{
  "data": {
    "category": {
      "area": "agent-runtime",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.browser",
        "sandbox.gpu"
      ],
      "description": "Isolated machines an agent can start in seconds to run code, install packages and use a filesystem, then throw away. Compared on start time, isolation, how long a sandbox can live, what it costs per second and whether state can be paused and resumed.",
      "indexed": [
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/antrieb.json",
          "kind": "mcp",
          "name": "antrieb",
          "slug": "antrieb",
          "url": "https://www.anchorterminal.com/tools/antrieb"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/authyouragent-mcp.json",
          "kind": "mcp",
          "name": "Auth Your Agent",
          "slug": "authyouragent-mcp",
          "url": "https://www.anchorterminal.com/tools/authyouragent-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencovenant-guard.json",
          "kind": "mcp",
          "name": "Covenant Guard",
          "slug": "opencovenant-guard",
          "url": "https://www.anchorterminal.com/tools/opencovenant-guard"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kenwea-marketplace.json",
          "kind": "mcp",
          "name": "Kenwea — Sandbox Attestation \u0026 Agent Marketplace",
          "slug": "kenwea-marketplace",
          "url": "https://www.anchorterminal.com/tools/kenwea-marketplace"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mupag-mcp-server.json",
          "kind": "mcp",
          "name": "MuPag Sandbox Payments",
          "slug": "mupag-mcp-server",
          "url": "https://www.anchorterminal.com/tools/mupag-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/parallelsandbox.json",
          "kind": "mcp",
          "name": "ParallelSandbox",
          "slug": "parallelsandbox",
          "url": "https://www.anchorterminal.com/tools/parallelsandbox"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/rivet-mcp.json",
          "kind": "mcp",
          "name": "Rivet",
          "slug": "rivet-mcp",
          "url": "https://www.anchorterminal.com/tools/rivet-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/withruntime-runtime.json",
          "kind": "mcp",
          "name": "Runtime Cloud",
          "slug": "withruntime-runtime",
          "url": "https://www.anchorterminal.com/tools/withruntime-runtime"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sandboxapis-mcp.json",
          "kind": "mcp",
          "name": "SandboxAPIs",
          "slug": "sandboxapis-mcp",
          "url": "https://www.anchorterminal.com/tools/sandboxapis-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/scratchrun-mcp.json",
          "kind": "mcp",
          "name": "ScratchRun",
          "slug": "scratchrun-mcp",
          "url": "https://www.anchorterminal.com/tools/scratchrun-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/securestamp-action-proof.json",
          "kind": "mcp",
          "name": "SecureStamp Action Proof — Cross-Cloud Public Beta (Unverified)",
          "slug": "securestamp-action-proof",
          "url": "https://www.anchorterminal.com/tools/securestamp-action-proof"
        }
      ],
      "indexedCount": 11,
      "json": "https://www.anchorterminal.com/categories/code-sandboxes.json",
      "name": "Code execution sandboxes",
      "slug": "code-sandboxes",
      "test": "The same task in every sandbox: start, install a package, run a script that writes files, pause and resume where supported, then tear down. We time each step, check isolation claims against the docs and add up the cost.",
      "title": "Code execution sandboxes for AI agents",
      "toolCount": 15,
      "tools": [
        "microsoft-execution-containers",
        "modal-sandboxes",
        "agentcore-code-interpreter",
        "vercel-sandbox",
        "e2b",
        "cloudflare-sandbox-sdk",
        "runloop",
        "daytona",
        "blaxel-sandboxes",
        "freestyle",
        "sprites",
        "together-code-sandbox",
        "morph-cloud",
        "deno-sandbox",
        "agent37"
      ],
      "url": "https://www.anchorterminal.com/categories/code-sandboxes"
    },
    "faq": [
      {
        "answer": "Microsoft Execution Containers has the highest benchmark score of the 15 ranked code execution sandboxes, 76.3 (BB). Modal Sandboxes is second with 75.5 (BB).",
        "question": "What are the highest-rated code execution sandboxes for AI agents?"
      },
      {
        "answer": "3 of the 15 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.",
        "question": "How many code execution sandboxes are agent-ready?"
      },
      {
        "answer": "None of the ranked listings here accepts x402 for its main call yet.",
        "question": "Which code execution sandboxes accept x402 payments?"
      },
      {
        "answer": "By published paid prices, Agent 37 Cloud, at $0.0011 per vCPU hour, the lowest of the 13 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.",
        "question": "Which of these code execution sandboxes is cheapest?"
      },
      {
        "answer": "By the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.",
        "question": "How is this list ranked?"
      }
    ],
    "howToChoose": [
      {
        "label": "Start time and concurrency",
        "detail": "Check the start time and how many sandboxes you can run at once, because an agent that waits on cold starts or hits a concurrency cap stalls mid-task."
      },
      {
        "label": "Isolation and what it covers",
        "detail": "Check what isolation the vendor documents and whether it covers the network, filesystem and host, because an agent running untrusted code needs a boundary it can rely on."
      },
      {
        "label": "Billing per second and idle time",
        "detail": "Work out the cost of a sandbox that sits paused or idle, since a plan may charge for memory or storage while nothing runs."
      },
      {
        "label": "Pause, resume and checkpoints",
        "detail": "Check whether state can be paused, resumed or checkpointed and what survives a restore, because a restore that drops installed packages forces the agent to start again."
      }
    ],
    "picks": [
      {
        "also": {
          "name": "Modal Sandboxes",
          "slug": "modal-sandboxes",
          "why": "BB, 75.5/100"
        },
        "name": "Microsoft Execution Containers",
        "need": "Highest score overall",
        "slug": "microsoft-execution-containers",
        "why": "BB, 76.3/100 on the benchmark"
      },
      {
        "name": "Modal Sandboxes",
        "need": "Reliability",
        "slug": "modal-sandboxes",
        "why": "95/100 on reliability, against 81 for the overall leader"
      },
      {
        "name": "E2B",
        "need": "Schema \u0026 documentation",
        "slug": "e2b",
        "why": "92/100 on schema \u0026 documentation, against 81 for the overall leader"
      },
      {
        "name": "Amazon Bedrock AgentCore Code Interpreter",
        "need": "Agent ergonomics",
        "slug": "agentcore-code-interpreter",
        "why": "75/100 on agent ergonomics, against 74 for the overall leader"
      },
      {
        "name": "Amazon Bedrock AgentCore Code Interpreter",
        "need": "Security \u0026 auth",
        "slug": "agentcore-code-interpreter",
        "why": "87/100 on security \u0026 auth, against 69 for the overall leader"
      },
      {
        "name": "Modal Sandboxes",
        "need": "Maintenance \u0026 community",
        "slug": "modal-sandboxes",
        "why": "93/100 on maintenance \u0026 community, against 92 for the overall leader"
      },
      {
        "also": {
          "name": "Sprites",
          "slug": "sprites",
          "why": "$0.0385 per vCPU hour"
        },
        "name": "Agent 37 Cloud",
        "need": "Lowest paid price per vCPU hour",
        "slug": "agent37",
        "why": "$0.0011 per vCPU hour, the lowest of the 13 listings here with a paid price in this unit (free allowances aside)"
      },
      {
        "name": "Blaxel Sandboxes",
        "need": "A hosted MCP endpoint",
        "slug": "blaxel-sandboxes",
        "why": "remote MCP server, nothing to install"
      },
      {
        "name": "E2B",
        "need": "Self-hosting under an open licence",
        "slug": "e2b",
        "why": "self-hosted, Apache-2 licence"
      },
      {
        "name": "Modal Sandboxes",
        "need": "The review panel's favourite",
        "slug": "modal-sandboxes",
        "why": "3.3/5 from 8 panel reviews"
      }
    ],
    "ranked": 15,
    "shortlist": [
      {
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "grade": "BB",
        "name": "Microsoft Execution Containers",
        "position": 1,
        "price": "Free · OSS",
        "score": 76.3,
        "slug": "microsoft-execution-containers",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties"
        ],
        "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "GPU work inside a sandbox, or agents already running on Modal.",
        "grade": "BB",
        "name": "Modal Sandboxes",
        "position": 2,
        "price": "$0.071 / vCPU-hr",
        "score": 75.5,
        "slug": "modal-sandboxes",
        "strengths": [
          "GPU sandboxes at the same per-second rates as the rest of Modal",
          "Outbound traffic blockable or limited to CIDR ranges, and no inbound connections without tunnels",
          "$30 of compute every month on Starter, no card"
        ],
        "url": "https://www.anchorterminal.com/tools/modal-sandboxes",
        "verdict": "GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta.",
        "weaknesses": [
          "No REST API, and the JavaScript and Go SDKs are beta",
          "Default lifetime of 5 minutes and a hard maximum of 24 hours",
          "gVisor rather than a VM unless you're on Team or Enterprise for the VM runtime"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "A team already on AWS that wants agent code to run under IAM, inside a VPC and beside S3 data, for sessions up to eight hours.",
        "grade": "BB",
        "name": "Amazon Bedrock AgentCore Code Interpreter",
        "position": 3,
        "price": "$0.0895 / vCPU-hr",
        "score": 73.1,
        "slug": "agentcore-code-interpreter",
        "strengths": [
          "Each session runs in a dedicated microVM, which AWS says is terminated and has its memory sanitised when the session ends",
          "Billing is per second on CPU used and peak memory, at $0.0895 a vCPU-hour and $0.00945 a GB-hour, with I/O wait and idle time free",
          "IAM actions cover each of the nine operations, with separate ARNs for the system interpreter and custom ones"
        ],
        "url": "https://www.anchorterminal.com/tools/agentcore-code-interpreter",
        "verdict": "Each session runs in its own microVM with 2 vCPU, 8 GB and a 10 GB disk for up to eight hours, and IAM can scope access to one interpreter. Sessions cannot be paused or resumed, and an AWS account with IAM set-up is needed before a first call.",
        "weaknesses": [
          "No pause, resume or snapshot. Session files are removed when the session ends, and persistence needs a customer-owned S3 Files or EFS mount inside a VPC",
          "Every session is capped at 2 vCPU, 8 GB of memory and 10 GB of disk, and the cap is not adjustable",
          "`InvokeCodeInterpreter` takes one flat `arguments` object for nine operations, so the reference does not say which fields each operation requires"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents that spend most of their time waiting on a model, and teams already on Vercel.",
        "grade": "B",
        "name": "Vercel Sandbox",
        "position": 4,
        "price": "$0.128 / vCPU-hr",
        "score": 69.6,
        "slug": "vercel-sandbox",
        "strengths": [
          "Active CPU billing, so waiting on model responses costs only memory",
          "Credential brokering proxy outside the sandbox that overwrites headers set by sandbox code",
          "Firecracker microVM with root access, and a firewall with deny-all, domain and CIDR rules"
        ],
        "url": "https://www.anchorterminal.com/tools/vercel-sandbox",
        "verdict": "Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.",
        "weaknesses": [
          "Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team",
          "Hobby caps sessions at 45 minutes and pauses creation once the monthly allowance is spent",
          "Snapshots keep the filesystem, not memory or running processes"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Code interpreters and agent workspaces that pause and resume with memory, and teams that may want to self-host later.",
        "grade": "B",
        "name": "E2B",
        "position": 5,
        "price": "$0.0504 / vCPU-hr",
        "score": 68.3,
        "slug": "e2b",
        "strengths": [
          "Firecracker microVM with its own kernel per sandbox",
          "Egress allow and deny lists by domain, IP or CIDR, and secrets filled in outside the sandbox",
          "Apache-2.0 infrastructure in e2b-dev/infra, self-hostable with Terraform"
        ],
        "url": "https://www.anchorterminal.com/tools/e2b",
        "verdict": "Firecracker microVM with its own kernel per sandbox. Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots.",
        "weaknesses": [
          "Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots",
          "One unscoped API key per project, with no audit log found",
          "Hobby sandboxes stop after 1 hour of continuous running"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.",
        "grade": "B",
        "name": "Cloudflare Sandbox SDK",
        "position": 6,
        "price": "$0.072 / vCPU-hr",
        "score": 67.5,
        "slug": "cloudflare-sandbox-sdk",
        "strengths": [
          "Each sandbox runs in its own VM with a separate filesystem, process space and network stack",
          "Outbound handlers hold credentials in the Worker and inject them, so the container never sees them",
          "Egress can be turned off or limited to a deny-by-default `allowedHosts` list"
        ],
        "url": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk",
        "verdict": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
        "weaknesses": [
          "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth",
          "Open bugs on backups that drop directories (#859) and restores of archives of 10 MB or more (#884)",
          "Needs Workers Paid at $5 a month, with no card-free route"
        ],
        "where": "local",
        "x402": "no"
      },
      {
        "bestFor": "Running and grading coding agents on full workstations with prebuilt blueprints and credential gateways.",
        "grade": "B",
        "name": "Runloop Devboxes",
        "position": 7,
        "price": "$0.108 / vCPU-hr",
        "score": 64.8,
        "slug": "runloop",
        "strengths": [
          "Agent gateways keep real credentials on Runloop's servers, with gateway tokens bound to one devbox",
          "Network policies that block egress or allow listed hostnames",
          "Public OpenAPI, llms.txt and typed Python and TypeScript SDKs with cursor pagination and 429 backoff"
        ],
        "url": "https://www.anchorterminal.com/tools/runloop",
        "verdict": "Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison.",
        "weaknesses": [
          "About twice the per-vCPU price of E2B or Daytona",
          "No published rate limits or API error-body reference",
          "Suspend keeps disk only, and processes need restarting after resume"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.",
        "grade": "B",
        "name": "Daytona",
        "position": 8,
        "price": "$0.0504 / vCPU-hr",
        "score": 64.3,
        "slug": "daytona",
        "strengths": [
          "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them",
          "Container, Linux VM, Windows and GPU sandbox classes behind one API",
          "Three public OpenAPI files, llms.txt and SDKs in five languages"
        ],
        "url": "https://www.anchorterminal.com/tools/daytona",
        "verdict": "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.",
        "weaknesses": [
          "The container class shares the host kernel. Only the VM classes get their own",
          "Full internet access and per-sandbox allow lists need Tier 3",
          "Platform code went private in June 2026, and the old repository's 311 open issues won't be answered"
        ],
        "where": "both",
        "x402": "no"
      },
      {
        "bestFor": "Long-lived, mostly idle agent workspaces that need to resume quickly with memory intact, and teams that want an MCP server per sandbox.",
        "grade": "C",
        "name": "Blaxel Sandboxes",
        "position": 9,
        "price": "$0.1656 / session-hr",
        "score": 60.7,
        "slug": "blaxel-sandboxes",
        "strengths": [
          "No compute charge in standby, only $0.20 a GB-month of snapshot storage",
          "MicroVM per sandbox with domain allow and deny lists that can be enforced at network level",
          "An MCP server in every sandbox over streamable HTTP, 18 tools"
        ],
        "url": "https://www.anchorterminal.com/tools/blaxel-sandboxes",
        "verdict": "No compute charge in standby, only $0.20 a GB-month of snapshot storage. 25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour.",
        "weaknesses": [
          "25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour",
          "No published request-rate limits, 429 guidance or SLA",
          "Domain filtering and secret injection are marked public preview, and egress is open by default"
        ],
        "where": "hosted",
        "x402": "no"
      },
      {
        "bestFor": "Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.",
        "grade": "C",
        "name": "Freestyle",
        "position": 10,
        "price": "$0.0403 / vCPU-hr",
        "score": 58.5,
        "slug": "freestyle",
        "strengths": [
          "Public OpenAPI 3.1 file with 88 `/v5` operations, each with a description and named error codes per status",
          "A new VM has no inbound or outbound network access until firewall rules allow it",
          "Identity access tokens limited to granted VMs and Linux users, revocable without rotating the team API key"
        ],
        "url": "https://www.anchorterminal.com/tools/freestyle",
        "verdict": "A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.",
        "weaknesses": [
          "No terms of service or service agreement found on the site, and the privacy policy covers the website only",
          "The status page shows three components with no incident history",
          "No request rate limit, Retry-After guidance or idempotency keys found in the docs or the OpenAPI file"
        ],
        "where": "hosted",
        "x402": "no"
      }
    ],
    "updated": "2026-10-08"
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/best/code-sandboxes/",
    "json": "https://www.anchorterminal.com/best/code-sandboxes/index.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/best/code-sandboxes/index.md",
    "slim": "https://www.anchorterminal.com/best/code-sandboxes/index.min.md"
  },
  "markdown": "The 10 highest-scoring of 15 code execution sandboxes on the Anchor benchmark, with a pick for each need and where each one falls short. Scores come from public evidence, re-checked as vendors change.\n\n- Ranked: 15 · agent-ready (BB or better): 3 · accept x402: 0 · hosted endpoints: 10\n- Full ranked table: https://www.anchorterminal.com/categories/code-sandboxes.md\n- Head-to-head comparisons: https://www.anchorterminal.com/compare/code-sandboxes/index.md (105)\n- Methodology: https://www.anchorterminal.com/benchmark/index.md\n\n## The shortlist\n\n| # | Tool | Grade | Score | Best for | Price | Where |\n| --- | --- | --- | --- | --- | --- | --- |\n| 1 | [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md) | BB | 76.3 | A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation. | Free · OSS | local |\n| 2 | [Modal Sandboxes](https://www.anchorterminal.com/tools/modal-sandboxes.md) | BB | 75.5 | GPU work inside a sandbox, or agents already running on Modal. | $0.071 / vCPU-hr | local |\n| 3 | [Amazon Bedrock AgentCore Code Interpreter](https://www.anchorterminal.com/tools/agentcore-code-interpreter.md) | BB | 73.1 | A team already on AWS that wants agent code to run under IAM, inside a VPC and beside S3 data, for sessions up to eight hours. | $0.0895 / vCPU-hr | hosted |\n| 4 | [Vercel Sandbox](https://www.anchorterminal.com/tools/vercel-sandbox.md) | B | 69.6 | Agents that spend most of their time waiting on a model, and teams already on Vercel. | $0.128 / vCPU-hr | hosted |\n| 5 | [E2B](https://www.anchorterminal.com/tools/e2b.md) | B | 68.3 | Code interpreters and agent workspaces that pause and resume with memory, and teams that may want to self-host later. | $0.0504 / vCPU-hr | hosted |\n| 6 | [Cloudflare Sandbox SDK](https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md) | B | 67.5 | Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge. | $0.072 / vCPU-hr | local |\n| 7 | [Runloop Devboxes](https://www.anchorterminal.com/tools/runloop.md) | B | 64.8 | Running and grading coding agents on full workstations with prebuilt blueprints and credential gateways. | $0.108 / vCPU-hr | hosted |\n| 8 | [Daytona](https://www.anchorterminal.com/tools/daytona.md) | B | 64.3 | Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys. | $0.0504 / vCPU-hr | hosted and local |\n| 9 | [Blaxel Sandboxes](https://www.anchorterminal.com/tools/blaxel-sandboxes.md) | C | 60.7 | Long-lived, mostly idle agent workspaces that need to resume quickly with memory intact, and teams that want an MCP server per sandbox. | $0.1656 / session-hr | hosted |\n| 10 | [Freestyle](https://www.anchorterminal.com/tools/freestyle.md) | C | 58.5 | Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking. | $0.0403 / vCPU-hr | hosted |\n\n## Picks by need\n\n- Highest score overall: [Microsoft Execution Containers](https://www.anchorterminal.com/tools/microsoft-execution-containers.md), BB, 76.3/100 on the benchmark. Also [Modal Sandboxes](https://www.anchorterminal.com/tools/modal-sandboxes.md), BB, 75.5/100.\n- Reliability: [Modal Sandboxes](https://www.anchorterminal.com/tools/modal-sandboxes.md), 95/100 on reliability, against 81 for the overall leader.\n- Schema \u0026 documentation: [E2B](https://www.anchorterminal.com/tools/e2b.md), 92/100 on schema \u0026 documentation, against 81 for the overall leader.\n- Agent ergonomics: [Amazon Bedrock AgentCore Code Interpreter](https://www.anchorterminal.com/tools/agentcore-code-interpreter.md), 75/100 on agent ergonomics, against 74 for the overall leader.\n- Security \u0026 auth: [Amazon Bedrock AgentCore Code Interpreter](https://www.anchorterminal.com/tools/agentcore-code-interpreter.md), 87/100 on security \u0026 auth, against 69 for the overall leader.\n- Maintenance \u0026 community: [Modal Sandboxes](https://www.anchorterminal.com/tools/modal-sandboxes.md), 93/100 on maintenance \u0026 community, against 92 for the overall leader.\n- Lowest paid price per vCPU hour: [Agent 37 Cloud](https://www.anchorterminal.com/tools/agent37.md), $0.0011 per vCPU hour, the lowest of the 13 listings here with a paid price in this unit (free allowances aside). Also [Sprites](https://www.anchorterminal.com/tools/sprites.md), $0.0385 per vCPU hour.\n- A hosted MCP endpoint: [Blaxel Sandboxes](https://www.anchorterminal.com/tools/blaxel-sandboxes.md), remote MCP server, nothing to install.\n- Self-hosting under an open licence: [E2B](https://www.anchorterminal.com/tools/e2b.md), self-hosted, Apache-2 licence.\n- The review panel's favourite: [Modal Sandboxes](https://www.anchorterminal.com/tools/modal-sandboxes.md), 3.3/5 from 8 panel reviews.\n\n## How to choose\n\n- Start time and concurrency: Check the start time and how many sandboxes you can run at once, because an agent that waits on cold starts or hits a concurrency cap stalls mid-task.\n- Isolation and what it covers: Check what isolation the vendor documents and whether it covers the network, filesystem and host, because an agent running untrusted code needs a boundary it can rely on.\n- Billing per second and idle time: Work out the cost of a sandbox that sits paused or idle, since a plan may charge for memory or storage while nothing runs.\n- Pause, resume and checkpoints: Check whether state can be paused, resumed or checkpointed and what survives a restore, because a restore that drops installed packages forces the agent to start again.\n\n- How the benchmark tests this category: The same task in every sandbox: start, install a package, run a script that writes files, pause and resume where supported, then tear down. We time each step, check isolation claims against the docs and add up the cost.\n\n## Each one in detail\n\n### 1. Microsoft Execution Containers, BB 76.3/100\n\nMicrosoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.\n\n- Verdict: MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n- Choose it for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n- Strength: MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages\n- Strength: Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths\n- Strength: A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties\n- Weakness: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n- Weakness: Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC\n- Weakness: Persistent containers exist only for `isolation_session` and `wslc`, both on Windows\n- Price: Free · OSS · Auth: None · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/microsoft-execution-containers.md\n\n### 2. Modal Sandboxes, BB 75.5/100\n\nModal's sandboxed compute environments for running code, with SDK access, GPU support and filesystem snapshots.\n\n- Verdict: GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta.\n- Choose it for: GPU work inside a sandbox, or agents already running on Modal.\n- Strength: GPU sandboxes at the same per-second rates as the rest of Modal\n- Strength: Outbound traffic blockable or limited to CIDR ranges, and no inbound connections without tunnels\n- Strength: $30 of compute every month on Starter, no card\n- Weakness: No REST API, and the JavaScript and Go SDKs are beta\n- Weakness: Default lifetime of 5 minutes and a hard maximum of 24 hours\n- Weakness: gVisor rather than a VM unless you're on Team or Enterprise for the VM runtime\n- Price: $0.071 / vCPU-hr · Auth: API key · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/modal-sandboxes.md\n- Against #1: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md\n\n### 3. Amazon Bedrock AgentCore Code Interpreter, BB 73.1/100\n\nAmazon Bedrock AgentCore Code Interpreter is AWS's managed sandbox for running agent-written Python, JavaScript and TypeScript. Each session is a dedicated microVM, reached through the AWS API, the AgentCore SDKs or an MCP server.\n\n- Verdict: Each session runs in its own microVM with 2 vCPU, 8 GB and a 10 GB disk for up to eight hours, and IAM can scope access to one interpreter. Sessions cannot be paused or resumed, and an AWS account with IAM set-up is needed before a first call.\n- Choose it for: A team already on AWS that wants agent code to run under IAM, inside a VPC and beside S3 data, for sessions up to eight hours.\n- Strength: Each session runs in a dedicated microVM, which AWS says is terminated and has its memory sanitised when the session ends\n- Strength: Billing is per second on CPU used and peak memory, at $0.0895 a vCPU-hour and $0.00945 a GB-hour, with I/O wait and idle time free\n- Strength: IAM actions cover each of the nine operations, with separate ARNs for the system interpreter and custom ones\n- Weakness: No pause, resume or snapshot. Session files are removed when the session ends, and persistence needs a customer-owned S3 Files or EFS mount inside a VPC\n- Weakness: Every session is capped at 2 vCPU, 8 GB of memory and 10 GB of disk, and the cap is not adjustable\n- Weakness: `InvokeCodeInterpreter` takes one flat `arguments` object for nine operations, so the reference does not say which fields each operation requires\n- Price: $0.0895 / vCPU-hr · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/agentcore-code-interpreter.md\n- Against #1: https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.md\n\n### 4. Vercel Sandbox, B 69.6/100\n\nFirecracker microVM sandboxes on Vercel, driven from the `@vercel/sandbox` JavaScript SDK, the Python `vercel` package, a CLI or the REST API.\n\n- Verdict: Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.\n- Choose it for: Agents that spend most of their time waiting on a model, and teams already on Vercel.\n- Strength: Active CPU billing, so waiting on model responses costs only memory\n- Strength: Credential brokering proxy outside the sandbox that overwrites headers set by sandbox code\n- Strength: Firecracker microVM with root access, and a firewall with deny-all, domain and CIDR rules\n- Weakness: Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team\n- Weakness: Hobby caps sessions at 45 minutes and pauses creation once the monthly allowance is spent\n- Weakness: Snapshots keep the filesystem, not memory or running processes\n- Price: $0.128 / vCPU-hr · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/vercel-sandbox.md\n- Against #1: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md\n\n### 5. E2B, B 68.3/100\n\nFirecracker microVM sandboxes for agent code, driven from Python and JavaScript SDKs, a CLI or a REST API.\n\n- Verdict: Firecracker microVM with its own kernel per sandbox. Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots.\n- Choose it for: Code interpreters and agent workspaces that pause and resume with memory, and teams that may want to self-host later.\n- Strength: Firecracker microVM with its own kernel per sandbox\n- Strength: Egress allow and deny lists by domain, IP or CIDR, and secrets filled in outside the sandbox\n- Strength: Apache-2.0 infrastructure in e2b-dev/infra, self-hostable with Terraform\n- Weakness: Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots\n- Weakness: One unscoped API key per project, with no audit log found\n- Weakness: Hobby sandboxes stop after 1 hour of continuous running\n- Price: $0.0504 / vCPU-hr · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/e2b.md\n- Against #1: https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md\n\n### 6. Cloudflare Sandbox SDK, B 67.5/100\n\nTypeScript library for running sandboxed Linux containers from a Cloudflare Worker.\n\n- Verdict: Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.\n- Choose it for: Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.\n- Strength: Each sandbox runs in its own VM with a separate filesystem, process space and network stack\n- Strength: Outbound handlers hold credentials in the Worker and inject them, so the container never sees them\n- Strength: Egress can be turned off or limited to a deny-by-default `allowedHosts` list\n- Weakness: No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth\n- Weakness: Open bugs on backups that drop directories (#859) and restores of archives of 10 MB or more (#884)\n- Weakness: Needs Workers Paid at $5 a month, with no card-free route\n- Price: $0.072 / vCPU-hr · Auth: None · x402: no · Where: local\n- Full assessment: https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md\n- Against #1: https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md\n\n### 7. Runloop Devboxes, B 64.8/100\n\nDevboxes, VM sandboxes for coding agents, with blueprints for prebuilt images, disk snapshots, suspend and resume, idle policies and a gateway that adds secret-backed headers to outbound API and MCP calls.\n\n- Verdict: Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison.\n- Choose it for: Running and grading coding agents on full workstations with prebuilt blueprints and credential gateways.\n- Strength: Agent gateways keep real credentials on Runloop's servers, with gateway tokens bound to one devbox\n- Strength: Network policies that block egress or allow listed hostnames\n- Strength: Public OpenAPI, llms.txt and typed Python and TypeScript SDKs with cursor pagination and 429 backoff\n- Weakness: About twice the per-vCPU price of E2B or Daytona\n- Weakness: No published rate limits or API error-body reference\n- Weakness: Suspend keeps disk only, and processes need restarting after resume\n- Price: $0.108 / vCPU-hr · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/runloop.md\n- Against #1: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md\n\n### 8. Daytona, B 64.3/100\n\nSandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API.\n\n- Verdict: API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.\n- Choose it for: Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.\n- Strength: API keys with per-action scopes, so an agent can create sandboxes without being able to delete them\n- Strength: Container, Linux VM, Windows and GPU sandbox classes behind one API\n- Strength: Three public OpenAPI files, llms.txt and SDKs in five languages\n- Weakness: The container class shares the host kernel. Only the VM classes get their own\n- Weakness: Full internet access and per-sandbox allow lists need Tier 3\n- Weakness: Platform code went private in June 2026, and the old repository's 311 open issues won't be answered\n- Price: $0.0504 / vCPU-hr · Auth: API key · x402: no · Where: hosted and local\n- Full assessment: https://www.anchorterminal.com/tools/daytona.md\n- Against #1: https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md\n\n### 9. Blaxel Sandboxes, C 60.7/100\n\nSandbox VMs that drop to standby seconds after the last connection and resume in about 25 ms with memory and filesystem kept, charging only for snapshot storage while idle.\n\n- Verdict: No compute charge in standby, only $0.20 a GB-month of snapshot storage. 25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour.\n- Choose it for: Long-lived, mostly idle agent workspaces that need to resume quickly with memory intact, and teams that want an MCP server per sandbox.\n- Strength: No compute charge in standby, only $0.20 a GB-month of snapshot storage\n- Strength: MicroVM per sandbox with domain allow and deny lists that can be enforced at network level\n- Strength: An MCP server in every sandbox over streamable HTTP, 18 tools\n- Weakness: 25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour\n- Weakness: No published request-rate limits, 429 guidance or SLA\n- Weakness: Domain filtering and secret injection are marked public preview, and egress is open by default\n- Price: $0.1656 / session-hr · Auth: OAuth or key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/blaxel-sandboxes.md\n- Against #1: https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md\n\n### 10. Freestyle, C 58.5/100\n\nFreestyle runs full Linux virtual machines for AI agents, with pause and resume that keeps memory, snapshots, private networks and domains. Agents drive it through a REST API, a TypeScript SDK and a CLI from one npm package.\n\n- Verdict: A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.\n- Choose it for: Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.\n- Strength: Public OpenAPI 3.1 file with 88 `/v5` operations, each with a description and named error codes per status\n- Strength: A new VM has no inbound or outbound network access until firewall rules allow it\n- Strength: Identity access tokens limited to granted VMs and Linux users, revocable without rotating the team API key\n- Weakness: No terms of service or service agreement found on the site, and the privacy policy covers the website only\n- Weakness: The status page shows three components with no incident history\n- Weakness: No request rate limit, Retry-After guidance or idempotency keys found in the docs or the OpenAPI file\n- Price: $0.0403 / vCPU-hr · Auth: API key · x402: no · Where: hosted\n- Full assessment: https://www.anchorterminal.com/tools/freestyle.md\n- Against #1: https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.md\n\n5 more are ranked in the full table: https://www.anchorterminal.com/categories/code-sandboxes.md\n\n## Head to head\n\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Modal Sandboxes](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-modal-sandboxes.md)\n- [Modal Sandboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox.md)\n- [E2B vs Modal Sandboxes](https://www.anchorterminal.com/compare/e2b-vs-modal-sandboxes.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Vercel Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-vercel-sandbox.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs E2B](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-e2b.md)\n- [E2B vs Vercel Sandbox](https://www.anchorterminal.com/compare/e2b-vs-vercel-sandbox.md)\n\n## Questions\n\n### What are the highest-rated code execution sandboxes for AI agents?\n\nMicrosoft Execution Containers has the highest benchmark score of the 15 ranked code execution sandboxes, 76.3 (BB). Modal Sandboxes is second with 75.5 (BB).\n\n### How many code execution sandboxes are agent-ready?\n\n3 of the 15 ranked here grade BB or better, the bar for agent-ready on the Anchor benchmark.\n\n### Which code execution sandboxes accept x402 payments?\n\nNone of the ranked listings here accepts x402 for its main call yet.\n\n### Which of these code execution sandboxes is cheapest?\n\nBy published paid prices, Agent 37 Cloud, at $0.0011 per vCPU hour, the lowest of the 13 listings here with a paid price in this unit (free allowances aside). Plans, volume tiers and free allowances change the sum, so check the listing's price table.\n\n### How is this list ranked?\n\nBy the Anchor benchmark score out of 100, a weighted mean of the scored categories minus deductions for negative events, from public evidence re-checked as vendors change. Listings cannot pay for a place. The latest assessment behind this page is from 8 October 2026.\n\n## How this list is made\n\nThe order is the Anchor benchmark score, the same number as on each listing. Each listing is graded from public evidence against the benchmark checklist, and the picks are worked out from those grades, prices and facts. No listing pays for its place, and paid audits or listing help never change a score.\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-10",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Best of",
        "url": "https://www.anchorterminal.com/best/"
      },
      {
        "name": "Code execution sandboxes",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers (BB), Modal Sandboxes (BB) and Amazon Bedrock AgentCore Code Interpreter (BB) lead the 15 ranked code execution sandboxes. Picks by need, strengths, weaknesses and prices from the Anchor benchmark.",
    "facts": [
      "Microsoft Execution Containers BB",
      "Modal Sandboxes BB",
      "Amazon Bedrock AgentCore Code Interpreter BB"
    ],
    "h1": "Best code execution sandboxes for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/best-code-sandboxes.png",
    "path": "/best/code-sandboxes/",
    "published": "",
    "section": "tools",
    "title": "Best code execution sandboxes for AI agents in 2026, ranked",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/best/code-sandboxes/"
  },
  "tokens": {
    "markdown": 5900,
    "slim": 1630
  },
  "version": 1
}
