Reference
Where Sessionboxer keeps its files, and the environment variables
config.json, the SQLite database, session containers, the Sandbox and snapshot images, downloaded binaries and models, and the SESSIONBOXER_* environment variables.
| Settings, tokens, MCP servers | ~/.sessionboxer/config.json |
| Sessions, chat history, scheduled tasks and their runs | ~/.sessionboxer/db.sqlite |
| Session containers | sbx-<session id> on the sessionboxer Docker network, no published ports |
| Windows VMs | sbx-win-<session id> (container and volume) next to the session's box; the shared base disk in the sbx-windows-base volume, its record in ~/.sessionboxer/windows-base.json |
| macOS VMs | sbx-mac-<session id> (container and volume) next to the session's box; the shared base disk in the sbx-macos-base volume, its record in ~/.sessionboxer/macos-base.json; sbx-macos-install while the base installs |
Workspace root in the box (repositories in /workspace/<name>) |
/workspace |
| Sandbox image | ghcr.io/talayolabs/sessionboxer-sandbox:<version> (pulled, or built locally by npm run build:image); SESSIONBOXER_IMAGE overrides |
| Snapshot images | sessionboxer/snapshot:<session id>-<n>; unreferenced ones are removed at startup |
| What was last pulled into a copied folder | ~/.sessionboxer/sync/<session id>.json |
| Files attached on the New session screen, until their box is up | ~/.sessionboxer/staging/<id>/ (swept after a day) |
Downloaded cloudflared / frpc (tunnels), whisper-cli (dictation) |
~/.sessionboxer/bin/ |
| Whisper models for dictation | ~/.sessionboxer/models/whisper/ggml-<name>.bin |
Sessionboxer tunnel secret, generated frpc.toml, CA bundle for frpc |
~/.sessionboxer/config.json, ~/.sessionboxer/frpc.toml (mode 600), ~/.sessionboxer/tunnel-ca.pem |
CLAUDE_CODE_OAUTH_TOKEN or WINDSURF_API_KEY set in the environment of npm start take precedence over the tokens in Settings. SESSIONBOXER_HOST / SESSIONBOXER_PORT change where the Control Plane listens (default 127.0.0.1:4000); SESSIONBOXER_PUBLIC_URL, SESSIONBOXER_TRUST_PROXY, SESSIONBOXER_TLS_CERT / SESSIONBOXER_TLS_KEY and SESSIONBOXER_ACCESS_TOKEN are described under Remote access.
This chapter is generated from docs/GUIDE.md in the Sessionboxer repository. Found a mistake? Open an issue.