1
Create a sandbox
Start with a small test project. Run these commands on your computer:Open this project in JetBrains using the same absolute path. The project must have the same path inside and outside the sandbox so the agent can find it.The project folder is shared: changes the agent makes also appear on your computer. The
jetbrains-agent-home volume saves the agent’s settings and login. Keep your host home directory unmounted.2
Connect the agent
In AI Chat > Add Custom Agent, open Keep
~/.jetbrains/acp.json and add the configuration below. If the file already has agents, merge the entries instead of replacing it.Replace /absolute/path/to/msb with the output of:--stream: it lets the IDE and agent exchange messages while the agent runs. Do not replace it with --no-tty or disconnect its stdin.The two MCP settings disable IDE and custom MCP tools, which may run outside the sandbox. These defaults also affect other agents that inherit them. Check that your sandbox agent does not override either setting to true.3
Try it in AI Chat
Select OpenCode in microsandbox and send:Your login is saved in the sandbox’s home volume. Do not commit credentials.
Create hello.txt, run ls and uname -s, then read hello.txt back to me.Check that
hello.txt appears in your project and the shell reports Linux.The example model was used with test data. Before opening a real project, choose a provider and model approved for your data, log in inside the sandbox, and replace the model name in the configuration:What the sandbox protects
The agent can edit the shared project. ACP also allows agents to ask the IDE to read files or run commands on the host, so running an agent in a sandbox does not automatically keep every tool inside it. The MCP settings above do not disable those ACP requests. Review any MCP servers configured in the agent, too. Scripted tests of OpenCode 1.18.32 kept file and shell operations inside the sandbox and could not read an unmounted host file. Recheck this behavior when changing agents or versions. The JetBrains GUI flow has not been verified, and the IDE can still send project context to the model.Other options
Use Claude Code instead
Use Claude Code instead
Install the adapter and Claude Code in the same sandbox, then log in:Complete the browser login and paste the returned code into the guest terminal if prompted.Add an entry under Keep both MCP settings
agent_servers with the same command path and these arguments:false. The adapter initialized in scripted testing, but authenticated prompts and isolation remain unverified. Its changelog says version 0.18.0 switched to built-in Claude tools; older adapters may behave differently.If using an API key, add "-e", "ANTHROPIC_API_KEY" before "--" to pass it into the sandbox. Values in acp.json’s env only reach the host subprocess unless explicitly forwarded. Prefer the saved guest login to putting keys in this file.Connect through SSH instead
Connect through SSH instead
Authorize your public key:Add this to Verify the host key on first connection. In JetBrains Gateway, enable parsing of
~/.ssh/config, replacing the msb path:~/.ssh/config and select this host.SSH commands and SFTP were tested. Gateway backend installation and IDE startup remain untested. See SSH and Gateway setup.