Sessionboxer

Get started

Connect Claude Code, Codex or Devin to Sessionboxer

First run: paste a token for Claude Code, Codex or Devin in Global settings, where it is stored, and the defaults every session inherits (git identity, CPU and memory).

Feature page: Your repositories, your subscription — screenshots, things you can do with it and how other products compare.

The first screen is the prompt box with four Provider logos above it: click the agent you want to use and the dialog opens. Sign in with is the short way: it opens the Provider's sign-in page in a new tab of this browser — the one where you are already signed in to Claude, ChatGPT, Cursor or Devin, or where Chrome has your password — and finishes the login for you. Claude Code and Devin show a code on their page once you are in: paste it into the field under the button. Codex is the other way round: the dialog shows a one-time code, type it into the page. Cursor needs nothing more; the dialog notices when the page is done. Behind the button, Sessionboxer runs the Provider's own login CLI (the one on the machine the server runs on when it is installed there, else a throwaway box from the Sandbox image) in a scratch home, so your own ~/.claude.json, ~/.codex/auth.json, … are never read or rewritten, and stores only what the CLI produced — the same token or file you would paste by hand. When the server runs on your own machine and its CLI is already logged in there, the dialog says signed in as you@…; for Codex, Cursor and Devin Use this machine's login copies it without any browser tab (Claude Code's own login is short-lived and cannot be copied, so the button signs in). Or using the CLI underneath is the terminal way, in three steps for your OS (macOS, Windows or Linux; switch with the tabs) — install its CLI, log in, paste (or import) what it produced. The same wizard is behind To set up → Connect a Provider in the sidebar and Global settings → Providers → Connect a Provider…. The To set up list starts with Runtime — Docker, or QEMU for Windows and macOS VMs — struck through when the machine has it; done items stay in the list, struck through. Connect a Git account next to it connects GitHub or Bitbucket (see Git accounts); skip it (later) if you only work on public repositories or none. What each Provider needs, by hand:

  • Claude Code: run claude setup-token on your machine and paste the result.
  • Codex: run codex login on your machine (it opens the browser; sign in with your ChatGPT account), then paste or import ~/.codex/auth.json. Settings shows the account, plan and last refresh it holds, never the file. Codex refreshes the tokens inside the file while it works; the refreshed file is stored back so other Codex sessions and your next session keep working. Paste it again if Codex answers Your access token could not be refreshed.
  • Cursor: install the Cursor CLI on your machine and run agent login (it opens the browser; sign in with your Cursor account), then paste or import the file it writes: ~/.config/cursor/auth.json on Linux, ~/.cursor/auth.json on macOS, %APPDATA%\Cursor\auth.json on Windows. An API key from cursor.com → Dashboard → Integrations works too, pasted in the same field. Settings shows whether it holds a login or an API key and until when the login's token is valid, never the file. Cursor refreshes the token inside the file while it works; the refreshed file is stored back so other Cursor sessions and your next session keep working. Paste it again if Cursor sessions fail to start with an authentication error.
  • Devin: run devin auth login on your machine, then paste the token from ~/.local/share/devin/credentials.toml.

Global settings (bottom of the sidebar) is laid out like the Advanced dialog: the groups down the left — Providers (logins, Claude API), Environment (CPU and memory, Docker inside the Sandbox, snapshots, Windows and macOS VMs, TLS certificates), Agent (Claude model aliases, system prompt), MCP & connectors (the built-in desktop and sessionboxer servers with their settings, Git accounts and author, GitHub OAuth App, your own servers), Auto QA, Interface (color theme, dictation), Devices and remote access — and the one you picked on the right, each caption with a ? for its explanation; #/settings/<group> links straight to one (old section links such as #/settings/agent-tools still open the right block). Save writes every section at once, whichever is on screen. Tokens are stored in ~/.sessionboxer/config.json (readable only by you) and are only handed to the containers of sessions that use that agent. Settings also holds the default git name and email that commits made by agents will carry (blank means your machine's git config; either can be overridden per session when creating it), and how much CPU and memory each session gets (2 CPUs and 4 GB by default).

This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.