Claude Sandbox for VS Code
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@Claude Sandbox for VS Codeshow me the diagnostics for this file and propose a fix"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Claude Sandbox for VS Code
Makes VS Code the IDE of a Claude Code session that runs inside claude-sandbox: Claude sees your editor selection, shows proposed edits as diffs in VS Code for you to accept or reject, and reads the workspace's diagnostics. It speaks Claude Code's IDE protocol (MCP over a WebSocket), the role Anthropic's own extension plays for an unsandboxed Claude. claude-sandbox itself is not changed.
Status: stage 1. The bridge works; the terminal launcher is not built yet.
Run Claude Sandbox: Copy launch command and paste the copied
claude --settings '…' into a devcontainer terminal in the workspace folder.
How it works
The extension listens on a Unix socket in the workspace root (
.claude-sandbox-vscode-<port>.sock, mode 0600), which the jail can see.claude-sandbox is given
--settingswithCLAUDE_CODE_SSE_PORTandSessionStart/SessionEndhooks. Inside the jail the start hook startssocat(TCP127.0.0.1:<port>to the socket) unless it already runs, and once it listens writes Claude Code's lock file (~/.claude/ide/<port>.lock, with the auth token), never over an existing one. The end hook removes it on a real exit (not on/clearor/resume).Claude Code connects; the extension checks the token and serves four MCP tools:
openDiff,close_tab,closeAllDiffTabs,getDiagnostics.
One linked Claude session per VS Code window, in a devcontainer with claude-sandbox installed: while it is connected, another connection is refused. Other Claude sessions run sandboxed without the IDE link.
The full design and the protocol notes are in docs/design.md.
Related MCP server: vscode-agent-bridge
Security
The extension host runs outside the sandbox with your full privileges, and anything inside the sandbox can read the token and reach the socket, so every message is treated as hostile (trust boundary):
Only the four tools above; nothing that runs code, opens URLs or writes files.
openDiffreads only real paths inside a workspace folder, never in.git, one path component at a time without following symlinks (a symlink swapped in after the check is refused).The extension never writes a workspace file: Accept hands the text back and Claude writes it from inside the sandbox. Closing a diff is a rejection. Accept and Reject work from either side of the diff.
Diagnostics and selections are sent only for workspace files.
The host never writes into the sandbox's
~/.claude; the in-sandbox hook writes the lock file, and every value in its shell command is validated and quoted. The host deletes nothing in the workspace either (its own socket goes when the link closes).The hand-written WebSocket server has no runtime dependencies: messages are capped at 16 MiB (from the frame header), at most 4 connections in their handshake and one linked session, a handshake timeout, backpressure on output (a client that stops reading is not read, and is dropped past 32 MiB queued), a ping every 30 s (a client that answers nothing is dropped), permessage-deflate refused, parsed JSON never merged into objects, and nothing from the sandbox logged unescaped.
The token appears in claude-sandbox's argv. Other users cannot use it (the socket is 0600); processes running as you are already trusted.
Every rule has a test in test/hostile/ or test/unit/; the mapping is in
docs/design.md.
Out of scope (residual risk). VS Code on a workspace the sandbox can write
is exposed whether or not this extension is installed: .vscode/settings.json
(interpreter paths, tasks) and .git/config (fsmonitor, filter drivers) run
on the host. Keep such workspaces untrusted in VS Code's Workspace Trust, or
review the agent's changes to them before reopening.
Development
Linux, Node 22.18 or later (tests run the TypeScript directly), and socat for
the end-to-end hook test.
npm ci
npm run typecheck
npm test # node --test: test/unit and test/hostile
npm run build # esbuild → dist/extension.cjs
npm run package # .vsix via @vscode/vsceLicense
MIT, Copyright (c) 2026 Diamond Light Source Ltd.
This server cannot be deployed
Maintenance
Related MCP Connectors
Enable secure connectivity between Sentry issues and debugging data, and LLM clients, using a Model Context Protocol (MCP) server.
Share context and questions between Claude instances — VS Code, claude.ai web, and mobile.
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
Live browser debugging for AI assistants — DOM, console, network via MCP.
Related MCP Servers
- FlicenseAqualityDmaintenanceBridges web browsers and Claude Code for seamless debugging workflows by receiving debug data from browser widgets and exposing it to Claude Code via MCP protocol.10-
- AlicenseNot gradedqualityBmaintenanceEnables AI agents to access live VS Code editor state, symbol navigation, diagnostics, and language-aware editing through MCP, bridging the gap between what the agent can infer from disk and what the editor actually knows.MIT
- AlicenseNot gradedqualityAmaintenanceProvides a read-only MCP bridge that lets Claude Web inspect workspace files, git state, and recorded test results while Codex remains the sole executor of changes.542 npm2MIT
- AlicenseNot gradedqualityCmaintenanceEnables MCP clients such as OpenCode, Claude Code, and Codex to control a real VS Code editor by opening files, visibly typing code, running terminal commands, reading diagnostics, and fixing errors through the VS Code API. It makes AI programming observable by applying real progressive edits and actions that are visible on screen.MIT