Skip to content
claudestream.policy
Edit
On this page

Sandbox and permission policy types for Claude Code sessions, defining allow, deny, and approval rules for tool execution requests.

#claudestream.policy

#claudestream.policy

Sandbox and permission policy types for Claude Code sessions, defining allow, deny, and approval rules for tool execution requests.

#Allow

Allow the tool to execute.

#Deny

Deny the tool execution.

#Sandbox

Declarative sandbox configuration for a Claude Code session.

Controls which tools are available, filesystem scope, and behavior flags.

#create_sandbox

python
def create_sandbox(*, tools: list[str] | None=None, bare: bool=False, write_paths: list[str] | None=None, log_violations: bool=False, skip_permissions: bool=False) -> Sandbox

Create a validated Sandbox configuration.

Raises:

  • ValueError: If any tool name is empty or not a string.

#sandbox_to_flags

python
def sandbox_to_flags(sandbox: Sandbox | None) -> list[str]

Convert a Sandbox to CLI flags for Claude Code.

None means no sandbox flags (use defaults).

#_resolve_path

python
def _resolve_path(path: str, cwd: str) -> str

Resolve a path to an absolute, symlink-free canonical form.

#_is_within

python
def _is_within(target: str, allowed: str) -> bool

Check if target is within allowed directory (both must be realpath'd).

Uses string-prefix comparison with a trailing separator to avoid '/src/foo' matching '/src/foobar'.

#sandbox_decide

python
def sandbox_decide(sandbox: Sandbox, tool_name: str, tool_input: dict, cwd: str) -> Allow | Deny

Decide whether a tool call is allowed under the given Sandbox.

The Sandbox is the complete authority -- this always returns Allow or Deny, never None.

More tools from this site

  • claudewheel A TUI Claude Code Launcher that lets you have more than one profile, manage sessions lifecycle, pick the exact CC version, model to use (even older unlisted ones), pick which GitHub account to use, etc.
  • dirstat Fast, single-binary directory statistics CLI: every file under a tree grouped by format, with counts, sizes, and lines of code, as a colored terminal table or as JSON
  • fastware A batteries-included ASGI framework: msgspec JSON, a managed Granian server, dependency injection, SSE, WebSockets, auth, and a test client
  • go-toml-edit Zero-dep TOML editing library for Go with comment preservation
  • howmuchleft The fastest Claude Code statusline: context window, 5-hour, and weekly limit usage as three customizable gradient bars, rendering in about 6 ms
  • orxtra
  • pgdesign
  • predraw Declarative rendering pipeline: describe a scene in JSON and get SVG, PNG and WebP out, with light and dark style tokens, reusable components and text converted to path outlines
  • reposummary Turn a git repository's history into a Markdown journal: pick a time window or revision range and get a readable digest of what changed, optionally narrated by an LLM
  • rlsbl Release orchestration and project scaffolding CLI that bumps versions, validates a structured JSONL changelog, tags only the commit CI verified, and publishes to npm, PyPI, Go and more
  • safegit git wrapper CLI that gives each commit its own temporary index and retries ref updates on conflict, so concurrent agents share one repository
  • saferm Command-line replacement for rm that archives every deletion with a mandatory reason and the context it ran in, so deleted files can be listed, inspected and restored
  • selfdoc Static Site Generator that builds a project's documentation site directly from its source code, so the docs can never drift from the code they describe, with SEO/AEO, first-class blog, search, and cross-project linking built in
  • strictcli
  • stricttest An always-on test-isolation floor: a pytest plugin and a Go env-hygiene module that make a test suite structurally unable to reach real credentials, the real HOME, the network, or the development repository.
  • wesktop A Python framework that turns an ASGI web app into a desktop application, serving it from a local Granian server and displaying it in a native OS window via pywebview
Search