---
title: "Sandbox network access"
canonical: "https://canmyagentuse.com/features/sandbox-network"
contentKind: "feature"
locale: "en"
description: "Allow, deny, or restrict outbound network access from a tool sandbox."
llmSummary: "Sandbox network access means a product documents allowing, denying, or restricting outbound access from its execution sandbox."
publishedAt: "2026-08-28T00:00:00.000Z"
updatedAt: "2026-08-28T00:00:00.000Z"
verifiedAt: "2026-08-28"
tags: ["runtime"]
---

# Sandbox network access

Sandbox network access means a product documents allowing, denying, or restricting outbound access from its execution sandbox.

- HTML: https://canmyagentuse.com/features/sandbox-network
- JSON: https://canmyagentuse.com/api/v1/features/sandbox-network.json
- Markdown: https://canmyagentuse.com/features/sandbox-network.md

Terminology basis: **Common product term** — https://docs.anthropic.com/en/docs/claude-code/corporate-proxy.

## Current support at a glance

Sandbox network access: 3 supported, 1 partial, 0 unsupported, 27 unreviewed across 31 cataloged products.

- Reviewed current products: 4 of 31
- Supported: 3
- Partial: 1
- Unsupported: 0
- Unreviewed: 27
- Not applicable: 0

Unknown or unreviewed means insufficient published evidence; it does not mean unsupported.

Allow or deny outbound network from a tool sandbox.

The matrix below lists published **web**, **desktop**, and **CLI** surfaces. Unreviewed cells remain **unknown** until a dated note and public source support a more specific status.

Use the Markdown and JSON twins if you are an agent reading this site.

## Catalog context

- Category: [runtime](/categories/runtime.md)
- Terminology basis: Common product term
- Aliases: None

## Compatibility assertions

Unknown means insufficient published evidence; it does not mean unsupported.

### ChatGPT (web)

- Harness: [ChatGPT](/harnesses/chatgpt-web.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (web)

- Harness: [Claude](/harnesses/claude-web.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini (web)

- Harness: [Gemini](/harnesses/gemini-web.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot (web)

- Harness: [Copilot](/harnesses/copilot-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok (web)

- Harness: [Grok](/harnesses/grok-web.md)
- current: **Unknown**
- preview: **Unknown**

### Grok Bot (desktop)

- Harness: [Grok Bot](/harnesses/grok-bot-desktop.md)
- current: **Unknown**

### Perplexity (web)

- Harness: [Perplexity](/harnesses/perplexity-web.md)
- current: **Unknown**
- preview: **Unknown**

### Le Chat (web)

- Harness: [Le Chat](/harnesses/le-chat.md)
- current: **Unknown**
- preview: **Unknown**

### Devin (web)

- Harness: [Devin](/harnesses/devin-web.md)
- current: **Unknown**
- preview: **Unknown**

### Replit Agent (web)

- Harness: [Replit Agent](/harnesses/replit-agent.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT (desktop)

- Harness: [ChatGPT](/harnesses/chatgpt-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Claude (desktop)

- Harness: [Claude](/harnesses/claude-desktop.md)
- current: **Unknown**
- preview: **Unknown**

### Cursor (desktop)

- Harness: [Cursor](/harnesses/cursor.md)
- current: **Partial**
  - Target: dated-documentation — current Cursor Cloud Agent security documentation; observed 2026-08-28
  - Environment: hosted-default
  - Constraint (runtime): applies to isolated Cloud Agent VMs; first-party documentation states that environments have operator-controlled network access and network policies without documenting the full rule model on the reviewed page
  - Evidence: [Cursor — What are background agents?](https://prod.cursor.com/help/ai-features/background-agents) — documented; observed 2026-08-28
  - Qualification note 4: Evidence checked 2026-08-28: Cursor documents isolated Cloud Agent VMs governed by network policies and operator-controlled network access, but the reviewed page does not expose the policy's complete rule syntax.
- preview: **Unknown**

### OpenWork Desktop (desktop)

- Harness: [OpenWork Desktop](/harnesses/openwork-desktop.md)
- current: **Unknown**

### Copilot Chat (desktop)

- Harness: [Copilot Chat](/harnesses/vscode-copilot.md)
- current: **Supported**
  - Target: dated-documentation — current VS Code approvals and sandbox documentation; observed 2026-08-28
  - Environment: local-default
  - Constraint (preview): agent terminal sandboxing is preview-only and available on macOS, Linux, and WSL2
  - Constraint (policy): outbound access is blocked unless allowed when sandboxing is enabled; domain allow and deny lists and an unrestricted-network switch are configurable
  - Evidence: [Microsoft — Manage approvals and permissions](https://code.visualstudio.com/docs/agents/run/approvals) — documented; observed 2026-08-28
  - Qualification note 3: Evidence checked 2026-08-28: VS Code documents preview agent sandboxing with network blocked by default, unrestricted-network opt-in, and allow/deny domain controls.
- preview: **Unknown**

### Chrome WebMCP origin trial (desktop)

- Harness: [Chrome WebMCP origin trial](/harnesses/chrome-webmcp-preview.md)
- current: **Unknown**

### Windsurf (desktop)

- Harness: [Windsurf](/harnesses/windsurf.md)
- current: **Unknown**
- preview: **Unknown**

### Zed Agent (desktop)

- Harness: [Zed Agent](/harnesses/zed-agent.md)
- current: **Unknown**
- preview: **Unknown**

### Continue (desktop)

- Harness: [Continue](/harnesses/continue.md)
- current: **Unknown**
- preview: **Unknown**

### Cline (desktop)

- Harness: [Cline](/harnesses/cline.md)
- current: **Unknown**
- preview: **Unknown**

### JetBrains AI (desktop)

- Harness: [JetBrains AI](/harnesses/jetbrains-ai.md)
- current: **Unknown**
- preview: **Unknown**

### Warp (desktop)

- Harness: [Warp](/harnesses/warp.md)
- current: **Unknown**
- preview: **Unknown**

### Claude CLI (cli)

- Harness: [Claude CLI](/harnesses/claude-cli.md)
- current: **Unknown**
- preview: **Unknown**

### ChatGPT CLI (cli)

- Harness: [ChatGPT CLI](/harnesses/chatgpt-cli.md)
- current: **Unknown**
- preview: **Unknown**

### Codex CLI (cli)

- Harness: [Codex CLI](/harnesses/codex-cli.md)
- current: **Unknown**
- preview: **Unknown**

### OpenCode (cli)

- Harness: [OpenCode](/harnesses/opencode.md)
- current: **Unknown**
- preview: **Unknown**

### Gemini CLI (cli)

- Harness: [Gemini CLI](/harnesses/gemini-cli.md)
- current: **Supported**
  - Target: dated-documentation — current Gemini CLI sandbox configuration; observed 2026-08-28
  - Environment: local-default
  - Constraint (runtime): sandboxing is configurable and disabled by default; tools.sandboxNetworkAccess defaults to false and changes require restart
  - Evidence: [Google — Gemini CLI configuration](https://geminicli.com/docs/reference/configuration/) — documented; observed 2026-08-28
  - Qualification note 2: Evidence checked 2026-08-28: Gemini CLI documents a sandbox network-access switch and sandbox profiles that allow direct or proxied network access.
- preview: **Unknown**

### Aider (cli)

- Harness: [Aider](/harnesses/aider.md)
- current: **Unknown**
- preview: **Unknown**

### Goose (cli)

- Harness: [Goose](/harnesses/goose.md)
- current: **Unknown**
- preview: **Unknown**

### Copilot CLI (cli)

- Harness: [Copilot CLI](/harnesses/copilot-cli.md)
- current: **Supported**
  - Target: dated-documentation — current GitHub Copilot CLI command reference; observed 2026-08-28
  - Environment: preview-enabled
  - Constraint (experimental): OS-level local sandboxing and the --sandbox switch require experimental mode
  - Constraint (policy): /sandbox exposes the effective network policy, while --allow-url and --deny-url control specific URLs or domains and deny rules take precedence
  - Evidence: [GitHub — Copilot CLI command reference](https://docs.github.com/en/copilot/reference/copilot-cli-reference/cli-command-reference) — documented; observed 2026-08-28
  - Qualification note 5: Evidence checked 2026-08-28: GitHub Copilot CLI documents experimental OS-level sandboxing, an effective network policy, and explicit URL/domain allow and deny controls.
- preview: **Unknown**

### Amp (cli)

- Harness: [Amp](/harnesses/amp-cli.md)
- current: **Unknown**
- preview: **Unknown**
