Sessionboxer

Working with code

Log in to GitHub once; the agent and the box use it

Connect GitHub through the GitHub CLI's login: the agent gets GitHub's MCP server, gh and git push work in the box, and several accounts can share one session.

Feature page: Your repositories, your subscription — screenshots, things you can do with it and how other products compare.

GitHub's own remote MCP server (issues, pull requests, code search, Actions…) needs a login token, and you do not have to paste one: click Connect GitHub in Settings → Git accounts (right under Provider logins), give the entry a name, and pick one of three logins. Log in with GitHub (GitHub CLI) runs the GitHub CLI's login (open the link, type the code, approve) and gets what your account can see, every organization included. The card then shows Connected as @you. Add it more than once with different names (github-work, github-personal…) to log in with different GitHub accounts and pick per session which one the agent uses. Reconnect logs in again, Disconnect forgets the token but keeps the entry. The token is stored like any other secret header and never shown or snapshotted.

The login goes through the GitHub CLI (gh) on purpose: organizations that restrict third-party OAuth Apps still allow GitHub's own CLI, so private organization repositories work without asking an owner to approve anything. If gh is already logged in on your machine the dialog also offers Use my gh login as @you (no browser step); if gh is not installed, Sessionboxer downloads the official release (checksum-verified) into ~/.sessionboxer/bin on first use. Either way it uses a private configuration under ~/.sessionboxer, so your own gh accounts are never touched. Log in with the Sessionboxer OAuth App is the second login: GitHub's consent page lists your organizations with Grant / Request (an organization owner approves requests, and one already granted to the app stays granted), and names the app's owner as the requester; to have it name you instead, register your own OAuth App on GitHub (callback <your public URL>/api/connectors/github/callback — Settings shows the exact address —, Device Flow enabled) and put its Client ID in Global settings → MCP & connectors → Git → Your own GitHub OAuth App; with the Client secret set too, that login switches from the device code to a plain browser redirect. The third login, Use a personal access token, is the one to pick when Sessionboxer should reach a single organization or a few repositories: the dialog links to GitHub's token page and lists what to tick (fine-grained: Contents, Pull requests, Issues and Workflows, read and write, for the repositories you choose; classic: repo, workflow, read:org), you paste the token, Sessionboxer checks it with GitHub and stores it like the other logins. Fine-grained tokens expire; Reconnect takes a new one.

While a GitHub entry is enabled for a session, the box itself is logged in as that account too: gh pr create --draft, gh pr view --comments, git push and git clone of private HTTPS repositories work in the agent's shell and in the Terminal pane. Switch the entry off in the session's MCP popover and the login is gone from the box; it lives on tmpfs, so Snapshots and stopped boxes never carry it. SSH remotes are not covered; use HTTPS URLs for the box.

Several accounts, one session. Each GitHub repository of a session is bound to one of the connected logins: the Account dropdown next to a git URL (in New Session and in the header's repository dialog) lists every Connected as @… entry, with auto as the default — Sessionboxer asks GitHub which of the session's accounts can push to that repository (else which can see it, else the first) and binds that one; picking an account that is not yet enabled for the session turns its entry on. The repository is cloned as that account, and inside its directory git push/git fetch and every gh command act as it, whatever gh auth status says is active elsewhere (the directory's .git/config names the login, sessionboxer.githubAccount, never a token; gh auth … itself is left alone). The header chip shows as @login, the agent's briefing and repos.json say which account each repository uses, and PR watching, actions and auto-merge on that repository's pull requests use it first. Change the binding any time in the repository dialog (also while the box is stopped; it applies at resume), or choose Active login (no binding) to fall back to the box's active gh account (the first enabled entry; gh auth switch picks another). Copied host folders are not bound. CLI: sessionboxer new --git <url> --as <login>.

This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.