{
  "data": {
    "a": {
      "slug": "cloudflare-sandbox-sdk",
      "name": "Cloudflare Sandbox SDK",
      "vendor": "Cloudflare",
      "vendorUrl": "https://developers.cloudflare.com/sandbox/",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "TypeScript library for running sandboxed Linux containers from a Cloudflare Worker.",
      "url": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk",
      "markdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json",
      "repo": "https://github.com/cloudflare/sandbox-sdk",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@cloudflare/sandbox"
        }
      ],
      "auth": "none",
      "authNotes": "There's no hosted API. The sandbox sits behind a Worker you deploy, so it has whatever auth you put in front of it, and the starter template has none. Deploying needs a Cloudflare account through Wrangler. Version 1.0 adds preview ports with custom hostnames and authentication.",
      "pricing": "paid",
      "pricingNotes": "Needs the Workers Paid plan, $5 a month minimum (https://developers.cloudflare.com/workers/platform/pricing/). Billed as Containers plus Workers and Durable Objects. Containers include 25 GiB-hours of memory, 375 vCPU-minutes and 200 GB-hours of disk a month, then $0.0000025 a GiB-second of memory, $0.000020 a vCPU-second of CPU used and $0.00000007 a GB-second of disk, in 10 ms steps while the container runs. Egress is $0.025 a GB in North America and Europe after 1 TB (https://developers.cloudflare.com/containers/pricing/). Durable Objects add $0.15 per million requests and $12.50 per million GB-seconds after the included amounts (https://developers.cloudflare.com/workers/platform/pricing/).",
      "priceSummary": "$0.072 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1100,
        "npmWeekly": 722733,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developers.cloudflare.com/sandbox/",
      "llmsTxt": "https://developers.cloudflare.com/sandbox/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "typescript",
        "open-source",
        "llms-txt"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.5,
        "grade": "B",
        "agentReady": false,
        "rank": 231,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
        "bestFor": "Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.",
        "strengths": [
          "Each sandbox runs in its own VM with a separate filesystem, process space and network stack",
          "Outbound handlers hold credentials in the Worker and inject them, so the container never sees them",
          "Egress can be turned off or limited to a deny-by-default `allowedHosts` list",
          "CPU billed on use at $0.000020 a vCPU-second, with a monthly allowance on Workers Paid",
          "Apache-2.0, with CodeQL and passing CI on main"
        ],
        "weaknesses": [
          "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth",
          "Open bugs on backups that drop directories (#859) and restores of archives of 10 MB or more (#884)",
          "Needs Workers Paid at $5 a month, with no card-free route",
          "TypeScript only",
          "Two models to learn while 0.x and 1.0 overlap until 31 December 2026"
        ],
        "agentNotes": [
          "Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets",
          "Put API keys in an outbound handler in the Worker, not in the container's environment",
          "Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default",
          "Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs",
          "Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.5
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 45
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm create cloudflare@latest -- my-sandbox --template=cloudflare/sandbox-sdk/examples/minimal"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/cloudflare-sandbox-sdk"
      },
      "sameCompany": [
        "cloudflare-web-search",
        "cloudflare-mcp",
        "cloudflare-email-service",
        "cloudflare-r2",
        "cloudflare-clef"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Container CPU",
          "unit": "vcpu-hour",
          "usd": 0.072,
          "note": "$0.000020 a vCPU-second of CPU used, after 375 vCPU-minutes a month"
        },
        {
          "item": "Workers Paid plan",
          "unit": "month",
          "usd": 5,
          "note": "Minimum charge"
        },
        {
          "item": "Egress, North America and Europe",
          "unit": "gb",
          "usd": 0.025,
          "note": "After 1 TB a month"
        }
      ],
      "provenance": {
        "legalEntity": "Cloudflare, Inc.",
        "domain": "cloudflare.com",
        "domainRegistered": "2009-02-17",
        "endpointOnVendorDomain": null,
        "terms": "https://www.cloudflare.com/terms/",
        "privacy": "https://www.cloudflare.com/privacypolicy/",
        "statusPage": "https://www.cloudflarestatus.com",
        "changelog": "https://developers.cloudflare.com/changelog/?product=sandbox",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The self-serve subscription agreement (updated 12 September 2025) names Cloudflare, Inc., 101 Townsend St., San Francisco.",
          "There's no vendor endpoint to check. Sandboxes are reached through a Worker on your own route or workers.dev subdomain.",
          "security.txt lists HackerOne and a disclosure policy, but we didn't see an Expires field.",
          "The GitHub README still says the SDK is in active development and APIs may change before v1.0, while npm has 1.0.0 (published 2026-09-30) and the changelog announces 1.0. The GitHub releases page showed 0.12.4 (21 July 2026) as its newest release when checked."
        ],
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
      "live": {
        "slug": "cloudflare-sandbox-sdk",
        "vendorStatus": {
          "page": "https://www.cloudflarestatus.com",
          "indicator": "major",
          "summary": "Partial System Outage",
          "checkedAt": "2026-10-09T10:41:29.713688294Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "cloudflare/sandbox-sdk",
            "version": "@cloudflare/sandbox@1.0.0",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:05:58.738938125Z"
          },
          {
            "registry": "npm",
            "name": "@cloudflare/sandbox",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:05:55.495012518Z"
          }
        ],
        "githubStars": 1147,
        "npmWeekly": 801244,
        "securityTxt": {
          "url": "https://cloudflare.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:39:03.720889469Z"
        },
        "llmsTxt": {
          "url": "https://developers.cloudflare.com/sandbox/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:17.587280212Z"
        },
        "domain": {
          "domain": "cloudflare.com",
          "registered": "2009-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/cloudflare.com",
          "checkedAt": "2026-10-04T13:06:22.743038628Z"
        },
        "pages": [
          {
            "url": "https://developers.cloudflare.com/changelog/?product=sandbox",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:34.044619169Z",
            "changedAt": "2026-10-08T18:17:34.044619169Z",
            "fingerprint": "cd28bcd1f0d9"
          },
          {
            "url": "https://developers.cloudflare.com/containers/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:38.095408277Z",
            "changedAt": "2026-10-06T16:07:26.756927967Z",
            "fingerprint": "f742d2e03f78"
          },
          {
            "url": "https://developers.cloudflare.com/workers/platform/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:46.027175456Z",
            "changedAt": "2026-10-08T18:17:46.027175456Z",
            "fingerprint": "209295c7da6d"
          }
        ],
        "updatedAt": "2026-10-09T10:41:29.713688294Z"
      }
    },
    "answer": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category.",
    "b": {
      "slug": "deno-sandbox",
      "name": "Deno Sandbox",
      "vendor": "Deno Land Inc.",
      "vendorUrl": "https://deno.com",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the `@deno/sandbox` JavaScript SDK, the `deno-sandbox` Python SDK or the `deno sandbox` CLI, and launched in beta on 3 February 2026.",
      "url": "https://www.anchorterminal.com/tools/deno-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json",
      "repo": "https://github.com/denoland/sandbox-py",
      "license": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@deno/sandbox"
        },
        {
          "registry": "pypi",
          "name": "deno-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "An organisation access token (prefix `ddo_`) created under Settings in console.deno.com, read by the SDKs from `DENO_DEPLOY_TOKEN` and sent as a Bearer token. The same token manages the organisation's Deno Deploy apps. No scopes or expiry were found in the reviewed docs, the docs say to rotate a leaked token from the dashboard, and all organisation members hold owner permissions. Signup is in a browser.",
      "pricing": "paid",
      "pricingNotes": "Sandboxes need the Pro plan ($20 a month) or above, and the Free plan does not include them. Compute bills through the Deploy meters at $0.10 a CPU-hour and $0.025 a GiB-hour of memory beyond the plan's allowance (50 CPU-hours and 750 GiB-hours on Pro), and volume storage at $0.20 a GiB-month beyond 5 GiB on Pro. Spend limits can be set on paid plans (https://deno.com/deploy/pricing, checked 2026-10-08).",
      "priceSummary": "$0.10 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the sandbox docs, the pricing page or the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 1971,
        "pypiWeekly": 31729,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.deno.com/sandbox/",
      "llmsTxt": "https://docs.deno.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "paid",
        "beta",
        "microvm",
        "typescript",
        "python",
        "cli",
        "llms-txt",
        "status-page",
        "enterprise"
      ],
      "lastRelease": "2026-07-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.3,
        "grade": "D",
        "agentReady": false,
        "rank": 689,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08: the Create page (last modified 28 January 2026) says a default sandbox has no outbound network access, while the Security page of the same date says outbound access is unrestricted unless `allowNet` is set. A reader of the first page would leave egress open. 2 points. https://docs.deno.com/sandbox/create/ and https://docs.deno.com/sandbox/security/"
        ],
        "verdict": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
        "bestFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "strengths": [
          "Secrets are held outside the VM. Code sees a placeholder, and the real value is substituted only on requests to hosts named for that secret",
          "`allowNet` restricts outbound traffic to listed hostnames, wildcard subdomains, ports or IP addresses",
          "Each sandbox is a Firecracker microVM per the product page, with 2 vCPUs, 768 MB to 4 GB of memory and 10 GB of disk",
          "Volumes of 300 MB to 20 GB persist between sandboxes, and read-only snapshots of a volume can boot new sandboxes",
          "Unit prices are public, $0.10 a CPU-hour, $0.025 a GiB-hour of memory and $0.20 a GiB-month of volume storage"
        ],
        "weaknesses": [
          "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found",
          "Sandboxes are not included in the Free plan. Access starts at Pro, $20 a month, after a browser signup",
          "The published OpenAPI document at `api.deno.com/v2/openapi.json` has 34 operations and none for sandboxes, volumes or snapshots",
          "The Create page says a default sandbox has no outbound network access, and the Security page says outbound access is unrestricted by default",
          "Maximum lifetime is 30 minutes, volumes exist only in `ord`, and no API rate limits or 429 guidance were found",
          "Organisation tokens carry no scopes in the reviewed docs, and every organisation member has owner permissions"
        ],
        "agentNotes": [
          "Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above",
          "Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted",
          "Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder",
          "The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes",
          "Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region",
          "`exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 35
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install @deno/sandbox  # or pip install deno-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/deno-sandbox"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active CPU beyond plan allowance",
          "unit": "vcpu-hour",
          "usd": 0.1,
          "note": "Memory extra at $0.025 a GiB-hour"
        },
        {
          "item": "Volume storage beyond plan allowance",
          "unit": "gb-month",
          "usd": 0.2,
          "note": "Priced per GiB"
        },
        {
          "item": "Pro plan, the lowest that includes sandboxes",
          "unit": "month",
          "usd": 20,
          "note": "Includes 50 CPU-hours, 750 GiB-hours of memory and 5 GiB of volume storage"
        }
      ],
      "provenance": {
        "legalEntity": "Deno Land Inc.",
        "domain": "deno.com",
        "domainRegistered": "1999-03-09",
        "endpointOnVendorDomain": false,
        "terms": "https://docs.deno.com/deploy/terms_and_conditions/",
        "privacy": "https://docs.deno.com/deploy/privacy_policy/",
        "statusPage": "https://denostatus.com",
        "changelog": "https://docs.deno.com/deploy/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Deno Deploy terms and conditions (last modified 30 September 2026) name Deno Land Inc. and govern the Deploy services, of which Sandbox is a part. No separate sandbox terms were found.",
          "The privacy policy (last modified 30 September 2026) gives Deno Land Inc., 1111 6th Ave Ste 550, PMB 702973, San Diego CA 92101. A DPA is listed under Enterprise only, and no public copy was found.",
          "The Python SDK's default sandbox endpoint is `\u003cregion\u003e.sandbox-api.deno.net`, a second domain of the vendor's, while listing and volumes go through console.deno.com.",
          "deno.com/.well-known/security.txt gives deploy@deno.com and a policy link and has no Expires field, which RFC 9116 requires. It is recorded as valid to match other listings with the same gap. The policy page gives security@deno.com.",
          "RDAP for deno.com gives a registration date of 1999-03-09.",
          "The Deploy changelog's newest entry is dated 12 March 2026."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/deno-sandbox.json",
      "live": {
        "slug": "deno-sandbox",
        "vendorStatus": {
          "page": "https://denostatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:48.013369722Z"
        },
        "updatedAt": "2026-10-09T07:57:48.013369722Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Cloudflare",
        "b": "Deno Land Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-07-22",
        "name": "Last release"
      },
      {
        "a": "2025-09-12",
        "b": "2026-09-30",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "2026-09-30",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.1k stars, 723k npm/wk",
        "b": "6 stars, 2k npm/wk, 32k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category.",
        "question": "Which is better for AI agents, Cloudflare Sandbox SDK or Deno Sandbox?"
      },
      {
        "answer": "No hosted endpoint is listed for Cloudflare Sandbox SDK. No hosted endpoint is listed for Deno Sandbox.",
        "question": "Can an agent call Cloudflare Sandbox SDK and Deno Sandbox without installing anything?"
      },
      {
        "answer": "Cloudflare Sandbox SDK is open source (Apache-2.0). No open-source release is listed for Deno Sandbox.",
        "question": "Are Cloudflare Sandbox SDK and Deno Sandbox open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 87 against 48",
          "Schema \u0026 documentation, 77 against 66",
          "Payments \u0026 pricing, 30 against 20",
          "Maintenance \u0026 community, 70 against 45",
          "Transparency \u0026 trust, 70 against 58"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.",
        "slug": "cloudflare-sandbox-sdk",
        "watchFor": "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth"
      },
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "slug": "deno-sandbox",
        "watchFor": "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-cloudflare-sandbox-sdk.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Cloudflare Sandbox SDK",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-cloudflare-sandbox-sdk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk.json",
        "title": "Blaxel Sandboxes vs Cloudflare Sandbox SDK",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.json",
        "title": "Blaxel Sandboxes vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.json",
        "title": "Cloudflare Sandbox SDK vs Daytona",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b.json",
        "title": "Cloudflare Sandbox SDK vs E2B",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle.json",
        "title": "Cloudflare Sandbox SDK vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.json",
        "title": "Cloudflare Sandbox SDK vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.json",
        "title": "Cloudflare Sandbox SDK vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.json",
        "title": "Cloudflare Sandbox SDK vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-sprites.json",
        "title": "Cloudflare Sandbox SDK vs Sprites",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.json",
        "title": "Daytona vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.json",
        "title": "Deno Sandbox vs E2B",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.json",
        "title": "Deno Sandbox vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
        "title": "Deno Sandbox vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.json",
        "title": "Deno Sandbox vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.json",
        "title": "Deno Sandbox vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.json",
        "title": "Deno Sandbox vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.json",
        "title": "Deno Sandbox vs Sprites",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.json",
        "title": "Deno Sandbox vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.json",
        "title": "Deno Sandbox vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-cloudflare-sandbox-sdk.json",
        "title": "Agent 37 Cloud vs Cloudflare Sandbox SDK",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-cloudflare-sandbox-sdk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.json",
        "title": "Agent 37 Cloud vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox"
      }
    ],
    "scores": [
      {
        "by": 39,
        "cloudflare-sandbox-sdk": 87,
        "deno-sandbox": 48,
        "edge": "cloudflare-sandbox-sdk",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 11,
        "cloudflare-sandbox-sdk": 77,
        "deno-sandbox": 66,
        "edge": "cloudflare-sandbox-sdk",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 3,
        "cloudflare-sandbox-sdk": 63,
        "deno-sandbox": 60,
        "edge": "cloudflare-sandbox-sdk",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 4,
        "cloudflare-sandbox-sdk": 65,
        "deno-sandbox": 61,
        "edge": "cloudflare-sandbox-sdk",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 10,
        "cloudflare-sandbox-sdk": 30,
        "deno-sandbox": 20,
        "edge": "cloudflare-sandbox-sdk",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 25,
        "cloudflare-sandbox-sdk": 70,
        "deno-sandbox": 45,
        "edge": "cloudflare-sandbox-sdk",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 12,
        "cloudflare-sandbox-sdk": 70,
        "deno-sandbox": 58,
        "edge": "cloudflare-sandbox-sdk",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category. Both do sandbox code.",
    "verdicts": {
      "cloudflare-sandbox-sdk": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
      "deno-sandbox": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox",
    "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.md",
    "slim": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.min.md"
  },
  "markdown": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category. Both do sandbox code.\n\n- Cloudflare Sandbox SDK: grade B, 67.5/100, rank #231 of 842. Markdown https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md · JSON https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json\n- Deno Sandbox: grade D, 50.3/100, rank #689 of 842. Markdown https://www.anchorterminal.com/tools/deno-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json\n\n## Which one, for what\n\n### Cloudflare Sandbox SDK (B)\n\nGood for: Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.\n\nAhead on:\n- Reliability, 87 against 48\n- Schema \u0026 documentation, 77 against 66\n- Payments \u0026 pricing, 30 against 20\n- Maintenance \u0026 community, 70 against 45\n- Transparency \u0026 trust, 70 against 58\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth\n\n### Deno Sandbox (D)\n\nGood for: Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.\n\nWatch for: Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found\n\n\n## Score by category\n\n| Category | Weight | Cloudflare Sandbox SDK | Deno Sandbox | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 87 | 48 | Cloudflare Sandbox SDK +39 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 66 | Cloudflare Sandbox SDK +11 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 60 | Cloudflare Sandbox SDK +3 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 61 | Cloudflare Sandbox SDK +4 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 20 | Cloudflare Sandbox SDK +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 45 | Cloudflare Sandbox SDK +25 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 58 | Cloudflare Sandbox SDK +12 |\n| Negative events | ≤15 | 0 | -2 | |\n| **Total** | | **67.5 · B** | **50.3 · D** | |\n\n## Facts side by side\n\n| Fact | Cloudflare Sandbox SDK | Deno Sandbox |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Cloudflare | Deno Land Inc. |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  | HTTP |\n| Auth | None | API key |\n| Pricing | Paid | Paid |\n| x402 | no | no |\n| Licence | Apache-2.0 | Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-07-22 |\n| Terms last updated | 2025-09-12 | 2026-09-30 |\n| Privacy policy last updated | no date given | 2026-09-30 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | yes | yes |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 1.1k stars, 723k npm/wk | 6 stars, 2k npm/wk, 32k PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Cloudflare Sandbox SDK.** Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.\n\n**Deno Sandbox.** Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.\n\n## Before you call either\n\n### Cloudflare Sandbox SDK\n\n1. Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets\n2. Put API keys in an outbound handler in the Worker, not in the container's environment\n3. Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default\n4. Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs\n5. Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026\n\n### Deno Sandbox\n\n1. Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above\n2. Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted\n3. Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder\n4. The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes\n5. Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region\n6. `exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret\n\n## Questions\n\n### Which is better for AI agents, Cloudflare Sandbox SDK or Deno Sandbox?\n\nCloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category.\n\n### Can an agent call Cloudflare Sandbox SDK and Deno Sandbox without installing anything?\n\nNo hosted endpoint is listed for Cloudflare Sandbox SDK. No hosted endpoint is listed for Deno Sandbox.\n\n### Are Cloudflare Sandbox SDK and Deno Sandbox open source?\n\nCloudflare Sandbox SDK is open source (Apache-2.0). No open-source release is listed for Deno Sandbox.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.json, and with the fewest tokens: https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"cloudflare-sandbox-sdk\", \"b\": \"deno-sandbox\"}`. From a terminal: `anchor compare cloudflare-sandbox-sdk deno-sandbox`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json and https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json\n\n## Other comparisons with Cloudflare Sandbox SDK or Deno Sandbox\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-cloudflare-sandbox-sdk.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.md)\n- [Blaxel Sandboxes vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk.md)\n- [Blaxel Sandboxes vs Deno Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.md)\n- [Cloudflare Sandbox SDK vs Daytona](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.md)\n- [Cloudflare Sandbox SDK vs E2B](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b.md)\n- [Cloudflare Sandbox SDK vs Freestyle](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Modal Sandboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.md)\n- [Cloudflare Sandbox SDK vs Morph Cloud](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.md)\n- [Cloudflare Sandbox SDK vs Runloop Devboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.md)\n- [Cloudflare Sandbox SDK vs Sprites](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-sprites.md)\n- [Cloudflare Sandbox SDK vs Together Code Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox.md)\n- [Cloudflare Sandbox SDK vs Vercel Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.md)\n- [Daytona vs Deno Sandbox](https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.md)\n- [Deno Sandbox vs E2B](https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.md)\n- [Deno Sandbox vs Freestyle](https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md)\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs Modal Sandboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.md)\n- [Deno Sandbox vs Morph Cloud](https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.md)\n- [Deno Sandbox vs Runloop Devboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.md)\n- [Deno Sandbox vs Sprites](https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.md)\n- [Deno Sandbox vs Together Code Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md)\n- [Deno Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/agent37-vs-cloudflare-sandbox-sdk.md)\n- [Agent 37 Cloud vs Deno Sandbox](https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cloudflare Sandbox SDK vs Deno Sandbox",
        "url": ""
      }
    ],
    "description": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cloudflare Sandbox SDK B 67.5",
      "Deno Sandbox D 50.3",
      "scores"
    ],
    "h1": "Cloudflare Sandbox SDK vs Deno Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/compare-cloudflare-sandbox-sdk-vs-deno-sandbox.png",
    "path": "/compare/cloudflare-sandbox-sdk-vs-deno-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cloudflare Sandbox SDK vs Deno Sandbox for AI agents, B 67.5 vs D 50.3",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox"
  },
  "tokens": {
    "markdown": 2600,
    "slim": 630
  },
  "version": 1
}
