Works behind a corporate proxy
Behind Cloudflare WARP, Zscaler or another proxy that re-signs HTTPS, an ordinary container sees self signed certificate in certificate chain and nothing works. Sessionboxer copies the CA certificates your machine trusts beyond the public ones into every box and points Node, Python and OpenSSL at them. Claude Code can be sent through your company's Claude proxy from Global settings.
Things you can do with it
Use it on the company laptop
You do not need an exception from IT. The proxy's root certificate is found in your system store and copied into each box at start.
Send Claude Code through the company gateway
Set the Claude API base URL in Global settings, and a proxy token or API key if the gateway wants one. Every new box uses it.
Build the Sandbox image behind the proxy
npm run build:image hands the same certificates to docker build, so apt, npm and GitHub downloads during the build pass too.
Add a CA that is not on this machine
Paste extra PEM certificates in Global settings → TLS certificates in Sandboxes for a CA the host does not have installed.
How it works
The Control Plane trusts the same certificates itself, so its own downloads (gh, cloudflared, frpc) pass the proxy too. Global settings lists what was found and lets you switch the copy off. Changes apply when a box starts, so Stop and Resume running sessions.
With Inspect LLM on, Claude Code's calls go Claude Code → recorder in the box → your proxy → Anthropic; the recorder trusts the extra certificates and records what Claude Code sent before any rewriting by the proxy. A localhost proxy on your machine works, reached from the box as host.docker.internal.
Compared with other products
| Sessionboxer | Devin | Cursor Cloud Agents | Codex cloud | Claude Code on the web | OpenHands | T3 Code | |
|---|---|---|---|---|---|---|---|
| Works behind a TLS-inspecting corporate proxy | ✓, CA copied into the box | n/a (their cloud) | n/a (their cloud) | n/a (their cloud) | n/a (their cloud) | host's setup | host's setup |
| Runs on your machine or your server | ✓ | ✗ | ✗ | ✗ | ✗ | ✓ | ✓ |
| Isolated sandbox per session | Docker, or a Windows/macOS VM | VM | VM | container | VM | Docker | ✗ (your machine) |
Hosted agents run in their own cloud, so your proxy is not in their path; the question there is whether the proxy lets you reach them, and whether your company allows code on their machines. OpenHands and T3 Code run on your machine and inherit its proxy setup; containers OpenHands starts need the CA configured by hand.
Based on each product's public documentation, September 2026; ✓ = offered, ✗ = not offered, — = not found in the docs. Corrections welcome as an issue.