{
  "data": {
    "category": {
      "area": "agent-runtime",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.browser",
        "sandbox.gpu"
      ],
      "description": "Isolated machines an agent can start in seconds to run code, install packages and use a filesystem, then throw away. Compared on start time, isolation, how long a sandbox can live, what it costs per second and whether state can be paused and resumed.",
      "indexed": [
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/antrieb.json",
          "kind": "mcp",
          "name": "antrieb",
          "slug": "antrieb",
          "url": "https://www.anchorterminal.com/tools/antrieb"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/opencovenant-guard.json",
          "kind": "mcp",
          "name": "Covenant Guard",
          "slug": "opencovenant-guard",
          "url": "https://www.anchorterminal.com/tools/opencovenant-guard"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/kenwea-marketplace.json",
          "kind": "mcp",
          "name": "Kenwea — Sandbox Attestation \u0026 Agent Marketplace",
          "slug": "kenwea-marketplace",
          "url": "https://www.anchorterminal.com/tools/kenwea-marketplace"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/mupag-mcp-server.json",
          "kind": "mcp",
          "name": "MuPag Sandbox Payments",
          "slug": "mupag-mcp-server",
          "url": "https://www.anchorterminal.com/tools/mupag-mcp-server"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/parallelsandbox.json",
          "kind": "mcp",
          "name": "ParallelSandbox",
          "slug": "parallelsandbox",
          "url": "https://www.anchorterminal.com/tools/parallelsandbox"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/rivet-mcp.json",
          "kind": "mcp",
          "name": "Rivet",
          "slug": "rivet-mcp",
          "url": "https://www.anchorterminal.com/tools/rivet-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/withruntime-runtime.json",
          "kind": "mcp",
          "name": "Runtime Cloud",
          "slug": "withruntime-runtime",
          "url": "https://www.anchorterminal.com/tools/withruntime-runtime"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sandboxapis-mcp.json",
          "kind": "mcp",
          "name": "SandboxAPIs",
          "slug": "sandboxapis-mcp",
          "url": "https://www.anchorterminal.com/tools/sandboxapis-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/scratchrun-mcp.json",
          "kind": "mcp",
          "name": "ScratchRun",
          "slug": "scratchrun-mcp",
          "url": "https://www.anchorterminal.com/tools/scratchrun-mcp"
        },
        {
          "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/securestamp-action-proof.json",
          "kind": "mcp",
          "name": "SecureStamp Action Proof — Cross-Cloud Public Beta (Unverified)",
          "slug": "securestamp-action-proof",
          "url": "https://www.anchorterminal.com/tools/securestamp-action-proof"
        }
      ],
      "indexedCount": 10,
      "json": "https://www.anchorterminal.com/categories/code-sandboxes.json",
      "name": "Code execution sandboxes",
      "slug": "code-sandboxes",
      "test": "The same task in every sandbox: start, install a package, run a script that writes files, pause and resume where supported, then tear down. We time each step, check isolation claims against the docs and add up the cost.",
      "title": "Code execution sandboxes for AI agents",
      "toolCount": 7,
      "tools": [
        "modal-sandboxes",
        "vercel-sandbox",
        "e2b",
        "cloudflare-sandbox-sdk",
        "runloop",
        "daytona",
        "blaxel-sandboxes"
      ],
      "url": "https://www.anchorterminal.com/categories/code-sandboxes"
    },
    "tools": [
      {
        "slug": "modal-sandboxes",
        "name": "Modal Sandboxes",
        "vendor": "Modal",
        "vendorUrl": "https://modal.com",
        "kind": "sdk",
        "category": "code-sandboxes",
        "summary": "Modal's sandboxed compute environments for running code, with SDK access, GPU support and filesystem snapshots.",
        "url": "https://www.anchorterminal.com/tools/modal-sandboxes",
        "markdownUrl": "https://www.anchorterminal.com/tools/modal-sandboxes.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/modal-sandboxes.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/modal-sandboxes.json",
        "repo": "https://github.com/modal-labs/modal-client",
        "license": "Apache-2.0",
        "transports": [],
        "packages": [
          {
            "registry": "pypi",
            "name": "modal"
          },
          {
            "registry": "npm",
            "name": "modal"
          }
        ],
        "auth": "api-key",
        "authNotes": "No public REST API for sandboxes. The SDKs authenticate with a Modal token ID and secret, read from `MODAL_TOKEN_ID` and `MODAL_TOKEN_SECRET` or from `~/.modal.toml` (written by `modal token set`). Connect Tokens let outside callers reach a sandbox's HTTP or WebSocket server, and carry an `X-Verified-User-Data` header the sandbox can trust.",
        "pricing": "freemium",
        "pricingNotes": "Sandboxes cost $0.00003942 a physical core-second (one core is 2 vCPU, minimum 0.125 cores) and $0.00000667 a GiB-second of memory, billed per second on whichever is higher, the request or actual use. GPUs bill at Modal's standard per-second GPU rates. Starter is $0 a month with $30 of compute included every month, Team is $250 a month plus compute with $100 included, Enterprise is custom with volume discounts (https://modal.com/pricing, https://modal.com/docs/guide/sandbox-resources.md).",
        "priceSummary": "$0.071 / vCPU-hr",
        "where": "local",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 514,
          "npmWeekly": 940973,
          "pypiWeekly": 10146778,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://modal.com/docs/guide/sandboxes",
        "llmsTxt": "https://modal.com/llms.txt",
        "capabilities": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist",
          "sandbox.gpu"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "python",
          "typescript",
          "go",
          "llms-txt",
          "enterprise"
        ],
        "lastRelease": "2026-09-28",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 75.6,
          "grade": "BB",
          "agentReady": true,
          "rank": 33,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 1,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 67,
            "maintenance": 93,
            "payments": 40,
            "reliability": 95,
            "schema": 79,
            "security": 76,
            "transparency": 74
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta.",
          "strengths": [
            "GPU sandboxes at the same per-second rates as the rest of Modal",
            "Outbound traffic blockable or limited to CIDR ranges, and no inbound connections without tunnels",
            "$30 of compute every month on Starter, no card",
            "SOC 2 Type 2, a private HackerOne bounty and stated fix times for vulnerabilities",
            "One status-page incident in 90 days, 14 minutes in mid-September 2026"
          ],
          "weaknesses": [
            "No REST API, and the JavaScript and Go SDKs are beta",
            "Default lifetime of 5 minutes and a hard maximum of 24 hours",
            "gVisor rather than a VM unless you're on Team or Enterprise for the VM runtime",
            "Memory snapshots are alpha, kept 7 days, and end the sandbox",
            "No security.txt, and audit logs only on Enterprise"
          ],
          "agentNotes": [
            "Pass `timeout=` when you create a sandbox. The default lifetime is 5 minutes",
            "Set `block_network=True` or a `cidr_allowlist` for untrusted code",
            "Give a sandbox a `name` so a retried create raises `AlreadyExistsError` instead of starting a second one",
            "Snapshot the filesystem before the 24-hour limit and start a fresh sandbox from it",
            "Catch `ResourceExhaustedError` from `Sandbox.create()` on SDK 1.6.0 and later"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 8,
          "avgRating": 3.3,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "BB",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 75.6
            }
          ],
          "editorialScores": {
            "ergonomics": 67,
            "maintenance": 93,
            "payments": 40,
            "reliability": 95,
            "schema": 79,
            "security": 76,
            "transparency": 60
          },
          "provenanceScore": 88
        },
        "connect": {
          "install": "pip install modal  # or npm i modal"
        },
        "letme": {
          "capability": "https://letme.dev/sandbox.code",
          "tool": "https://letme.dev/modal-sandboxes"
        },
        "sameCompany": [
          "modal"
        ],
        "alsoIn": [
          "gpu-compute"
        ],
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Sandbox CPU",
            "unit": "vcpu-hour",
            "usd": 0.071,
            "note": "$0.00003942 a physical core-second, one core is 2 vCPU. Memory extra at $0.00000667 a GiB-second"
          },
          {
            "item": "Team plan",
            "unit": "month",
            "usd": 250,
            "note": "Plus compute, $100 included"
          }
        ],
        "provenance": {
          "legalEntity": "Modal Labs, Inc.",
          "domain": "modal.com",
          "domainRegistered": "1999-03-18",
          "domainNote": "modal.com was registered in 1999, long before Modal Labs, so the domain was bought later.",
          "endpointOnVendorDomain": null,
          "terms": "https://modal.com/legal/terms",
          "privacy": "https://modal.com/legal/privacy-policy",
          "statusPage": "https://status.modal.com",
          "changelog": "https://modal.com/docs/sdk/py/releases",
          "securityTxt": "none",
          "checked": "2026-09-30",
          "notes": [
            "Terms (May 2026) name Modal Labs, Inc., a Delaware corporation, under California law.",
            "Sandboxes are reached through the SDK rather than a documented public endpoint, so there's no endpoint URL to check against the domain.",
            "modal.com/.well-known/security.txt returns 404. The security guide gives security@modal.com and a private HackerOne programme."
          ],
          "score": 88
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/modal-sandboxes.json",
        "live": {
          "slug": "modal-sandboxes",
          "vendorStatus": {
            "page": "https://status.modal.com",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:40:15.629276461Z"
          },
          "versions": [
            {
              "registry": "npm",
              "name": "modal",
              "version": "0.11.0",
              "seenAt": "2026-10-04T16:33:42.820417551Z"
            },
            {
              "registry": "pypi",
              "name": "modal",
              "version": "1.6.1",
              "released": "2026-10-03",
              "seenAt": "2026-10-04T16:33:42.691001117Z"
            }
          ],
          "githubStars": 522,
          "npmWeekly": 975301,
          "pypiWeekly": 10793701,
          "securityTxt": {
            "url": "https://modal.com/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:42.140189006Z"
          },
          "llmsTxt": {
            "url": "https://modal.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:59.208696898Z"
          },
          "domain": {
            "domain": "modal.com",
            "registered": "1999-03-18",
            "source": "https://rdap.verisign.com/com/v1/domain/modal.com",
            "checkedAt": "2026-10-04T13:03:51.14581991Z"
          },
          "pages": [
            {
              "url": "https://modal.com/docs/sdk/py/releases",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:02.530693875Z",
              "changedAt": "2026-10-04T15:46:02.530693875Z",
              "fingerprint": "2d8a24963498"
            },
            {
              "url": "https://modal.com/pricing",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:09.066130964Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "ebb11d7b0f6a"
            },
            {
              "url": "https://modal.com/legal/privacy-policy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:05.494045324Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "ba881cee4162"
            },
            {
              "url": "https://modal.com/legal/terms",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:46:06.7314142Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "94e2edecd464"
            }
          ],
          "updatedAt": "2026-10-04T21:40:15.629276461Z"
        }
      },
      {
        "slug": "vercel-sandbox",
        "name": "Vercel Sandbox",
        "vendor": "Vercel",
        "vendorUrl": "https://vercel.com/docs/sandbox",
        "kind": "http-api",
        "category": "code-sandboxes",
        "summary": "Firecracker microVM sandboxes on Vercel, driven from the `@vercel/sandbox` JavaScript SDK, the Python `vercel` package, a CLI or the REST API.",
        "url": "https://www.anchorterminal.com/tools/vercel-sandbox",
        "markdownUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json",
        "repo": "https://github.com/vercel/sandbox",
        "license": "Apache-2.0",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.vercel.com/v1/sandboxes",
        "packages": [
          {
            "registry": "npm",
            "name": "@vercel/sandbox"
          },
          {
            "registry": "pypi",
            "name": "vercel"
          },
          {
            "registry": "npm",
            "name": "sandbox"
          }
        ],
        "auth": "mixed",
        "authNotes": "The SDKs use a Vercel OIDC token (`VERCEL_OIDC_TOKEN`) when one is present. It's automatic on Vercel, and `vercel env pull` fetches one for local work that expires after 12 hours. Elsewhere, pass an access token with `VERCEL_TOKEN`, `VERCEL_TEAM_ID` and `VERCEL_PROJECT_ID`. The REST API takes the access token as a Bearer header.",
        "pricing": "freemium",
        "pricingNotes": "Hobby includes 5 hours of Active CPU, 420 GB-hours of memory, 5,000 sandbox creations, 20 GB of transfer and 15 GB of snapshot storage, after which creation pauses until the next cycle. Pro and Enterprise pay $0.128 an Active CPU hour, $0.0212 a GB-hour of provisioned memory, $0.60 per million creations, $0.08 a GB-month of snapshot storage and $0.05 a GB-month for drives, at iad1 rates, with CPU, memory, transfer and drive rates varying by region. Pro usage draws first on the plan's $20 monthly credit. Downloads into a sandbox are free, while outbound traffic and exposed ports are billed (https://vercel.com/docs/sandbox/pricing).",
        "priceSummary": "$0.128 / vCPU-hr",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 168,
          "npmWeekly": 6482660,
          "pypiWeekly": 461527,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://vercel.com/docs/sandbox",
        "llmsTxt": "https://vercel.com/llms.txt",
        "capabilities": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "typescript",
          "python",
          "llms-txt",
          "enterprise"
        ],
        "lastRelease": "2026-09-11",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 69.6,
          "grade": "B",
          "agentReady": false,
          "rank": 111,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 2,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 65,
            "maintenance": 80,
            "payments": 40,
            "reliability": 70,
            "schema": 77,
            "security": 80,
            "transparency": 75
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.",
          "strengths": [
            "Active CPU billing, so waiting on model responses costs only memory",
            "Credential brokering proxy outside the sandbox that overwrites headers set by sandbox code",
            "Firecracker microVM with root access, and a firewall with deny-all, domain and CIDR rules",
            "Persistent by default, with automatic snapshots and resume on the next SDK call",
            "Sandbox has its own status-page component, and the feed shows only degradations from July to September 2026"
          ],
          "weaknesses": [
            "Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team",
            "Hobby caps sessions at 45 minutes and pauses creation once the monthly allowance is spent",
            "Snapshots keep the filesystem, not memory or running processes",
            "Egress is allow-all until you set a policy",
            "No MCP server for Sandbox and no public OpenAPI for its endpoints found"
          ],
          "agentNotes": [
            "Call `sandbox.stop()` when the task is done. Memory bills until the session ends",
            "Use `Sandbox.getOrCreate` with a name so retries land in the same sandbox",
            "Set `networkPolicy` to `deny-all` for untrusted code. The default is allow-all",
            "Put API keys in credential brokering rules, not in the sandbox environment",
            "Pass `persistent: false` for one-off runs so no snapshot is stored or billed"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3.5,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 69.6
            }
          ],
          "editorialScores": {
            "ergonomics": 65,
            "maintenance": 80,
            "payments": 40,
            "reliability": 70,
            "schema": 77,
            "security": 80,
            "transparency": 50
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "npm i @vercel/sandbox  # or pip install vercel",
          "http": "curl -X POST \"https://api.vercel.com/v1/sandboxes?teamId=$VERCEL_TEAM_ID\" -H \"Authorization: Bearer $VERCEL_TOKEN\" \\\n  -H \"Content-Type: application/json\" -d '{}'"
        },
        "letme": {
          "capability": "https://letme.dev/sandbox.code",
          "tool": "https://letme.dev/vercel-sandbox"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Active CPU (iad1)",
            "unit": "vcpu-hour",
            "usd": 0.128,
            "note": "Billed only while the CPU is busy. Memory extra at $0.0212 a GB-hour"
          },
          {
            "item": "Snapshot storage",
            "unit": "gb-month",
            "usd": 0.08
          },
          {
            "item": "Drive storage (iad1)",
            "unit": "gb-month",
            "usd": 0.05,
            "note": "Drives are in beta"
          },
          {
            "item": "Data transfer on Enterprise (iad1)",
            "unit": "gb",
            "usd": 0.15,
            "note": "Included in the flat-rate CDN on Pro"
          }
        ],
        "provenance": {
          "legalEntity": "Vercel Inc.",
          "domain": "vercel.com",
          "domainRegistered": "1999-10-04",
          "domainNote": "vercel.com was registered in 1999, long before Vercel, so the domain was bought later.",
          "endpointOnVendorDomain": true,
          "terms": "https://vercel.com/legal/terms",
          "privacy": "https://vercel.com/legal/privacy-policy",
          "statusPage": "https://www.vercel-status.com",
          "changelog": "https://vercel.com/changelog",
          "securityTxt": "valid",
          "checked": "2026-09-30",
          "notes": [
            "Terms (updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, California.",
            "security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28.",
            "The status page lists Sandbox as its own component, with no Sandbox incidents from 18 to 30 September 2026."
          ],
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.json",
        "live": {
          "slug": "vercel-sandbox",
          "probe": {
            "target": "https://api.vercel.com/v1/sandboxes",
            "method": "get",
            "lastAt": "2026-10-04T22:35:33.245701067Z",
            "lastOk": true,
            "lastStatus": 403,
            "lastMs": 524,
            "lastNote": "asks for credentials",
            "authRequired": true,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 527,
            "p95ms24h": 650,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://www.vercel-status.com",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:34:11.18753385Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "vercel/sandbox",
              "version": "@vercel/sandbox-mock@3.5.1",
              "released": "2026-09-28",
              "seenAt": "2026-10-04T16:43:20.902296091Z"
            },
            {
              "registry": "npm",
              "name": "@vercel/sandbox",
              "version": "3.5.1",
              "seenAt": "2026-10-04T16:43:18.687547241Z"
            },
            {
              "registry": "npm",
              "name": "sandbox",
              "version": "4.6.0",
              "seenAt": "2026-10-04T16:43:19.372037752Z"
            },
            {
              "registry": "pypi",
              "name": "vercel",
              "version": "0.11.4",
              "released": "2026-09-23",
              "seenAt": "2026-10-04T16:43:19.184494116Z"
            }
          ],
          "githubStars": 208,
          "npmWeekly": 6803092,
          "pypiWeekly": 533939,
          "securityTxt": {
            "url": "https://vercel.com/.well-known/security.txt",
            "state": "valid",
            "expires": "2027-09-28T12:00:00.000Z",
            "checkedAt": "2026-10-04T15:15:36.802255035Z"
          },
          "llmsTxt": {
            "url": "https://vercel.com/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:20.527836235Z"
          },
          "domain": {
            "domain": "vercel.com",
            "registered": "1999-10-04",
            "source": "https://rdap.verisign.com/com/v1/domain/vercel.com",
            "checkedAt": "2026-10-04T13:04:52.527918567Z"
          },
          "pages": [
            {
              "url": "https://vercel.com/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:48:45.85143464Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5f838658b352"
            },
            {
              "url": "https://vercel.com/docs/sandbox/pricing",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:48:47.949372715Z",
              "changedAt": "2026-10-04T15:48:47.949372715Z",
              "fingerprint": "f3917ada6bab"
            },
            {
              "url": "https://vercel.com/legal/privacy-policy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:48:50.700832237Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "4d5cec199c56"
            },
            {
              "url": "https://vercel.com/legal/terms",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:48:52.005054023Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "e51c90f98cbc"
            }
          ],
          "updatedAt": "2026-10-04T22:35:33.245701067Z"
        }
      },
      {
        "slug": "e2b",
        "name": "E2B",
        "vendor": "E2B",
        "vendorUrl": "https://e2b.dev",
        "kind": "http-api",
        "category": "code-sandboxes",
        "summary": "Firecracker microVM sandboxes for agent code, driven from Python and JavaScript SDKs, a CLI or a REST API.",
        "url": "https://www.anchorterminal.com/tools/e2b",
        "markdownUrl": "https://www.anchorterminal.com/tools/e2b.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/e2b.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/e2b.json",
        "repo": "https://github.com/e2b-dev/E2B",
        "license": "Apache-2.0",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.e2b.app",
        "packages": [
          {
            "registry": "npm",
            "name": "e2b"
          },
          {
            "registry": "pypi",
            "name": "e2b"
          },
          {
            "registry": "npm",
            "name": "@e2b/code-interpreter"
          },
          {
            "registry": "pypi",
            "name": "e2b-code-interpreter"
          }
        ],
        "auth": "api-key",
        "authNotes": "API key in the `X-API-Key` header on api.e2b.app. The SDKs and CLI read `E2B_API_KEY`. SDKs from 2.46.0 leave key validation to the server. `E2B_ACCESS_TOKEN` was switched off on 1 August 2026. Code inside a sandbox can get short-lived workload identity tokens instead of long-lived secrets, and stored secrets can be filled into outbound HTTPS headers by the egress proxy without entering the sandbox.",
        "pricing": "freemium",
        "pricingNotes": "Hobby is free with a one-time $100 usage credit and no card, sandboxes up to 1 hour and 20 running at once. Pro is $150 a month plus usage, sandboxes up to 24 hours and 100 concurrent (up to 1,100 with add-ons). Enterprise starts at $3,000 a month and adds BYOC. Compute is billed per second while a sandbox runs, $0.000014 a vCPU-second and $0.0000045 a GiB-second of RAM, so the default 2 vCPU, 4 GiB sandbox costs $0.1656 an hour. 10 GiB of storage free on Hobby, 20 GiB on Pro (https://e2b.dev/pricing). Paused sandboxes aren't billed, and when the credit runs out the account is blocked until a card is added (https://docs.e2b.dev/billing.md).",
        "priceSummary": "$0.0504 / vCPU-hr",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 13400,
          "npmWeekly": 2217920,
          "pypiWeekly": 1408079,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.e2b.dev",
        "llmsTxt": "https://docs.e2b.dev/llms.txt",
        "openapi": "https://docs.e2b.dev/openapi-public.yaml",
        "capabilities": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist",
          "sandbox.browser"
        ],
        "tags": [
          "hosted",
          "freemium",
          "free-tier",
          "no-card",
          "open-source",
          "self-hosted",
          "llms-txt",
          "python",
          "typescript",
          "enterprise"
        ],
        "lastRelease": "2026-10-01",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 68.5,
          "grade": "B",
          "agentReady": false,
          "rank": 122,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 3,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 65,
            "maintenance": 88,
            "payments": 50,
            "reliability": 60,
            "schema": 92,
            "security": 62,
            "transparency": 71
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Firecracker microVM with its own kernel per sandbox. Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots.",
          "strengths": [
            "Firecracker microVM with its own kernel per sandbox",
            "Egress allow and deny lists by domain, IP or CIDR, and secrets filled in outside the sandbox",
            "Apache-2.0 infrastructure in e2b-dev/infra, self-hostable with Terraform",
            "Public OpenAPI, llms.txt and a weekly dated changelog",
            "Per-second billing at published rates and a $100 credit without a card"
          ],
          "weaknesses": [
            "Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots",
            "One unscoped API key per project, with no audit log found",
            "Hobby sandboxes stop after 1 hour of continuous running",
            "Pro costs $150 a month before any compute",
            "No security.txt or bug bounty, and no published subprocessor list"
          ],
          "agentNotes": [
            "Set a timeout when you create a sandbox. The default is 5 minutes",
            "Pause rather than kill when you'll come back. Resume takes about a second and nothing is billed while paused",
            "Use `Secret.fill` in network transforms instead of passing API keys into the sandbox environment",
            "Pace sandbox creation. Hobby allows 1 a second and 20 running at once",
            "Move to the v2 sandbox endpoints. SDK 2.51.0 and later use them by default"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 68.5
            }
          ],
          "editorialScores": {
            "ergonomics": 65,
            "maintenance": 88,
            "payments": 50,
            "reliability": 60,
            "schema": 92,
            "security": 62,
            "transparency": 75
          },
          "provenanceScore": 67
        },
        "connect": {
          "install": "pip install e2b-code-interpreter  # or npm i @e2b/code-interpreter",
          "http": "curl https://api.e2b.app/v2/sandboxes -H \"X-API-Key: $E2B_API_KEY\""
        },
        "letme": {
          "capability": "https://letme.dev/sandbox.code",
          "tool": "https://letme.dev/e2b"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "vCPU",
            "unit": "vcpu-hour",
            "usd": 0.0504,
            "note": "$0.000014 a vCPU-second, RAM extra at $0.0000045 a GiB-second"
          },
          {
            "item": "Default sandbox (2 vCPU, 4 GiB)",
            "unit": "session-hour",
            "usd": 0.1656,
            "note": "Billed per second while running"
          },
          {
            "item": "Pro plan",
            "unit": "month",
            "usd": 150,
            "note": "Usage billed on top"
          },
          {
            "item": "Enterprise minimum",
            "unit": "month",
            "usd": 3000
          }
        ],
        "provenance": {
          "legalEntity": "FoundryLabs, Inc.",
          "domain": "e2b.dev",
          "domainRegistered": "2023-04-03",
          "endpointOnVendorDomain": false,
          "terms": "https://e2b.dev/terms",
          "privacy": "https://e2b.dev/privacy",
          "statusPage": "https://status.e2b.dev",
          "changelog": "https://docs.e2b.dev/changelog",
          "securityTxt": "none",
          "checked": "2026-09-30",
          "notes": [
            "Terms (updated 4 December 2024) and privacy policy (8 April 2024) name FoundryLabs, Inc., a Delaware corporation, with arbitration in San Francisco.",
            "The API runs on api.e2b.app, a separate registrable domain from e2b.dev.",
            "e2b.dev/.well-known/security.txt returns 404."
          ],
          "score": 67
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/e2b.json",
        "live": {
          "slug": "e2b",
          "probe": {
            "target": "https://api.e2b.app",
            "method": "get",
            "lastAt": "2026-10-04T22:35:22.628195299Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 195,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 205,
            "p95ms24h": 673,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.e2b.dev",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:33:51.710666933Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "e2b-dev/E2B",
              "version": "e2b@2.52.0",
              "released": "2026-10-01",
              "seenAt": "2026-10-04T16:26:00.111403217Z"
            },
            {
              "registry": "npm",
              "name": "@e2b/code-interpreter",
              "version": "2.8.0",
              "seenAt": "2026-10-04T16:25:58.219240858Z"
            },
            {
              "registry": "npm",
              "name": "e2b",
              "version": "2.52.0",
              "seenAt": "2026-10-04T16:25:57.300487346Z"
            },
            {
              "registry": "pypi",
              "name": "e2b",
              "version": "2.52.0",
              "released": "2026-10-01",
              "seenAt": "2026-10-04T16:25:58.102980494Z"
            },
            {
              "registry": "pypi",
              "name": "e2b-code-interpreter",
              "version": "2.10.1",
              "released": "2026-10-01",
              "seenAt": "2026-10-04T16:25:59.558821824Z"
            }
          ],
          "githubStars": 14158,
          "npmWeekly": 2206823,
          "pypiWeekly": 1455625,
          "securityTxt": {
            "url": "https://e2b.dev/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:56.659139974Z"
          },
          "llmsTxt": {
            "url": "https://docs.e2b.dev/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:31.181154301Z"
          },
          "domain": {
            "domain": "e2b.dev",
            "registered": "2023-04-03",
            "source": "https://pubapi.registry.google/rdap/domain/e2b.dev",
            "checkedAt": "2026-10-04T13:07:00.866894573Z"
          },
          "pages": [
            {
              "url": "https://docs.e2b.dev/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:43:36.049541817Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "6144e11d9a0f"
            },
            {
              "url": "https://e2b.dev/pricing",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:44:25.826627767Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "9315b9c222a9"
            },
            {
              "url": "https://e2b.dev/privacy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:44:28.012557957Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "7cea0e859599"
            },
            {
              "url": "https://e2b.dev/terms",
              "kind": "terms",
              "status": 200,
              "checkedAt": "2026-10-04T15:44:29.980992298Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "dc202679f513"
            }
          ],
          "updatedAt": "2026-10-04T22:35:22.628195299Z"
        }
      },
      {
        "slug": "cloudflare-sandbox-sdk",
        "name": "Cloudflare Sandbox SDK",
        "vendor": "Cloudflare",
        "vendorUrl": "https://developers.cloudflare.com/sandbox/",
        "kind": "sdk",
        "category": "code-sandboxes",
        "summary": "TypeScript library for running sandboxed Linux containers from a Cloudflare Worker.",
        "url": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk",
        "markdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json",
        "repo": "https://github.com/cloudflare/sandbox-sdk",
        "license": "Apache-2.0",
        "transports": [],
        "packages": [
          {
            "registry": "npm",
            "name": "@cloudflare/sandbox"
          }
        ],
        "auth": "none",
        "authNotes": "There's no hosted API. The sandbox sits behind a Worker you deploy, so it has whatever auth you put in front of it, and the starter template has none. Deploying needs a Cloudflare account through Wrangler. Version 1.0 adds preview ports with custom hostnames and authentication.",
        "pricing": "paid",
        "pricingNotes": "Needs the Workers Paid plan, $5 a month minimum (https://developers.cloudflare.com/workers/platform/pricing/). Billed as Containers plus Workers and Durable Objects. Containers include 25 GiB-hours of memory, 375 vCPU-minutes and 200 GB-hours of disk a month, then $0.0000025 a GiB-second of memory, $0.000020 a vCPU-second of CPU used and $0.00000007 a GB-second of disk, in 10 ms steps while the container runs. Egress is $0.025 a GB in North America and Europe after 1 TB (https://developers.cloudflare.com/containers/pricing/). Durable Objects add $0.15 per million requests and $12.50 per million GB-seconds after the included amounts (https://developers.cloudflare.com/workers/platform/pricing/).",
        "priceSummary": "$0.072 / vCPU-hr",
        "where": "local",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 1100,
          "npmWeekly": 722733,
          "pypiWeekly": null,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://developers.cloudflare.com/sandbox/",
        "llmsTxt": "https://developers.cloudflare.com/sandbox/llms.txt",
        "capabilities": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "tags": [
          "hosted",
          "typescript",
          "open-source",
          "llms-txt"
        ],
        "lastRelease": "2026-09-30",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 67.8,
          "grade": "B",
          "agentReady": false,
          "rank": 137,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 4,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 63,
            "maintenance": 70,
            "payments": 30,
            "reliability": 87,
            "schema": 77,
            "security": 65,
            "transparency": 73
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
          "strengths": [
            "Each sandbox runs in its own VM with a separate filesystem, process space and network stack",
            "Outbound handlers hold credentials in the Worker and inject them, so the container never sees them",
            "Egress can be turned off or limited to a deny-by-default `allowedHosts` list",
            "CPU billed on use at $0.000020 a vCPU-second, with a monthly allowance on Workers Paid",
            "Apache-2.0, with CodeQL and passing CI on main"
          ],
          "weaknesses": [
            "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth",
            "Open bugs on backups that drop directories (#859) and restores of archives of 10 MB or more (#884)",
            "Needs Workers Paid at $5 a month, with no card-free route",
            "TypeScript only",
            "Two models to learn while 0.x and 1.0 overlap until 31 December 2026"
          ],
          "agentNotes": [
            "Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets",
            "Put API keys in an outbound handler in the Worker, not in the container's environment",
            "Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default",
            "Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs",
            "Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 67.8
            }
          ],
          "editorialScores": {
            "ergonomics": 63,
            "maintenance": 70,
            "payments": 30,
            "reliability": 87,
            "schema": 77,
            "security": 65,
            "transparency": 45
          },
          "provenanceScore": 100
        },
        "connect": {
          "install": "npm create cloudflare@latest -- my-sandbox --template=cloudflare/sandbox-sdk/examples/minimal"
        },
        "letme": {
          "capability": "https://letme.dev/sandbox.code",
          "tool": "https://letme.dev/cloudflare-sandbox-sdk"
        },
        "sameCompany": [
          "cloudflare-mcp",
          "cloudflare-r2",
          "cloudflare-clef"
        ],
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Container CPU",
            "unit": "vcpu-hour",
            "usd": 0.072,
            "note": "$0.000020 a vCPU-second of CPU used, after 375 vCPU-minutes a month"
          },
          {
            "item": "Workers Paid plan",
            "unit": "month",
            "usd": 5,
            "note": "Minimum charge"
          },
          {
            "item": "Egress, North America and Europe",
            "unit": "gb",
            "usd": 0.025,
            "note": "After 1 TB a month"
          }
        ],
        "provenance": {
          "legalEntity": "Cloudflare, Inc.",
          "domain": "cloudflare.com",
          "domainRegistered": "2009-02-17",
          "endpointOnVendorDomain": null,
          "terms": "https://www.cloudflare.com/terms/",
          "privacy": "https://www.cloudflare.com/privacypolicy/",
          "statusPage": "https://www.cloudflarestatus.com",
          "changelog": "https://developers.cloudflare.com/changelog/?product=sandbox",
          "securityTxt": "valid",
          "checked": "2026-10-01",
          "notes": [
            "The self-serve subscription agreement (updated 12 September 2025) names Cloudflare, Inc., 101 Townsend St., San Francisco.",
            "There's no vendor endpoint to check. Sandboxes are reached through a Worker on your own route or workers.dev subdomain.",
            "security.txt lists HackerOne and a disclosure policy, but we didn't see an Expires field.",
            "The GitHub README still says the SDK is in active development and APIs may change before v1.0, while npm has 1.0.0 (published 2026-09-30) and the changelog announces 1.0. The GitHub releases page showed 0.12.4 (21 July 2026) as its newest release when checked."
          ],
          "score": 100
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
        "live": {
          "slug": "cloudflare-sandbox-sdk",
          "vendorStatus": {
            "page": "https://www.cloudflarestatus.com",
            "indicator": "minor",
            "summary": "Minor Service Outage",
            "checkedAt": "2026-10-04T22:33:49.160418196Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "cloudflare/sandbox-sdk",
              "version": "@cloudflare/sandbox@0.12.10",
              "released": "2026-09-23",
              "seenAt": "2026-10-04T16:24:02.293431378Z"
            },
            {
              "registry": "npm",
              "name": "@cloudflare/sandbox",
              "version": "1.0.0",
              "seenAt": "2026-10-04T16:24:01.356030499Z"
            }
          ],
          "githubStars": 1144,
          "npmWeekly": 797840,
          "securityTxt": {
            "url": "https://cloudflare.com/.well-known/security.txt",
            "state": "valid",
            "checkedAt": "2026-10-04T15:15:51.95928161Z"
          },
          "llmsTxt": {
            "url": "https://developers.cloudflare.com/sandbox/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:31.097149892Z"
          },
          "domain": {
            "domain": "cloudflare.com",
            "registered": "2009-02-17",
            "source": "https://rdap.verisign.com/com/v1/domain/cloudflare.com",
            "checkedAt": "2026-10-04T13:06:22.743038628Z"
          },
          "pages": [
            {
              "url": "https://developers.cloudflare.com/changelog/?product=sandbox",
              "kind": "deprecations",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:50.869019575Z",
              "changedAt": "2026-10-04T15:42:50.869019575Z",
              "fingerprint": "aa7b5fb58872"
            },
            {
              "url": "https://developers.cloudflare.com/containers/pricing/",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:42:52.872169011Z",
              "changedAt": "2026-10-03T15:31:01.576635047Z",
              "fingerprint": "a81e9d7bb64a"
            },
            {
              "url": "https://developers.cloudflare.com/workers/platform/pricing/",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:43:00.847585458Z",
              "changedAt": "2026-10-04T15:43:00.847585458Z",
              "fingerprint": "ea6eab1a375f"
            }
          ],
          "updatedAt": "2026-10-04T22:33:49.160418196Z"
        }
      },
      {
        "slug": "runloop",
        "name": "Runloop Devboxes",
        "vendor": "Runloop",
        "vendorUrl": "https://runloop.ai",
        "kind": "http-api",
        "category": "code-sandboxes",
        "summary": "Devboxes, VM sandboxes for coding agents, with blueprints for prebuilt images, disk snapshots, suspend and resume, idle policies and a gateway that adds secret-backed headers to outbound API and MCP calls.",
        "url": "https://www.anchorterminal.com/tools/runloop",
        "markdownUrl": "https://www.anchorterminal.com/tools/runloop.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/runloop.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/runloop.json",
        "repo": "https://github.com/runloopai/api-client-ts",
        "license": "MIT",
        "transports": [
          "http"
        ],
        "remoteUrl": "https://api.runloop.ai",
        "packages": [
          {
            "registry": "pypi",
            "name": "runloop_api_client"
          },
          {
            "registry": "npm",
            "name": "@runloop/api-client"
          }
        ],
        "auth": "api-key",
        "authNotes": "Bearer API key on api.runloop.ai. The SDKs read `RUNLOOP_API_KEY`.",
        "pricing": "usage",
        "pricingNotes": "Billed per second while a devbox is initialising, running, suspending or resuming. $0.108 a CPU-hour ($0.00003 a second), $0.0252 a GB-hour of memory, $0.00034236 a GB-hour of disk and $0.000072 a GB-hour of snapshot storage. Basic is free with 100 GB of storage and usage billing, Pro is $250 a month with 1 TB of storage, suspend and resume and repo connections, Enterprise adds VPC deployment. New accounts get a $50 credit without a card, limited to 3 running devboxes, 5 blueprints and 10 snapshots during the trial (https://runloop.ai/pricing). Suspended devboxes keep paying for storage (https://docs.runloop.ai/docs/devboxes/lifecycle).",
        "priceSummary": "$0.108 / vCPU-hr",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 34,
          "npmWeekly": 23267,
          "pypiWeekly": 136023,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.runloop.ai",
        "llmsTxt": "https://docs.runloop.ai/llms.txt",
        "openapi": "https://docs.runloop.ai/openapi-specs/stainless-processed-openapi.json",
        "capabilities": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "tags": [
          "hosted",
          "openapi",
          "llms-txt",
          "python",
          "typescript",
          "no-card",
          "enterprise"
        ],
        "lastRelease": "2026-09-08",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 65,
          "grade": "B",
          "agentReady": false,
          "rank": 177,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 5,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 66,
            "maintenance": 83,
            "payments": 50,
            "reliability": 60,
            "schema": 85,
            "security": 60,
            "transparency": 51
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison.",
          "strengths": [
            "Agent gateways keep real credentials on Runloop's servers, with gateway tokens bound to one devbox",
            "Network policies that block egress or allow listed hostnames",
            "Public OpenAPI, llms.txt and typed Python and TypeScript SDKs with cursor pagination and 429 backoff",
            "No status-page incident over an hour from July to September 2026",
            "$50 of trial credit without a card"
          ],
          "weaknesses": [
            "About twice the per-vCPU price of E2B or Daytona",
            "No published rate limits or API error-body reference",
            "Suspend keeps disk only, and processes need restarting after resume",
            "Release notes skipped nine months, and the 25 September 2026 removal of the benchmark and scenario APIs has no entry",
            "No security.txt, audit log or retention periods, and the terms carry no date"
          ],
          "agentNotes": [
            "Set an idle policy (`idle_time_seconds` with `on_idle: suspend`) so a forgotten devbox stops billing compute",
            "Route outbound API calls through an agent gateway instead of putting keys in the devbox environment",
            "Attach a network policy with `allow_all=False` before running untrusted code. Egress is open by default",
            "Restart background services after every resume. Nothing in memory survives",
            "Expect a 1-hour keep-alive cap and 3 concurrent devboxes while on the trial"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 65
            }
          ],
          "editorialScores": {
            "ergonomics": 66,
            "maintenance": 83,
            "payments": 50,
            "reliability": 60,
            "schema": 85,
            "security": 60,
            "transparency": 27
          },
          "provenanceScore": 75
        },
        "connect": {
          "install": "pip install runloop_api_client  # or npm i @runloop/api-client",
          "http": "curl -X POST https://api.runloop.ai/v1/devboxes -H \"Authorization: Bearer $RUNLOOP_API_KEY\" \\\n  -H \"Content-Type: application/json\" -d '{}'"
        },
        "letme": {
          "capability": "https://letme.dev/sandbox.code",
          "tool": "https://letme.dev/runloop"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "CPU",
            "unit": "vcpu-hour",
            "usd": 0.108,
            "note": "Memory extra at $0.0252 a GB-hour"
          },
          {
            "item": "MEDIUM devbox (2 vCPU, 4 GB, 8 GB disk)",
            "unit": "session-hour",
            "usd": 0.3195
          },
          {
            "item": "Pro plan",
            "unit": "month",
            "usd": 250,
            "note": "Usage billed on top, 1 TB storage included"
          }
        ],
        "provenance": {
          "legalEntity": "Runloop AI, Inc.",
          "domain": "runloop.ai",
          "domainRegistered": "",
          "endpointOnVendorDomain": true,
          "terms": "https://runloop.ai/legal/terms-of-service",
          "privacy": "https://runloop.ai/legal/privacy-policy",
          "statusPage": "https://status.runloop.ai",
          "changelog": "https://docs.runloop.ai/docs/overview/release-notes",
          "securityTxt": "none",
          "checked": "2026-09-30",
          "notes": [
            "Terms name Runloop AI, Inc. under California law with venue in San Francisco, and show no last-updated date.",
            "runloop.ai/.well-known/security.txt returns 404.",
            "The .ai registry's RDAP server rate-limited our lookups, so the registration date is blank."
          ],
          "score": 75
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/runloop.json",
        "live": {
          "slug": "runloop",
          "probe": {
            "target": "https://api.runloop.ai",
            "method": "get",
            "lastAt": "2026-10-04T22:35:30.428883843Z",
            "lastOk": true,
            "lastStatus": 404,
            "lastMs": 297,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 295,
            "p95ms24h": 348,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.runloop.ai",
            "indicator": "major",
            "summary": "Partial System Outage",
            "checkedAt": "2026-10-04T22:34:07.713290058Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "runloopai/api-client-ts",
              "version": "v1.32.0",
              "released": "2026-09-08",
              "seenAt": "2026-10-04T16:38:40.627080941Z"
            },
            {
              "registry": "npm",
              "name": "@runloop/api-client",
              "version": "1.32.0",
              "seenAt": "2026-10-04T16:38:39.715466302Z"
            },
            {
              "registry": "pypi",
              "name": "runloop_api_client",
              "version": "1.32.0",
              "released": "2026-09-08",
              "seenAt": "2026-10-04T16:38:39.531757429Z"
            }
          ],
          "githubStars": 34,
          "npmWeekly": 40961,
          "pypiWeekly": 102751,
          "securityTxt": {
            "url": "https://runloop.ai/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:49.734821106Z"
          },
          "llmsTxt": {
            "url": "https://docs.runloop.ai/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:18:14.400215978Z"
          },
          "domain": {
            "domain": "runloop.ai",
            "registered": "2023-11-16",
            "source": "https://rdap.identitydigital.services/rdap/domain/runloop.ai",
            "checkedAt": "2026-10-04T13:06:05.128518554Z"
          },
          "pages": [
            {
              "url": "https://docs.runloop.ai/docs/overview/release-notes",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:43:58.579783969Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0c29a3c7a014"
            },
            {
              "url": "https://runloop.ai/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:47:24.608769194Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0d9550987c81"
            },
            {
              "url": "https://runloop.ai/legal/privacy-policy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:47:20.583804446Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "d513c58cc41e"
            },
            {
              "url": "https://runloop.ai/legal/terms-of-service",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:47:22.624897549Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "a2e40c03fa5b"
            }
          ],
          "updatedAt": "2026-10-04T22:35:30.428883843Z"
        }
      },
      {
        "slug": "daytona",
        "name": "Daytona",
        "vendor": "Daytona",
        "vendorUrl": "https://www.daytona.io",
        "kind": "http-api",
        "category": "code-sandboxes",
        "summary": "Sandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API.",
        "url": "https://www.anchorterminal.com/tools/daytona",
        "markdownUrl": "https://www.anchorterminal.com/tools/daytona.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/daytona.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/daytona.json",
        "repo": "https://github.com/daytona/clients",
        "license": "Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI)",
        "transports": [
          "http",
          "stdio"
        ],
        "remoteUrl": "https://app.daytona.io/api",
        "packages": [
          {
            "registry": "pypi",
            "name": "daytona"
          },
          {
            "registry": "npm",
            "name": "@daytona/sdk"
          }
        ],
        "auth": "api-key",
        "authNotes": "Bearer API key in the `Authorization` header. The SDKs read `DAYTONA_API_KEY`, `DAYTONA_API_URL` (default https://app.daytona.io/api) and `DAYTONA_TARGET` (us or eu). Keys take scopes, so an agent's key can have `write:sandboxes` without `delete:sandboxes`. The MCP server uses the CLI session from `daytona login`.",
        "pricing": "usage",
        "pricingNotes": "Billed per second. $0.0504 a vCPU-hour, $0.0162 a GiB-hour of memory and $0.000108 a GiB-hour of storage after the first 5 GiB, Windows $0.0858 a vCPU-hour. GPUs from $0.57 an hour (RTX 4090, preemptible) to $6.25 (B300 or B200, on demand), with H100 at $2.27 preemptible or $3.95 on demand. $200 of free compute without a card, and up to $50,000 in startup credits (https://www.daytona.io/pricing). Higher limits unlock with a linked card and a $25 top-up (Tier 2), a $500 top-up (Tier 3) or $2,000 every 30 days (Tier 4) (https://www.daytona.io/docs/en/limits.md).",
        "priceSummary": "$0.0504 / vCPU-hr",
        "where": "both",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 6,
          "npmWeekly": 705790,
          "pypiWeekly": 1406178,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://www.daytona.io/docs",
        "llmsTxt": "https://www.daytona.io/docs/llms.txt",
        "openapi": "https://www.daytona.io/docs/openapi.json",
        "capabilities": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist",
          "sandbox.browser",
          "sandbox.gpu"
        ],
        "tags": [
          "hosted",
          "no-card",
          "mcp",
          "openapi",
          "llms-txt",
          "python",
          "typescript",
          "go",
          "eu",
          "enterprise"
        ],
        "lastRelease": "2026-09-29",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 64.4,
          "grade": "B",
          "agentReady": false,
          "rank": 183,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 6,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 55,
            "maintenance": 80,
            "payments": 50,
            "reliability": 60,
            "schema": 87,
            "security": 63,
            "transparency": 58
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.",
          "strengths": [
            "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them",
            "Container, Linux VM, Windows and GPU sandbox classes behind one API",
            "Three public OpenAPI files, llms.txt and SDKs in five languages",
            "Rate limits published per tier, with Retry-After and rate-limit headers on 429s",
            "$200 of compute without a card, billed per second"
          ],
          "weaknesses": [
            "The container class shares the host kernel. Only the VM classes get their own",
            "Full internet access and per-sandbox allow lists need Tier 3",
            "Platform code went private in June 2026, and the old repository's 311 open issues won't be answered",
            "Two Windows runner outages over an hour in July and August 2026",
            "No security.txt, SOC 2 report or bug bounty found"
          ],
          "agentNotes": [
            "Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead",
            "Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking",
            "Give the agent a key without `delete:sandboxes` if it shouldn't destroy work",
            "Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation",
            "Check the organisation's tier before relying on outbound calls from inside the sandbox"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 3,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "B",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 64.4
            }
          ],
          "editorialScores": {
            "ergonomics": 55,
            "maintenance": 80,
            "payments": 50,
            "reliability": 60,
            "schema": 87,
            "security": 63,
            "transparency": 40
          },
          "provenanceScore": 75
        },
        "connect": {
          "install": "pip install daytona  # or npm i @daytona/sdk",
          "http": "curl -X POST https://app.daytona.io/api/sandbox -H \"Authorization: Bearer $DAYTONA_API_KEY\" \\\n  -H \"Content-Type: application/json\" -d '{}'",
          "claudeCode": "claude mcp add daytona -- daytona mcp start",
          "config": {
            "mcpServers": {
              "daytona": {
                "args": [
                  "mcp",
                  "start"
                ],
                "command": "daytona"
              }
            }
          }
        },
        "letme": {
          "capability": "https://letme.dev/sandbox.code",
          "tool": "https://letme.dev/daytona"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "vCPU",
            "unit": "vcpu-hour",
            "usd": 0.0504,
            "note": "Memory extra at $0.0162 a GiB-hour"
          },
          {
            "item": "Nvidia H100, on demand",
            "unit": "gpu-hour",
            "usd": 3.95
          },
          {
            "item": "Nvidia H100, preemptible",
            "unit": "gpu-hour",
            "usd": 2.27
          },
          {
            "item": "Nvidia RTX 4090, preemptible",
            "unit": "gpu-hour",
            "usd": 0.57
          }
        ],
        "provenance": {
          "legalEntity": "Daytona Platforms Inc.",
          "domain": "daytona.io",
          "domainRegistered": "",
          "endpointOnVendorDomain": true,
          "terms": "https://www.daytona.io/terms-of-service",
          "privacy": "https://www.daytona.io/privacy-policy",
          "statusPage": "https://status.app.daytona.io",
          "changelog": "https://www.daytona.io/changelog",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "notes": [
            "Terms and privacy policy (both updated 22 August 2025) name Daytona Platforms Inc., 224 W 35th St, New York, under Delaware law.",
            "The status page lists Windows runner outages on 31 July (3 hours 50 minutes) and 1 August 2026 (1 hour 40 minutes), a 17.5-hour regional degradation on 11 August, short incidents in July and September, and a 2-hour degradation of sandbox listing on 1 October 2026.",
            "www.daytona.io/.well-known/security.txt returns 404. daytona/clients has a SECURITY.md.",
            "The .io registry's RDAP server rate-limited our lookups, so the registration date is blank."
          ],
          "score": 75
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/daytona.json",
        "live": {
          "slug": "daytona",
          "probe": {
            "target": "https://app.daytona.io/api",
            "method": "get",
            "lastAt": "2026-10-04T22:35:21.876529555Z",
            "lastOk": true,
            "lastStatus": 200,
            "lastMs": 99,
            "authRequired": false,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 104,
            "p95ms24h": 161,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.app.daytona.io",
            "indicator": "unknown",
            "summary": "no machine-readable status found",
            "checkedAt": "2026-10-04T21:39:56.041466604Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "daytona/clients",
              "version": "v0.220.0",
              "released": "2026-09-29",
              "seenAt": "2026-10-04T16:25:08.289274609Z"
            },
            {
              "registry": "npm",
              "name": "@daytona/sdk",
              "version": "0.220.0",
              "seenAt": "2026-10-04T16:25:07.364662963Z"
            },
            {
              "registry": "pypi",
              "name": "daytona",
              "version": "0.220.0",
              "released": "2026-09-29",
              "seenAt": "2026-10-04T16:25:07.171178997Z"
            }
          ],
          "githubStars": 12,
          "npmWeekly": 742531,
          "pypiWeekly": 1367845,
          "securityTxt": {
            "url": "https://daytona.io/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:38.986416206Z"
          },
          "llmsTxt": {
            "url": "https://www.daytona.io/docs/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:30.007359335Z"
          },
          "domain": {
            "domain": "daytona.io",
            "checkedAt": "2026-10-04T13:04:31.91436109Z"
          },
          "pages": [
            {
              "url": "https://www.daytona.io/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:49:58.72051538Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "b3e70c220b5c"
            },
            {
              "url": "https://www.daytona.io/pricing",
              "kind": "pricing",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:02.007859806Z",
              "changedAt": "2026-10-03T15:37:58.260333039Z",
              "fingerprint": "8c2c3fd83e7e"
            },
            {
              "url": "https://www.daytona.io/privacy-policy",
              "kind": "privacy",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:03.162657346Z",
              "changedAt": "2026-10-03T15:37:59.162897733Z",
              "fingerprint": "c712b184a1f3"
            },
            {
              "url": "https://www.daytona.io/terms-of-service",
              "kind": "terms",
              "status": 304,
              "checkedAt": "2026-10-04T15:50:05.046601049Z",
              "changedAt": "2026-10-03T15:38:01.284671381Z",
              "fingerprint": "c42adfc2b432"
            }
          ],
          "updatedAt": "2026-10-04T22:35:21.876529555Z"
        }
      },
      {
        "slug": "blaxel-sandboxes",
        "name": "Blaxel Sandboxes",
        "vendor": "Blaxel",
        "vendorUrl": "https://blaxel.ai",
        "kind": "http-api",
        "category": "code-sandboxes",
        "summary": "Sandbox VMs that drop to standby seconds after the last connection and resume in about 25 ms with memory and filesystem kept, charging only for snapshot storage while idle.",
        "url": "https://www.anchorterminal.com/tools/blaxel-sandboxes",
        "markdownUrl": "https://www.anchorterminal.com/tools/blaxel-sandboxes.md",
        "slimMarkdownUrl": "https://www.anchorterminal.com/tools/blaxel-sandboxes.min.md",
        "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/blaxel-sandboxes.json",
        "repo": "https://github.com/blaxel-ai/sdk-python",
        "license": "MIT",
        "transports": [
          "http",
          "streamable-http"
        ],
        "remoteUrl": "https://api.blaxel.ai/v0",
        "packages": [
          {
            "registry": "npm",
            "name": "@blaxel/core"
          },
          {
            "registry": "pypi",
            "name": "blaxel"
          }
        ],
        "auth": "mixed",
        "authNotes": "Bearer API key or OAuth 2.0 token on api.blaxel.ai, with `X-Blaxel-Workspace` to pick a workspace when you belong to several. API keys can be set never to expire. OAuth client-credentials tokens last 2 hours. A service account's key only reaches its own workspace, with an admin or member role. The SDKs read `BL_API_KEY` and `BL_WORKSPACE`. The per-sandbox MCP server takes the same Bearer key.",
        "pricing": "usage",
        "pricingNotes": "Active sandboxes cost $0.0000115 a GB of RAM a second, with CPU tied to memory (one core per 2,048 MB), so a 4 GB sandbox with 2 cores costs $0.1656 an hour. Standby has no compute charge, only $0.20 a GB-month for memory and filesystem snapshots, and images cost $0.045 a GB-month. Up to $200 of free credits for new accounts. Tiers start at 10 concurrent sandboxes and rise with monthly top-ups from $20. Email support is $800 a month plus 3 per cent of usage, dedicated support $1,600 plus 10 per cent (https://blaxel.ai/pricing).",
        "priceSummary": "$0.1656 / session-hr",
        "where": "hosted",
        "x402": {
          "level": "no",
          "endpoints": []
        },
        "toolCount": null,
        "popularity": {
          "githubStars": 27,
          "npmWeekly": 353025,
          "pypiWeekly": 74970,
          "asOf": "2026-09-30"
        },
        "docsUrl": "https://docs.blaxel.ai",
        "llmsTxt": "https://docs.blaxel.ai/llms.txt",
        "capabilities": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "tags": [
          "hosted",
          "mcp",
          "llms-txt",
          "python",
          "typescript",
          "go"
        ],
        "lastRelease": "2026-09-30",
        "graded": true,
        "anchor": {
          "graded": true,
          "score": 61,
          "grade": "C",
          "agentReady": false,
          "rank": 234,
          "ranked": true,
          "rankOf": 452,
          "categoryRank": 7,
          "methodology": "0.3",
          "run": "2026-10-01",
          "scores": {
            "ergonomics": 70,
            "maintenance": 85,
            "payments": 40,
            "reliability": 35,
            "schema": 80,
            "security": 64,
            "transparency": 68
          },
          "pending": [
            "performance",
            "tasks"
          ],
          "assessment": {
            "confidence": "medium",
            "date": "2026-10-01"
          },
          "negative": 0,
          "verdict": "No compute charge in standby, only $0.20 a GB-month of snapshot storage. 25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour.",
          "strengths": [
            "No compute charge in standby, only $0.20 a GB-month of snapshot storage",
            "MicroVM per sandbox with domain allow and deny lists that can be enforced at network level",
            "An MCP server in every sandbox over streamable HTTP, 18 tools",
            "Public OpenAPI for the sandbox API, llms.txt and an error-code reference with retryable flags",
            "Up to $200 of free credits, and account creation through Stripe Projects"
          ],
          "weaknesses": [
            "25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour",
            "No published request-rate limits, 429 guidance or SLA",
            "Domain filtering and secret injection are marked public preview, and egress is open by default",
            "No security.txt, and the privacy policy lives on a portal that blocks automated readers",
            "Billed by memory, and about half of it goes to the writable tmpfs layer"
          ],
          "agentNotes": [
            "Close WebSocket and terminal connections when done. An open connection keeps the sandbox active and billed",
            "Set a TTL or idle expiry on throwaway sandboxes. The default is to keep them",
            "Set `forbiddenDomains` or an allow list at creation, with `network.firewall` for tools that ignore proxy settings. Both can only be set when the sandbox is created",
            "Retry only on WORKLOAD_UNAVAILABLE. The error reference says other codes won't succeed on retry",
            "Connect to `\u003csandbox URL\u003e/mcp` with your API key instead of wrapping the REST API in tools yourself"
          ],
          "metrics": {
            "kind": "remote",
            "measured": false
          },
          "reviewCount": 2,
          "avgRating": 2,
          "history": [
            {
              "basis": "public evidence",
              "confidence": "medium",
              "grade": "C",
              "methodology": "0.3",
              "pending": [
                "performance",
                "tasks"
              ],
              "run": "2026-10-01",
              "runLabel": "October 2026 research run",
              "score": 61
            }
          ],
          "editorialScores": {
            "ergonomics": 70,
            "maintenance": 85,
            "payments": 40,
            "reliability": 35,
            "schema": 80,
            "security": 64,
            "transparency": 60
          },
          "provenanceScore": 75
        },
        "connect": {
          "install": "pip install blaxel  # or npm i @blaxel/core",
          "http": "curl -X POST https://api.blaxel.ai/v0/sandboxes -H \"Authorization: Bearer $BL_API_KEY\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{\"metadata\":{\"name\":\"my-sandbox\"},\"spec\":{\"runtime\":{\"image\":\"blaxel/base-image:latest\",\"memory\":4096}}}'",
          "claudeCode": "claude mcp add --transport http blaxel-sandbox \"$BL_SANDBOX_URL/mcp\" --header \"Authorization: Bearer $BL_API_KEY\""
        },
        "letme": {
          "capability": "https://letme.dev/sandbox.code",
          "tool": "https://letme.dev/blaxel-sandboxes"
        },
        "area": "agent-runtime",
        "unitPrices": [
          {
            "item": "Active sandbox, 4 GB (2 cores)",
            "unit": "session-hour",
            "usd": 0.1656,
            "note": "$0.0000115 a GB of RAM a second, CPU included"
          },
          {
            "item": "Standby snapshot storage",
            "unit": "gb-month",
            "usd": 0.2
          },
          {
            "item": "Image storage",
            "unit": "gb-month",
            "usd": 0.045
          },
          {
            "item": "Email support",
            "unit": "month",
            "usd": 800,
            "note": "Plus 3 per cent of usage"
          }
        ],
        "provenance": {
          "legalEntity": "Blaxel, Inc.",
          "domain": "blaxel.ai",
          "domainRegistered": "",
          "endpointOnVendorDomain": true,
          "terms": "https://blaxel.ai/legal/terms/2025-12-10-blaxel-terms-and-conditions.pdf",
          "privacy": "https://blaxel.ai/privacy",
          "statusPage": "https://status.blaxel.ai",
          "changelog": "https://docs.blaxel.ai/changelog",
          "securityTxt": "none",
          "checked": "2026-10-01",
          "notes": [
            "The standard terms (amended 10 December 2025) name Blaxel, Inc., formerly Beamlit, Inc., a Delaware corporation, under California law with venue in San Francisco.",
            "www.blaxel.ai/.well-known/security.txt returns 404.",
            "The status page runs on incident.io. Its incident feed lists 25 incidents from 9 July to 1 October 2026, including a critical workload outage in us-was-1 on 1 October, and shows 99.48 per cent uptime for Sandboxes over July to October.",
            "blaxel.ai/privacy links to a privacy policy on compliance.blaxel.ai, which disallows automated fetching.",
            "The .ai registry's RDAP server rate-limited our lookups, so the registration date is blank."
          ],
          "score": 75
        },
        "pageJsonUrl": "https://www.anchorterminal.com/tools/blaxel-sandboxes.json",
        "live": {
          "slug": "blaxel-sandboxes",
          "probe": {
            "target": "https://api.blaxel.ai/v0",
            "method": "get",
            "lastAt": "2026-10-04T22:35:19.965167477Z",
            "lastOk": true,
            "lastStatus": 401,
            "lastMs": 80,
            "lastNote": "asks for credentials",
            "authRequired": true,
            "uptime24h": 100,
            "uptime30d": 100,
            "p50ms24h": 70,
            "p95ms24h": 131,
            "samples24h": 272,
            "samples30d": 884,
            "days": [
              {
                "date": "2026-10-01",
                "probes": 109,
                "ok": 109
              },
              {
                "date": "2026-10-02",
                "probes": 248,
                "ok": 248
              },
              {
                "date": "2026-10-03",
                "probes": 271,
                "ok": 271
              },
              {
                "date": "2026-10-04",
                "probes": 256,
                "ok": 256
              }
            ]
          },
          "vendorStatus": {
            "page": "https://status.blaxel.ai",
            "indicator": "none",
            "summary": "All Systems Operational",
            "checkedAt": "2026-10-04T22:33:47.419851836Z"
          },
          "versions": [
            {
              "registry": "github",
              "name": "blaxel-ai/sdk-python",
              "version": "v0.4.1",
              "released": "2026-07-28",
              "seenAt": "2026-10-04T16:22:24.830998146Z"
            },
            {
              "registry": "npm",
              "name": "@blaxel/core",
              "version": "0.3.25",
              "seenAt": "2026-10-04T16:22:22.619449725Z"
            },
            {
              "registry": "pypi",
              "name": "blaxel",
              "version": "0.4.13",
              "released": "2026-09-30",
              "seenAt": "2026-10-04T16:22:24.645966759Z"
            }
          ],
          "githubStars": 25,
          "npmWeekly": 388609,
          "pypiWeekly": 67999,
          "securityTxt": {
            "url": "https://blaxel.ai/.well-known/security.txt",
            "state": "none",
            "checkedAt": "2026-10-04T15:15:49.82305612Z"
          },
          "llmsTxt": {
            "url": "https://docs.blaxel.ai/llms.txt",
            "ok": true,
            "status": 200,
            "checkedAt": "2026-10-04T15:17:21.007493957Z"
          },
          "domain": {
            "domain": "blaxel.ai",
            "registered": "2025-02-17",
            "source": "https://rdap.identitydigital.services/rdap/domain/blaxel.ai",
            "checkedAt": "2026-10-04T13:09:20.159771679Z"
          },
          "pages": [
            {
              "url": "https://docs.blaxel.ai/changelog",
              "kind": "changelog",
              "status": 200,
              "checkedAt": "2026-10-04T15:43:19.937510026Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "a17f1aa593ad"
            },
            {
              "url": "https://blaxel.ai/pricing",
              "kind": "pricing",
              "status": 200,
              "checkedAt": "2026-10-04T15:41:31.75141291Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "5758cb83f86d"
            },
            {
              "url": "https://blaxel.ai/privacy",
              "kind": "privacy",
              "status": 200,
              "checkedAt": "2026-10-04T15:41:33.831599103Z",
              "changedAt": "0001-01-01T00:00:00Z",
              "fingerprint": "0c43f1fab685"
            }
          ],
          "updatedAt": "2026-10-04T22:35:19.965167477Z"
        }
      }
    ]
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/categories/code-sandboxes",
    "json": "https://www.anchorterminal.com/categories/code-sandboxes.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/categories/code-sandboxes.md",
    "slim": "https://www.anchorterminal.com/categories/code-sandboxes.min.md"
  },
  "markdown": "Isolated machines an agent can start in seconds to run code, install packages and use a filesystem, then throw away. Compared on start time, isolation, how long a sandbox can live, what it costs per second and whether state can be paused and resumed.\n\n- Tools ranked: 7 · agent-ready (BB or better): 1 · accept x402: 0 · hosted endpoints: 5 · desk reviews by the panel: 20\n- JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability)\n- Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/\n\n- Capabilities in this category: sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser, sandbox.gpu\n- https://letme.dev/sandbox.code picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md)\n\n## Ranking\n\n| # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page |\n| --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- |\n| 33 | Modal Sandboxes | Modal | SDK + MCP | Sandboxes | BB | 75.6 | medium | no | API key | local | 3.3/5 (8) | https://www.anchorterminal.com/tools/modal-sandboxes.md |\n| 111 | Vercel Sandbox | Vercel | HTTP API | Sandboxes | B | 69.6 | medium | no | OAuth or key | hosted | 3.5/5 (2) | https://www.anchorterminal.com/tools/vercel-sandbox.md |\n| 122 | E2B | E2B | HTTP API | Sandboxes | B | 68.5 | medium | no | API key | hosted | 3/5 (2) | https://www.anchorterminal.com/tools/e2b.md |\n| 137 | Cloudflare Sandbox SDK | Cloudflare | SDK + MCP | Sandboxes | B | 67.8 | medium | no | None | local | 3/5 (2) | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md |\n| 177 | Runloop Devboxes | Runloop | HTTP API | Sandboxes | B | 65 | medium | no | API key | hosted | 3/5 (2) | https://www.anchorterminal.com/tools/runloop.md |\n| 183 | Daytona | Daytona | HTTP API | Sandboxes | B | 64.4 | medium | no | API key | hosted + local | 3/5 (2) | https://www.anchorterminal.com/tools/daytona.md |\n| 234 | Blaxel Sandboxes | Blaxel | HTTP API | Sandboxes | C | 61 | medium | no | OAuth or key | hosted | 2/5 (2) | https://www.anchorterminal.com/tools/blaxel-sandboxes.md |\n\nScores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet.\n\n## Summaries\n\n### 33. Modal Sandboxes, BB (75.6)\n\nModal's sandboxed compute environments for running code, with SDK access, GPU support and filesystem snapshots. GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta.\n\n- Page: https://www.anchorterminal.com/tools/modal-sandboxes · Markdown: https://www.anchorterminal.com/tools/modal-sandboxes.md · JSON: https://www.anchorterminal.com/api/v1/tools/modal-sandboxes.json\n- Capabilities: sandbox.code, sandbox.fs, sandbox.persist, sandbox.gpu\n\n### 111. Vercel Sandbox, B (69.6)\n\nFirecracker microVM sandboxes on Vercel, driven from the `@vercel/sandbox` JavaScript SDK, the Python `vercel` package, a CLI or the REST API. Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.\n\n- Page: https://www.anchorterminal.com/tools/vercel-sandbox · Markdown: https://www.anchorterminal.com/tools/vercel-sandbox.md · JSON: https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json\n- Capabilities: sandbox.code, sandbox.fs, sandbox.persist · endpoint: `https://api.vercel.com/v1/sandboxes`\n\n### 122. E2B, B (68.5)\n\nFirecracker microVM sandboxes for agent code, driven from Python and JavaScript SDKs, a CLI or a REST API. Firecracker microVM with its own kernel per sandbox. Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots.\n\n- Page: https://www.anchorterminal.com/tools/e2b · Markdown: https://www.anchorterminal.com/tools/e2b.md · JSON: https://www.anchorterminal.com/api/v1/tools/e2b.json\n- Capabilities: sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser · endpoint: `https://api.e2b.app`\n\n### 137. Cloudflare Sandbox SDK, B (67.8)\n\nTypeScript library for running sandboxed Linux containers from a Cloudflare Worker. Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.\n\n- Page: https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk · Markdown: https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md · JSON: https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json\n- Capabilities: sandbox.code, sandbox.fs, sandbox.persist\n\n### 177. Runloop Devboxes, B (65)\n\nDevboxes, VM sandboxes for coding agents, with blueprints for prebuilt images, disk snapshots, suspend and resume, idle policies and a gateway that adds secret-backed headers to outbound API and MCP calls. Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison.\n\n- Page: https://www.anchorterminal.com/tools/runloop · Markdown: https://www.anchorterminal.com/tools/runloop.md · JSON: https://www.anchorterminal.com/api/v1/tools/runloop.json\n- Capabilities: sandbox.code, sandbox.fs, sandbox.persist · endpoint: `https://api.runloop.ai`\n\n### 183. Daytona, B (64.4)\n\nSandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API. API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.\n\n- Page: https://www.anchorterminal.com/tools/daytona · Markdown: https://www.anchorterminal.com/tools/daytona.md · JSON: https://www.anchorterminal.com/api/v1/tools/daytona.json\n- Capabilities: sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser, sandbox.gpu · endpoint: `https://app.daytona.io/api`\n\n### 234. Blaxel Sandboxes, C (61)\n\nSandbox VMs that drop to standby seconds after the last connection and resume in about 25 ms with memory and filesystem kept, charging only for snapshot storage while idle. No compute charge in standby, only $0.20 a GB-month of snapshot storage. 25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour.\n\n- Page: https://www.anchorterminal.com/tools/blaxel-sandboxes · Markdown: https://www.anchorterminal.com/tools/blaxel-sandboxes.md · JSON: https://www.anchorterminal.com/api/v1/tools/blaxel-sandboxes.json\n- Capabilities: sandbox.code, sandbox.fs, sandbox.persist · endpoint: `https://api.blaxel.ai/v0`\n\n## How we test this category\n\nThe same task in every sandbox: start, install a package, run a script that writes files, pause and resume where supported, then tear down. We time each step, check isolation claims against the docs and add up the cost. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence.\n\n## Indexed, not reviewed (10)\n\nSorted into this category from public catalogues, with facts and our own checks but no score, grade or rank (https://www.anchorterminal.com/indexed/index.md).\n\n| Listing | Kind | What it does | Why it's here |\n| --- | --- | --- | --- |\n| [antrieb](https://www.anchorterminal.com/tools/antrieb.md) | MCP server | Validates AI infra code on real VMs. Self-corrects until it works. No containers, no sandboxes. | vendor's own |\n| [Covenant Guard](https://www.anchorterminal.com/tools/opencovenant-guard.md) | MCP server | Hard spend cap, OS sandbox, and signed receipts for unattended coding agents like Claude Code. | vendor's own |\n| [Kenwea — Sandbox Attestation \u0026 Agent Marketplace](https://www.anchorterminal.com/tools/kenwea-marketplace.md) | MCP server | Signed sandbox verdicts on any artifact, plus an agent marketplace. No key, no signup, no payment. | vendor's own, widely used |\n| [MuPag Sandbox Payments](https://www.anchorterminal.com/tools/mupag-mcp-server.md) | MCP server | Sandbox-only MuPag MCP server for approved payments, subscriptions, refunds, and reconciliation. | vendor's own |\n| [ParallelSandbox](https://www.anchorterminal.com/tools/parallelsandbox.md) | MCP server | Remote Linux boxes for coding agents: Docker, a browser, screenshots, logs, human takeover. | vendor's own, widely used |\n| [Rivet](https://www.anchorterminal.com/tools/rivet-mcp.md) | MCP server | Manage Rivet Cloud namespaces and actors, run Code Mode, and open the Rivet Actor Inspector. | vendor's own |\n| [Runtime Cloud](https://www.anchorterminal.com/tools/withruntime-runtime.md) | MCP server | Linux microVM sandboxes for AI agents: run commands, files, processes, pause and wake. | vendor's own, widely used |\n| [SandboxAPIs](https://www.anchorterminal.com/tools/sandboxapis-mcp.md) | MCP server | Drop-in read-only replicas of GitHub, Jira, Slack and 18 more, preloaded with one fake company. | vendor's own |\n| [ScratchRun](https://www.anchorterminal.com/tools/scratchrun-mcp.md) | MCP server | Ephemeral MicroVM-isolated code execution for AI agents. Fresh VM per call, hard-purged after. | vendor's own |\n| [SecureStamp Action Proof — Cross-Cloud Public Beta (Unverified)](https://www.anchorterminal.com/tools/securestamp-action-proof.md) | MCP server | UNVERIFIED: cross-cloud beta; sandbox by default; production opt-in via customer Guardian. | vendor's own |\n\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Code execution sandboxes",
        "url": ""
      }
    ],
    "description": "7 code execution sandboxes ranked by the Anchor benchmark. Leader Modal Sandboxes (BB). Isolated machines an agent can start in seconds to run code, install packages and use a filesystem, then throw away. Compared on start time, isolation, how long a sandbox can live, what it costs per second and whether state can be paused and resumed.",
    "facts": [
      "Modal Sandboxes BB",
      "Vercel Sandbox B",
      "E2B B"
    ],
    "h1": "Code execution sandboxes for AI agents",
    "image": "https://www.anchorterminal.com/assets/og/categories-code-sandboxes.png",
    "path": "/categories/code-sandboxes",
    "published": "",
    "section": "tools",
    "title": "Code execution sandboxes for AI agents, ranked | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/categories/code-sandboxes"
  },
  "tokens": {
    "markdown": 2650,
    "slim": 430
  },
  "version": 1
}
