# msb-manager > Run coding agents in per-project microVMs with deny-by-default egress, and credentials and SSH keys that never enter the VM. msb-manager is a single-file, dependency-free Python CLI (`msbctl`) around microsandbox (`msb`). The Markdown pages below are the full documentation; `https://sandbox-manager.runoverlabs.dev/llms-full.txt` is all of them in one file. Source: https://github.com/runoverlabs/sandbox-manager ## Start here - [Overview](https://sandbox-manager.runoverlabs.dev/index.md): msb-manager runs coding agents in per-project microVMs with deny-by-default egress and credentials that never enter the VM. - [Install](https://sandbox-manager.runoverlabs.dev/install.md): Requirements, the one-line installer, verifying a release, and installing from a checkout. - [Get started](https://sandbox-manager.runoverlabs.dev/quickstart.md): From a fresh install to Claude Code running in your first sandbox. - [Everyday use](https://sandbox-manager.runoverlabs.dev/everyday.md): The current-folder shortcuts, shell and exec, the menu and the picker. ## Guides - [How it works](https://sandbox-manager.runoverlabs.dev/how-it-works.md): The security model, the four configuration layers, and what is fixed at create time. - [Network & egress](https://sandbox-manager.runoverlabs.dev/egress.md): Rule groups, the rule grammar, the three properties that are easy to get backwards, and adding hosts. - [Credentials & SSH](https://sandbox-manager.runoverlabs.dev/credentials.md): Tokens a sandbox can use but never see, the filtered SSH agent, and commit signing. - [Advanced usage](https://sandbox-manager.runoverlabs.dev/advanced.md): Observe mode, caches and podman, resizing, version pins, renaming and moving, extra folders, project setup. - [Troubleshooting](https://sandbox-manager.runoverlabs.dev/troubleshooting.md): Refused connections, dropped API connections, NXDOMAIN on your LAN, and other failures that look like something else. ## Reference - [Commands](https://sandbox-manager.runoverlabs.dev/commands.md): Every msbctl subcommand, its arguments and options. - [Configuration](https://sandbox-manager.runoverlabs.dev/configuration.md): Every key in config.toml, .msb/sandbox.toml and the registry entry, and where files live. ## Project - [Contributing](https://sandbox-manager.runoverlabs.dev/contributing.md): Working on msb-manager: the checks, the rules, the spikes, the docs and releases. ## Optional - [Changelog](https://sandbox-manager.runoverlabs.dev/changelog.md): Every user-visible change to msb-manager, by release.