Skip to main content
Run Claude Code in a CoreWeave sandbox and choose how you interact with it. With the terminal user interface (TUI), you use your local terminal to control Claude Code inside the sandbox. With Remote Control, you use the Claude mobile app, Claude Desktop, or claude.ai/code. In both cases, the agent process, tools, and workspace run in the sandbox. Model requests go to your configured model provider. For an integration where Anthropic manages the agent loop and a sandbox executes tools, see Claude Managed Agents.

Prerequisites

Before you begin, you need the following:
  • W&B APIキー。これらのサンプルでは W&B 認証を使用します。
  • ターミナルインターフェースを使用する場合は、Claude アカウント、または Claude Code がサポートする API 認証情報が必要です。Remote Control を使用する場合は、Claude Pro、Max、Team、または Enterprise のサブスクリプションが必要です。APIキーや claude setup-token のトークンでは Remote Control を認証できません。
  • サンドボックスからクローンできるリポジトリの URL。サンプルでは公開リポジトリを使用します。プライベートリポジトリを使用する場合は、サンドボックス内に Git の認証情報が必要です。
このガイドの手順を実行するターミナルで、W&B APIキーをエクスポートします。cws-agent が W&B 認証を選択するよう、CoreWeave トークンが設定されている場合は解除してください。
For Remote Control, Team and Enterprise accounts need an Owner to enable the feature. Your organization must also permit its transcript storage. Organizations with Zero Data Retention requirements can’t enable it. Review Anthropic’s Remote Control requirements. Connections use outbound HTTPS and don’t require a public sandbox endpoint or inbound port. Both setup paths use an 8-hour sandbox lifetime for a working day. The lifetime starts at creation, includes setup and idle time, and can’t be extended. When it expires, the sandbox stops even if Claude is working, ending the session. Save your results and stop the sandbox when you’re finished, before the lifetime expires. For overnight work, choose 24 hours at creation. With cws-agent, use --lifetime 24h. In the software development kit (SDK) examples, set Python’s max_lifetime_seconds or TypeScript’s maxLifetimeSeconds to 24 * 3600.

Quick start with cws-agent

Choose this setup path to create the sandbox with cws-agent. To create it directly with a client library, skip to Set up with the Sandbox SDK. Both paths support either interface. cws-agent のインストール手順に従ってください。このツールは、ファイルシステムスナップショットによるワークスペースの保存と復元に使用するスナップショットボリュームを設定します。 Before Claude opens, cws-agent may show a preview of local skills and Model Context Protocol (MCP) servers to import. For this guide, press Enter at the import prompt to skip it. You can configure imports later using the agent tools guidance. Choose one of the following interfaces. Replace [SANDBOX-NAME] with a cws-agent session name and [REPOSITORY-URL] with a public repository URL. Use 1 to 40 lowercase letters, digits, or hyphens for the session name, starting with a letter or digit.

Use the terminal interface

To use an Anthropic API key, load it into ANTHROPIC_API_KEY in your local terminal before launching or restoring the sandbox. cws-agent passes this variable into the sandbox. API-key authentication doesn’t require browser sign-in. See Claude Code authentication. Launch Claude Code and connect your local terminal:
Claude Code opens in the sandbox’s project directory. Follow any workspace trust prompts. For API-key authentication, approve the key when prompted. If you need account authentication, exit Claude and run cws-agent login [SANDBOX-NAME], then complete /login there. The --permission-mode native option uses Claude’s own approval settings. Without it, cws-agent defaults to bypassing those approval prompts. See permission modes. If Claude reports Not logged in despite a configured API key and never offers to approve it, exit with /exit, then reconnect with onboarding enabled:
This command uses Claude’s own approval settings. Accept the workspace trust and API-key prompts before continuing. Continue to Check the session to send a prompt and verify the result.

Use Remote Control

Create a detached sandbox, then connect your terminal for subscription sign-in:
The connection command clears settings that would prevent subscription sign-in or Remote Control feature checks. It also unsets IS_DEMO to enable onboarding. See Claude Code environment variables. Inside Claude, complete /login with your Claude subscription account and accept the project trust prompt. Run /remote-control and accept its first-use confirmation, then exit Claude with /exit. Complete this step interactively to answer the confirmation before you start the detached server. From your local terminal, start Remote Control with Claude’s own approval settings:
Open the session URL when it appears. A message that a process started isn’t sufficient to confirm the connection. Send a prompt from the web, mobile, or desktop client and verify its result as described in Check the session. If no URL appears, inspect the remote log:
Resolve any sign-in or eligibility error before retrying. If the server is waiting for an interactive prompt, restart it in an attached tmux session in the same sandbox. The cws-agent rc command redirects output to the log, so attaching to its existing session doesn’t display the prompts. From your local terminal, stop the waiting server and open a replacement session:
Inside tmux, start Remote Control so its sessions use the project directory:
Answer any prompts and open the displayed Claude Code URL. After the connection works, detach with Ctrl-b, then d, to leave the server running. The replacement session displays output in tmux instead of updating the log. To return, run cws-agent connect [SANDBOX-NAME] --cmd 'tmux attach -t cws-remote-control'.

Set up with the Sandbox SDK

Use this alternative to create a sandbox for either interface with the Sandbox SDK. It doesn’t depend on cws-agent or configure snapshots. Run Python snippets in the virtual environment created in this guide. Save TypeScript snippets as .mts files in the project where you install the client, then run them with npx tsx [FILENAME].mts.

Create the sandbox

Choose a client and install it locally:
Python 3.11 以降と uv を使用します。
Save the script for your language using the filename shown. It installs Claude Code and tmux, then clones the repository you pass on the command line. Both scripts require the container to run as root to install packages with apt-get and use /root/.local/bin/claude. Your runner’s policy must allow that user.
create_claude_sandbox.py
Replace [REPOSITORY-URL] with your public repository URL:
Keep the printed sandbox ID. These standalone examples leave the sandbox running after the script exits. The sandbox runs until you stop it or its 8-hour lifetime expires. In Python, wrapping the sandbox in a Session or context manager changes that cleanup behavior.

Attach your terminal

SDK を使用し、W&B 認証を利用してローカルターミナルをサンドボックスにアタッチします。このスクリプトはキー入力をサンドボックスのシェルに転送し、シェルが終了するとターミナルを元の状態に戻します。
macOS または Linux では、次の内容を attach_sandbox.py として保存します。
attach_sandbox.py
Replace [SANDBOX-ID] with the printed ID, then run:
Your terminal is now attached to a shell inside the sandbox. Choose one of the following interfaces to start Claude Code.

Start the terminal interface

For API-key authentication, enter the key in the sandbox’s Bash shell before starting Claude. The input is hidden and isn’t included in the command history:
Inside the sandbox, start Claude from the cloned repository:
If you use an API key, approve it. Otherwise, complete account sign-in. Then accept the workspace trust prompts and continue to Check the session.

Start Remote Control

Use Claude subscription sign-in for this interface. If you previously used an API key in this sandbox, remove it from the shell and any Claude settings before signing in:
Inside the sandbox, open a named tmux session in your project:
In tmux, start Claude:
Complete subscription sign-in and accept the workspace trust prompt. Exit Claude with /exit, then start the Remote Control server in the same directory:
The --spawn same-dir option uses the project directory for remote sessions. If prompted, accept the first-use confirmation. Open the displayed Claude Code URL in a browser signed in to the same Claude account. After the connection works, detach from tmux with Ctrl-b, then d, and exit the sandbox shell. The tmux session keeps the server running. To return, rerun the attachment script and run tmux attach -t claude-remote.

Check the session

For the terminal interface, send the prompt in the attached Claude Code TUI. For Remote Control, open the session at claude.ai/code in your browser, or in the Claude mobile or Desktop app, using the same account. Choose a unique, non-secret test value and replace [PROOF-VALUE] in this prompt:
If asked, approve the file write. If you used the terminal interface, exit Claude with /exit and, for the SDK setup, exit the sandbox shell with exit. From your local terminal, verify the result using the command for your setup:
Matching the value confirms that Claude wrote to the sandbox you created.

Return to a running sandbox

Exiting Claude or closing your terminal leaves the sandbox running. To return from another terminal or machine, install the same client and authenticate with credentials that can access the sandbox. For cws-agent, find the session by name and open a new Claude terminal:
The connect command uses the existing sandbox and files. It doesn’t resume a previous conversation. To continue a saved conversation, first exit its original Claude process. Then list the history and replace [CONVERSATION-ID] with the ID to resume:
For the SDK path, rerun the terminal attachment script with the same sandbox ID, then start Claude again. A single SDK shell session ends after 24 hours, even when the sandbox’s lifetime is longer. The sandbox keeps running, so rerun the script to reconnect. For Remote Control, reopen the session URL while its server is still running. A sandbox connection and an agent process have separate lifetimes. If a terminal agent must keep working after you disconnect, use tmux or the cws-agent worktree sessions. Reconnecting doesn’t reset the sandbox’s lifetime. If the sandbox has stopped, restore a saved workspace instead.

Keep results and stop

Save progress during a long session instead of waiting until the lifetime is nearly over. With cws-agent, wait for Claude to finish writing and pause other workspace writers, then capture the /workspace directory without stopping the sandbox:
Wait for the command to report a READY snapshot. A snapshot captures files at that point in time. Later edits need another snapshot. For capture behavior and saved credentials, see the snapshot guidance. Don’t rely on lifetime expiry to save your latest changes. In your local terminal, copy the verified text result to your machine:
For code changes, see Get changes back. A snapshot preserves the remote workspace. It doesn’t copy files to your machine. When you finish, wait for active tasks and workspace writes to complete, then save the workspace and stop compute:
The down command confirms a snapshot before stopping. If snapshot creation fails, it leaves the sandbox running. Check cws-agent status [SANDBOX-NAME] and resolve the failure before retrying. To stop without saving current changes, use cws-agent down [SANDBOX-NAME] --no-snapshot. SDK を直接使用する場合、この例では永続マウントを使用しません。ワークスペースを復元できるようにするには、作成時にファイルシステムスナップショットを設定してください。ファイル操作で結果を取り出してから、サンドボックスを停止してください。
Exiting Claude alone leaves the sandbox running. Stopping the sandbox ends its agent processes, including Remote Control. Restoring files from a snapshot doesn’t restore that process. Sign in as needed and start Remote Control again. To return to a workspace saved by cws-agent, restore it into a new sandbox. If the skills/MCP import prompt appears, press Enter to skip it:
For Remote Control, exit the restored Claude TUI with /exit, then repeat the sign-in and server startup steps, starting with cws-agent connect. Skip the launch command because restore has already created the sandbox. For saved conversations and parallel worktrees, see the cws-agent sessions guide.

Troubleshoot

Use these checks to resolve common issues:
  • サンドボックスの作成に失敗する場合は、W&B APIキーと認証設定を確認してください。
  • インストール、クローン、またはモデルへのリクエストが失敗する場合は、アウトバウンドの接続性と、該当するプロバイダーの認証情報を確認してください。
  • ターミナルが切断された場合は、サンドボックスの実行中であれば再度アタッチできます。ターミナルが切断されてもプロセスを維持したい場合は、tmux などのターミナルマルチプレクサ内で実行してください。
  • Remote Control で認証が拒否される場合は、Claude のサブスクリプションでサインインしてください。また、リモート環境または Claude の設定から、競合する APIキーの認証情報を削除してください。
  • Remote Control を利用できない場合は、Anthropic のトラブルシューティングガイドを参照し、組織設定、カスタム API エンドポイント、および必須の機能チェックを無効にする環境変数を確認してください。
  • サンドボックスの有効期限が切れた場合は、新しいサンドボックスを作成してください。有効期間は作成後に延長できません。また、この SDK の例ではファイルシステムが自動保存されない点に注意してください。

Data handling

Commands execute in the sandbox, while model requests go to your configured provider. Remote Control sends prompts, tool activity, and conversation content to Anthropic and stores a transcript to synchronize connected devices. See Remote Control security and Claude Code data usage.

Next steps

For more information, see these guides:
最終更新日 2026年9月30日