Claude Code Sandbox — User Guide ( PDF)
This guide walks you through setting up and using your personal cloud development environment with Sandbox Connect. Sandbox Connect handles everything — enrollment, certificates, SSH connections, and file transfer — so you can focus on coding.
You will need:
- Your corporate laptop (Windows, macOS, or Linux).
- Your NBG corporate account.
- About 15 minutes for first-time setup.
1. Quick vocabulary
- VM (Virtual Machine) — a Linux computer in NBG's cloud that you control from your laptop. You don't see it physically — you connect to it through Sandbox Connect.
- Terminal — a window where you type commands as text. Sandbox Connect opens one for you automatically when you connect.
- GCP / Vertex AI — Google Cloud Platform hosts the Claude AI models via Vertex AI. Each user has their own GCP project for usage tracking.
2. Log in to the portal
- Open your browser and go to: https://claude-code-sandbox.azurewebsites.net
- Sign in with your corporate account when redirected to the identity provider.
- You land on the Dashboard.
Trouble logging in? Make sure you are on the NBG corporate network or VPN. If login fails with "access denied", contact the platform team — your account may not be authorized yet.
3. Install Sandbox Connect
On the Dashboard, download the installer matching your OS:
- Windows: double-click the
.exe. If SmartScreen blocks it, click "More info" → "Run anyway". - macOS: double-click the
.pkgand follow the installer. If macOS blocks it, open System Settings → Privacy & Security, scroll down to find the blocked-installer message, and click "Open Anyway". - Linux: download the AppImage, make it executable (
chmod +x), and run it.
4. Enroll your device (one-time)
- Right-click the Sandbox Connect tray/menu-bar icon and select Connect. Since this is your first time, the enrollment window appears asking for a device label (e.g.
MacBook Pro,Office Desktop). Type something memorable and confirm. - Sandbox Connect displays an 8-character fingerprint (like
ABCD-1234), a link to the portal's pending enrollments page, and a 15-minute countdown. Leave this window open. - Click the link in the Sandbox Connect window to open the pending enrollments page in your browser. Sign in if prompted.
- You see your pending device request. Verify the fingerprint matches the one Sandbox Connect is showing. If they don't match, click Deny and start over — a mismatch means someone else minted a request from your network.
- Type the fingerprint into the confirmation box and click Approve.
- The portal may prompt you to re-authenticate with MFA. Complete it.
- Within a few seconds, Sandbox Connect transitions to the main UI. You're enrolled.
Fingerprint expired? Click Connect in Sandbox Connect and repeat steps 4–6.
5. Connect to your VM
Right-click the Sandbox Connect tray/menu-bar icon and select Connect. Sandbox Connect handles everything behind the scenes — if you don't have a VM yet, it creates one automatically. After a moment you land on the VM terminal, ready to work.
6. First-time VM setup (one-time)
The first time you connect to your VM, you need to configure Claude Code:
- Find your GCP project number. Open console.cloud.google.com, sign in with your corporate Google account, select your project, and find the Project number (a 12-digit number like
1071209071325). - On the VM, type:
claude - The wrapper prompts for your GCP project number. Enter the 12-digit number.
- It then prints a URL for Google sign-in. Copy the URL, paste it in your browser, sign in, click Allow, copy the authorization code, paste it back into the terminal, and press Enter.
Claude Code starts immediately. On subsequent logins, just type claude — no prompts.
No GCP project yet? Request one through the NBG GCP onboarding process. It must have Vertex AI API enabled and billing attached.
7. Daily use
- Right-click the Sandbox Connect tray/menu-bar icon and select Connect.
- Sandbox Connect opens a terminal to your VM automatically.
- Type
claudeto start Claude Code. - When done, type
exitto leave the VM.
Sandbox Connect renews certificates silently in the background (every 12 hours, 24-hour cert lifetime). You never need to manage certificates manually.
Terminal links are clickable. To work in VS Code, open the Sandbox Connect VS Code view, choose a remote folder, and open it through the Remote-SSH extension.
8. File transfer
Open Sandbox Connect → tray/menu-bar icon → File Manager. Two panes appear:
- Local (left): files on your laptop.
- Remote (right): files on your VM.
Use → to upload and ← to download, or drag files between panes. Both panes refresh automatically. You can also search within each pane, sort columns, create folders/files, rename items, and open files with your local default apps. The path bar can be clicked to edit, paste, or copy a path directly.
On Windows, the local pane can browse mapped drives from This PC. Hidden files can be shown from Settings when needed.
Files uploaded to the VM are scanned by the DLP pipeline (see section 12). Downloads are logged for audit but are not copied into DLP storage.
9. Port forwarding
Sandbox Connect automatically detects development servers running on the VM and forwards their ports to your laptop. If you start a web server on port 3000 on the VM, it becomes available at http://127.0.0.1:3000 on your laptop — no configuration needed.
To view forwarded ports, right-click the Sandbox Connect tray/menu-bar icon and select Ports. The panel shows:
- Port number — click to open in your browser.
- Status — Active (tunnel working) or Conflict (something on your laptop is already using that port). Click Free port to resolve conflicts.
- Traffic — real-time bytes in/out through the tunnel.
Ports are detected automatically every second. Start a dev server on the VM and it appears in the panel within moments. Up to 16 ports can be forwarded simultaneously.
10. Screenshot Drop
Screenshot Drop allows you to enter pictures via screenshots on your clipboard or simply by dragging a picture into the page. This creates a temporary file with your image inside the VM, which you or Claude Code can access. The path of that image is automatically copied to your local clipboard when you paste or drag an image into the page.
To use screenshot drop, click the Sandbox Connect tray/menu-bar and select Screenshot Drop. It will open a page.
- Paste or Drag an image into the page
- The page will show the path where the image was placed inside the VM
- The page will automatically copy the path into your clipboard
- You can paste the path directly into the VM/Claude terminal
11. Managing devices
You can manage your enrolled devices from the Devices page (accessible from the top navigation bar).
- Revoke a device if your laptop is lost or compromised. The device stops working within 60 seconds.
- Re-enroll by launching Sandbox Connect again and repeating the enrollment flow (section 4).
New laptop or reinstall? A fresh OS means a fresh enrollment. Same flow as section 4.
12. What gets logged
NBG records:
- File uploads into your VM — DLP-scanned and stored.
- File downloads from your VM through Sandbox Connect — audit-only rows with file path and metadata.
- Login/logout events.
- Certificate issuance and revocation.
- VM lifecycle (create, start, stop, delete).
- Device enrollment and revocation.
Not captured: your private keys (never leave your laptop), your Claude prompts and responses (flow directly between VM and Google Vertex AI), your Google credentials (local to the VM only).
13. Troubleshooting
| Problem | Fix |
|---|---|
| Sandbox Connect shows "Request expired" | 15-minute TTL elapsed. Click Connect and re-approve. |
| "Fingerprint did not match" | Re-type from the Sandbox Connect screen. Case insensitive, dashes optional. |
| "Cannot reach portal" | Check your VPN connection. If the portal loads in a browser but not in Sandbox Connect, restart the app. |
| "Account disabled" / 403 | Your NBG account is disabled. Contact IT. |
| "Device revoked" | An admin (or you) revoked this device. Re-enroll if needed (section 4). |
| Tray icon greyed out | Background process crashed. Quit and relaunch. |
| "Server certificate untrusted" | Helper needs a newer version. Check for updates — the auto-updater may already be downloading. |
claude says "project not found" |
Run echo "$ANTHROPIC_VERTEX_PROJECT_ID" — should be your 12-digit project number. If wrong, run unset ANTHROPIC_VERTEX_PROJECT_ID && claude to re-trigger setup. |
gcloud "Reauthentication required" |
Run claude again — it detects expired credentials and re-runs Google sign-in automatically. |
Need more help?
- Platform team contact: see the NBG internal directory.
- Source of this guide:
docs/user-guide.mdin the portal repository.
Build: dev · Last updated: 2026-10-01