Skip to content

docs(claude-code): describe sandbox OAuth token as optional - #163

Merged
gatezh merged 1 commit into
masterfrom
docs/sandbox-oauth-optional
Sep 23, 2026
Merged

gatezh merged 1 commit into
masterfrom
docs/sandbox-oauth-optional

Conversation

@gatezh

@gatezh gatezh commented Sep 23, 2026

Copy link
Copy Markdown
Owner

What

Changes how the sandbox's CLAUDE_CODE_OAUTH_TOKEN injection is described, from "Required" to optional, and reorders the README's Sandbox Authentication section to lead with the usual path.

Why

Both template variants mount the same myproject-claude-config-${localWorkspaceFolderBasename} volume at /home/node/.claude. Signing in once in the default variant therefore already authenticates the sandbox. The token is only needed when the sandbox is used standalone. Calling it "Required", combined with ${localEnv:} silently injecting "" when the host var is unset, led a downstream project to carry an unused token for months (#118 Part 1).

Changes

  • claude-code/.devcontainer/claude-sandbox/devcontainer.json: rewrote the comment above CLAUDE_CODE_OAUTH_TOKEN (optional, shared-volume path, resolves to "" when unset). The mechanism itself is unchanged.
  • claude-code/README.md "Sandbox Authentication": now leads with "sign in once in the default variant", scopes the claude setup-token flow to standalone sandbox use, and explains the empty-string case.

Notes

Refs #118

The sandbox devcontainer.json labelled CLAUDE_CODE_OAUTH_TOKEN as
Required, but both variants mount the same claude-config volume at
/home/node/.claude, so signing in once in the default variant already
authenticates the sandbox. The token is only needed for standalone
sandbox use. Re-describe it as optional, note that ${localEnv:} yields
an empty string when the host var is unset, and lead the README's
Sandbox Authentication section with the shared-volume path.

Part 2 of the issue (remoteEnv + firewall allowlist for token-bearing
MCP plugins) is left for a separate change.

Refs #118
@gatezh
gatezh merged commit d802f93 into master Sep 23, 2026
11 checks passed
gatezh added a commit that referenced this pull request Sep 23, 2026
Missed by #163: the variant summary still said the token must be
injected from the host.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant