{
  "data": {
    "a": {
      "slug": "cloudflare-sandbox-sdk",
      "name": "Cloudflare Sandbox SDK",
      "vendor": "Cloudflare",
      "vendorUrl": "https://developers.cloudflare.com/sandbox/",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "TypeScript library for running sandboxed Linux containers from a Cloudflare Worker.",
      "url": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk",
      "markdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json",
      "repo": "https://github.com/cloudflare/sandbox-sdk",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@cloudflare/sandbox"
        }
      ],
      "auth": "none",
      "authNotes": "There's no hosted API. The sandbox sits behind a Worker you deploy, so it has whatever auth you put in front of it, and the starter template has none. Deploying needs a Cloudflare account through Wrangler. Version 1.0 adds preview ports with custom hostnames and authentication.",
      "pricing": "paid",
      "pricingNotes": "Needs the Workers Paid plan, $5 a month minimum (https://developers.cloudflare.com/workers/platform/pricing/). Billed as Containers plus Workers and Durable Objects. Containers include 25 GiB-hours of memory, 375 vCPU-minutes and 200 GB-hours of disk a month, then $0.0000025 a GiB-second of memory, $0.000020 a vCPU-second of CPU used and $0.00000007 a GB-second of disk, in 10 ms steps while the container runs. Egress is $0.025 a GB in North America and Europe after 1 TB (https://developers.cloudflare.com/containers/pricing/). Durable Objects add $0.15 per million requests and $12.50 per million GB-seconds after the included amounts (https://developers.cloudflare.com/workers/platform/pricing/).",
      "priceSummary": "$0.072 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1100,
        "npmWeekly": 722733,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developers.cloudflare.com/sandbox/",
      "llmsTxt": "https://developers.cloudflare.com/sandbox/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "typescript",
        "open-source",
        "llms-txt"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.5,
        "grade": "B",
        "agentReady": false,
        "rank": 206,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 5,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
        "bestFor": "Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.",
        "strengths": [
          "Each sandbox runs in its own VM with a separate filesystem, process space and network stack",
          "Outbound handlers hold credentials in the Worker and inject them, so the container never sees them",
          "Egress can be turned off or limited to a deny-by-default `allowedHosts` list",
          "CPU billed on use at $0.000020 a vCPU-second, with a monthly allowance on Workers Paid",
          "Apache-2.0, with CodeQL and passing CI on main"
        ],
        "weaknesses": [
          "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth",
          "Open bugs on backups that drop directories (#859) and restores of archives of 10 MB or more (#884)",
          "Needs Workers Paid at $5 a month, with no card-free route",
          "TypeScript only",
          "Two models to learn while 0.x and 1.0 overlap until 31 December 2026"
        ],
        "agentNotes": [
          "Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets",
          "Put API keys in an outbound handler in the Worker, not in the container's environment",
          "Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default",
          "Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs",
          "Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.5
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 45
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm create cloudflare@latest -- my-sandbox --template=cloudflare/sandbox-sdk/examples/minimal"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/cloudflare-sandbox-sdk"
      },
      "sameCompany": [
        "cloudflare-web-search",
        "cloudflare-mcp",
        "cloudflare-email-service",
        "cloudflare-r2",
        "cloudflare-clef"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Container CPU",
          "unit": "vcpu-hour",
          "usd": 0.072,
          "note": "$0.000020 a vCPU-second of CPU used, after 375 vCPU-minutes a month"
        },
        {
          "item": "Workers Paid plan",
          "unit": "month",
          "usd": 5,
          "note": "Minimum charge"
        },
        {
          "item": "Egress, North America and Europe",
          "unit": "gb",
          "usd": 0.025,
          "note": "After 1 TB a month"
        }
      ],
      "provenance": {
        "legalEntity": "Cloudflare, Inc.",
        "domain": "cloudflare.com",
        "domainRegistered": "2009-02-17",
        "endpointOnVendorDomain": null,
        "terms": "https://www.cloudflare.com/terms/",
        "privacy": "https://www.cloudflare.com/privacypolicy/",
        "statusPage": "https://www.cloudflarestatus.com",
        "changelog": "https://developers.cloudflare.com/changelog/?product=sandbox",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The self-serve subscription agreement (updated 12 September 2025) names Cloudflare, Inc., 101 Townsend St., San Francisco.",
          "There's no vendor endpoint to check. Sandboxes are reached through a Worker on your own route or workers.dev subdomain.",
          "security.txt lists HackerOne and a disclosure policy, but we didn't see an Expires field.",
          "The GitHub README still says the SDK is in active development and APIs may change before v1.0, while npm has 1.0.0 (published 2026-09-30) and the changelog announces 1.0. The GitHub releases page showed 0.12.4 (21 July 2026) as its newest release when checked."
        ],
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
      "live": {
        "slug": "cloudflare-sandbox-sdk",
        "vendorStatus": {
          "page": "https://www.cloudflarestatus.com",
          "indicator": "major",
          "summary": "Partial System Outage",
          "checkedAt": "2026-10-08T20:22:23.932738358Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "cloudflare/sandbox-sdk",
            "version": "@cloudflare/sandbox@1.0.0",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:05:58.738938125Z"
          },
          {
            "registry": "npm",
            "name": "@cloudflare/sandbox",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:05:55.495012518Z"
          }
        ],
        "githubStars": 1147,
        "npmWeekly": 801244,
        "securityTxt": {
          "url": "https://cloudflare.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-08T15:39:03.720889469Z"
        },
        "llmsTxt": {
          "url": "https://developers.cloudflare.com/sandbox/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:17.587280212Z"
        },
        "domain": {
          "domain": "cloudflare.com",
          "registered": "2009-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/cloudflare.com",
          "checkedAt": "2026-10-04T13:06:22.743038628Z"
        },
        "pages": [
          {
            "url": "https://developers.cloudflare.com/changelog/?product=sandbox",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:34.044619169Z",
            "changedAt": "2026-10-08T18:17:34.044619169Z",
            "fingerprint": "cd28bcd1f0d9"
          },
          {
            "url": "https://developers.cloudflare.com/containers/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:38.095408277Z",
            "changedAt": "2026-10-06T16:07:26.756927967Z",
            "fingerprint": "f742d2e03f78"
          },
          {
            "url": "https://developers.cloudflare.com/workers/platform/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:17:46.027175456Z",
            "changedAt": "2026-10-08T18:17:46.027175456Z",
            "fingerprint": "209295c7da6d"
          }
        ],
        "updatedAt": "2026-10-08T20:22:23.932738358Z"
      }
    },
    "answer": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category.",
    "b": {
      "slug": "morph-cloud",
      "name": "Morph Cloud",
      "vendor": "Morph Labs",
      "vendorUrl": "https://cloud.morph.so",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Cloud virtual machines for AI agents from Morph Labs. Instances boot from snapshots and can be paused with memory intact, branched into copies, and driven through a REST API, Python and TypeScript SDKs and a CLI.",
      "url": "https://www.anchorterminal.com/tools/morph-cloud",
      "markdownUrl": "https://www.anchorterminal.com/tools/morph-cloud.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/morph-cloud.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/morph-cloud.json",
      "repo": "https://github.com/morph-labs/morph-python-sdk",
      "license": "Proprietary hosted service with no published terms found. The Python and TypeScript SDKs are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://cloud.morph.so/api",
      "packages": [
        {
          "registry": "pypi",
          "name": "morphcloud"
        },
        {
          "registry": "npm",
          "name": "morphcloud"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key on https://cloud.morph.so/api, created in the dashboard at cloud.morph.so/web/keys after a browser signup. The SDKs and CLI read `MORPH_API_KEY`. Keys are bound to an organisation and can be listed and deleted through the API. An agent inside a devbox can use a devbox agent token limited to that devbox and to named scopes.",
      "pricing": "usage",
      "pricingNotes": "Billed in Morph Compute Units. 1 MCU is 1 vCPU-hour with 4 GB RAM-hours and 16 GB disk-hours, or 5 TB snapshot-hours, at a stated standard rate of $0.05. The Free plan is $0 a month with 0 MCUs, so compute needs a purchase. Developer is $40 a month with 1,000 MCUs and Team is $250 a month with 7,500, with more billed as used (https://cloud.morph.so/web/pricing, checked 2026-10-08). No sandbox or free credit was found that lets an agent start without paying.",
      "priceSummary": "$0.05 / unit",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3,
        "npmWeekly": 339,
        "pypiWeekly": 13199,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://cloud.morph.so/docs",
      "llmsTxt": "https://cloud.morph.so/docs/llms.txt",
      "openapi": "https://cloud.morph.so/api/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "cli",
        "status-page"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.8,
        "grade": "D",
        "agentReady": false,
        "rank": 589,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 58,
          "payments": 20,
          "reliability": 63,
          "schema": 72,
          "security": 39,
          "transparency": 25
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Pause and snapshot keep memory and running processes, and one call branches an instance into several copies. A public OpenAPI file covers 69 operations. No terms of service, privacy policy or security page was found, the free plan includes no compute credit, and the changelog holds one entry from November 2024.",
        "bestFor": "Agents that need to checkpoint and fork a running machine with memory intact, for parallel attempts, evaluations or reinforcement learning rollouts.",
        "strengths": [
          "Pause and snapshot preserve memory and running processes, and a paused instance is billed for its snapshot only",
          "Branch creates a snapshot and starts a chosen number of copies in one call",
          "Public OpenAPI 3.1 file with 69 operations, plus llms.txt and llms-full.txt",
          "Devbox agent tokens are bound to one devbox and carry named scopes",
          "Status page shows 90 days without downtime to 8 October 2026 and no incident since 5 December 2025"
        ],
        "weaknesses": [
          "No terms of service, privacy policy, DPA or subprocessor list found on morph.so or cloud.morph.so",
          "The Free plan starts with 0 MCUs, so compute needs a purchase, and signup is in a browser",
          "No request rate limits, SLA or error-code reference in the reviewed documentation",
          "The changelog has one entry, the beta release of 19 November 2024",
          "The TypeScript SDK's last release is 0.0.20 of 6 October 2025",
          "No security.txt, disclosure policy or certification found, and no isolation technology is named in the docs"
        ],
        "agentNotes": [
          "Set `ttl_seconds` and `ttl_action` when starting an instance. Nothing in the docs stops an instance with no TTL from billing MCUs",
          "Pass `auth_mode: api_key` when exposing an HTTP service. The default is `none`, which makes the URL public",
          "Enable `wake_on_ssh` before calling exec on an instance that may be paused. There is no separate exec wake setting",
          "Use `/api/instance/list` and `/api/snapshot/list` with `page` and `limit` (default 50, maximum 1,000). The plain list routes return everything",
          "On a 503 from snapshot, branch, pause or reboot, wait for the `Retry-After` value before repeating the call"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.8
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 58,
          "payments": 20,
          "reliability": 63,
          "schema": 72,
          "security": 39,
          "transparency": 14
        },
        "provenanceScore": 35
      },
      "connect": {
        "install": "pip install morphcloud  # or npm install morphcloud@0.0.20",
        "http": "curl -sS -H \"Authorization: Bearer $MORPH_API_KEY\" \\\n  https://cloud.morph.so/api/snapshot/snapshot_your_snapshot_id"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/morph-cloud"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Morph Compute Unit",
          "unit": "compute-unit",
          "usd": 0.05,
          "note": "1 vCPU-hour with 4 GB RAM-hours and 16 GB disk-hours, or 5 TB snapshot-hours"
        },
        {
          "item": "Instance compute",
          "unit": "vcpu-hour",
          "usd": 0.05,
          "note": "Includes 4 GB RAM and 16 GB disk per vCPU. MCUs are the largest of the three ratios"
        },
        {
          "item": "Developer plan",
          "unit": "month",
          "usd": 40,
          "note": "1,000 MCUs included"
        },
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 250,
          "note": "7,500 MCUs included"
        }
      ],
      "provenance": {
        "legalEntity": "",
        "domain": "morph.so",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "https://status.cloud.morph.so",
        "changelog": "https://cloud.morph.so/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No terms of service, service agreement or privacy policy was found. /terms and /privacy return 404 on cloud.morph.so and www.morph.so, and the morph.so site map lists only the home page, blog and careers, so both fields are left out.",
          "No registered legal entity was found. The SDK licence reads Copyright 2024 Morph Labs.",
          "The API answers at cloud.morph.so/api and exposed services at morphcloud.io addresses, per the docs.",
          "security.txt returns 404 on cloud.morph.so and www.morph.so.",
          "No RDAP service answers for the .so registry, so the registration date is blank.",
          "The status page's own data names Morph Labs, cloud.morph.so and support@morph.so. The page is not linked from the docs."
        ],
        "score": 35
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/morph-cloud.json",
      "live": {
        "slug": "morph-cloud",
        "probe": {
          "target": "https://cloud.morph.so/api",
          "method": "get",
          "lastAt": "2026-10-08T20:21:20.626793322Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 166,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 139,
          "p95ms24h": 272,
          "samples24h": 32,
          "samples30d": 32,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 32,
              "ok": 32
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.cloud.morph.so",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:48.969384653Z"
        },
        "pages": [
          {
            "url": "https://cloud.morph.so/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:17.092678678Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a911488f7933"
          },
          {
            "url": "https://cloud.morph.so/web/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:19.269281319Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fc791aaa2ac"
          }
        ],
        "updatedAt": "2026-10-08T20:21:20.626793322Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Cloudflare",
        "b": "Morph Labs",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://cloud.morph.so/api",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0",
        "b": "Proprietary hosted service with no published terms found. The Python and TypeScript SDKs are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-30",
        "b": "2026-09-01",
        "name": "Last release"
      },
      {
        "a": "2025-09-12",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no date given",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.1k stars, 723k npm/wk",
        "b": "3 stars, 339 npm/wk, 13k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category.",
        "question": "Which is better for AI agents, Cloudflare Sandbox SDK or Morph Cloud?"
      },
      {
        "answer": "No hosted endpoint is listed for Cloudflare Sandbox SDK. Morph Cloud has a hosted endpoint at https://cloud.morph.so/api.",
        "question": "Can an agent call Cloudflare Sandbox SDK and Morph Cloud without installing anything?"
      },
      {
        "answer": "Cloudflare Sandbox SDK is open source (Apache-2.0). No open-source release is listed for Morph Cloud.",
        "question": "Are Cloudflare Sandbox SDK and Morph Cloud open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 87 against 63",
          "Schema \u0026 documentation, 77 against 72",
          "Security \u0026 auth, 65 against 39",
          "Payments \u0026 pricing, 30 against 20",
          "Maintenance \u0026 community, 70 against 58",
          "Transparency \u0026 trust, 70 against 25"
        ],
        "also": [
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.",
        "slug": "cloudflare-sandbox-sdk",
        "watchFor": "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth"
      },
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agents that need to checkpoint and fork a running machine with memory intact, for parallel attempts, evaluations or reinforcement learning rollouts.",
        "slug": "morph-cloud",
        "watchFor": "No terms of service, privacy policy, DPA or subprocessor list found on morph.so or cloud.morph.so"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk.json",
        "title": "Blaxel Sandboxes vs Cloudflare Sandbox SDK",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-morph-cloud.json",
        "title": "Blaxel Sandboxes vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.json",
        "title": "Cloudflare Sandbox SDK vs Daytona",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b.json",
        "title": "Cloudflare Sandbox SDK vs E2B",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.json",
        "title": "Cloudflare Sandbox SDK vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.json",
        "title": "Cloudflare Sandbox SDK vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.json",
        "title": "Daytona vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-morph-cloud.json",
        "title": "E2B vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud.json",
        "title": "Modal Sandboxes vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-runloop.json",
        "title": "Morph Cloud vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox.json",
        "title": "Morph Cloud vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-cloudflare-sandbox-sdk.json",
        "title": "Agent 37 Cloud vs Cloudflare Sandbox SDK",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-cloudflare-sandbox-sdk"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-morph-cloud.json",
        "title": "Agent 37 Cloud vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-morph-cloud"
      }
    ],
    "scores": [
      {
        "by": 24,
        "cloudflare-sandbox-sdk": 87,
        "edge": "cloudflare-sandbox-sdk",
        "key": "reliability",
        "morph-cloud": 63,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "cloudflare-sandbox-sdk": 77,
        "edge": "cloudflare-sandbox-sdk",
        "key": "schema",
        "morph-cloud": 72,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 2,
        "cloudflare-sandbox-sdk": 63,
        "edge": "cloudflare-sandbox-sdk",
        "key": "ergonomics",
        "morph-cloud": 61,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 26,
        "cloudflare-sandbox-sdk": 65,
        "edge": "cloudflare-sandbox-sdk",
        "key": "security",
        "morph-cloud": 39,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 10,
        "cloudflare-sandbox-sdk": 30,
        "edge": "cloudflare-sandbox-sdk",
        "key": "payments",
        "morph-cloud": 20,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "cloudflare-sandbox-sdk": 70,
        "edge": "cloudflare-sandbox-sdk",
        "key": "maintenance",
        "morph-cloud": 58,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 45,
        "cloudflare-sandbox-sdk": 70,
        "edge": "cloudflare-sandbox-sdk",
        "key": "transparency",
        "morph-cloud": 25,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category. Both do sandbox code.",
    "verdicts": {
      "cloudflare-sandbox-sdk": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
      "morph-cloud": "Pause and snapshot keep memory and running processes, and one call branches an instance into several copies. A public OpenAPI file covers 69 operations. No terms of service, privacy policy or security page was found, the free plan includes no compute credit, and the changelog holds one entry from November 2024."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud",
    "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.md",
    "slim": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.min.md"
  },
  "markdown": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category. Both do sandbox code.\n\n- Cloudflare Sandbox SDK: grade B, 67.5/100, rank #206 of 722. Markdown https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md · JSON https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json\n- Morph Cloud: grade D, 50.8/100, rank #589 of 722. Markdown https://www.anchorterminal.com/tools/morph-cloud.md · JSON https://www.anchorterminal.com/api/v1/tools/morph-cloud.json\n\n## Which one, for what\n\n### Cloudflare Sandbox SDK (B)\n\nGood for: Agents already built on Workers and Durable Objects that want sandboxes in the same account with credential injection at the edge.\n\nAhead on:\n- Reliability, 87 against 63\n- Schema \u0026 documentation, 77 against 72\n- Security \u0026 auth, 65 against 39\n- Payments \u0026 pricing, 30 against 20\n- Maintenance \u0026 community, 70 against 58\n- Transparency \u0026 trust, 70 against 25\n\nAlso in its favour:\n- No key needed to call it\n- Open source\n\nWatch for: No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth\n\n### Morph Cloud (D)\n\nGood for: Agents that need to checkpoint and fork a running machine with memory intact, for parallel attempts, evaluations or reinforcement learning rollouts.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: No terms of service, privacy policy, DPA or subprocessor list found on morph.so or cloud.morph.so\n\n\n## Score by category\n\n| Category | Weight | Cloudflare Sandbox SDK | Morph Cloud | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 87 | 63 | Cloudflare Sandbox SDK +24 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 72 | Cloudflare Sandbox SDK +5 |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 61 | Cloudflare Sandbox SDK +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 39 | Cloudflare Sandbox SDK +26 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 20 | Cloudflare Sandbox SDK +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 58 | Cloudflare Sandbox SDK +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 70 | 25 | Cloudflare Sandbox SDK +45 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **67.5 · B** | **50.8 · D** | |\n\n## Facts side by side\n\n| Fact | Cloudflare Sandbox SDK | Morph Cloud |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Cloudflare | Morph Labs |\n| Hosted endpoint | no (local only) | `https://cloud.morph.so/api` |\n| Transports |  | HTTP |\n| Auth | None | API key |\n| Pricing | Paid | Pay per use |\n| x402 | no | no |\n| Licence | Apache-2.0 | Proprietary hosted service with no published terms found. The Python and TypeScript SDKs are Apache-2.0 |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| Last release | 2026-09-30 | 2026-09-01 |\n| Terms last updated | 2025-09-12 | no document linked |\n| Privacy policy last updated | no date given | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | yes |  |\n| Terms restrict benchmarking | not found in the text |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 1.1k stars, 723k npm/wk | 3 stars, 339 npm/wk, 13k PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Cloudflare Sandbox SDK.** Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.\n\n**Morph Cloud.** Pause and snapshot keep memory and running processes, and one call branches an instance into several copies. A public OpenAPI file covers 69 operations. No terms of service, privacy policy or security page was found, the free plan includes no compute credit, and the changelog holds one entry from November 2024.\n\n## Before you call either\n\n### Cloudflare Sandbox SDK\n\n1. Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets\n2. Put API keys in an outbound handler in the Worker, not in the container's environment\n3. Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default\n4. Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs\n5. Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026\n\n### Morph Cloud\n\n1. Set `ttl_seconds` and `ttl_action` when starting an instance. Nothing in the docs stops an instance with no TTL from billing MCUs\n2. Pass `auth_mode: api_key` when exposing an HTTP service. The default is `none`, which makes the URL public\n3. Enable `wake_on_ssh` before calling exec on an instance that may be paused. There is no separate exec wake setting\n4. Use `/api/instance/list` and `/api/snapshot/list` with `page` and `limit` (default 50, maximum 1,000). The plain list routes return everything\n5. On a 503 from snapshot, branch, pause or reboot, wait for the `Retry-After` value before repeating the call\n\n## Questions\n\n### Which is better for AI agents, Cloudflare Sandbox SDK or Morph Cloud?\n\nCloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category.\n\n### Can an agent call Cloudflare Sandbox SDK and Morph Cloud without installing anything?\n\nNo hosted endpoint is listed for Cloudflare Sandbox SDK. Morph Cloud has a hosted endpoint at https://cloud.morph.so/api.\n\n### Are Cloudflare Sandbox SDK and Morph Cloud open source?\n\nCloudflare Sandbox SDK is open source (Apache-2.0). No open-source release is listed for Morph Cloud.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.json, and with the fewest tokens: https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"cloudflare-sandbox-sdk\", \"b\": \"morph-cloud\"}`. From a terminal: `anchor compare cloudflare-sandbox-sdk morph-cloud`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json and https://www.anchorterminal.com/api/v1/tools/morph-cloud.json\n\n## Other comparisons with Cloudflare Sandbox SDK or Morph Cloud\n\n- [Blaxel Sandboxes vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk.md)\n- [Blaxel Sandboxes vs Morph Cloud](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-morph-cloud.md)\n- [Cloudflare Sandbox SDK vs Daytona](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.md)\n- [Cloudflare Sandbox SDK vs E2B](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Modal Sandboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.md)\n- [Cloudflare Sandbox SDK vs Runloop Devboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.md)\n- [Cloudflare Sandbox SDK vs Vercel Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.md)\n- [Daytona vs Morph Cloud](https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.md)\n- [E2B vs Morph Cloud](https://www.anchorterminal.com/compare/e2b-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Modal Sandboxes vs Morph Cloud](https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud.md)\n- [Morph Cloud vs Runloop Devboxes](https://www.anchorterminal.com/compare/morph-cloud-vs-runloop.md)\n- [Morph Cloud vs Vercel Sandbox](https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/agent37-vs-cloudflare-sandbox-sdk.md)\n- [Agent 37 Cloud vs Morph Cloud](https://www.anchorterminal.com/compare/agent37-vs-morph-cloud.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cloudflare Sandbox SDK vs Morph Cloud",
        "url": ""
      }
    ],
    "description": "Cloudflare Sandbox SDK scores 67.5 (B) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cloudflare Sandbox SDK B 67.5",
      "Morph Cloud D 50.8",
      "scores"
    ],
    "h1": "Cloudflare Sandbox SDK vs Morph Cloud",
    "image": "https://www.anchorterminal.com/assets/og/compare-cloudflare-sandbox-sdk-vs-morph-cloud.png",
    "path": "/compare/cloudflare-sandbox-sdk-vs-morph-cloud",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cloudflare Sandbox SDK vs Morph Cloud for AI agents, B 67.5 vs D 50.8",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud"
  },
  "tokens": {
    "markdown": 2300,
    "slim": 730
  },
  "version": 1
}
