Install without uv#
Prefer the PyPI quick start. Use these fallbacks when uv is unavailable.
Host launcher#
The launcher is an ordinary Python package with no dependencies, and pipx
or pip installs the same claude-sandbox command that uvx runs. With
Python 3.11 or later on the host, install it with pipx:
pipx install claude-sandbox==5.0.0
cd ~/src/my-project
claude-sandbox
Or into a venv of its own:
python3 -m venv ~/.local/share/claude-sandbox-venv
~/.local/share/claude-sandbox-venv/bin/pip install claude-sandbox==5.0.0
cd ~/src/my-project
~/.local/share/claude-sandbox-venv/bin/claude-sandbox
The package version selects the matching image, as it does with uv.
Rootless Podman and the other
host prerequisites
still apply. Upgrade with pipx upgrade claude-sandbox (or pip install --upgrade in the venv), then claude-sandbox --recreate in each project.
When the image is newer than the launcher, the launcher says so and prints
the pipx command.
Install into a devcontainer#
Inside a Debian/Ubuntu devcontainer, as root:
CSBX_DIR="$(mktemp -d)"
git clone --depth 1 --branch 5.0.0 https://github.com/DiamondLightSource/claude-sandbox "$CSBX_DIR"
bash "$CSBX_DIR/install" --here
claude
install is a short bootstrap: it fetches a pinned uv (checked against a
pinned SHA-256, and kept under /usr/libexec/claude-sandbox/uv), has it
install the sandbox’s own pinned Python, then runs the same Python installer
as uvx claude-sandbox install. The container does not need uv or Python
beforehand, only apt-get; it needs network access during installation, as
it does to fetch the agents.
--here installs the chosen checkout. Without it, the installer attempts
to select the newest release and refuses a pinned or modified checkout.
The installed sandbox does not depend on the temporary clone afterwards.
Use the same block in postCreate.sh for a pinned team install.
The team guide covers the tun device,
configuration and verification.