Sessionboxer

One box per session

Every conversation with an agent gets its own Docker container. The code is cloned into it, the agent runs inside it, and the container is the safety boundary: nothing the agent does reaches your machine. Delete the session and the container, its files and its snapshots go with it.

Sessionboxer's first screen with a prompt typed in and, under the box, the agent Claude Code, a Repository button, Advanced… and Start
A new session: the prompt, the agent, the repositories that go into the box, Start.

Things you can do with it

Run three approaches at once

Start three sessions on the same repository with three different prompts. Each works in its own container and none of them can see, or break, the others.

Let the agent install whatever it needs

apt packages, a Postgres, a different Node version: the agent installs them in the box. Your machine keeps its own setup.

Give a stranger's repository a try

Clone an unknown project into a session and let the agent build and run it. If the install script does something odd, it does it inside the container.

Throw the whole thing away

Delete the session and the container, its files and its snapshots are removed. There is nothing to clean up on the host.

How it works

One Control Plane process runs on your machine and creates a Docker container per session from the Sandbox image. Inside it run the agent, a Linux desktop, the Sandbox Daemon and the workspace under /workspace, seeded from one or several git URLs or a copy of a folder on your machine. The container is on a private Docker network and publishes no host ports; the browser reaches everything through the Control Plane on 127.0.0.1:4000.

CPU and memory limits are set per box (defaults in Global settings). The sidebar shows how much disk each session uses, including its snapshots.

The Sandbox section of the Advanced settings dialog: Docker inside the Sandbox, CPUs, memory in GB, and the git author used for commits made in the box
Each box gets its own CPU and memory limits and its own git identity.

Compared with other products

SessionboxerDevinCursor Cloud AgentsCodex cloudClaude Code on the webOpenHandsT3 Code
Runs on your machine or your server✓✗✗✗✗✓✓
Isolated sandbox per sessionDocker, or a Windows/macOS VMVMVMcontainerVMDocker✗ (your machine)
Several repositories in one session✓✓✓————
Open sourceMIT✗✗✗✗MITMIT

Hosted agents such as Devin, Cursor Cloud Agents, Codex cloud and Claude Code on the web also give each task an isolated machine, but that machine runs in their cloud, on their account. Sessionboxer gives the same kind of isolation on your laptop or your server, with the agent and subscription you already have.

T3 Code runs the agent directly on your machine, so there is no container between the agent and your files. OpenHands, like Sessionboxer, runs each conversation in a Docker container on your own hardware.

Based on each product's public documentation, September 2026; ✓ = offered, ✗ = not offered, — = not found in the docs. Corrections welcome as an issue.