Choose and set up your agent
Every box runs one agent: each new terminal tab starts it. Claude Code, Codex, OpenCode and Gemini CLI come preinstalled with approvals off, next to Docker and a full set of developer tools.
Pick the agent for a box
You pick the agent under 2. Agent when you create a box. To change it later:
- Open the box and stay on Overview.
- In the Agent panel, pick a new value under Every new tab starts.
- Open a new tab. The change applies to tabs you open from now on. Open tabs keep their agent.

| Agent | How it signs in |
|---|---|
| Claude Code | Your Claude subscription, connected in the dashboard, or a sign-in inside the box |
| Codex | Your ChatGPT subscription, connected in the dashboard, or a sign-in inside the box |
| OpenCode | Its own sign-in, inside the box |
| Gemini CLI | Its own sign-in, inside the box |
| Claude Code · Z.ai | Your own Z.ai API key |
| Claude Code · DeepSeek | Your own DeepSeek API key |
| Shell | A plain login shell. Start any tool you like |
Switching to an agent with another subscription slot unbinds the old subscription and turns rotation off. Connecting subscriptions is covered in Subscriptions.
What every box ships with
New boxes run the box-v3 image:
- Ubuntu 26.04 LTS, Docker Engine with compose, Node 24, Python 3.14, git and tmux.
- The user
devwith passwordlesssudo, in thedockergroup. - Agent CLIs: Claude Code, Codex, OpenCode, Gemini CLI, Happy and DeepSeek Harness (
dsh), plus theclaude-zaiandclaude-deepseekwrappers. - Git and GitHub:
gh,glab,git-lfs,delta. - Search and data:
ripgrep,fd,fzf,jq,yq,bat,httpie. - Database clients:
sqlite3,psql,redis-cli,mariadb. - Package managers:
pipx,uv,mise,bun,pnpm,yarn. - Cloud:
kubectl,helm, OpenTofu (tofu), AWS CLI v2.
Language toolchains are not preinstalled, so they don't eat your disk. Add one with mise:
mise use -g go@latest
The CLIs live in your home folder, so they update without sudo. A box created before box-v3 keeps its older Debian image until you reset it. The Image line under Settings shows which one a box runs.
Approvals are off
A box is a sandbox you can reset, so every agent ships in its no-prompt mode. An agent that waits for a yes at 2 a.m. finishes nothing.
| Agent | Mode |
|---|---|
| Claude Code | bypassPermissions |
| Codex | Approval policy never, full access |
| Gemini CLI | --approval-mode=yolo |
| OpenCode | Permission allow |
First-run screens and folder trust questions are answered already. Open a tab and the agent is ready for a task.
Shared instructions in AGENTS.md
/etc/detachbox/AGENTS.md is one instructions file that every agent reads. It tells agents how preview URLs work and how to hand you an SSH command for raw TCP ports. It is linked into ~/.claude/CLAUDE.md, ~/.codex/AGENTS.md, ~/.config/opencode/AGENTS.md and ~/.gemini/GEMINI.md.
Keep your own file in one of those places and it stays yours. detachbox only adds a reference to the shared file.
Run Claude Code on Z.ai or DeepSeek
claude-zai and claude-deepseek run Claude Code against the vendor's Anthropic-compatible endpoint, on your own API key. Each has its own config folder, ~/.claude-zai or ~/.claude-deepseek, so your Claude login in ~/.claude stays untouched.
Put the key in the box once, and every tab picks it up:
mkdir -p ~/.config/detachbox
read -rs -p 'Key: ' k && printf '%s\n' "$k" > ~/.config/detachbox/zai.key
chmod 600 ~/.config/detachbox/zai.key
For DeepSeek, write ~/.config/detachbox/deepseek.key instead. Exporting ZHIPU_API_KEY or DEEPSEEK_API_KEY works too. Without a key, the wrapper prints where to put it. OpenCode's built-in Z.ai and DeepSeek providers turn on from the same key files.
Box details in box.env
/etc/detachbox/box.env describes the box to every shell and agent. detachbox rewrites it on create, reset, start and size change, so don't edit it.
| Variable | Value |
|---|---|
DETACHBOX_BOX | The box name |
DETACHBOX_SSH | The SSH command for this box |
DETACHBOX_PLAN | The plan code |
DETACHBOX_CPUS | vCPU count |
DETACHBOX_RAM_GB | Memory in GB |
DETACHBOX_DISK_GB | Disk in GB |
DETACHBOX_URL | The box page in the dashboard |
The variables load in login, interactive and non-interactive shells, including ssh <name>@ssh.detachbox.com <command>.
Open a page in your browser with detachbox-open
detachbox-open <url> opens an http or https link in the browser of the person at the box's terminal. xdg-open, open and $BROWSER all point to it. Sign-ins started by gh, Python's webbrowser or an agent land in your browser this way.
A link to the box's own localhost:<port> becomes its preview URL. Other schemes, such as file:, are refused. The terminal guide shows what the dashboard does when a page arrives.
Hand an agent a prompt with detachbox-say
detachbox-say <tmux session> <text> delivers text to the agent in that tab as a new prompt. It uses the agent's own delivery, never keystrokes, so a line you are typing stays intact. It works with Claude Code and Codex.
The server uses it to type "continue" when a limit resets. Exit code 3 means the tab has no running Claude Code or Codex to deliver to.