Skip to main content
Claude Toolsets is a browser use and computer use package that lets you run Claude Sonnet 5.5, trained specifically for Anthropic’s browser and computer use toolsets, on E2B sandboxes. It ships special tools for both: E2BBrowserToolset drives Chrome through the page itself (elements, forms, tabs, navigation), and E2BComputerToolset drives the whole Linux desktop through screenshots, mouse and keyboard, so Claude can work in any desktop app, from a terminal to a LibreOffice spreadsheet. Each sandbox is a private cloud desktop that you can watch live while Claude works.

How it works

The Claude SDK defines the toolsets (browser_toolset_20260801 and computer_toolset_20260801): it parses the model’s input, asks for confirmation, and renders each result for the model. Claude Toolsets is the E2B driver underneath, which executes every action inside an E2B desktop sandbox instead of on your machine.
  1. Create a toolset. It creates a desktop sandbox, or attaches to one you pass in.
  2. Pass it in tools. The toolset instance is the tools[] entry; there is no wrapper.
  3. Run the tool runner. The SDK’s tool runner calls the toolset for every action Claude takes.
  4. Close it. The tool runner never closes a toolset. Use try/finally in TypeScript and with in Python.

Install

Set E2B_API_KEY (get one) and ANTHROPIC_API_KEY in your environment.

Browser use

The browser toolset starts Chrome on an E2B desktop sandbox. Without a sandbox option it creates one and kills it on close().
GitHub serves its CSS, scripts and images from githubassets.com and githubusercontent.com, so those hosts are allowed too.

Computer use

The computer toolset borrows a desktop sandbox you create. It gives Claude screenshots and mouse and keyboard actions, so it can use any app on the desktop. liveView streams that desktop to a local URL so you can watch.
The confirm hook is where an application can ask a person before Claude types or presses keys. Returning true approves every call, which suits unattended runs.

Watch live

liveView(desktop) (live_view in Python) starts the desktop’s VNC stream and serves it on a random loopback URL on your machine. The E2B traffic token stays in your process, so the sandbox keeps allowPublicTraffic: false and only you can watch. Stopping the view closes the stream but never kills the desktop.
The live view needs a fresh desktop created with allowPublicTraffic: false. It refuses a desktop that already streams, because stopping a stream is sandbox-wide. Do not share the URL.

Use both toolsets on one desktop

Pass both toolsets to the same tool runner and Claude picks the right one per step: the browser toolset for web apps, which is faster and more precise than clicking pixels, and the computer toolset for desktop apps and Chrome’s own popups, which the page cannot see. To share one desktop, create it yourself and pass it to the browser toolset as sandbox.
For a full run, see the Excel to OrangeHRM example in the E2B cookbook: Claude reads new hires from a spreadsheet in LibreOffice Calc with computer use, enters each one into the OrangeHRM web app with browser use, and writes the assigned Employee Ids back into the spreadsheet.

Network control

Use both layers. They check different things. Egress is fixed when the sandbox is created; a URL policy does not change it. allowHosts permits HTTP(S) hosts and their subdomains. It is a sample policy, not a DNS firewall, so keep sandbox egress restrictive for sensitive browsing.

Sandbox ownership

You close what you create:
  • Toolset creates the sandbox (no sandbox option): close() kills it. Creation options are apiKey, template (default desktop), allowOut, timeoutMs (default 10 minutes; timeout in seconds in Python) and metadata.
  • You pass a sandbox: the toolset borrows it, and close() stops only the Chrome it started and leaves the sandbox running. The sandbox must already have allowPublicTraffic: false and maskRequestHost: 'localhost:${PORT}'; creation options are refused.
On a desktop sandbox, Chrome opens visibly so it shows in the live view. Pass headless: true to hide it.

Optional browser actions

Four browser actions are off by default: file_upload, javascript_exec, read_console and read_network. Enable them through the SDK’s configs option. The SDK refuses to enable them without a confirm hook.

Python async

Python has native asyncio drivers next to the sync ones: AsyncE2BBrowserToolset and AsyncE2BComputerToolset. They accept the same options and borrow an e2b.AsyncSandbox.
Python

Supported actions

Limits

  • Screen size: browser viewport and desktop resolution up to 2560×1440 pixels in total, default 1280×800. Larger sizes are refused rather than silently scaled, because the API would shrink the screenshots and clicks would miss. At 1280×800 each screenshot costs about 1,400 tokens.
  • Fixed resolution: keep the desktop resolution fixed for the whole run. Coordinates are screenshot pixels.
  • Input: waits and held keys are limited to 30 seconds, key repeats to 100. Input assumes a US keyboard layout.
  • Downloads stay in the sandbox. Their bytes are never added to the conversation.

Excel to OrangeHRM

Claude uses both toolsets on one desktop to copy new hires into an HR system

Computer use

How computer use agents drive E2B Desktop sandboxes

Internet access

Control sandbox egress with allow and deny lists