Skip to main content

Safe for third parties

One switch sets the security of an environment.

On

Use it for sandboxes that other people use, for example your own end users. Boat passes nothing of yours. The sandbox gets no GitHub access, no secrets, and no sandbox or Agents credentials. This is true whatever the section toggles say. The sandbox is confined to itself. It cannot act on your account or your other sandboxes.

Off

Use it for sandboxes that only you use. The four section toggles below apply. You choose exactly what goes in.

The --no-env flag

The --no-env flag (noEnv in the API) gives the same protection to one sandbox. Boat keeps this flag forever.
  • boat new --no-env works exactly like a start in an environment that is safe for third parties.
  • Use the environment when more than a few sandboxes need this protection.
  • The environment setting applies to every sandbox that uses it.
  • The environment setting stays through forks and resumes. Your code does not have to pass a flag.

What a normal sandbox receives

This table shows what a sandbox gets from your account when Boat withholds nothing. A protected sandbox receives none of these. It keeps only the neutral Boat-internal vars and the values that you pass with env.

Protect an existing sandbox

A snapshot of a normal sandbox can contain your secrets. To protect a sandbox made from such a snapshot, resume or fork it with --no-env:
Before the sandbox becomes reachable, Boat removes every owner secret that the snapshot can contain:
  • The managed ~/.bashrc blocks.
  • ~/.config/gh/hosts.yml. Boat also runs a gh logout.
  • ~/.git-credentials.
  • The ~/.ssh/id_* private keys.
  • The Codex and Claude credential files.
  • The in-sandbox Boat CLI token.
  • Every secret file that you configured.
Boat keeps authorized_keys and known_hosts, so you can still reach the sandbox. Boat does not touch credentials that it did not write. These stay:
  • aws and gcloud credentials.
  • .netrc and .npmrc.
  • Docker logins added inside the sandbox.
While the removal runs, SSH and desktop return a boat_securing error. Retry the request. This change goes one way only. The sandbox stays protected after it.
Boat removes the Claude and Codex credential files even when the sandbox’s own user signed in with a personal account inside the sandbox. Boat cannot tell whose files they are. If they belong to the sandbox’s user, back them up first and restore them after.

The four section toggles

When Safe for third parties is off, four separate toggles decide what a sandbox receives. Each toggle is a section in the dashboard. Open a section to edit what is inside it.