E2BBrowserToolset drives Chrome through the page itself (elements, forms, tabs, navigation), and E2BComputerToolset drives the whole Linux desktop through screenshots, mouse and keyboard, so Claude can work in any desktop app, from a terminal to a LibreOffice spreadsheet. Each sandbox is a private cloud desktop that you can watch live while Claude works.
How it works
The Claude SDK defines the toolsets (browser_toolset_20260801 and computer_toolset_20260801): it parses the model’s input, asks for confirmation, and renders each result for the model. Claude Toolsets is the E2B driver underneath, which executes every action inside an E2B desktop sandbox instead of on your machine.
- Create a toolset. It creates a desktop sandbox, or attaches to one you pass in.
- Pass it in
tools. The toolset instance is thetools[]entry; there is no wrapper. - Run the tool runner. The SDK’s tool runner calls the toolset for every action Claude takes.
- Close it. The tool runner never closes a toolset. Use
try/finallyin TypeScript andwithin Python.
Install
E2B_API_KEY (get one) and ANTHROPIC_API_KEY in your environment.
Browser use
The browser toolset starts Chrome on an E2B desktop sandbox. Without asandbox option it creates one and kills it on close().
githubassets.com and githubusercontent.com, so those hosts are allowed too.
Computer use
The computer toolset borrows a desktop sandbox you create. It gives Claude screenshots and mouse and keyboard actions, so it can use any app on the desktop.liveView streams that desktop to a local URL so you can watch.
confirm hook is where an application can ask a person before Claude types or presses keys. Returning true approves every call, which suits unattended runs.
Watch live
liveView(desktop) (live_view in Python) starts the desktop’s VNC stream and serves it on a random loopback URL on your machine. The E2B traffic token stays in your process, so the sandbox keeps allowPublicTraffic: false and only you can watch. Stopping the view closes the stream but never kills the desktop.
The live view needs a fresh desktop created with
allowPublicTraffic: false. It refuses a desktop that already streams, because stopping a stream is sandbox-wide. Do not share the URL.Use both toolsets on one desktop
Pass both toolsets to the same tool runner and Claude picks the right one per step: the browser toolset for web apps, which is faster and more precise than clicking pixels, and the computer toolset for desktop apps and Chrome’s own popups, which the page cannot see. To share one desktop, create it yourself and pass it to the browser toolset assandbox.
Network control
Use both layers. They check different things.
Egress is fixed when the sandbox is created; a URL policy does not change it.
allowHosts permits HTTP(S) hosts and their subdomains. It is a sample policy, not a DNS firewall, so keep sandbox egress restrictive for sensitive browsing.
Sandbox ownership
You close what you create:- Toolset creates the sandbox (no
sandboxoption):close()kills it. Creation options areapiKey,template(defaultdesktop),allowOut,timeoutMs(default 10 minutes;timeoutin seconds in Python) andmetadata. - You pass a sandbox: the toolset borrows it, and
close()stops only the Chrome it started and leaves the sandbox running. The sandbox must already haveallowPublicTraffic: falseandmaskRequestHost: 'localhost:${PORT}'; creation options are refused.
headless: true to hide it.
Optional browser actions
Four browser actions are off by default:file_upload, javascript_exec, read_console and read_network. Enable them through the SDK’s configs option. The SDK refuses to enable them without a confirm hook.
Python async
Python has native asyncio drivers next to the sync ones:AsyncE2BBrowserToolset and AsyncE2BComputerToolset. They accept the same options and borrow an e2b.AsyncSandbox.
Python
Supported actions
Limits
- Screen size: browser viewport and desktop resolution up to 2560×1440 pixels in total, default 1280×800. Larger sizes are refused rather than silently scaled, because the API would shrink the screenshots and clicks would miss. At 1280×800 each screenshot costs about 1,400 tokens.
- Fixed resolution: keep the desktop resolution fixed for the whole run. Coordinates are screenshot pixels.
- Input: waits and held keys are limited to 30 seconds, key repeats to 100. Input assumes a US keyboard layout.
- Downloads stay in the sandbox. Their bytes are never added to the conversation.
Related guides
Excel to OrangeHRM
Claude uses both toolsets on one desktop to copy new hires into an HR system
Computer use
How computer use agents drive E2B Desktop sandboxes
Internet access
Control sandbox egress with allow and deny lists