Sessionboxer

The agent knows where it is

Every box has a second built-in MCP server next to desktop: sessionboxer. The agent's briefing opens with the session's name and environment, .sessionboxer/session.json in the workspace has the id, agent, model, branch and parent, and whoami and docs answer "where are you?" and "how do I turn on Docker in the box?" from the guide shipped in the box rather than from memory. With the same server the agent acts on its session the way you would from the UI, and, if you allow it, on other sessions: create one with a first prompt, fork itself with a handoff it writes, message another session's agent, wait for its turn, schedule prompts. Every action leaves a marker in the chat.

Global settings → Agent tools: The Agent may act on: This Session only; When the Agent creates a Session: Ask me (a card in the chat: Allow / Deny); Sessions created by Agents alive at once, over all Sessions: 10
Global settings → MCP & connectors → sessionboxer sets the default policy; each session can override it under Advanced…

Things you can do with it

Ask the session about itself

"Which model are you on, how full is the context, what is in the queue?" — answered from whoami, exact, no guessing.

Let it attach the PR it opened

After gh pr create the agent calls pr_attach; the PRs pane starts following comments and checks without you pasting the URL.

Split work across sessions

"Create a session for the backend tests and message me the result." A card asks Allow / Deny; the child appears in the sidebar as child of this one and its reply lands in this chat marked from Session X.

Have it show you something

ui_open switches your page to Terminal, Code, PRs or Verification, or opens a Terminal running a command visibly, only while you are looking at that session and not typing.

How it works

The box has no route to Sessionboxer's API and no token: the MCP talks to the box's own daemon, which forwards over the connection the Control Plane already holds to it, so a box can only ever speak for its own session. Policy is Off, This Session only or All Sessions (the default since 1.4.1), per session or globally; creating a session shows an Allow / Deny card by default, expiring in 10 minutes. Limits hold a runaway or prompt-injected agent: 3 alive children per agent, a global cap on agent-created sessions, 4 hops in a chain of agents prompting agents, one message in flight per target. Windows and macOS guests get the server through the same bridge as desktop. Every tool of both servers, with parameters, limits and returns, is in the MCP tools reference.

Compared with other products

SessionboxerDevinCursor Cloud AgentsCodex cloudClaude Code on the webOpenHandsT3 Code
MCP servers✓, switched per session✓✓——✓via the agent
Hand a session over to a different agent✓✗✗✗✗——
Runs on your machine or your server✓✗✗✗✗✓✓

Devin has an MCP server and an API for creating and messaging sessions from outside; whether a session can call them on itself is not described. The other hosted products document MCP for their agents but no self-knowledge or session-to-session tools. Sessionboxer gives the agent both, scoped to the session it runs in unless you widen it.

Based on each product's public documentation, September 2026; ✓ = offered, ✗ = not offered, — = not found in the docs. Corrections welcome as an issue.