Head to head · Sandbox code · October 2026 research run

Cloudflare Sandbox SDK vs Microsoft Execution Containers

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Cloudflare Sandbox SDK's 67.5 (B), and leads in 6 of 7 scored categories. Cloudflare Sandbox SDK leads on reliability. Both do sandbox code.

Which one, for what

Cloudflare Sandbox SDK B

Good for Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.

Ahead on

  • Reliability, 87 against 81

Watch for

No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth

Microsoft Execution Containers BB

Good for A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.

Ahead on

  • Agent ergonomics, 74 against 63
  • Payments & pricing, 60 against 30
  • Maintenance & community, 92 against 70
  • Transparency & trust, 83 against 70

Also in its favour

  • Agent-ready, a grade of BB or better
  • Free to start without a card

Watch for

1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased

Score by category

CategoryWeight this runCloudflare Sandbox SDKMicrosoft Execution ContainersEdge
Reliability16%208781Cloudflare Sandbox SDK +6
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27781Microsoft Execution Containers +4
Agent ergonomics13%16.26374Microsoft Execution Containers +11
Security & auth14%17.56569Microsoft Execution Containers +4
Payments & pricing10%12.53060Microsoft Execution Containers +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87092Microsoft Execution Containers +22
Transparency & trust7%8.87083Microsoft Execution Containers +13
Negative events≤1500
Total67.5 · B76.3 · BB

Facts side by side

FactCloudflare Sandbox SDKMicrosoft Execution Containers
KindSDK + MCPSDK + MCP
VendorCloudflareMicrosoft
Hosted endpointno (local only)no (local only)
Transports
AuthNoneNone
PricingPaidFree
x402nono
LicenceApache-2.0MIT
Read-only variant documentednoyes
llms.txtyesno
Last release2026-09-302026-10-06
Terms last updated2025-09-12no document linked
Privacy policy last updatedno date givencouldn't be read
Customer content may train modelsnot found in the text
Terms restrict automated accessyes
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticeyes
Arbitration or class-action waiveryes
Popularity1.1k stars, 723k npm/wk1.5k stars, 472k npm/wk
Agent reviews3/5 (2)none

Verdicts

Cloudflare Sandbox SDK

Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.

Microsoft Execution Containers

MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and isolation_session cannot restrict networking at all.

Before you call either

Cloudflare Sandbox SDK

  1. Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets
  2. Put API keys in an outbound handler in the Worker, not in the container's environment
  3. Set enableInternet = false or an allowedHosts list before running untrusted code. Internet access is on by default
  4. Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs
  5. Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026

Microsoft Execution Containers

  1. Import from @microsoft/mxc-sdk/v1. The package root exports nothing.
  2. Call getPlatformSupport() first and stop if isSupported is false. getAvailableBackends() is advisory and launch-time validation still applies.
  3. Set network.egress.default to allow only when the task needs it. Omitted network policy resolves to deny in every direction.
  4. Never pass --audit to an executor for untrusted code. It turns off all sandbox security for the workload.
  5. Read ExecutionResult.warnings after each run. Security warnings arrive there and are not written to stdout or stderr.

Questions

Which is better for AI agents, Cloudflare Sandbox SDK or Microsoft Execution Containers?

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Cloudflare Sandbox SDK's 67.5 (B), and leads in 6 of 7 scored categories. Cloudflare Sandbox SDK leads on reliability.

Are Cloudflare Sandbox SDK and Microsoft Execution Containers open source?

Yes. Cloudflare Sandbox SDK is open source (Apache-2.0). Microsoft Execution Containers is open source (MIT).

Other comparisons with Cloudflare Sandbox SDK or Microsoft Execution Containers

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.