flatpak-spawn uses the Flatpak portal to create a copy the sandbox it was called from, optionally using tighter permissions and the latest version of the app and runtime.
The following options are understood:
-h, --help
-v, --verbose
--forward-fd=FD
--clear-env
--watch-bus
--env=VAR=VALUE
--latest-version
--no-network
--sandbox
See the --sandbox-expose and --sandbox-expose-ro options for selective file access.
--sandbox-expose=NAME
Note that absolute paths or subdirectories are not allowed. The files must be in the sandbox subdirectory of the instance directory (i.e. ~/.var/app/$APP_ID/sandbox).
This option is useful in combination with --sandbox (otherwise the instance directory is accessible anyway).
--sandbox-expose-ro=NAME
Note that absolute paths or subdirectories are not allowed. The files must be in the sandbox subdirectory of the instance directory (i.e. ~/.var/app/$APP_ID/sandbox).
This option is useful in combination with --sandbox (otherwise the instance directory is accessible anyway).
--host
--directory=DIR
Note that the given directory must exist in the sandbox or, when used in conjunction with --host, on the host.
flatpak(1)