One API call gives Claude Code a real Linux machine — repo checked out, tools installed, network locked down, and nothing left behind when the session ends.
It reads files, runs your test suite, installs packages and edits in place. On a laptop that is fine. In production — parallel sessions, untrusted repos, agent-authored shell commands — it needs a boundary.
Create an API key and run your first session in the next few minutes.