{
  "data": {
    "a": {
      "slug": "cloudflare-sandbox-sdk",
      "name": "Cloudflare Sandbox SDK",
      "vendor": "Cloudflare",
      "vendorUrl": "https://developers.cloudflare.com/sandbox/",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "TypeScript library for running sandboxed Linux containers from a Cloudflare Worker.",
      "url": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk",
      "markdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json",
      "repo": "https://github.com/cloudflare/sandbox-sdk",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@cloudflare/sandbox"
        }
      ],
      "auth": "none",
      "authNotes": "There's no hosted API. The sandbox sits behind a Worker you deploy, so it has whatever auth you put in front of it, and the starter template has none. Deploying needs a Cloudflare account through Wrangler. Version 1.0 adds preview ports with custom hostnames and authentication.",
      "pricing": "paid",
      "pricingNotes": "Needs the Workers Paid plan, $5 a month minimum (https://developers.cloudflare.com/workers/platform/pricing/). Billed as Containers plus Workers and Durable Objects. Containers include 25 GiB-hours of memory, 375 vCPU-minutes and 200 GB-hours of disk a month, then $0.0000025 a GiB-second of memory, $0.000020 a vCPU-second of CPU used and $0.00000007 a GB-second of disk, in 10 ms steps while the container runs. Egress is $0.025 a GB in North America and Europe after 1 TB (https://developers.cloudflare.com/containers/pricing/). Durable Objects add $0.15 per million requests and $12.50 per million GB-seconds after the included amounts (https://developers.cloudflare.com/workers/platform/pricing/).",
      "priceSummary": "$0.072 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1100,
        "npmWeekly": 722733,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://developers.cloudflare.com/sandbox/",
      "llmsTxt": "https://developers.cloudflare.com/sandbox/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "typescript",
        "open-source",
        "llms-txt"
      ],
      "lastRelease": "2026-09-30",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 67.8,
        "grade": "B",
        "agentReady": false,
        "rank": 137,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 4,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 73
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.",
        "strengths": [
          "Each sandbox runs in its own VM with a separate filesystem, process space and network stack",
          "Outbound handlers hold credentials in the Worker and inject them, so the container never sees them",
          "Egress can be turned off or limited to a deny-by-default `allowedHosts` list",
          "CPU billed on use at $0.000020 a vCPU-second, with a monthly allowance on Workers Paid",
          "Apache-2.0, with CodeQL and passing CI on main"
        ],
        "weaknesses": [
          "No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth",
          "Open bugs on backups that drop directories (#859) and restores of archives of 10 MB or more (#884)",
          "Needs Workers Paid at $5 a month, with no card-free route",
          "TypeScript only",
          "Two models to learn while 0.x and 1.0 overlap until 31 December 2026"
        ],
        "agentNotes": [
          "Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets",
          "Put API keys in an outbound handler in the Worker, not in the container's environment",
          "Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default",
          "Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs",
          "Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 67.8
          }
        ],
        "editorialScores": {
          "ergonomics": 63,
          "maintenance": 70,
          "payments": 30,
          "reliability": 87,
          "schema": 77,
          "security": 65,
          "transparency": 45
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm create cloudflare@latest -- my-sandbox --template=cloudflare/sandbox-sdk/examples/minimal"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/cloudflare-sandbox-sdk"
      },
      "sameCompany": [
        "cloudflare-mcp",
        "cloudflare-r2",
        "cloudflare-clef"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Container CPU",
          "unit": "vcpu-hour",
          "usd": 0.072,
          "note": "$0.000020 a vCPU-second of CPU used, after 375 vCPU-minutes a month"
        },
        {
          "item": "Workers Paid plan",
          "unit": "month",
          "usd": 5,
          "note": "Minimum charge"
        },
        {
          "item": "Egress, North America and Europe",
          "unit": "gb",
          "usd": 0.025,
          "note": "After 1 TB a month"
        }
      ],
      "provenance": {
        "legalEntity": "Cloudflare, Inc.",
        "domain": "cloudflare.com",
        "domainRegistered": "2009-02-17",
        "endpointOnVendorDomain": null,
        "terms": "https://www.cloudflare.com/terms/",
        "privacy": "https://www.cloudflare.com/privacypolicy/",
        "statusPage": "https://www.cloudflarestatus.com",
        "changelog": "https://developers.cloudflare.com/changelog/?product=sandbox",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The self-serve subscription agreement (updated 12 September 2025) names Cloudflare, Inc., 101 Townsend St., San Francisco.",
          "There's no vendor endpoint to check. Sandboxes are reached through a Worker on your own route or workers.dev subdomain.",
          "security.txt lists HackerOne and a disclosure policy, but we didn't see an Expires field.",
          "The GitHub README still says the SDK is in active development and APIs may change before v1.0, while npm has 1.0.0 (published 2026-09-30) and the changelog announces 1.0. The GitHub releases page showed 0.12.4 (21 July 2026) as its newest release when checked."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
      "live": {
        "slug": "cloudflare-sandbox-sdk",
        "vendorStatus": {
          "page": "https://www.cloudflarestatus.com",
          "indicator": "minor",
          "summary": "Minor Service Outage",
          "checkedAt": "2026-10-04T23:49:08.31714726Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "cloudflare/sandbox-sdk",
            "version": "@cloudflare/sandbox@0.12.10",
            "released": "2026-09-23",
            "seenAt": "2026-10-04T16:24:02.293431378Z"
          },
          {
            "registry": "npm",
            "name": "@cloudflare/sandbox",
            "version": "1.0.0",
            "seenAt": "2026-10-04T16:24:01.356030499Z"
          }
        ],
        "githubStars": 1144,
        "npmWeekly": 797840,
        "securityTxt": {
          "url": "https://cloudflare.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:51.95928161Z"
        },
        "llmsTxt": {
          "url": "https://developers.cloudflare.com/sandbox/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:31.097149892Z"
        },
        "domain": {
          "domain": "cloudflare.com",
          "registered": "2009-02-17",
          "source": "https://rdap.verisign.com/com/v1/domain/cloudflare.com",
          "checkedAt": "2026-10-04T13:06:22.743038628Z"
        },
        "pages": [
          {
            "url": "https://developers.cloudflare.com/changelog/?product=sandbox",
            "kind": "deprecations",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:50.869019575Z",
            "changedAt": "2026-10-04T15:42:50.869019575Z",
            "fingerprint": "aa7b5fb58872"
          },
          {
            "url": "https://developers.cloudflare.com/containers/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:42:52.872169011Z",
            "changedAt": "2026-10-03T15:31:01.576635047Z",
            "fingerprint": "a81e9d7bb64a"
          },
          {
            "url": "https://developers.cloudflare.com/workers/platform/pricing/",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:00.847585458Z",
            "changedAt": "2026-10-04T15:43:00.847585458Z",
            "fingerprint": "ea6eab1a375f"
          }
        ],
        "updatedAt": "2026-10-04T23:49:08.31714726Z"
      }
    },
    "b": {
      "slug": "vercel-sandbox",
      "name": "Vercel Sandbox",
      "vendor": "Vercel",
      "vendorUrl": "https://vercel.com/docs/sandbox",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Firecracker microVM sandboxes on Vercel, driven from the `@vercel/sandbox` JavaScript SDK, the Python `vercel` package, a CLI or the REST API.",
      "url": "https://www.anchorterminal.com/tools/vercel-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json",
      "repo": "https://github.com/vercel/sandbox",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.vercel.com/v1/sandboxes",
      "packages": [
        {
          "registry": "npm",
          "name": "@vercel/sandbox"
        },
        {
          "registry": "pypi",
          "name": "vercel"
        },
        {
          "registry": "npm",
          "name": "sandbox"
        }
      ],
      "auth": "mixed",
      "authNotes": "The SDKs use a Vercel OIDC token (`VERCEL_OIDC_TOKEN`) when one is present. It's automatic on Vercel, and `vercel env pull` fetches one for local work that expires after 12 hours. Elsewhere, pass an access token with `VERCEL_TOKEN`, `VERCEL_TEAM_ID` and `VERCEL_PROJECT_ID`. The REST API takes the access token as a Bearer header.",
      "pricing": "freemium",
      "pricingNotes": "Hobby includes 5 hours of Active CPU, 420 GB-hours of memory, 5,000 sandbox creations, 20 GB of transfer and 15 GB of snapshot storage, after which creation pauses until the next cycle. Pro and Enterprise pay $0.128 an Active CPU hour, $0.0212 a GB-hour of provisioned memory, $0.60 per million creations, $0.08 a GB-month of snapshot storage and $0.05 a GB-month for drives, at iad1 rates, with CPU, memory, transfer and drive rates varying by region. Pro usage draws first on the plan's $20 monthly credit. Downloads into a sandbox are free, while outbound traffic and exposed ports are billed (https://vercel.com/docs/sandbox/pricing).",
      "priceSummary": "$0.128 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 168,
        "npmWeekly": 6482660,
        "pypiWeekly": 461527,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://vercel.com/docs/sandbox",
      "llmsTxt": "https://vercel.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "typescript",
        "python",
        "llms-txt",
        "enterprise"
      ],
      "lastRelease": "2026-09-11",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.6,
        "grade": "B",
        "agentReady": false,
        "rank": 111,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 80,
          "payments": 40,
          "reliability": 70,
          "schema": 77,
          "security": 80,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.",
        "strengths": [
          "Active CPU billing, so waiting on model responses costs only memory",
          "Credential brokering proxy outside the sandbox that overwrites headers set by sandbox code",
          "Firecracker microVM with root access, and a firewall with deny-all, domain and CIDR rules",
          "Persistent by default, with automatic snapshots and resume on the next SDK call",
          "Sandbox has its own status-page component, and the feed shows only degradations from July to September 2026"
        ],
        "weaknesses": [
          "Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team",
          "Hobby caps sessions at 45 minutes and pauses creation once the monthly allowance is spent",
          "Snapshots keep the filesystem, not memory or running processes",
          "Egress is allow-all until you set a policy",
          "No MCP server for Sandbox and no public OpenAPI for its endpoints found"
        ],
        "agentNotes": [
          "Call `sandbox.stop()` when the task is done. Memory bills until the session ends",
          "Use `Sandbox.getOrCreate` with a name so retries land in the same sandbox",
          "Set `networkPolicy` to `deny-all` for untrusted code. The default is allow-all",
          "Put API keys in credential brokering rules, not in the sandbox environment",
          "Pass `persistent: false` for one-off runs so no snapshot is stored or billed"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.6
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 80,
          "payments": 40,
          "reliability": 70,
          "schema": 77,
          "security": 80,
          "transparency": 50
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm i @vercel/sandbox  # or pip install vercel",
        "http": "curl -X POST \"https://api.vercel.com/v1/sandboxes?teamId=$VERCEL_TEAM_ID\" -H \"Authorization: Bearer $VERCEL_TOKEN\" \\\n  -H \"Content-Type: application/json\" -d '{}'"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/vercel-sandbox"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active CPU (iad1)",
          "unit": "vcpu-hour",
          "usd": 0.128,
          "note": "Billed only while the CPU is busy. Memory extra at $0.0212 a GB-hour"
        },
        {
          "item": "Snapshot storage",
          "unit": "gb-month",
          "usd": 0.08
        },
        {
          "item": "Drive storage (iad1)",
          "unit": "gb-month",
          "usd": 0.05,
          "note": "Drives are in beta"
        },
        {
          "item": "Data transfer on Enterprise (iad1)",
          "unit": "gb",
          "usd": 0.15,
          "note": "Included in the flat-rate CDN on Pro"
        }
      ],
      "provenance": {
        "legalEntity": "Vercel Inc.",
        "domain": "vercel.com",
        "domainRegistered": "1999-10-04",
        "domainNote": "vercel.com was registered in 1999, long before Vercel, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://vercel.com/legal/terms",
        "privacy": "https://vercel.com/legal/privacy-policy",
        "statusPage": "https://www.vercel-status.com",
        "changelog": "https://vercel.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "Terms (updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, California.",
          "security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28.",
          "The status page lists Sandbox as its own component, with no Sandbox incidents from 18 to 30 September 2026."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.json",
      "live": {
        "slug": "vercel-sandbox",
        "probe": {
          "target": "https://api.vercel.com/v1/sandboxes",
          "method": "get",
          "lastAt": "2026-10-04T23:48:17.782200994Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 524,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 527,
          "p95ms24h": 650,
          "samples24h": 272,
          "samples30d": 898,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 270,
              "ok": 270
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.vercel-status.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:49:30.454874214Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "vercel/sandbox",
            "version": "@vercel/sandbox-mock@3.5.1",
            "released": "2026-09-28",
            "seenAt": "2026-10-04T16:43:20.902296091Z"
          },
          {
            "registry": "npm",
            "name": "@vercel/sandbox",
            "version": "3.5.1",
            "seenAt": "2026-10-04T16:43:18.687547241Z"
          },
          {
            "registry": "npm",
            "name": "sandbox",
            "version": "4.6.0",
            "seenAt": "2026-10-04T16:43:19.372037752Z"
          },
          {
            "registry": "pypi",
            "name": "vercel",
            "version": "0.11.4",
            "released": "2026-09-23",
            "seenAt": "2026-10-04T16:43:19.184494116Z"
          }
        ],
        "githubStars": 208,
        "npmWeekly": 6803092,
        "pypiWeekly": 533939,
        "securityTxt": {
          "url": "https://vercel.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-09-28T12:00:00.000Z",
          "checkedAt": "2026-10-04T15:15:36.802255035Z"
        },
        "llmsTxt": {
          "url": "https://vercel.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:20.527836235Z"
        },
        "domain": {
          "domain": "vercel.com",
          "registered": "1999-10-04",
          "source": "https://rdap.verisign.com/com/v1/domain/vercel.com",
          "checkedAt": "2026-10-04T13:04:52.527918567Z"
        },
        "pages": [
          {
            "url": "https://vercel.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:45.85143464Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "5f838658b352"
          },
          {
            "url": "https://vercel.com/docs/sandbox/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:47.949372715Z",
            "changedAt": "2026-10-04T15:48:47.949372715Z",
            "fingerprint": "f3917ada6bab"
          },
          {
            "url": "https://vercel.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:50.700832237Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4d5cec199c56"
          },
          {
            "url": "https://vercel.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:48:52.005054023Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "e51c90f98cbc"
          }
        ],
        "updatedAt": "2026-10-04T23:49:30.454874214Z"
      }
    },
    "summary": "Vercel Sandbox has a score of 69.6 (B) against Cloudflare Sandbox SDK's 67.8 (B). Both do sandbox code. The largest gap is reliability, 17 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox",
    "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.md",
    "slim": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.min.md"
  },
  "markdown": "Vercel Sandbox has a score of 69.6 (B) against Cloudflare Sandbox SDK's 67.8 (B). Both do sandbox code. The largest gap is reliability, 17 points.\n\n- Cloudflare Sandbox SDK: grade B, 67.8/100, rank #137 of 452. Markdown https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md · JSON https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json\n- Vercel Sandbox: grade B, 69.6/100, rank #111 of 452. Markdown https://www.anchorterminal.com/tools/vercel-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json\n\n## Which one, for what\n\nPick Cloudflare Sandbox SDK for reliability (+17).\n\nPick Vercel Sandbox for security \u0026 auth (+15), payments \u0026 pricing (+10), maintenance \u0026 community (+10).\n\n## Score by category\n\n| Category | Weight | Cloudflare Sandbox SDK | Vercel Sandbox | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 87 | 70 | Cloudflare Sandbox SDK +17 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 77 | 77 | even |\n| Agent ergonomics | 13% (16.2 this run) | 63 | 65 | Vercel Sandbox +2 |\n| Security \u0026 auth | 14% (17.5 this run) | 65 | 80 | Vercel Sandbox +15 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 40 | Vercel Sandbox +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 70 | 80 | Vercel Sandbox +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 73 | 75 | Vercel Sandbox +2 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **67.8 · B** | **69.6 · B** | |\n\n## Facts side by side\n\n| Fact | Cloudflare Sandbox SDK | Vercel Sandbox |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Cloudflare | Vercel |\n| Hosted endpoint | no (local only) | `https://api.vercel.com/v1/sandboxes` |\n| Transports |  | HTTP |\n| Auth | None | OAuth or key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Apache-2.0 | Apache-2.0 |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | no |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-09-30 | 2026-09-11 |\n| Popularity | 1.1k stars, 723k npm/wk | 168 stars, 6.5M npm/wk, 462k PyPI/wk |\n| Agent reviews | 3/5 (2) | 3.5/5 (2) |\n\n## Verdicts\n\n**Cloudflare Sandbox SDK.** Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth.\n\n**Vercel Sandbox.** Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.\n\n## Before you call either\n\n### Cloudflare Sandbox SDK\n\n1. Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets\n2. Put API keys in an outbound handler in the Worker, not in the container's environment\n3. Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default\n4. Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs\n5. Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026\n\n### Vercel Sandbox\n\n1. Call `sandbox.stop()` when the task is done. Memory bills until the session ends\n2. Use `Sandbox.getOrCreate` with a name so retries land in the same sandbox\n3. Set `networkPolicy` to `deny-all` for untrusted code. The default is allow-all\n4. Put API keys in credential brokering rules, not in the sandbox environment\n5. Pass `persistent: false` for one-off runs so no snapshot is stored or billed\n\n## Other comparisons with Cloudflare Sandbox SDK or Vercel Sandbox\n\n- [Blaxel Sandboxes vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-cloudflare-sandbox-sdk.md)\n- [Blaxel Sandboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-vercel-sandbox.md)\n- [Cloudflare Sandbox SDK vs Daytona](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.md)\n- [Cloudflare Sandbox SDK vs E2B](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-e2b.md)\n- [Cloudflare Sandbox SDK vs Modal Sandboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.md)\n- [Cloudflare Sandbox SDK vs Runloop Devboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.md)\n- [Daytona vs Vercel Sandbox](https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.md)\n- [E2B vs Vercel Sandbox](https://www.anchorterminal.com/compare/e2b-vs-vercel-sandbox.md)\n- [Modal Sandboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox.md)\n- [Runloop Devboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/runloop-vs-vercel-sandbox.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Cloudflare Sandbox SDK vs Vercel Sandbox",
        "url": ""
      }
    ],
    "description": "Vercel Sandbox has a score of 69.6 (B) against Cloudflare Sandbox SDK's 67.8 (B). Both do sandbox code. The largest gap is reliability, 17 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Cloudflare Sandbox SDK B 67.8",
      "Vercel Sandbox B 69.6",
      "scores"
    ],
    "h1": "Cloudflare Sandbox SDK vs Vercel Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/compare-cloudflare-sandbox-sdk-vs-vercel-sandbox.png",
    "path": "/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Cloudflare Sandbox SDK vs Vercel Sandbox for AI agents",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox"
  },
  "tokens": {
    "markdown": 1450,
    "slim": 330
  },
  "version": 1
}
