Head to head · Sandbox code · October 2026 research run

Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Amazon Bedrock AgentCore Code Interpreter's 73.1 (BB), and leads in 3 of 7 scored categories. Amazon Bedrock AgentCore Code Interpreter leads on security & auth. Both do sandbox code.

Which one, for what

Amazon Bedrock AgentCore Code Interpreter BB

Good for A team already on AWS that wants agent code to run under IAM, inside a VPC and beside S3 data, for sessions up to eight hours.

Ahead on

  • Security & auth, 87 against 69

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No pause, resume or snapshot. Session files are removed when the session ends, and persistence needs a customer-owned S3 Files or EFS mount inside a VPC

Microsoft Execution Containers BB

Good for A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.

Ahead on

  • Payments & pricing, 60 against 30
  • Maintenance & community, 92 against 65
  • Transparency & trust, 83 against 70

Also in its favour

  • No key needed to call it
  • Open source

Watch for

1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased

Score by category

CategoryWeight this runAmazon Bedrock AgentCore Code InterpreterMicrosoft Execution ContainersEdge
Reliability16%208581Amazon Bedrock AgentCore Code Interpreter +4
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28181even
Agent ergonomics13%16.27574Amazon Bedrock AgentCore Code Interpreter +1
Security & auth14%17.58769Amazon Bedrock AgentCore Code Interpreter +18
Payments & pricing10%12.53060Microsoft Execution Containers +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86592Microsoft Execution Containers +27
Transparency & trust7%8.87083Microsoft Execution Containers +13
Negative events≤1500
Total73.1 · BB76.3 · BB

Facts side by side

FactAmazon Bedrock AgentCore Code InterpreterMicrosoft Execution Containers
KindHTTP APISDK + MCP
VendorAmazon Web ServicesMicrosoft
Hosted endpointhttps://bedrock-agentcore.{region}.amazonaws.com/code-interpreters/{id}/tools/invokeno (local only)
TransportsHTTP
AuthAPI keyNone
PricingPay per useFree
x402nono
LicenceProprietary service under the AWS Service Terms. The AgentCore SDKs for Python and TypeScript and the AgentCore MCP server are Apache-2.0MIT
Read-only variant documentednoyes
llms.txtyesno
Last release2026-10-072026-10-06
Terms last updated2026-10-01no document linked
Privacy policy last updated2026-05-18couldn't be read
Customer content may train modelsyes, with an opt-out
Terms restrict automated accessyes
Terms restrict benchmarkingyes
Terms or service can change without noticeyes
Arbitration or class-action waivernot found in the text
Popularity776 stars, 335k npm/wk1.5k stars, 472k npm/wk

Verdicts

Amazon Bedrock AgentCore Code Interpreter

Each session runs in its own microVM with 2 vCPU, 8 GB and a 10 GB disk for up to eight hours, and IAM can scope access to one interpreter. Sessions cannot be paused or resumed, and an AWS account with IAM set-up is needed before a first call.

Microsoft Execution Containers

MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and isolation_session cannot restrict networking at all.

Before you call either

Amazon Bedrock AgentCore Code Interpreter

  1. Start a session with StartCodeInterpreterSession, then pass its id in the x-amzn-code-interpreter-session-id header on every InvokeCodeInterpreter call
  2. Set sessionTimeoutSeconds when starting. The default is 900 seconds and the maximum is eight hours, and the session ends itself at the timeout
  3. Stop sessions when done. Billing runs per second while code is busy, and a session left open counts against the 1,000 concurrent-session quota
  4. Use startCommandExecution, getTask and stopTask for work longer than the 15-minute synchronous request limit
  5. Retry ThrottlingException (429) and InternalServerException (500) with exponential backoff, and treat ServiceQuotaExceededException, returned as HTTP 402, as a quota to raise

Microsoft Execution Containers

  1. Import from @microsoft/mxc-sdk/v1. The package root exports nothing.
  2. Call getPlatformSupport() first and stop if isSupported is false. getAvailableBackends() is advisory and launch-time validation still applies.
  3. Set network.egress.default to allow only when the task needs it. Omitted network policy resolves to deny in every direction.
  4. Never pass --audit to an executor for untrusted code. It turns off all sandbox security for the workload.
  5. Read ExecutionResult.warnings after each run. Security warnings arrive there and are not written to stdout or stderr.

Questions

Which is better for AI agents, Amazon Bedrock AgentCore Code Interpreter or Microsoft Execution Containers?

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Amazon Bedrock AgentCore Code Interpreter's 73.1 (BB), and leads in 3 of 7 scored categories. Amazon Bedrock AgentCore Code Interpreter leads on security & auth.

Can an agent call Amazon Bedrock AgentCore Code Interpreter and Microsoft Execution Containers without installing anything?

Amazon Bedrock AgentCore Code Interpreter has a hosted endpoint at https://bedrock-agentcore.{region}.amazonaws.com/code-interpreters/{id}/tools/invoke. No hosted endpoint is listed for Microsoft Execution Containers.

Are Amazon Bedrock AgentCore Code Interpreter and Microsoft Execution Containers open source?

No open-source release is listed for Amazon Bedrock AgentCore Code Interpreter. Microsoft Execution Containers is open source (MIT).

Other comparisons with Amazon Bedrock AgentCore Code Interpreter or Microsoft Execution Containers

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.