Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 3 additions & 2 deletions claude-code/.devcontainer/claude-sandbox/devcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -122,8 +122,9 @@
"DEVCONTAINER": "true",
"NODE_OPTIONS": "--max-old-space-size=4096",
"CLAUDE_CONFIG_DIR": "/home/node/.claude",
// Required — the sandbox firewall blocks OAuth login, so the token must be
// injected from the host. See "Sandbox Authentication" section in README.
// Optional — only needed when the sandbox is used without the default variant, whose
// sign-in lands on the shared ~/.claude volume. Resolves to "" when the host var is
// unset. See "Sandbox Authentication" section in README.
"CLAUDE_CODE_OAUTH_TOKEN": "${localEnv:CLAUDE_CODE_OAUTH_TOKEN}"
},
// The find command chowns all node_modules volume mount points in one pass.
Expand Down
8 changes: 6 additions & 2 deletions claude-code/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -164,9 +164,13 @@ After the one-time copy, the skill manages its own updates.

### Sandbox Authentication

The sandbox firewall blocks outbound traffic, so `claude login` (which opens a browser OAuth flow) won't work inside the container. Instead, generate a token on the host and inject it via environment variable.
**Usual path: sign in once in the default variant.** Both variants mount the same `myproject-claude-config-*` volume at `/home/node/.claude`, so credentials created by signing in to the default variant (VS Code extension, or `claude` in a terminal) are already there when the sandbox starts. No token is needed.

**Setup (one-time):**
**Standalone sandbox: inject a token.** If you use the sandbox without ever opening the default variant, sign-in has to happen inside the sandbox, where the firewall blocks the browser OAuth flow that `claude login` opens. Generate a token on the host and inject it via environment variable instead.

When `CLAUDE_CODE_OAUTH_TOKEN` is unset on the host, `${localEnv:CLAUDE_CODE_OAUTH_TOKEN}` resolves to an empty string, so the variable still exists in the container, but empty. That is expected: with an empty token, Claude Code authenticates from the credentials on the shared volume.

**Setup (one-time, standalone sandbox only):**

1. Generate a setup token on your host machine:
```bash
Expand Down
Loading