The daemon has full desktop control. It can click, type, read clipboard text, launch applications, and read or write artifacts. Do not expose its control routes as an unauthenticated public service.
Require authentication
Use the default attested tunnel for SDK-created Sandboxes. It uses an SDK-managed bootstrap bearer to mint short-lived session tokens.
Use Connect ingress when your policy requires all daemon traffic to use Modal Connect. Raw and
attested tunnel modes authenticate through their own configured credentials.
For local development, set COMPUTER_USE_LOCAL_TOKEN. Send it in the Authorization header. Do not put a token in a URL query.
The daemon fails closed when it has no authenticator. COMPUTER_USE_ALLOW_UNAUTHENTICATED_LOOPBACK=true is a local-only escape hatch. It cannot bind to a non-loopback address.
A minted session token still grants full computer use. Give it only to a party that may control that Sandbox.
A serialized session handle carries handoff identity. The placed Function must authenticate its
caller, authorize the target, and resolve fresh access during borrow entry.
Keep noVNC off by default
Use expose_vnc="off" unless an operator needs live access.
Use "view_only" to watch the desktop. Use "control" to watch and send input.
Boolean True maps to "control". Use the explicit "view_only" value for observation.
A noVNC URL grants live desktop access. Treat the URL and password as secrets. Do not paste them into chat, tickets, logs, or documentation.
Use the view-only example to create a desktop with view-only noVNC access. The example reports URL availability while keeping the URL secret.
Limit network and runtime access
Use outbound domain or CIDR allowlists for a restricted workload. Use network.block_all=True with Connect ingress when the desktop needs no network access.
Set Sandbox lifetime, idle policy, action budgets, screenshot budgets, artifact quotas, and
recording limits. Apply authentication as a separate access-control layer.
Treat desktop data as sensitive
Do not log these values:
- noVNC URLs or daemon URLs.
- Bearer tokens or provider keys.
- Clipboard text or typed text.
- Screenshot or recording bytes.
- Artifact bytes or raw artifact locations.
- Session handles, operation receipts, and provider call identities.
Structured SDK and daemon logs redact these values. Application logs and provider payload logs remain your responsibility.
Artifact paths reject absolute paths, traversal, encoded traversal, symlink escape, and control characters. Treat accepted artifacts and recordings as sensitive run data until your application sanitizes them.
Own provider policy
The OpenAI and Anthropic adapters normalize actions. Your application owns approval policy.
Use before_action to review normalized actions before execution. Require confirmation for consequential external actions. Restrict domains. Define takeover rules.
Treat page content, screenshots, tool output, and provider payloads as untrusted input. Keep provider credentials in the user application. Do not put them in core modules or the daemon image.
The weighted input bucket protects daemon resources. Require application approval for
consequential actions.
Recover without replay
computer.step() may complete a mutation before the caller receives its result. Use operation
receipts and explicit observation recovery. Never replay a step after dispatch may have started.
Treat a capture failure after completed actions as a completed mutation with an unavailable
observation. Reconcile the receipt before any later mutation.
Respond to exposure
If a noVNC URL becomes public, terminate the Sandbox. Create a new Sandbox to get a new tunnel and generated password.
If a bearer token becomes public, terminate the affected resource and rotate any operator-managed credential. Review logs for use during the exposure window.
Report a product vulnerability through the repository security policy.