Sessionboxer

Works behind a corporate proxy

Behind Cloudflare WARP, Zscaler or another proxy that re-signs HTTPS, an ordinary container sees self signed certificate in certificate chain and nothing works. Sessionboxer copies the CA certificates your machine trusts beyond the public ones into every box and points Node, Python and OpenSSL at them. Claude Code can be sent through your company's Claude proxy from Global settings.

Sessionboxer's first screen with a prompt and a Repository button; the clone into the box goes through the same proxy as the machine running Sessionboxer
Cloning, npm installs and MCP servers in the box pass the proxy like your own shell does.

Things you can do with it

Use it on the company laptop

You do not need an exception from IT. The proxy's root certificate is found in your system store and copied into each box at start.

Send Claude Code through the company gateway

Set the Claude API base URL in Global settings, and a proxy token or API key if the gateway wants one. Every new box uses it.

Build the Sandbox image behind the proxy

npm run build:image hands the same certificates to docker build, so apt, npm and GitHub downloads during the build pass too.

Add a CA that is not on this machine

Paste extra PEM certificates in Global settings → TLS certificates in Sandboxes for a CA the host does not have installed.

How it works

The Control Plane trusts the same certificates itself, so its own downloads (gh, cloudflared, frpc) pass the proxy too. Global settings lists what was found and lets you switch the copy off. Changes apply when a box starts, so Stop and Resume running sessions.

With Inspect LLM on, Claude Code's calls go Claude Code → recorder in the box → your proxy → Anthropic; the recorder trusts the extra certificates and records what Claude Code sent before any rewriting by the proxy. A localhost proxy on your machine works, reached from the box as host.docker.internal.

Global settings with the provider tokens; the Claude API base URL and proxy credentials sit in the same settings
Global settings holds the Claude API base URL for a company proxy, with a proxy token or key shown only as set or not set.

Compared with other products

SessionboxerDevinCursor Cloud AgentsCodex cloudClaude Code on the webOpenHandsT3 Code
Works behind a TLS-inspecting corporate proxy✓, CA copied into the boxn/a (their cloud)n/a (their cloud)n/a (their cloud)n/a (their cloud)host's setuphost's setup
Runs on your machine or your server✓✗✗✗✗✓✓
Isolated sandbox per sessionDocker, or a Windows/macOS VMVMVMcontainerVMDocker✗ (your machine)

Hosted agents run in their own cloud, so your proxy is not in their path; the question there is whether the proxy lets you reach them, and whether your company allows code on their machines. OpenHands and T3 Code run on your machine and inherit its proxy setup; containers OpenHands starts need the CA configured by hand.

Based on each product's public documentation, September 2026; ✓ = offered, ✗ = not offered, — = not found in the docs. Corrections welcome as an issue.