{
  "data": {
    "a": {
      "slug": "cloudflare-sandbox-sdk",
      "name": "Cloudflare Sandbox SDK",
      "vendor": "Cloudflare",
      "vendorUrl": "https://developers.cloudflare.com/sandbox/",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "TypeScript library for running sandboxed Linux containers from a Cloudflare Worker.",
      "url": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk",
      "markdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json",
      "repo": "https://github.com/cloudflare/sandbox-sdk",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@cloudflare/sandbox"
        }
      ],
      "auth": "none",
      "authNotes": "There's no hosted API. The sandbox sits behind a Worker you deploy, so it has whatever auth you put in front of it, and the starter template has none. Deploying needs a Cloudflare account through Wrangler. Version 1.0 adds preview ports with custom hostnames and authentication.",
      "pricing": "paid",
      "pricingNotes": "Needs the Workers Paid plan, $5 a month minimum (https://developers.cloudflare.com/workers/platform/pricing/). Billed as Containers plus Workers and Durable Objects. Containers include 25 GiB-hours of memory, 375 vCPU-minutes and 200 GB-hours of disk a month, then $0.0000025 a GiB-second of memory, $0.000020 a vCPU-second of CPU used and $0.00000007 a GB-second of disk, in 10 ms steps while the container runs. Egress is $0.025 a GB in North America and Europe after 1 TB (https://developers.cloudflare.com/containers/pricing/). Durable Objects add $0.15 per million requests and $12.50 per million GB-seconds after the included amounts (https://developers.cloudflare.com/workers/platform/pricing/).",
      "priceSummary": "$0.072 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1100,
        "npmWeekly": 722733,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developers.cloudflare.com/sandbox/",
      "llmsTxt": "https://developers.cloudflare.com/sandbox/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "typescript",
        "open-source",
        "llms-txt"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.8,
        "grade": "B",
        "agentReady": false,
        "rank": 137,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
        "strengths": [
          "Each sandbox runs in its own VM with a separate filesystem, process space and network stack",
          "Outbound handlers hold credentials in the Worker and inject them, so the container never sees them",
          "Egress can be turned off or limited to a deny-by-default `allowedHosts` list",
          "CPU billed on use at $0.000020 a vCPU-second, with a monthly allowance on Workers Paid",
          "Apache-2.0, with CodeQL and passing CI on main"
        ],
        "weaknesses": [
          "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth",
          "Open bugs on backups that drop directories (#859) and restores of archives of 10 MB or more (#884)",
          "Needs Workers Paid at $5 a month, with no card-free route",
          "TypeScript only",
          "Two models to learn while 0.x and 1.0 overlap until 31 December 2026"
        ],
        "agentNotes": [
          "Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets",
          "Put API keys in an outbound handler in the Worker, not in the container's environment",
          "Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default",
          "Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs",
          "Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.8
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 45
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm create cloudflare@latest -- my-sandbox --template=cloudflare/sandbox-sdk/examples/minimal"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/cloudflare-sandbox-sdk"
      },
      "sameCompany": [
        "cloudflare-mcp",
        "cloudflare-r2",
        "cloudflare-clef"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Container CPU",
          "unit": "vcpu-hour",
          "usd": 0.072,
          "note": "$0.000020 a vCPU-second of CPU used, after 375 vCPU-minutes a month"
        },
        {
          "item": "Workers Paid plan",
          "unit": "month",
          "usd": 5,
          "note": "Minimum charge"
        },
        {
          "item": "Egress, North America and Europe",
          "unit": "gb",
          "usd": 0.025,
          "note": "After 1 TB a month"
        }
      ],
      "provenance": {
        "legalEntity": "Cloudflare, Inc.",
        "domain": "cloudflare.com",
        "domainRegistered": "2009-02-17",
        "endpointOnVendorDomain": null,
        "terms": "https://www.cloudflare.com/terms/",
        "privacy": "https://www.cloudflare.com/privacypolicy/",
        "statusPage": "https://www.cloudflarestatus.com",
        "changelog": "https://developers.cloudflare.com/changelog/?product=sandbox",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The self-serve subscription agreement (updated 12 September 2025) names Cloudflare, Inc., 101 Townsend St., San Francisco.",
          "There's no vendor endpoint to check. Sandboxes are reached through a Worker on your own route or workers.dev subdomain.",
          "security.txt lists HackerOne and a disclosure policy, but we didn't see an Expires field.",
          "The GitHub README still says the SDK is in active development and APIs may change before v1.0, while npm has 1.0.0 (published 2026-09-30) and the changelog announces 1.0. The GitHub releases page showed 0.12.4 (21 July 2026) as its newest release when checked."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
      "live": {
        "slug": "cloudflare-sandbox-sdk",
        "vendorStatus": {
          "page": "https://www.cloudflarestatus.com",
          "indicator": "minor",
          "summary": "Minor Service Outage",
          "checkedAt": "2026-10-04T23:27:42.32906391Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "cloudflare/sandbox-sdk",
            "version": "@cloudflare/sandbox@0.12.10",
            "released": "2026-09-23",
            "seenAt": "2026-10-04T16:24:02.293431378Z"
          },
          {
            "registry": "npm",
            "name": "@cloudflare/sandbox",
            "version": "1.0.0",
            "seenAt": "2026-10-04T16:24:01.356030499Z"
          }
        ],
        "githubStars": 1144,
        "npmWeekly": 797840,
        "securityTxt": {
          "url": "https://cloudflare.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:51.95928161Z"
        },
        "llmsTxt": {
          "url": "https://developers.cloudflare.com/sandbox/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:31.097149892Z"
        },
        "domain": {
          "domain": "cloudflare.com",
          "registered": "2009-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/cloudflare.com",
          "checkedAt": "2026-10-04T13:06:22.743038628Z"
        },
        "pages": [
          {
            "url": "https://developers.cloudflare.com/changelog/?product=sandbox",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:50.869019575Z",
            "changedAt": "2026-10-04T15:42:50.869019575Z",
            "fingerprint": "aa7b5fb58872"
          },
          {
            "url": "https://developers.cloudflare.com/containers/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:52.872169011Z",
            "changedAt": "2026-10-03T15:31:01.576635047Z",
            "fingerprint": "a81e9d7bb64a"
          },
          {
            "url": "https://developers.cloudflare.com/workers/platform/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:00.847585458Z",
            "changedAt": "2026-10-04T15:43:00.847585458Z",
            "fingerprint": "ea6eab1a375f"
          }
        ],
        "updatedAt": "2026-10-04T23:27:42.32906391Z"
      }
    },
    "b": {
      "slug": "daytona",
      "name": "Daytona",
      "vendor": "Daytona",
      "vendorUrl": "https://www.daytona.io",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Sandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API.",
      "url": "https://www.anchorterminal.com/tools/daytona",
      "markdownUrl": "https://www.anchorterminal.com/tools/daytona.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/daytona.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/daytona.json",
      "repo": "https://github.com/daytona/clients",
      "license": "Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI)",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://app.daytona.io/api",
      "packages": [
        {
          "registry": "pypi",
          "name": "daytona"
        },
        {
          "registry": "npm",
          "name": "@daytona/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key in the `Authorization` header. The SDKs read `DAYTONA_API_KEY`, `DAYTONA_API_URL` (default https://app.daytona.io/api) and `DAYTONA_TARGET` (us or eu). Keys take scopes, so an agent's key can have `write:sandboxes` without `delete:sandboxes`. The MCP server uses the CLI session from `daytona login`.",
      "pricing": "usage",
      "pricingNotes": "Billed per second. $0.0504 a vCPU-hour, $0.0162 a GiB-hour of memory and $0.000108 a GiB-hour of storage after the first 5 GiB, Windows $0.0858 a vCPU-hour. GPUs from $0.57 an hour (RTX 4090, preemptible) to $6.25 (B300 or B200, on demand), with H100 at $2.27 preemptible or $3.95 on demand. $200 of free compute without a card, and up to $50,000 in startup credits (https://www.daytona.io/pricing). Higher limits unlock with a linked card and a $25 top-up (Tier 2), a $500 top-up (Tier 3) or $2,000 every 30 days (Tier 4) (https://www.daytona.io/docs/en/limits.md).",
      "priceSummary": "$0.0504 / vCPU-hr",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 705790,
        "pypiWeekly": 1406178,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.daytona.io/docs",
      "llmsTxt": "https://www.daytona.io/docs/llms.txt",
      "openapi": "https://www.daytona.io/docs/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.browser",
        "sandbox.gpu"
      ],
      "tags": [
        "hosted",
        "no-card",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "eu",
        "enterprise"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.4,
        "grade": "B",
        "agentReady": false,
        "rank": 183,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 6,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 80,
          "payments": 50,
          "reliability": 60,
          "schema": 87,
          "security": 63,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.",
        "strengths": [
          "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them",
          "Container, Linux VM, Windows and GPU sandbox classes behind one API",
          "Three public OpenAPI files, llms.txt and SDKs in five languages",
          "Rate limits published per tier, with Retry-After and rate-limit headers on 429s",
          "$200 of compute without a card, billed per second"
        ],
        "weaknesses": [
          "The container class shares the host kernel. Only the VM classes get their own",
          "Full internet access and per-sandbox allow lists need Tier 3",
          "Platform code went private in June 2026, and the old repository's 311 open issues won't be answered",
          "Two Windows runner outages over an hour in July and August 2026",
          "No security.txt, SOC 2 report or bug bounty found"
        ],
        "agentNotes": [
          "Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead",
          "Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking",
          "Give the agent a key without `delete:sandboxes` if it shouldn't destroy work",
          "Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation",
          "Check the organisation's tier before relying on outbound calls from inside the sandbox"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.4
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 80,
          "payments": 50,
          "reliability": 60,
          "schema": 87,
          "security": 63,
          "transparency": 40
        },
        "provenanceScore": 75
      },
      "connect": {
        "install": "pip install daytona  # or npm i @daytona/sdk",
        "http": "curl -X POST https://app.daytona.io/api/sandbox -H \"Authorization: Bearer $DAYTONA_API_KEY\" \\\n  -H \"Content-Type: application/json\" -d '{}'",
        "claudeCode": "claude mcp add daytona -- daytona mcp start",
        "config": {
          "mcpServers": {
            "daytona": {
              "args": [
                "mcp",
                "start"
              ],
              "command": "daytona"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/daytona"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.0504,
          "note": "Memory extra at $0.0162 a GiB-hour"
        },
        {
          "item": "Nvidia H100, on demand",
          "unit": "gpu-hour",
          "usd": 3.95
        },
        {
          "item": "Nvidia H100, preemptible",
          "unit": "gpu-hour",
          "usd": 2.27
        },
        {
          "item": "Nvidia RTX 4090, preemptible",
          "unit": "gpu-hour",
          "usd": 0.57
        }
      ],
      "provenance": {
        "legalEntity": "Daytona Platforms Inc.",
        "domain": "daytona.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.daytona.io/terms-of-service",
        "privacy": "https://www.daytona.io/privacy-policy",
        "statusPage": "https://status.app.daytona.io",
        "changelog": "https://www.daytona.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "Terms and privacy policy (both updated 22 August 2025) name Daytona Platforms Inc., 224 W 35th St, New York, under Delaware law.",
          "The status page lists Windows runner outages on 31 July (3 hours 50 minutes) and 1 August 2026 (1 hour 40 minutes), a 17.5-hour regional degradation on 11 August, short incidents in July and September, and a 2-hour degradation of sandbox listing on 1 October 2026.",
          "www.daytona.io/.well-known/security.txt returns 404. daytona/clients has a SECURITY.md.",
          "The .io registry's RDAP server rate-limited our lookups, so the registration date is blank."
        ],
        "score": 75
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/daytona.json",
      "live": {
        "slug": "daytona",
        "probe": {
          "target": "https://app.daytona.io/api",
          "method": "get",
          "lastAt": "2026-10-04T23:32:46.156837628Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 102,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 104,
          "p95ms24h": 158,
          "samples24h": 272,
          "samples30d": 895,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 267,
              "ok": 267
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.app.daytona.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-04T21:39:56.041466604Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "daytona/clients",
            "version": "v0.220.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:25:08.289274609Z"
          },
          {
            "registry": "npm",
            "name": "@daytona/sdk",
            "version": "0.220.0",
            "seenAt": "2026-10-04T16:25:07.364662963Z"
          },
          {
            "registry": "pypi",
            "name": "daytona",
            "version": "0.220.0",
            "released": "2026-09-29",
            "seenAt": "2026-10-04T16:25:07.171178997Z"
          }
        ],
        "githubStars": 12,
        "npmWeekly": 742531,
        "pypiWeekly": 1367845,
        "securityTxt": {
          "url": "https://daytona.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-04T15:15:38.986416206Z"
        },
        "llmsTxt": {
          "url": "https://www.daytona.io/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:30.007359335Z"
        },
        "domain": {
          "domain": "daytona.io",
          "checkedAt": "2026-10-04T13:04:31.91436109Z"
        },
        "pages": [
          {
            "url": "https://www.daytona.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:49:58.72051538Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b3e70c220b5c"
          },
          {
            "url": "https://www.daytona.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:02.007859806Z",
            "changedAt": "2026-10-03T15:37:58.260333039Z",
            "fingerprint": "8c2c3fd83e7e"
          },
          {
            "url": "https://www.daytona.io/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:03.162657346Z",
            "changedAt": "2026-10-03T15:37:59.162897733Z",
            "fingerprint": "c712b184a1f3"
          },
          {
            "url": "https://www.daytona.io/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-04T15:50:05.046601049Z",
            "changedAt": "2026-10-03T15:38:01.284671381Z",
            "fingerprint": "c42adfc2b432"
          }
        ],
        "updatedAt": "2026-10-04T23:32:46.156837628Z"
      }
    },
    "summary": "Cloudflare Sandbox SDK has a score of 67.8 (B) against Daytona's 64.4 (B). Both do sandbox code. The largest gap is reliability, 27 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona",
    "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.md",
    "slim": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.min.md"
  },
  "markdown": "Cloudflare Sandbox SDK has a score of 67.8 (B) against Daytona's 64.4 (B). Both do sandbox code. The largest gap is reliability, 27 points.\n\n- Cloudflare Sandbox SDK: grade B, 67.8/100, rank #137 of 452. Markdown https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md · JSON https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json\n- Daytona: grade B, 64.4/100, rank #183 of 452. Markdown https://www.anchorterminal.com/tools/daytona.md · JSON https://www.anchorterminal.com/api/v1/tools/daytona.json\n\n## Which one, for what\n\nPick Cloudflare Sandbox SDK for reliability (+27), agent ergonomics (+8), transparency \u0026 trust (+15).\n\nPick Daytona for schema \u0026 documentation (+10), payments \u0026 pricing (+20), maintenance \u0026 community (+10).\n\n## Score by category\n\n| Category | Weight | Cloudflare Sandbox SDK | Daytona | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 87 | 60 | Cloudflare Sandbox SDK +27 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 87 | Daytona +10 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 55 | Cloudflare Sandbox SDK +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 63 | Cloudflare Sandbox SDK +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 50 | Daytona +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 80 | Daytona +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 58 | Cloudflare Sandbox SDK +15 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **67.8 · B** | **64.4 · B** | |\n\n## Facts side by side\n\n| Fact | Cloudflare Sandbox SDK | Daytona |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Cloudflare | Daytona |\n| Hosted endpoint | no (local only) | `https://app.daytona.io/api` |\n| Transports |  | HTTP, stdio |\n| Auth | None | API key |\n| Pricing | Paid | Pay per use |\n| x402 | no | no |\n| Licence | Apache-2.0 | Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI) |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-30 | 2026-09-29 |\n| Popularity | 1.1k stars, 723k npm/wk | 6 stars, 706k npm/wk, 1.4M PyPI/wk |\n| Agent reviews | 3/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**Cloudflare Sandbox SDK.** Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.\n\n**Daytona.** API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.\n\n## Before you call either\n\n### Cloudflare Sandbox SDK\n\n1. Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets\n2. Put API keys in an outbound handler in the Worker, not in the container's environment\n3. Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default\n4. Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs\n5. Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026\n\n### Daytona\n\n1. Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead\n2. Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking\n3. Give the agent a key without `delete:sandboxes` if it shouldn't destroy work\n4. Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation\n5. Check the organisation's tier before relying on outbound calls from inside the sandbox\n\n## Other comparisons with Cloudflare Sandbox SDK or Daytona\n\n- [Blaxel Sandboxes vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk.md)\n- [Blaxel Sandboxes vs Daytona](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-daytona.md)\n- [Cloudflare Sandbox SDK vs E2B](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b.md)\n- [Cloudflare Sandbox SDK vs Modal Sandboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.md)\n- [Cloudflare Sandbox SDK vs Runloop Devboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.md)\n- [Cloudflare Sandbox SDK vs Vercel Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.md)\n- [Daytona vs E2B](https://www.anchorterminal.com/compare/daytona-vs-e2b.md)\n- [Daytona vs Modal Sandboxes](https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes.md)\n- [Daytona vs Runloop Devboxes](https://www.anchorterminal.com/compare/daytona-vs-runloop.md)\n- [Daytona vs Vercel Sandbox](https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cloudflare Sandbox SDK vs Daytona",
        "url": ""
      }
    ],
    "description": "Cloudflare Sandbox SDK has a score of 67.8 (B) against Daytona's 64.4 (B). Both do sandbox code. The largest gap is reliability, 27 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cloudflare Sandbox SDK B 67.8",
      "Daytona B 64.4",
      "scores"
    ],
    "h1": "Cloudflare Sandbox SDK vs Daytona",
    "image": "https://www.anchorterminal.com/assets/og/compare-cloudflare-sandbox-sdk-vs-daytona.png",
    "path": "/compare/cloudflare-sandbox-sdk-vs-daytona",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cloudflare Sandbox SDK vs Daytona for AI agents, B 67.8 vs B 64.4",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
