Safe for third parties
One switch sets the security of an environment.On
Use it for sandboxes that other people use, for example your own end users. Boat passes nothing of yours. The sandbox gets no GitHub access, no secrets, and no sandbox or Agents credentials. This is true whatever the section toggles say. The sandbox is confined to itself. It cannot act on your account or your other sandboxes.
Off
Use it for sandboxes that only you use. The four section toggles below apply. You choose exactly what goes in.
The --no-env flag
The --no-env flag (noEnv in the API) gives the same protection to one sandbox. Boat keeps this flag forever.
boat new --no-envworks exactly like a start in an environment that is safe for third parties.- Use the environment when more than a few sandboxes need this protection.
- The environment setting applies to every sandbox that uses it.
- The environment setting stays through forks and resumes. Your code does not have to pass a flag.
What a normal sandbox receives
This table shows what a sandbox gets from your account when Boat withholds nothing.
A protected sandbox receives none of these. It keeps only the neutral Boat-internal vars and the values that you pass with
env.
Protect an existing sandbox
A snapshot of a normal sandbox can contain your secrets. To protect a sandbox made from such a snapshot, resume or fork it with--no-env:
- The managed
~/.bashrcblocks. ~/.config/gh/hosts.yml. Boat also runs aghlogout.~/.git-credentials.- The
~/.ssh/id_*private keys. - The Codex and Claude credential files.
- The in-sandbox Boat CLI token.
- Every secret file that you configured.
authorized_keys and known_hosts, so you can still reach the sandbox.
Boat does not touch credentials that it did not write. These stay:
awsandgcloudcredentials..netrcand.npmrc.- Docker logins added inside the sandbox.
boat_securing error. Retry the request. This change goes one way only. The sandbox stays protected after it.