Same repo. Same coding agent. Different GitHub access. Two Docker-sandboxed Claude Code sessions use the same personal GitHub credential through Stashbase Remote Proxy. github-all can list PRs. github-deny is blocked. The token never reaches the local machine or agent. stashbase.dev
3
1
95
An agent can make 200 requests before you finish your coffee. “I told it to be careful” is a strange security strategy. Agent access should be configured and enforced outside the prompt. That’s what we’re building at Stashbase: stashbase.dev
1
2
22
One thing I like here: the Stashbase Remote Proxy works even when the agent itself runs locally in a Docker sandbox.
Claude Code in a local Docker sandbox can call gh api user through the Stashbase Remote Proxy. It only sees a placeholder. The real GitHub token stays in Stashbase and is injected only for approved api.github.com requests. stashbase.dev
23
One of the details I like a lot. Go ahead and try it. CLI repo: github.com/stashbase/cli
A sandbox that starts from zero every time won’t become part of a real daily workflow. Stashbase Docker sandbox sessions now persist for Claude Code and Codex. Same login. Same session state. Still running under the filesystem, network, credential, and MCP rules you chose. It sounds small, but it makes sandboxing much more practical to use every day.
1
35
agents. agents. agents.
1
16
Can your coding agent read files outside the repo? Can it connect to any host? Can it use every credential and MCP tool on your machine? For many local setups: yes. Stashbase runs coding agents in a Docker sandbox and scopes files, credentials, network access, and MCP tools by profile. stashbase.dev
2
2
109
A sandbox that makes you start from zero every time won’t get used for long. We made Stashbase Docker sandbox sessions persistent for Claude Code and Codex. Same login. Same session state. Still running with the filesystem, network, credential, and MCP rules you chose. It sounds small, but it matters if sandboxing is going to be part of a real daily workflow. stashbase.dev/#sandbox
3
64
proper sleep beats caffeine, proper sleep and caffeine beat proper sleep without caffeine
1
14
You start Claude Code or Codex locally to work on a real repo. It needs to read code, run tests, install dependencies, and use GitHub. But it is also running with access to your machine. It can read ~/.aws/credentials, delete files in your home directory, or send data to an arbitrary host. Permission prompts help, but they are not an enforced boundary. We’re building Stashbase so the agent gets the access it needs, while files, credentials, network destinations, and MCP tools are explicitly scoped by policy. The model proposes. The profile decides. stashbase.dev
3
3
111
Coding agents need enough access to do useful work. They do not need unrestricted access to your .env, production APIs, filesystem, network, or every MCP tool. The agent can work in a real repo. Policy decides which files it can read, which hosts and API paths it can reach, and which credentials can be used. Now supports Docker sandboxing. stashbase.dev
3
4
269
Docker sandboxing is now available in Stashbase. Run Claude Code or Codex or any agent in an isolated Docker environment, configured alongside your existing agent access policy. The same profile can control filesystem access, credentials, network egress, and MCP tools. Agent traffic goes through the Stashbase Agent Proxy and a separate firewall layer, with no direct outbound network access from the container. Docs: stashbase.dev/#sandbox
1
24
We’ve added a Docker sandbox option to Stashbase for running coding agents like Claude Code and Codex. Enable it in a Stashbase profile, then start the agent with one command. It uses our default image, or you can bring your own image or Dockerfile. Agent state persists between sessions, so you do not need to log in every time. stashbase.dev
3
4
60
What enforces it after that one command? The sandbox uses the policies already defined in a Stashbase profile, including filesystem restrictions, egress rules, credentials, and MCP tool access. The agent container has no direct outbound network access. A separate firewall layer allows it to reach only the Stashbase Agent Proxy, where egress and credential policy are enforced. So the agent gets an environment it can work in, while Stashbase controls what it is actually allowed to access.
10
Th redesigned ChatGPT apps is awesome, only one thing i misssing: tabs
17
Really nice experience with @warpdotdev and Claude Code lately.
17
Fellow founders, always take care of your health.
9
An HTTPS_PROXY variable is not a sandbox. A coding agent can just ignore it. If access is meant to be scoped, the network boundary has to hold even when the agent tries to bypass it. That is the kind of sandboxing we have been working on. More soon.
4
1
3
83