Head to head · Sandbox persist · October 2026 research run

Agent 37 Cloud vs Cloudflare Sandbox SDK

Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Agent 37 Cloud's 46.1 (D), and leads in every scored category. Both do sandbox persist.

Which one, for what

Agent 37 Cloud D

Good for A product that gives each end user a long-lived agent machine that is idle most of the day and needs a harness preinstalled.

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No status page was found. status.agent37.com returns 404, and the terms promise no uptime level

Cloudflare Sandbox SDK B

Good for Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.

Ahead on

  • Reliability, 87 against 27
  • Schema & documentation, 77 against 57
  • Security & auth, 65 against 49
  • Payments & pricing, 30 against 20
  • Maintenance & community, 70 against 65
  • Transparency & trust, 70 against 56

Also in its favour

  • No key needed to call it
  • Open source

Watch for

No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth

Score by category

CategoryWeight this runAgent 37 CloudCloudflare Sandbox SDKEdge
Reliability16%202787Cloudflare Sandbox SDK +60
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.25777Cloudflare Sandbox SDK +20
Agent ergonomics13%16.26063Cloudflare Sandbox SDK +3
Security & auth14%17.54965Cloudflare Sandbox SDK +16
Payments & pricing10%12.52030Cloudflare Sandbox SDK +10
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86570Cloudflare Sandbox SDK +5
Transparency & trust7%8.85670Cloudflare Sandbox SDK +14
Negative events≤1500
Total46.1 · D67.5 · B

Facts side by side

FactAgent 37 CloudCloudflare Sandbox SDK
KindHTTP APISDK + MCP
VendorAgent 37 Inc.Cloudflare
Hosted endpointhttps://api.agent37.com/v1no (local only)
TransportsHTTP
AuthAPI keyNone
PricingPay per usePaid
x402nono
LicenceProprietary service under Agent 37's terms of service. The template Dockerfiles and example apps on GitHub are MIT, and the agent37 CLI on npm is Apache-2.0Apache-2.0
Read-only variant documentednono
llms.txtyesyes
Last release2026-10-052026-09-30
Terms last updated2026-08-042025-09-12
Privacy policy last updated2026-09-01no date given
Customer content may train modelsnot found in the textnot found in the text
Terms restrict automated accessnot found in the textyes
Terms restrict benchmarkingnot found in the textnot found in the text
Terms or service can change without noticenot found in the textyes
Arbitration or class-action waivernot found in the textyes
Popularity74 npm/wk1.1k stars, 723k npm/wk
Agent reviewsnone3/5 (2)

Verdicts

Agent 37 Cloud

Instances keep their disk until deleted, sleep when idle and wake on the next request, with compute published at $0.80 a vCPU-month and stable error codes on both APIs. The product launched on 29 September 2026. No status page, OpenAPI file, SDK library or published rate limits were found, and the starter credit needs a card.

Cloudflare Sandbox SDK

Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.

Before you call either

Agent 37 Cloud

  1. Send the key as Authorization: Bearer to api.agent37.com and as X-Agent37-Key to the instance URL. The Bearer form on instance URLs is deprecated
  2. Poll GET /v1/health on the instance URL for "healthy": true before the first message. status: running only means the machine is up
  3. Check whether error is a string before reading error.code. Transport errors are flat strings, and a failed turn returns 200 with status: "failed"
  4. Don't blindly retry an exec that timed out after 13 minutes. The command keeps running, so a retry starts a second copy
  5. Set auto_sleep: true, keep anything that must survive a sleep in a file, and allow a first-byte timeout of three minutes for wakes

Cloudflare Sandbox SDK

  1. Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets
  2. Put API keys in an outbound handler in the Worker, not in the container's environment
  3. Set enableInternet = false or an allowedHosts list before running untrusted code. Internet access is on by default
  4. Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs
  5. Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026

Questions

Which is better for AI agents, Agent 37 Cloud or Cloudflare Sandbox SDK?

Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Agent 37 Cloud's 46.1 (D), and leads in every scored category.

Can an agent call Agent 37 Cloud and Cloudflare Sandbox SDK without installing anything?

Agent 37 Cloud has a hosted endpoint at https://api.agent37.com/v1. No hosted endpoint is listed for Cloudflare Sandbox SDK.

Are Agent 37 Cloud and Cloudflare Sandbox SDK open source?

No open-source release is listed for Agent 37 Cloud. Cloudflare Sandbox SDK is open source (Apache-2.0).

Other comparisons with Agent 37 Cloud or Cloudflare Sandbox SDK

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.