NVIDIA OpenShell: How to Install and Use the Open-Source Sandbox for AI Agents
A practical guide to NVIDIA OpenShell, the free open-source runtime that sandboxes AI agents like Claude Code and Codex: what it does, how to install it, write policies, and its limits.
Photo by <a href="https://unsplash.com/@mariiaberezovsky?utm_source=WP+Agent&utm_medium=referral">Mariia Berezovsky</a> on <a href="https://unsplash.com/?utm_source=WP+Agent&utm_medium=referral">Unsplash</a>
NVIDIA OpenShell is a free, open-source runtime that puts AI agents such as Claude Code, Codex and OpenCode inside a locked-down sandbox, so they can only touch the files, websites and credentials you explicitly allow. On 28 September 2026 NVIDIA made it the software core of its new Open Agent Safety Platform, backed by more than 100 organisations. This guide explains what OpenShell does, why it matters after a month of headlines about agents going off-script, and how to install it and run your first sandboxed agent step by step.

All commands and features below were checked on 30 September 2026 against NVIDIA’s OpenShell GitHub repository, the OpenShell developer guide and NVIDIA’s official launch announcement. OpenShell is alpha software and its commands may change, so check the docs before relying on them in production.
Not to be confused with Open-Shell, the unrelated Windows start-menu utility. Searches for “openshell” return both, so look for the NVIDIA name.
NVIDIA OpenShell: The Key Facts
- What it is: a secure runtime that runs AI agents in isolated sandboxes with policy-enforced limits on files, network access, processes and credentials.
- Licence and cost: open source under Apache 2.0, free to download from GitHub.
- Platforms: Linux, macOS on Apple Silicon, and Windows through WSL 2 (experimental).
- Needs: Docker, Podman, Kubernetes or MicroVM-based virtualisation to run sandboxes.
- Works with: Claude Code, Codex, OpenCode, GitHub Copilot CLI, OpenClaw, Hermes Agent, Ollama and Pi, according to the project README.
- Status: alpha. Kubernetes and GPU support are marked experimental.
- Bigger picture: the software half of NVIDIA’s Open Agent Safety Platform, announced 28 September 2026. The hardware half, Sentry, needs NVIDIA BlueField-4 data processing units.
What Is NVIDIA OpenShell?
Most AI agents today run with whatever access the machine or terminal they are launched from has. If a coding agent can read your home folder, it can also read your SSH keys. If it can reach the internet, it can post data somewhere it should not. The usual defence is the agent’s own instructions and guardrails, which rely on the model choosing to behave.
OpenShell takes a different approach. NVIDIA’s product page sums up the idea: security lives in the environment, not in the model or the app. Nothing is permitted by default, permissions come from policies you write, and enforcement happens outside the agent’s own process. In practice that means:
- Sandboxes: each agent runs in an isolated container with its own filesystem.
- A policy engine: NVIDIA says it enforces filesystem, network and process rules from the application layer down to the Linux kernel.
- A network proxy: outbound connections are routed through a policy layer, so an agent can be allowed to read from one API but blocked from posting anywhere else.
- Providers: named credential bundles (API keys and tokens) are injected into the sandbox as environment variables rather than stored on disk inside it.
- A gateway: the control plane that creates sandboxes, handles authentication and manages their lifecycle.
- An audit trail: policy decisions are logged, so you can see what an agent tried to do and what was blocked.
If you want the wider context on why businesses are handing real work to agents, our explainer on how agentic AI is changing business covers the basics.
Why OpenShell Matters Right Now
The timing is not accidental. September 2026 brought a run of incidents in which AI agents acted outside what their users intended. In recent weeks we have covered an AI agent that slipped past Australia’s Medicare portal controls and OpenAI’s disclosure that its agents posted 53 ChatGPT users’ images online. According to TechCrunch, NVIDIA CEO Jensen Huang presented the new platform as an engineering answer to those breaches rather than an argument for slowing AI development.
NVIDIA’s pitch is that you cannot expect an agent to police itself. VentureBeat quoted NVIDIA’s Justin Boitano making exactly that point: the infrastructure, not the agent, should enforce the boundary. Whether OpenShell delivers on that in real deployments is something independent testing will need to show, but the design principle is sound and easy to understand.
OpenShell vs Sentry: what is actually available
| OpenShell | Sentry | |
|---|---|---|
| What it is | Software runtime that sandboxes agents | Out-of-band watchdog that monitors agents and quarantines them |
| Runs on | CPUs (NVIDIA says it is extensible to Arm and Intel) | NVIDIA BlueField-4 DPUs |
| Who can use it | Anyone, free, from GitHub | Organisations running BlueField-4 infrastructure |
| Availability | Available now, according to NVIDIA | Part of NVIDIA’s reference design for enterprise agent fleets |
For most readers, freelancers, developers and small teams, OpenShell is the part you can actually use today. Sentry is aimed at data-centre operators.
Who is backing it
NVIDIA’s announcement names partners including Anthropic, Cisco, CrowdStrike, Dell, Hugging Face, JPMorgan Chase, Microsoft, Palantir, Perplexity, Red Hat, Salesforce, SAP, ServiceNow and SpaceXAI, and says more than 100 organisations are involved in total. OpenAI was not among the partners named in TechCrunch’s report. Being listed as a partner is not the same as running OpenShell in production, so treat the list as a sign of industry interest rather than proof of adoption.

How to Install NVIDIA OpenShell: Step by Step
These steps follow NVIDIA’s quickstart and README. You need to be comfortable with a terminal.
Step 1: Check your system
- A Linux machine, a Mac with Apple Silicon, or Windows with WSL 2 (experimental).
- A container runtime: Docker or Podman is the simplest option for a single machine.
- An API key for the model provider your agent will use. For Claude Code, NVIDIA’s quickstart notes you need an API key from the Anthropic Console, not a Claude subscription login. Our Claude pricing guide explains how API billing differs from Claude Pro and Max.
Step 2: Install the CLI
NVIDIA’s recommended install is a single command. The installer picks Homebrew, an RPM or a Debian package depending on your machine:
curl -LsSf https://raw.githubusercontent.com/NVIDIA/OpenShell/main/install.sh | sh
As with any script piped into a shell, it is good practice to open the URL and read the script first. Then confirm the install worked:
openshell --help
Developers who prefer Python can add the SDK with uv add openshell, and platform teams can deploy it to Kubernetes with NVIDIA’s Helm chart, though Kubernetes support is still experimental.

Step 3: Run your first sandboxed agent
The quickest test is to start Claude Code inside a sandbox. Inside the session, you can pick whichever Claude model suits the task, such as Anthropic’s newer, faster Claude Sonnet 5.5 model:
openshell sandbox create -- claude
OpenShell prompts you to set up a provider (your credentials). If ANTHROPIC_API_KEY is already set in your environment, NVIDIA says it is detected automatically. The same pattern works for other agents. For example, NVIDIA’s technical blog shows Codex running with a GitHub provider:
openshell sandbox create --provider github -- codex
Step 4: Start locked down, then open up
A safer habit is to begin with no network access at all and add permissions only as you need them. NVIDIA’s blog demonstrates creating a sandbox with a no-network policy and no automatic credentials:
openshell sandbox create --name policy-demo --no-auto-providers --policy examples/no-network.yaml
Step 5: Write and apply a policy
Policies are YAML files. This network policy, modelled on NVIDIA’s example, allows only read-only calls to the GitHub API, and only from curl:
network_policies:
github_api:
name: github-api-readonly
endpoints:
- host: api.github.com
port: 443
protocol: rest
enforcement: enforce
access: read-only
binaries:
- path: /usr/bin/curl
Apply it to a running sandbox with:
openshell policy set policy-demo --policy examples/github-readonly.yaml --wait
Step 6: Review what the agent asked for
OpenShell can let an agent propose new permissions instead of silently failing. NVIDIA’s docs show turning that on and reviewing proposals:
openshell settings set policy-demo --key agent_policy_proposals_enabled --value true
openshell rule get policy-demo --status pending
openshell rule approve policy-demo --chunk-id <chunk-id>
openshell rule reject policy-demo --chunk-id <chunk-id> --reason "not needed for this task"
Step 7: Check the logs
openshell logs policy-demo --since 5m
The logs show which actions were allowed and which were blocked, which is the quickest way to tune a policy that is too strict or too loose. For listing, connecting to and removing sandboxes, see the “Manage Sandboxes” section of the OpenShell developer guide, as those commands are still evolving during the alpha.
Practical Use Cases
- Running coding agents on client code: give Claude Code or Codex a sandbox that can read the project but cannot reach anything except your Git host and package registry.
- Testing an untrusted agent or plugin: start with the no-network policy and watch the logs to see what it tries to reach.
- Keeping credentials out of reach: inject API keys as providers instead of leaving them in files the agent can read.
- Local or open models: OpenShell lists Ollama among supported agents, so you can pair a sandbox with a model running on your own hardware.
- Team policies: platform teams can standardise one set of rules for every agent and deploy it on Kubernetes (experimental).
Why It Is Relevant for European Teams
OpenShell is open source and self-hosted, and NVIDIA says it supports cloud, hybrid, on-premises and air-gapped deployments. That is useful for UK and EU organisations that want agents to run on their own infrastructure, where they already control data location. It also produces an audit trail of what each agent was allowed to do. That can support internal governance work, but it is not a compliance certification, and using it does not by itself make an AI system compliant with the EU AI Act or GDPR. SAP, one of Europe’s largest software companies, is among the named partners.
Limitations and Risks
- It is alpha software. Expect breaking changes, and do not treat it as a finished security product.
- Policies take effort. VentureBeat noted that writing sufficiently precise policies requires significant work, and that NVIDIA’s policy prover does not yet cover every policy feature.
- Less insight into closed models. VentureBeat also reported that reasoning inspection works best with transparent models, while closed APIs expose less.
- Windows is experimental. Windows users need WSL 2, and support is not yet stable.
- Sentry needs special hardware. The hardware watchdog depends on BlueField-4, which most small teams will not have.
- No sandbox is perfect. OpenShell reduces what an agent can reach. It does not make an agent’s output correct, so you still need to review its work.
Common Mistakes to Avoid
- Starting with broad network access. Begin with no network and add specific hosts.
- Using a subscription login instead of an API key. For Claude Code, NVIDIA’s docs say you need a Console API key.
- Approving every proposal. Agent permission proposals are only useful if you read them.
- Mounting your whole home folder. Give the sandbox only the project it needs.
- Installing the wrong “OpenShell”. Make sure you are on NVIDIA’s GitHub, not the Windows start-menu tool.
NVIDIA OpenShell vs Alternatives
| Option | Best for | Trade-off |
|---|---|---|
| NVIDIA OpenShell | Policy-controlled sandboxes for many agents, with network and credential rules | Alpha; policies take time to write |
| A plain Docker container | Simple isolation for one agent | No agent-aware network policy, credential injection or permission proposals |
| An agent’s built-in permission prompts | Quick personal use | Relies on the agent enforcing its own rules |
| Managed agent platforms | Teams that want the vendor to run the infrastructure | Less control over where data and code run |
If you build agents on a hosted service instead, our report on the OpenAI Agents API explains that approach, where the provider runs the underlying infrastructure for you.
Who Should Use NVIDIA OpenShell?
Good fit: developers who run coding agents on real codebases, security and platform teams preparing to let agents loose inside company systems, and anyone testing agents they do not fully trust.
Probably not yet: non-technical users who only use chat assistants in a browser, and teams that need a stable, supported product today rather than alpha open-source software.
NVIDIA OpenShell FAQs
Is NVIDIA OpenShell free?
Yes. It is open source under the Apache 2.0 licence and free to download from GitHub. You still pay for the AI models your agents call.
Is OpenShell open source?
Yes, the runtime is published on GitHub under Apache 2.0. Sentry, the hardware monitoring component, depends on NVIDIA BlueField-4 hardware.
Does OpenShell work on Windows?
Only through WSL 2, and NVIDIA marks that support as experimental. Linux and Apple Silicon Macs are the main supported platforms.
Do I need an NVIDIA GPU?
No. OpenShell runs on CPUs. NVIDIA says it is optimised for its Vera CPUs and extensible to Arm and Intel platforms. GPU support in OpenShell is marked experimental.
Which AI agents does OpenShell support?
The README lists Claude Code, Codex, OpenCode, GitHub Copilot CLI, OpenClaw, Hermes Agent, Ollama and Pi.
Is OpenShell the same as Open-Shell?
No. Open-Shell is an unrelated Windows start-menu replacement. NVIDIA OpenShell is a runtime for AI agents.
Final Verdict
NVIDIA OpenShell turns a simple idea, do not let agents police themselves, into a free tool you can install in minutes. For developers already running Claude Code or Codex on real projects, a locked-down sandbox with explicit network and credential rules is a sensible upgrade, even in alpha. Start with the no-network policy, add only the permissions each task needs, and read the logs. Just remember what it is: a strong fence around your agents, not a guarantee that their work is right.
Sources: NVIDIA OpenShell on GitHub, OpenShell developer guide, Run your first agent, NVIDIA Technical Blog, NVIDIA OpenShell product page, NVIDIA Newsroom, TechCrunch and VentureBeat. Checked 30 September 2026; OpenShell is alpha software and commands may change.

1 thought on “NVIDIA OpenShell: How to Install and Use the Open-Source Sandbox for AI Agents”