Highlights
Docker Sandboxes v0.47.0 adds automatic cleanup after agent sessions with sbx run --rm and a kit capability for keeping local sandboxes running after sessions disconnect.
What's new
Security
- Fixed OAuth token interception when a provider hostname uses different capitalization or a trailing dot, preventing real tokens from reaching the sandbox instead of the proxy's placeholders.
- The proxy rejects unrecognized OAuth token grants and prevents their responses from replacing host-managed credentials. Supported in-sandbox sign-in flows remain available.
- The proxy returns an error when it cannot safely mask a successful Anthropic API-key creation response, instead of forwarding the unmasked response to the sandbox.
- Included since v0.46.0: fixed raw TCP connections to denied hostnames being permitted by an allow rule for the hostname's resolved IP address. This fix applies to TCP; the related UDP case with multiple tracked hostnames remains outside its scope.
- Included since v0.45.0: CLI-created cloud hostname allowlists no longer gain implicit
0.0.0.0/0and::/0rules. Existing stored policies are unchanged; remove those rules or recreate the policy to apply the restriction. Explicit IP and CIDR allowances remain supported. - The proxy rejects TLS handshakes that fill its inspection buffer before a complete ClientHello can be checked on a non-MITM CONNECT tunnel or during the transparent proxy's late handshake check.
- The proxy closes incomplete TLS handshakes on those paths after a two-minute timeout instead of retaining the connections for the sandbox's lifetime.
- Sandboxes reject UDP to multicast, link-local, and unspecified destinations, limited broadcast, and broadcast addresses derived from the host's interface prefixes, regardless of network policy. UDP to
host.docker.internalis unaffected. Broadcast addresses configured outside that derivation and networks reachable only through routes are not covered by this check. - Kit pulls enforce limits on registry-declared blob sizes, decompressed content, and archive entry counts.
Sandbox lifecycle and workspaces
sbx run --rmremoves a local or cloud sandbox after its agent session ends. It cannot be combined with--detached. If a cloud session is interrupted, such as by a dropped connection, the sandbox is kept and the CLI prints the command to remove it.- Running
sbx run -dagainst an existing local sandbox keeps it running after sessions disconnect, until you stop or remove it. - Dynamic mounts and permissions created through symlink paths can be removed without reappearing after a restart. Incompatible saved records include recovery guidance.
Kits
- Local kit inspection, validation, and pulling require the daemon to be running.
- Kits can declare
com.docker.sandbox/long-running@1to keep local sandboxes running after all sessions disconnect. Cloud sandboxes andsbx kit addcannot provide this capability: required entries are rejected, and optional entries are skipped. sbx kit signandsbx kit push --signsucceed on registries that refuse manifest deletion, including GitHub Container Registry and Docker Hub, instead of reporting failure after attaching the signature.- Adding a kit to a sandbox whose guest has stopped responding fails without leaving the sandbox unusable until the daemon restarts.
Cloud sandboxes
sbx --cloud ttlreports stopped sandboxes as stopped instead of expired. The time-to-live restarts when the sandbox resumes. JSON output includesstoppedandttl_paused; while the sandbox is resuming, onlyttl_pausedis true.- Creating a cloud sandbox or moving a local sandbox to the cloud applies cloud policy and the kit's network rules without copying locally added network rules. Moving a sandbox with local HTTP method or path restrictions warns that those restrictions will not apply in the cloud.
Settings and proxies
- Upstream proxy recovery no longer blocks unrelated sandboxes or deletes isolated container data when credentials are unavailable. Local host services remain reachable.
sbx settings setrejects invalid upstream proxy values before saving them.
MCP
- MCP authorization requests
offline_accesswhen the server advertises it and authorization uses saved defaults or resource-required scopes, so the server can issue refresh tokens. Explicit--scopevalues are unchanged. Runsbx mcp authagain to obtain a grant with a refresh token for existing credentials. - Fixed MCP gateway availability in sandboxes created from the TUI and when connecting over SSH after a daemon restart or automatic sandbox creation.
CLI and updates
sbx envreports the correct file, line, and column for unrecognized keys even when another entry in the file fails custom validation. Multiple validation errors appear on separate lines.- Help remains available when the settings directory is unwritable or local settings cannot be opened, with a warning instead of a panic.
- Host-port collisions from
sbx ports --publishidentify the occupied binding and offer a retry with an automatically allocated port when safe. - Windows update notices appear only after WinGet confirms that the version is available in its catalog.