Sessionboxer

Watching the agent

Inspect every API call Claude Code makes, byte for byte

Inspect LLM records each request and response between Claude Code and the Anthropic API: exact bodies, a parsed tree and a diff against the previous call. Also covers a company proxy.

Feature page: See exactly what goes to the model — screenshots, things you can do with it and how other products compare.

For Claude Code sessions, Inspect LLM (on by default for new sessions; the switch is in New Session and in the session's Session settings) records the agent's model API calls: from then on every request Claude Code makes to the Anthropic API (or to your company's proxy, see below) and the response it got are kept, byte for byte. The agent bubbles and tool calls that came out of a call get an LLM #n label over their top-left corner; click it (or Tab to it and press Enter) for the call: Request and Response are the exact decoded bodies (byte count, pretty JSON, Copy, Download), Tree parses both (settings, the system blocks with their cache markers, every tool schema with its size, each message block; the response's content and stream events) and Diff shows what changed against the previous conversation call, so you can see what a turn added. Calls that produce no bubble (Claude naming the session, counting tokens, health checks) are in Context → Model API calls, a table of every call with its kind, model, status, tokens, sizes and duration; each row opens the same dialog. The recording turns on for the next call: switching it while the agent is working shows pending until the turn ends, since the agent process is restarted in place (it keeps the conversation).

The bodies stay inside the box, in memory (tmpfs): the last 40 calls with their bodies, older ones keep their summary line but say body no longer in the Sandbox, each body cut at 4 MB, and all of it goes when the box stops (the summaries stay in the chat). Headers are never recorded, so tokens and API keys are not either; what is recorded is everything the agent read, the system prompt and your prompts, which is why it is off by default and per session. Devin sessions have no such label: what its CLI sends from the box is a message to Cognition's servers, where the prompt is assembled and the model called, so there are no exact model bytes to show.

Global settings → Providers → Claude API shows where Claude Code in each box sends its calls right now and where that comes from: a URL set there, else the ANTHROPIC_BASE_URL of the Control Plane's environment, else Anthropic's https://api.anthropic.com. Set your company's Claude proxy there (a localhost URL on your machine works, the box reaches it as host.docker.internal), plus, if the proxy wants its own credential instead of the OAuth token, a Proxy auth token (ANTHROPIC_AUTH_TOKEN) or Proxy API key (ANTHROPIC_API_KEY), which are shown only as set/not set afterwards and stripped from snapshots like the tokens. With inspection on the chain is Claude Code → loopback recorder in the box → your proxy → Anthropic: the recorder forwards to the configured URL (trusting the extra CA certificates from Settings, as the agent does) and records what Claude Code sent, before any rewriting your proxy may do; with it off there is no hop at all. It applies to Sandboxes created afterwards.

This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.