logo for the three commands that connect it on your OS; a Git account is one more click.

Sessionboxer's first screen with a prompt typed in and, under the box, the agent Claude Code, a Repository button, Advanced… and Start

One box per session

Each Sessionboxer session runs in its own Docker container with its own copy of the code. Nothing the agent does touches your machine; delete it and it is gone.

Sessionboxer session with the Desktop pane open: the agent is working and Firefox in the box shows the web app it started on localhost

A real desktop

Each box runs a Linux desktop with Firefox. The agent takes screenshots, clicks, types and drags; you watch the same screen live and can take control.

An opened turn in the chat: numbered LLM calls, Read and Execute tool rows marked completed, and a screenshot the agent took of Firefox shown inline

Agents that don't ask

Inside a Sessionboxer box the agent runs with all permissions granted, so it never stops to ask. The Docker container is the safety boundary.

The Code pane showing VS Code inside the box with the workspace folders sessionboxer-demo and sessionboxer-site in the explorer, in the same dark theme as the chat

VS Code and terminals

Full VS Code and as many shells as you want, running inside the Sessionboxer box. Files named in the chat open in the editor at that line.

The Context pane: 4.3% of 1,000,000 tokens used, a history chart, the breakdown note, and a table of model API calls with time, kind, model and result

Context you can see

A gauge shows how full the agent's context window is, how often it was compacted and what each turn cost, with a breakdown by system prompt, tools and messages.

A screenshot the agent took of Firefox, shown inline inside its tool row in the chat, next to the live Desktop pane

Videos and documents in the chat

Ask for a screen recording and the agent records the box's desktop to a captioned .mp4 you play in the chat, with optional offline narration. Images and PDFs too.

The Fork dialog: fork point snapshot #3, agent Devin, conversation options Continue it, Start a new one or Hand off, a title and what the fork does first

Snapshots, forks, handoffs

Snapshot the whole box after any turn and fork a new session from it: continue the chat, start fresh on the same files, or hand off to another agent.

The PRs pane listing two pull requests with state, review, unread items, threads, checks and activity, and a box to attach another by URL

Pull requests attached to a session

Attach a GitHub or Bitbucket pull request to a session: comments, reviews and checks in a table, buttons to have the agent address them, auto-merge when checks pass.

The LLM call #11 dialog: the decoded 209 kB request body as pretty JSON with the system reminder and instructions, tabs for Request, Response, Tree and Diff, and Copy and Download buttons

See exactly what goes to the model

For Claude Code sessions, Sessionboxer records each Anthropic API request and response. An LLM #n label on each bubble opens the request, response, tree and diff.

The MCP servers section of Global settings: a github entry connected as a GitHub account with Reconnect, Disconnect, Edit and Delete, and buttons Add server, Import JSON, Add GitHub and Add Bitbucket

MCP servers, registered once

Register MCP servers once, as a command run in the box or an HTTP URL, and switch them per session. GitHub's MCP server connects with one click and logs the box in.

The session header's ⋯ menu with Terminal, Context, Snapshot, Fork, Session settings, Stop and Delete

Stop and resume

Stop a Sessionboxer session to free CPU and memory; resume it later with the conversation, files and installed tools exactly where they were.

The Sandbox section of the Advanced settings dialog with the checkbox Docker inside the Sandbox, CPU and memory fields

Docker inside the box

Optional Docker inside each box: agents run docker, docker compose and docker build in their own container, unprivileged when Sysbox is installed on the host.

The Repositories dialog of a running session: one repository already in /workspace with its branch and GitHub account, and a second git URL being added with an account dropdown

Your repositories, your subscription

Start from one or several git URLs, an empty directory or a folder on your machine. Sessionboxer uses your own Claude, ChatGPT or Devin account.

A session with the agent working and a Queue (1) box under the chat holding the next message, with Load, Send, reorder and Pause controls

Prompts with files, a queue, dictation

Attach files by dropping or pasting them, enqueue the next request while the agent works, and dictate prompts with whisper.cpp running offline on your machine.

Sessionboxer's first screen with a prompt and a Repository button; the clone into the box goes through the same proxy as the machine running Sessionboxer

Works behind a corporate proxy

Behind Cloudflare WARP, Zscaler or another TLS-inspecting proxy, Sessionboxer copies your machine's CA certificates into every box, so HTTPS works.

The New scheduled task form: name Morning dependency check, cron 0 9 * * 1-5 in UTC with the next three runs listed, Enabled, what to do on missed runs, and the choice between prompting an existing session or starting a new one from a template

Scheduled tasks

Run a prompt on a cron schedule in its time zone: into an existing session, or a new one from a template that stops when the turn ends. Runs and outcomes are listed.

A chat where a finished turn is folded to Show all 163 messages, 17:27, between turn dividers that show context change, model calls, tokens and cost, with snapshot markers

A chat that stays readable

The agent's messages of a turn fold into one line with a count and a timer; only the summary stays when the turn ends. Open the fold to see every step.

The Verification section of the Advanced settings dialog: Verify each turn end to end, with the explanation that the agent checks what it changed, plans 2–5 test cases, runs them on the desktop while recording, fixes and reruns what fails and hands the video to the chat

Verify each turn

After each turn the agent plans a few end-to-end test cases, runs them on the desktop with mouse and browser, fixes what fails and records a captioned video.

Above the prompt box: an orange session-usage bar, a green weekly bar, a hatched third bar, and the context gauge reading 103k / 1M 10%

Usage limits, seen and continued

Three bars show how much of your Claude or ChatGPT plan is used. When the agent hits a limit, a countdown shows the reset and Auto-continue picks the turn up.

Global settings in the Catppuccin Latte light theme: the Color theme grid with eleven themes and a Follow the system's light or dark setting checkbox

Themes, shared with VS Code

Eleven light and dark themes (GitHub, Catppuccin, Solarized, Dracula, Nord, One Dark) or follow the system. Chat, terminal and the VS Code in the box switch together.

The New session form with the Environment dropdown open: Docker · Linux ticked, QEMU · Windows, and QEMU · macOS marked not installed

Windows and macOS sessions

Pick QEMU · Windows or QEMU · macOS under the prompt and the agent runs inside a Windows or macOS virtual machine, with its repositories, terminal and MCP servers there, its desktop in the same pane.

Global settings → Agent tools: The Agent may act on: This Session only; When the Agent creates a Session: Ask me (a card in the chat: Allow / Deny); Sessions created by Agents alive at once, over all Sessions: 10

The agent knows where it is

A built-in sessionboxer MCP server tells the agent which session it is in and answers questions from the guide; allowed, it attaches PRs, snapshots, opens panes, and creates or messages other sessions.

A session's ⋯ menu open over the Desktop pane: Terminal, Context, Snapshot, Fork…, Connect USB device…, Session settings, Stop, Delete

A USB device in the box

Plug a device into the machine running Sessionboxer and connect it to one session from the header menu. The agent gets that device only, follows it through resets, and can adb install its own build.