Skip to content

Open Key Path

OpenKeyPath is a sandbox setting in Sandboxie Ini. It specifies a path patterns, for which Sandboxie will not apply sandboxing for registry keys. This lets sandboxed programs have direct access to update system settings outside the sandbox. This setting essentially punches a hole in the sandbox, at a particular registry key location.

Program Name Prefix may be specified.

Example:

   .
   .
   .
   [DefaultBox]
   OpenKeyPath=firefox.exe,HKEY_LOCAL_MACHINE\Software\Mozilla
   OpenKeyPath=firefox.exe,HKEY_CURRENT_USER\Software\Mozilla

These examples let the Firefox program, firefox.exe, have direct access to the Mozilla registry key trees (both system-wide and per-user registry trees).

The value specified for OpenKeyPath can include wildcards, although for registry keys, the use of wildcards is rarely needed. For more information on this, including examples that show the use of wildcards, see OpenFilePath. (OpenFilePath deals with files, not registry keys, but the principle of using wildcards remains the same.)

Note: Ordinary OpenKeyPath entries are normally excluded when the requesting executable itself resides inside the sandbox while Sandboxie's boxed-image Open restriction is active. This is an eligibility rule, not an unconditional property of the syntax; configurations such as Application Compartment can alter that policy. OpenConfPath is not excluded by that normal gate. Eligibility does not guarantee that a rule wins; see Rule Specificity.

Related Sandboxie Control setting: Sandbox Settings > Resource Access > Registry Access > Direct Access

Related Sandboxie Plus setting: Sandbox Options > Resource Access > Registry > Add Reg Key > Access column > Open