> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.nvidia.com/openshell/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.nvidia.com/openshell/_mcp/server.

# Tutorials

> Step-by-step walkthroughs for OpenShell, from first sandbox to production-ready policies.

Hands-on walkthroughs that teach OpenShell concepts by building real configurations. Each tutorial builds on the previous one, starting with core sandbox mechanics and progressing to production workflows.

#### [Run Pi with OpenRouter](/tutorials/run-pi-with-openrouter)

Build a Pi coding-agent image, configure OpenRouter access, and run it inside an OpenShell sandbox.

#### [First Network Policy](/tutorials/first-network-policy)

Create a sandbox, observe default-deny networking, apply a read-only L7 policy, and inspect audit logs. No AI agent required.

#### [GitHub Push Access](/tutorials/github-push-access)

Launch Claude Code in a sandbox, diagnose a policy denial, and iterate on a custom GitHub policy from outside the sandbox.

#### [Microsoft Graph Provider Refresh](/tutorials/microsoft-graph-provider-refresh)

Configure a Microsoft Graph provider profile with gateway-managed OAuth2 refresh-token rotation.