Sessionboxer

Working with code

Behind Cloudflare WARP or Zscaler: your proxy's certificates in every box

Sessionboxer copies the CA certificates your machine trusts into every box, so agents and MCP servers behind a TLS-inspecting proxy do not fail on self-signed certificate errors.

Feature page: Works behind a corporate proxy — screenshots, things you can do with it and how other products compare.

If your machine goes through a proxy that re-signs HTTPS, the agent and MCP servers inside a box would see self signed certificate in certificate chain, because the box only trusts the public CAs. Sessionboxer therefore copies the CA certificates your machine trusts beyond the public ones (the proxy's root) into every box at start and points Node, Python and OpenSSL at them, so HTTPS from the box works like from your machine. The Control Plane trusts the same certificates itself (Node alone would not), so its own downloads (gh, cloudflared, frpc) and the tunnel server's API pass the proxy too. Global settings → Environment → TLS certificates lists what was found, lets you turn the copy off, and takes extra PEM certificates for CAs not installed on this machine. Changes apply at Sandbox start: Stop → Resume running sessions. npm run build:image hands the same certificates to docker build, so the downloads during the image build (apt, npm, GitHub releases) pass the proxy too; it prints which ones it found.

This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.