I’m building a product that runs the official Claude Code and Codex CLIs in cloud coding workspaces. Users should be able to connect their Claude or ChatGPT subscription once and run several workspaces at the same time.
So far, I’ve successfully tested two workspaces running concurrently inside one Sandbox, sharing a native CLI login. I’ve also tested replacing that Sandbox and reusing the login from a private Drive without signing in again.
Ideally, though, I’d like a separate Sandbox for each workspace. The part I haven’t solved is how to reuse one subscription login across those Sandboxes without running into token refresh conflicts.
Has anyone built something like this, or found an example that keeps login and token refresh handled by the official CLIs?
Vercel’s support bot suggested storing and refreshing tokens in my backend, then passing them into each Sandbox. But Anthropic’s authentication rules (https://code.claude.com/docs/en/legal-and-compliance#authentication-and-credential-use) seem to rule that out for Claude subscription tokens. From what I’ve read, AI Gateway still leaves authentication with Claude Code, so I’m not sure it solves this either.
I’d appreciate any pointers or experience with this. Would you use separate Sandboxes, or keep one Sandbox per user and run their workspaces inside it?
Thanks! Camron