Skip to content

Troubleshooting

What we hit (newcomers will too)

.pkg won’t open — “Apple could not verify”

The package is unsigned. macOS Gatekeeper refuses.

Quick fix (Terminal): open Terminal and run:

sudo xattr -rd com.apple.quarantine ~/Downloads/sandbox-connect-*.pkg
open ~/Downloads/sandbox-connect-*.pkg

GUI alternative: click Done (not “Move to Trash”). Open System Settings → Privacy & Security, scroll down, click Open Anyway next to the blocked-package message. Re-double-click the .pkg.

I installed it but can’t find the app

Sandbox Connect is menu-bar-only. No Dock icon. Look in the top-right of your screen for a navy “SC” tile.

If it’s not there even though pgrep -fl sandbox-connect shows a PID, the icon is hidden behind your notch. Quit a menu-bar app (Slack, your terminal) to free space, or install Ice / Bartender to expose overflow icons.

Three menu items are greyed out

File Manager, Ports, Screenshot Drop are disabled until you’ve successfully connected to a VM. Click Connect first.

ssh: connect to host … port 22: Operation timed out

The most common newcomer surprise. Login + enrollment worked from home, but the VM is unreachable.

Why: the portal is publicly reachable; the VM is in NBG’s private network. Outside the office, you need NBG VPN.

Fix: connect to NBG VPN, click Connect again. No VPN client on your Mac? Ask IT which one NBG uses (Cisco Secure Client / GlobalProtect / FortiClient / Zscaler).

Terminal flashes open and closes

Combined with the SSH timeout above. The .command file Sandbox Connect runs ends with ; exit; so Terminal closes the moment SSH dies.

Fix: open Terminal manually first, then run ~/.ssh/cc-sandbox-scratch/ccs-ccs-…command by hand — without ; exit; it stays open so you can read the error.

Sandbox Connect always opens Apple Terminal, even though I use iTerm/Ghostty/cmux

By design — it routes .command files through whichever app is registered. Apple Terminal usually wins.

Workaround: accept it for the Sandbox session; open your preferred terminal in a separate window for local shells.

Cold-boot terminal sits at a blank prompt

The VM is still finishing boot after the seven-step Connect sequence completes. Wait 30s. If still nothing, SC → Connect again.

claude says “project not found”

Two checks:

  1. Your GCP project must have Vertex AI API enabled (console.cloud.google.com/apis/library/aiplatform.googleapis.com).
  2. Your project must have billing attached.

If both are true and claude still complains:

unset ANTHROPIC_VERTEX_PROJECT_ID
unset CLAUDE_CODE_USE_VERTEX
claude

Wrapper re-runs the project + OAuth setup.

From the official user guide

ProblemFix
”Request expired”15-min enrollment window elapsed. Click Δοκιμή ξανά in Sandbox Connect.
Browser shows “start again from Sandbox Connect”The enrollment link was already used or expired. Click Δοκιμή ξανά.
”Account disabled” / 403Contact IT.
”Device revoked”Re-enrol via Sandbox Connect.
”Server certificate untrusted”Helper needs an update — check for updates.
gcloud “Reauthentication required”Run claude again — it re-triggers Google sign-in.

Where to get help

  • Internal Teams channel (ask your manager which).
  • 556devops@nbg.gr for bugs.
  • NBG AI Hub → Tips for Claude Code itself.