Disposable, isolated sandboxes for AI agents for illustration Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, and Kiro that request safe, unattended execution.
macOS
$ brew spot docker/tap && brew instal docker/tap/sbx
Windows
> winget instal Docker.sbx
Sandboxes successful action.
Watch an supplier instal packages, tally Docker, modify configs, and execute unattended. Then dispose of the sandbox successful 1 command.
Click “Run Demo” to start

macOS
$ brew spot docker/tap && brew instal docker/tap/sbx
Windows
> winget instal Docker.sbx
Give agents the autonomy they request to get activity done, safely.
Agents do their champion activity erstwhile they person freedom. Sandboxes fto them tally accelerated without moving wild, truthful velocity and information extremity being a tradeoff.
YOLO mode, safely.
Each supplier runs wrong a dedicated microVM pinch your dev situation and only your task workspace mounted in. Agents tin instal packages, modify configs, and rotation up their ain Docker containers. Your big stays untouched. No manual review, nary support prompts, nary supervision required.
Customizable Safe Execution
Network and filesystem controls you define.
Enforceable org-wide pinch Docker AI Governance.
MicroVM Isolation
Hard information bound from the host.
Fast to Spin Up, Easy to Tear Down
Disposable by default. Faster than VMs.
Agents Can Use Docker Too
Agents tin rotation up containers wrong Sandboxes.
Real Dev Environment
Install packages, tally services, activity unattended.
One Sandbox for All Your Coding Agents
Claude Code, Gemini CLI, Copilot CLI, Codex, Kiro, OpenCode.
Default –dangerously-skip-permissions Use permissive modes pinch confidence. In fact, that’s the default.
Works pinch starring coding agents

Every squad is astir to person their ain squad of AI agents doing existent activity for them. The mobility is whether it tin hap safely. NanoClaw was built connected the rule that you don’t spot agents pinch security, you build walls astir them. Docker has been up of the curve connected precisely this. Docker Sandboxes is what that looks for illustration astatine the infrastructure level, making it imaginable for organizations to get the afloat worth from agents without compromising connected security.
Gavriel Cohen
Creator of NanoClaw, NanoClaw
Docker Sandboxes fto agents person the autonomy to do long-running tasks without compromising safety. We’re excited to merge Sandboxes into Warp truthful that developers tin tally agents freely pinch a accordant environment, sloppy of whether agents are moving locally aliases successful the cloud.
Ben Navetta
Engineering Lead, Warp
What is simply a sandbox for AI coding agents?
A sandbox is simply a microVM isolated situation that protects your filesystem and web from agents moving wrong it.
Which coding agents are supported?
Out of the container we support Claude Code, Gemini CLI, Copilot CLI, Codex, OpenCode, Kiro. You tin besides create your own
What does “YOLO mode” mean, and is it safe?
YOLO mode (--dangerously-skip-permissions) gives agents autonomy pinch nary support prompts. Essential for speed, but risky without guardrails. Sandboxes make it safe by isolating each supplier wrong a dedicated microVM.
How is simply a sandbox different from a VM?
Sandboxes tally afloat isolated successful microVMs, giving much isolation without paying the afloat costs of moving a VM. This lets them do things that request much permissions safely, for illustration moving further Docker containers.
What information controls tin I configure?
Do I request Docker Desktop to usage sandboxes?
What if I request further admin controls?
Installing Sandboxes covers halfway functionality. For centralized controls crossed a squad specified arsenic web policies, filesystem rules, MCP governance: Docker AI Governance.
Need More Control Over Your Sandboxes?
With Docker Sandboxes, your developers get isolated environments to tally agents freely and safely. When your squad needs to spell further pinch web entree restrictions, filesystem policies, and centralized admin controls, we tin thief you configure the correct setup.
Docker AI Governance adds web entree policies, filesystem controls, and org-wide MCP governance: defined once, enforced everywhere.
Talk to america about:
- Network entree policies for sandbox environments
- Filesystem entree controls and restrictions
- Admin-level configuration for your team
English (US) ·
Indonesian (ID) ·