# Code execution sandboxes for AI agents > 7 code execution sandboxes ranked by the Anchor benchmark. Leader Modal Sandboxes (BB). Isolated machines an agent can start in seconds to run code, install packages and use a filesystem, then throw away. Compared on start time, isolation, how long a sandbox can live, what it costs per second and whether state can be paused and resumed. - Canonical: https://www.anchorterminal.com/categories/code-sandboxes - Markdown: https://www.anchorterminal.com/categories/code-sandboxes.md (~2,650 tokens) - Slim: https://www.anchorterminal.com/categories/code-sandboxes.min.md (~430 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/categories/code-sandboxes.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-04 Isolated machines an agent can start in seconds to run code, install packages and use a filesystem, then throw away. Compared on start time, isolation, how long a sandbox can live, what it costs per second and whether state can be paused and resumed. - Tools ranked: 7 · agent-ready (BB or better): 1 · accept x402: 0 · hosted endpoints: 5 · desk reviews by the panel: 20 - JSON: https://www.anchorterminal.com/api/v1/tools.json (list) · https://www.anchorterminal.com/api/v1/rankings.json (ranked) · https://www.anchorterminal.com/api/v1/x402.json (payable) · https://www.anchorterminal.com/api/v1/capabilities.json (by capability) - Grades run AA, A, BB, B, C, D, E, F · methodology: https://www.anchorterminal.com/benchmark/ - Capabilities in this category: sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser, sandbox.gpu - https://letme.dev/sandbox.code picks the top-graded tool in this list and says how to call it direct; calling through letme comes later (https://www.anchorterminal.com/letme/index.md) ## Ranking | # | Tool | Vendor | Kind | Category | Grade | Score | Confidence | x402 | Auth | Where | Reviews | Page | | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | --- | | 33 | Modal Sandboxes | Modal | SDK + MCP | Sandboxes | BB | 75.6 | medium | no | API key | local | 3.3/5 (8) | https://www.anchorterminal.com/tools/modal-sandboxes.md | | 111 | Vercel Sandbox | Vercel | HTTP API | Sandboxes | B | 69.6 | medium | no | OAuth or key | hosted | 3.5/5 (2) | https://www.anchorterminal.com/tools/vercel-sandbox.md | | 122 | E2B | E2B | HTTP API | Sandboxes | B | 68.5 | medium | no | API key | hosted | 3/5 (2) | https://www.anchorterminal.com/tools/e2b.md | | 137 | Cloudflare Sandbox SDK | Cloudflare | SDK + MCP | Sandboxes | B | 67.8 | medium | no | None | local | 3/5 (2) | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md | | 177 | Runloop Devboxes | Runloop | HTTP API | Sandboxes | B | 65 | medium | no | API key | hosted | 3/5 (2) | https://www.anchorterminal.com/tools/runloop.md | | 183 | Daytona | Daytona | HTTP API | Sandboxes | B | 64.4 | medium | no | API key | hosted + local | 3/5 (2) | https://www.anchorterminal.com/tools/daytona.md | | 234 | Blaxel Sandboxes | Blaxel | HTTP API | Sandboxes | C | 61 | medium | no | OAuth or key | hosted | 2/5 (2) | https://www.anchorterminal.com/tools/blaxel-sandboxes.md | Scores are from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/), with Performance and Task success pending. p95 latency and context cost come from our probes, which haven't run yet. ## Summaries ### 33. Modal Sandboxes, BB (75.6) Modal's sandboxed compute environments for running code, with SDK access, GPU support and filesystem snapshots. GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta. - Page: https://www.anchorterminal.com/tools/modal-sandboxes · Markdown: https://www.anchorterminal.com/tools/modal-sandboxes.md · JSON: https://www.anchorterminal.com/api/v1/tools/modal-sandboxes.json - Capabilities: sandbox.code, sandbox.fs, sandbox.persist, sandbox.gpu ### 111. Vercel Sandbox, B (69.6) Firecracker microVM sandboxes on Vercel, driven from the `@vercel/sandbox` JavaScript SDK, the Python `vercel` package, a CLI or the REST API. Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team. - Page: https://www.anchorterminal.com/tools/vercel-sandbox · Markdown: https://www.anchorterminal.com/tools/vercel-sandbox.md · JSON: https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json - Capabilities: sandbox.code, sandbox.fs, sandbox.persist · endpoint: `https://api.vercel.com/v1/sandboxes` ### 122. E2B, B (68.5) Firecracker microVM sandboxes for agent code, driven from Python and JavaScript SDKs, a CLI or a REST API. Firecracker microVM with its own kernel per sandbox. Two major incidents over an hour in September 2026, on sandbox creation and on creating from snapshots. - Page: https://www.anchorterminal.com/tools/e2b · Markdown: https://www.anchorterminal.com/tools/e2b.md · JSON: https://www.anchorterminal.com/api/v1/tools/e2b.json - Capabilities: sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser · endpoint: `https://api.e2b.app` ### 137. Cloudflare Sandbox SDK, B (67.8) TypeScript library for running sandboxed Linux containers from a Cloudflare Worker. Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth. - Page: https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk · Markdown: https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md · JSON: https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json - Capabilities: sandbox.code, sandbox.fs, sandbox.persist ### 177. Runloop Devboxes, B (65) Devboxes, VM sandboxes for coding agents, with blueprints for prebuilt images, disk snapshots, suspend and resume, idle policies and a gateway that adds secret-backed headers to outbound API and MCP calls. Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison. - Page: https://www.anchorterminal.com/tools/runloop · Markdown: https://www.anchorterminal.com/tools/runloop.md · JSON: https://www.anchorterminal.com/api/v1/tools/runloop.json - Capabilities: sandbox.code, sandbox.fs, sandbox.persist · endpoint: `https://api.runloop.ai` ### 183. Daytona, B (64.4) Sandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API. API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own. - Page: https://www.anchorterminal.com/tools/daytona · Markdown: https://www.anchorterminal.com/tools/daytona.md · JSON: https://www.anchorterminal.com/api/v1/tools/daytona.json - Capabilities: sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser, sandbox.gpu · endpoint: `https://app.daytona.io/api` ### 234. Blaxel Sandboxes, C (61) Sandbox VMs that drop to standby seconds after the last connection and resume in about 25 ms with memory and filesystem kept, charging only for snapshot storage while idle. No compute charge in standby, only $0.20 a GB-month of snapshot storage. 25 status-page incidents from 9 July to 1 October 2026, three of them sandbox outages over an hour. - Page: https://www.anchorterminal.com/tools/blaxel-sandboxes · Markdown: https://www.anchorterminal.com/tools/blaxel-sandboxes.md · JSON: https://www.anchorterminal.com/api/v1/tools/blaxel-sandboxes.json - Capabilities: sandbox.code, sandbox.fs, sandbox.persist · endpoint: `https://api.blaxel.ai/v0` ## How we test this category The same task in every sandbox: start, install a package, run a script that writes files, pause and resume where supported, then tear down. We time each step, check isolation claims against the docs and add up the cost. This test hasn't run yet, so Task success is pending and the grades here come from the categories assessed from public evidence. ## Indexed, not reviewed (10) Sorted into this category from public catalogues, with facts and our own checks but no score, grade or rank (https://www.anchorterminal.com/indexed/index.md). | Listing | Kind | What it does | Why it's here | | --- | --- | --- | --- | | [antrieb](https://www.anchorterminal.com/tools/antrieb.md) | MCP server | Validates AI infra code on real VMs. Self-corrects until it works. No containers, no sandboxes. | vendor's own | | [Covenant Guard](https://www.anchorterminal.com/tools/opencovenant-guard.md) | MCP server | Hard spend cap, OS sandbox, and signed receipts for unattended coding agents like Claude Code. | vendor's own | | [Kenwea — Sandbox Attestation & Agent Marketplace](https://www.anchorterminal.com/tools/kenwea-marketplace.md) | MCP server | Signed sandbox verdicts on any artifact, plus an agent marketplace. No key, no signup, no payment. | vendor's own, widely used | | [MuPag Sandbox Payments](https://www.anchorterminal.com/tools/mupag-mcp-server.md) | MCP server | Sandbox-only MuPag MCP server for approved payments, subscriptions, refunds, and reconciliation. | vendor's own | | [ParallelSandbox](https://www.anchorterminal.com/tools/parallelsandbox.md) | MCP server | Remote Linux boxes for coding agents: Docker, a browser, screenshots, logs, human takeover. | vendor's own, widely used | | [Rivet](https://www.anchorterminal.com/tools/rivet-mcp.md) | MCP server | Manage Rivet Cloud namespaces and actors, run Code Mode, and open the Rivet Actor Inspector. | vendor's own | | [Runtime Cloud](https://www.anchorterminal.com/tools/withruntime-runtime.md) | MCP server | Linux microVM sandboxes for AI agents: run commands, files, processes, pause and wake. | vendor's own, widely used | | [SandboxAPIs](https://www.anchorterminal.com/tools/sandboxapis-mcp.md) | MCP server | Drop-in read-only replicas of GitHub, Jira, Slack and 18 more, preloaded with one fake company. | vendor's own | | [ScratchRun](https://www.anchorterminal.com/tools/scratchrun-mcp.md) | MCP server | Ephemeral MicroVM-isolated code execution for AI agents. Fresh VM per call, hard-purged after. | vendor's own | | [SecureStamp Action Proof — Cross-Cloud Public Beta (Unverified)](https://www.anchorterminal.com/tools/securestamp-action-proof.md) | MCP server | UNVERIFIED: cross-cloud beta; sandbox by default; production opt-in via customer Guardian. | vendor's own |