{
  "data": {
    "a": {
      "slug": "daytona",
      "name": "Daytona",
      "vendor": "Daytona",
      "vendorUrl": "https://www.daytona.io",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Sandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API.",
      "url": "https://www.anchorterminal.com/tools/daytona",
      "markdownUrl": "https://www.anchorterminal.com/tools/daytona.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/daytona.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/daytona.json",
      "repo": "https://github.com/daytona/clients",
      "license": "Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI)",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://app.daytona.io/api",
      "packages": [
        {
          "registry": "pypi",
          "name": "daytona"
        },
        {
          "registry": "npm",
          "name": "@daytona/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key in the `Authorization` header. The SDKs read `DAYTONA_API_KEY`, `DAYTONA_API_URL` (default https://app.daytona.io/api) and `DAYTONA_TARGET` (us or eu). Keys take scopes, so an agent's key can have `write:sandboxes` without `delete:sandboxes`. The MCP server uses the CLI session from `daytona login`.",
      "pricing": "usage",
      "pricingNotes": "Billed per second. $0.0504 a vCPU-hour, $0.0162 a GiB-hour of memory and $0.000108 a GiB-hour of storage after the first 5 GiB, Windows $0.0858 a vCPU-hour. GPUs from $0.57 an hour (RTX 4090, preemptible) to $6.25 (B300 or B200, on demand), with H100 at $2.27 preemptible or $3.95 on demand. $200 of free compute without a card, and up to $50,000 in startup credits (https://www.daytona.io/pricing). Higher limits unlock with a linked card and a $25 top-up (Tier 2), a $500 top-up (Tier 3) or $2,000 every 30 days (Tier 4) (https://www.daytona.io/docs/en/limits.md).",
      "priceSummary": "$0.0504 / vCPU-hr",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 705790,
        "pypiWeekly": 1406178,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.daytona.io/docs",
      "llmsTxt": "https://www.daytona.io/docs/llms.txt",
      "openapi": "https://www.daytona.io/docs/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.browser",
        "sandbox.gpu"
      ],
      "tags": [
        "hosted",
        "no-card",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "eu",
        "enterprise"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.3,
        "grade": "B",
        "agentReady": false,
        "rank": 320,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 8,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 80,
          "payments": 50,
          "reliability": 60,
          "schema": 87,
          "security": 63,
          "transparency": 56
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.",
        "bestFor": "Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.",
        "strengths": [
          "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them",
          "Container, Linux VM, Windows and GPU sandbox classes behind one API",
          "Three public OpenAPI files, llms.txt and SDKs in five languages",
          "Rate limits published per tier, with Retry-After and rate-limit headers on 429s",
          "$200 of compute without a card, billed per second"
        ],
        "weaknesses": [
          "The container class shares the host kernel. Only the VM classes get their own",
          "Full internet access and per-sandbox allow lists need Tier 3",
          "Platform code went private in June 2026, and the old repository's 311 open issues won't be answered",
          "Two Windows runner outages over an hour in July and August 2026",
          "No security.txt, SOC 2 report or bug bounty found"
        ],
        "agentNotes": [
          "Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead",
          "Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking",
          "Give the agent a key without `delete:sandboxes` if it shouldn't destroy work",
          "Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation",
          "Check the organisation's tier before relying on outbound calls from inside the sandbox"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.3
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 80,
          "payments": 50,
          "reliability": 60,
          "schema": 87,
          "security": 63,
          "transparency": 40
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "pip install daytona  # or npm i @daytona/sdk",
        "http": "curl -X POST https://app.daytona.io/api/sandbox -H \"Authorization: Bearer $DAYTONA_API_KEY\" \\\n  -H \"Content-Type: application/json\" -d '{}'",
        "claudeCode": "claude mcp add daytona -- daytona mcp start",
        "config": {
          "mcpServers": {
            "daytona": {
              "args": [
                "mcp",
                "start"
              ],
              "command": "daytona"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/daytona"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.0504,
          "note": "Memory extra at $0.0162 a GiB-hour"
        },
        {
          "item": "Nvidia H100, on demand",
          "unit": "gpu-hour",
          "usd": 3.95
        },
        {
          "item": "Nvidia H100, preemptible",
          "unit": "gpu-hour",
          "usd": 2.27
        },
        {
          "item": "Nvidia RTX 4090, preemptible",
          "unit": "gpu-hour",
          "usd": 0.57
        }
      ],
      "provenance": {
        "legalEntity": "Daytona Platforms Inc.",
        "domain": "daytona.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.daytona.io/terms-of-service",
        "privacy": "https://www.daytona.io/privacy-policy",
        "statusPage": "https://status.app.daytona.io",
        "changelog": "https://www.daytona.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "Terms and privacy policy (both updated 22 August 2025) name Daytona Platforms Inc., 224 W 35th St, New York, under Delaware law.",
          "The status page lists Windows runner outages on 31 July (3 hours 50 minutes) and 1 August 2026 (1 hour 40 minutes), a 17.5-hour regional degradation on 11 August, short incidents in July and September, and a 2-hour degradation of sandbox listing on 1 October 2026.",
          "www.daytona.io/.well-known/security.txt returns 404. daytona/clients has a SECURITY.md.",
          "The .io registry's RDAP server rate-limited our lookups, so the registration date is blank."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/daytona.json",
      "live": {
        "slug": "daytona",
        "probe": {
          "target": "https://app.daytona.io/api",
          "method": "get",
          "lastAt": "2026-10-09T11:46:26.504877198Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 107,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 106,
          "p95ms24h": 167,
          "samples24h": 259,
          "samples30d": 2109,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 268,
              "ok": 268
            },
            {
              "date": "2026-10-09",
              "probes": 125,
              "ok": 125
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.app.daytona.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:47.041472134Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "daytona/clients",
            "version": "v0.223.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:07:59.235643031Z"
          },
          {
            "registry": "npm",
            "name": "@daytona/sdk",
            "version": "0.223.0",
            "seenAt": "2026-10-08T16:07:56.298006682Z"
          },
          {
            "registry": "pypi",
            "name": "daytona",
            "version": "0.223.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:07:56.168303679Z"
          }
        ],
        "githubStars": 13,
        "npmWeekly": 754322,
        "pypiWeekly": 1558208,
        "securityTxt": {
          "url": "https://daytona.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:36.850747632Z"
        },
        "llmsTxt": {
          "url": "https://www.daytona.io/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:18.273054429Z"
        },
        "domain": {
          "domain": "daytona.io",
          "checkedAt": "2026-10-04T13:04:31.91436109Z"
        },
        "pages": [
          {
            "url": "https://www.daytona.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:27:18.444429554Z",
            "changedAt": "2026-10-07T18:11:34.123095103Z",
            "fingerprint": "e3e95e827d6a"
          },
          {
            "url": "https://www.daytona.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-08T18:27:21.539160036Z",
            "changedAt": "2026-10-03T15:37:58.260333039Z",
            "fingerprint": "8c2c3fd83e7e"
          },
          {
            "url": "https://www.daytona.io/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-08T18:27:22.921547198Z",
            "changedAt": "2026-10-03T15:37:59.162897733Z",
            "fingerprint": "c712b184a1f3"
          },
          {
            "url": "https://www.daytona.io/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:27:24.654038357Z",
            "changedAt": "2026-10-03T15:38:01.284671381Z",
            "fingerprint": "c42adfc2b432"
          }
        ],
        "updatedAt": "2026-10-09T11:46:26.504877198Z"
      }
    },
    "answer": "Daytona scores 64.3 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 5 of 7 scored categories. Deno Sandbox leads on agent ergonomics.",
    "b": {
      "slug": "deno-sandbox",
      "name": "Deno Sandbox",
      "vendor": "Deno Land Inc.",
      "vendorUrl": "https://deno.com",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the `@deno/sandbox` JavaScript SDK, the `deno-sandbox` Python SDK or the `deno sandbox` CLI, and launched in beta on 3 February 2026.",
      "url": "https://www.anchorterminal.com/tools/deno-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json",
      "repo": "https://github.com/denoland/sandbox-py",
      "license": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@deno/sandbox"
        },
        {
          "registry": "pypi",
          "name": "deno-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "An organisation access token (prefix `ddo_`) created under Settings in console.deno.com, read by the SDKs from `DENO_DEPLOY_TOKEN` and sent as a Bearer token. The same token manages the organisation's Deno Deploy apps. No scopes or expiry were found in the reviewed docs, the docs say to rotate a leaked token from the dashboard, and all organisation members hold owner permissions. Signup is in a browser.",
      "pricing": "paid",
      "pricingNotes": "Sandboxes need the Pro plan ($20 a month) or above, and the Free plan does not include them. Compute bills through the Deploy meters at $0.10 a CPU-hour and $0.025 a GiB-hour of memory beyond the plan's allowance (50 CPU-hours and 750 GiB-hours on Pro), and volume storage at $0.20 a GiB-month beyond 5 GiB on Pro. Spend limits can be set on paid plans (https://deno.com/deploy/pricing, checked 2026-10-08).",
      "priceSummary": "$0.10 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the sandbox docs, the pricing page or the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 1971,
        "pypiWeekly": 31729,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.deno.com/sandbox/",
      "llmsTxt": "https://docs.deno.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "paid",
        "beta",
        "microvm",
        "typescript",
        "python",
        "cli",
        "llms-txt",
        "status-page",
        "enterprise"
      ],
      "lastRelease": "2026-07-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.3,
        "grade": "D",
        "agentReady": false,
        "rank": 689,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08: the Create page (last modified 28 January 2026) says a default sandbox has no outbound network access, while the Security page of the same date says outbound access is unrestricted unless `allowNet` is set. A reader of the first page would leave egress open. 2 points. https://docs.deno.com/sandbox/create/ and https://docs.deno.com/sandbox/security/"
        ],
        "verdict": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
        "bestFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "strengths": [
          "Secrets are held outside the VM. Code sees a placeholder, and the real value is substituted only on requests to hosts named for that secret",
          "`allowNet` restricts outbound traffic to listed hostnames, wildcard subdomains, ports or IP addresses",
          "Each sandbox is a Firecracker microVM per the product page, with 2 vCPUs, 768 MB to 4 GB of memory and 10 GB of disk",
          "Volumes of 300 MB to 20 GB persist between sandboxes, and read-only snapshots of a volume can boot new sandboxes",
          "Unit prices are public, $0.10 a CPU-hour, $0.025 a GiB-hour of memory and $0.20 a GiB-month of volume storage"
        ],
        "weaknesses": [
          "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found",
          "Sandboxes are not included in the Free plan. Access starts at Pro, $20 a month, after a browser signup",
          "The published OpenAPI document at `api.deno.com/v2/openapi.json` has 34 operations and none for sandboxes, volumes or snapshots",
          "The Create page says a default sandbox has no outbound network access, and the Security page says outbound access is unrestricted by default",
          "Maximum lifetime is 30 minutes, volumes exist only in `ord`, and no API rate limits or 429 guidance were found",
          "Organisation tokens carry no scopes in the reviewed docs, and every organisation member has owner permissions"
        ],
        "agentNotes": [
          "Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above",
          "Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted",
          "Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder",
          "The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes",
          "Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region",
          "`exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 35
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install @deno/sandbox  # or pip install deno-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/deno-sandbox"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active CPU beyond plan allowance",
          "unit": "vcpu-hour",
          "usd": 0.1,
          "note": "Memory extra at $0.025 a GiB-hour"
        },
        {
          "item": "Volume storage beyond plan allowance",
          "unit": "gb-month",
          "usd": 0.2,
          "note": "Priced per GiB"
        },
        {
          "item": "Pro plan, the lowest that includes sandboxes",
          "unit": "month",
          "usd": 20,
          "note": "Includes 50 CPU-hours, 750 GiB-hours of memory and 5 GiB of volume storage"
        }
      ],
      "provenance": {
        "legalEntity": "Deno Land Inc.",
        "domain": "deno.com",
        "domainRegistered": "1999-03-09",
        "endpointOnVendorDomain": false,
        "terms": "https://docs.deno.com/deploy/terms_and_conditions/",
        "privacy": "https://docs.deno.com/deploy/privacy_policy/",
        "statusPage": "https://denostatus.com",
        "changelog": "https://docs.deno.com/deploy/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Deno Deploy terms and conditions (last modified 30 September 2026) name Deno Land Inc. and govern the Deploy services, of which Sandbox is a part. No separate sandbox terms were found.",
          "The privacy policy (last modified 30 September 2026) gives Deno Land Inc., 1111 6th Ave Ste 550, PMB 702973, San Diego CA 92101. A DPA is listed under Enterprise only, and no public copy was found.",
          "The Python SDK's default sandbox endpoint is `\u003cregion\u003e.sandbox-api.deno.net`, a second domain of the vendor's, while listing and volumes go through console.deno.com.",
          "deno.com/.well-known/security.txt gives deploy@deno.com and a policy link and has no Expires field, which RFC 9116 requires. It is recorded as valid to match other listings with the same gap. The policy page gives security@deno.com.",
          "RDAP for deno.com gives a registration date of 1999-03-09.",
          "The Deploy changelog's newest entry is dated 12 March 2026."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/deno-sandbox.json",
      "live": {
        "slug": "deno-sandbox",
        "vendorStatus": {
          "page": "https://denostatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:48.013369722Z"
        },
        "updatedAt": "2026-10-09T07:57:48.013369722Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Daytona",
        "b": "Deno Land Inc.",
        "name": "Vendor"
      },
      {
        "a": "https://app.daytona.io/api",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Paid",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI)",
        "b": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-29",
        "b": "2026-07-22",
        "name": "Last release"
      },
      {
        "a": "2025-08-22",
        "b": "2026-09-30",
        "name": "Terms last updated"
      },
      {
        "a": "2025-08-22",
        "b": "2026-09-30",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6 stars, 706k npm/wk, 1.4M PyPI/wk",
        "b": "6 stars, 2k npm/wk, 32k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Daytona scores 64.3 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 5 of 7 scored categories. Deno Sandbox leads on agent ergonomics.",
        "question": "Which is better for AI agents, Daytona or Deno Sandbox?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Daytona and Deno Sandbox need an API key?"
      },
      {
        "answer": "Daytona has a hosted endpoint at https://app.daytona.io/api. No hosted endpoint is listed for Deno Sandbox.",
        "question": "Can an agent call Daytona and Deno Sandbox without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 60 against 48",
          "Schema \u0026 documentation, 87 against 66",
          "Payments \u0026 pricing, 50 against 20",
          "Maintenance \u0026 community, 80 against 45"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine",
          "Free to start without a card"
        ],
        "goodFor": "Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.",
        "slug": "daytona",
        "watchFor": "The container class shares the host kernel. Only the VM classes get their own"
      },
      {
        "aheadOn": [
          "Agent ergonomics, 60 against 55"
        ],
        "also": null,
        "goodFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "slug": "deno-sandbox",
        "watchFor": "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-daytona.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Daytona",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-daytona.json",
        "title": "Blaxel Sandboxes vs Daytona",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.json",
        "title": "Blaxel Sandboxes vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.json",
        "title": "Cloudflare Sandbox SDK vs Daytona",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-e2b.json",
        "title": "Daytona vs E2B",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-freestyle.json",
        "title": "Daytona vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes.json",
        "title": "Daytona vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.json",
        "title": "Daytona vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-runloop.json",
        "title": "Daytona vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-sprites.json",
        "title": "Daytona vs Sprites",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox.json",
        "title": "Daytona vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.json",
        "title": "Daytona vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.json",
        "title": "Deno Sandbox vs E2B",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.json",
        "title": "Deno Sandbox vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
        "title": "Deno Sandbox vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.json",
        "title": "Deno Sandbox vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.json",
        "title": "Deno Sandbox vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.json",
        "title": "Deno Sandbox vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.json",
        "title": "Deno Sandbox vs Sprites",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.json",
        "title": "Deno Sandbox vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.json",
        "title": "Deno Sandbox vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-daytona.json",
        "title": "Agent 37 Cloud vs Daytona",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.json",
        "title": "Agent 37 Cloud vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox"
      }
    ],
    "scores": [
      {
        "by": 12,
        "daytona": 60,
        "deno-sandbox": 48,
        "edge": "daytona",
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 21,
        "daytona": 87,
        "deno-sandbox": 66,
        "edge": "daytona",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 5,
        "daytona": 55,
        "deno-sandbox": 60,
        "edge": "deno-sandbox",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 2,
        "daytona": 63,
        "deno-sandbox": 61,
        "edge": "daytona",
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 30,
        "daytona": 50,
        "deno-sandbox": 20,
        "edge": "daytona",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 35,
        "daytona": 80,
        "deno-sandbox": 45,
        "edge": "daytona",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 2,
        "daytona": 56,
        "deno-sandbox": 58,
        "edge": "deno-sandbox",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Daytona scores 64.3 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 5 of 7 scored categories. Deno Sandbox leads on agent ergonomics. Both do sandbox code.",
    "verdicts": {
      "daytona": "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.",
      "deno-sandbox": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox",
    "json": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.md",
    "slim": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.min.md"
  },
  "markdown": "Daytona scores 64.3 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 5 of 7 scored categories. Deno Sandbox leads on agent ergonomics. Both do sandbox code.\n\n- Daytona: grade B, 64.3/100, rank #320 of 842. Markdown https://www.anchorterminal.com/tools/daytona.md · JSON https://www.anchorterminal.com/api/v1/tools/daytona.json\n- Deno Sandbox: grade D, 50.3/100, rank #689 of 842. Markdown https://www.anchorterminal.com/tools/deno-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json\n\n## Which one, for what\n\n### Daytona (B)\n\nGood for: Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.\n\nAhead on:\n- Reliability, 60 against 48\n- Schema \u0026 documentation, 87 against 66\n- Payments \u0026 pricing, 50 against 20\n- Maintenance \u0026 community, 80 against 45\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n- Free to start without a card\n\nWatch for: The container class shares the host kernel. Only the VM classes get their own\n\n### Deno Sandbox (D)\n\nGood for: Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.\n\nAhead on:\n- Agent ergonomics, 60 against 55\n\nWatch for: Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found\n\n\n## Score by category\n\n| Category | Weight | Daytona | Deno Sandbox | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 48 | Daytona +12 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 87 | 66 | Daytona +21 |\n| Agent ergonomics | 13% (16.2 this run) | 55 | 60 | Deno Sandbox +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 61 | Daytona +2 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 20 | Daytona +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 45 | Daytona +35 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 56 | 58 | Deno Sandbox +2 |\n| Negative events | ≤15 | 0 | -2 | |\n| **Total** | | **64.3 · B** | **50.3 · D** | |\n\n## Facts side by side\n\n| Fact | Daytona | Deno Sandbox |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Daytona | Deno Land Inc. |\n| Hosted endpoint | `https://app.daytona.io/api` | no (local only) |\n| Transports | HTTP, stdio | HTTP |\n| Auth | API key | API key |\n| Pricing | Pay per use | Paid |\n| x402 | no | no |\n| Licence | Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI) | Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-09-29 | 2026-07-22 |\n| Terms last updated | 2025-08-22 | 2026-09-30 |\n| Privacy policy last updated | 2025-08-22 | 2026-09-30 |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | not found in the text | yes |\n| Arbitration or class-action waiver | yes | yes |\n| Popularity | 6 stars, 706k npm/wk, 1.4M PyPI/wk | 6 stars, 2k npm/wk, 32k PyPI/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Daytona.** API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.\n\n**Deno Sandbox.** Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.\n\n## Before you call either\n\n### Daytona\n\n1. Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead\n2. Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking\n3. Give the agent a key without `delete:sandboxes` if it shouldn't destroy work\n4. Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation\n5. Check the organisation's tier before relying on outbound calls from inside the sandbox\n\n### Deno Sandbox\n\n1. Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above\n2. Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted\n3. Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder\n4. The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes\n5. Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region\n6. `exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret\n\n## Questions\n\n### Which is better for AI agents, Daytona or Deno Sandbox?\n\nDaytona scores 64.3 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 5 of 7 scored categories. Deno Sandbox leads on agent ergonomics.\n\n### Do Daytona and Deno Sandbox need an API key?\n\nBoth need an API key.\n\n### Can an agent call Daytona and Deno Sandbox without installing anything?\n\nDaytona has a hosted endpoint at https://app.daytona.io/api. No hosted endpoint is listed for Deno Sandbox.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.json, and with the fewest tokens: https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"daytona\", \"b\": \"deno-sandbox\"}`. From a terminal: `anchor compare daytona deno-sandbox`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/daytona.json and https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json\n\n## Other comparisons with Daytona or Deno Sandbox\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Daytona](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-daytona.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.md)\n- [Blaxel Sandboxes vs Daytona](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-daytona.md)\n- [Blaxel Sandboxes vs Deno Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.md)\n- [Cloudflare Sandbox SDK vs Daytona](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.md)\n- [Cloudflare Sandbox SDK vs Deno Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.md)\n- [Daytona vs E2B](https://www.anchorterminal.com/compare/daytona-vs-e2b.md)\n- [Daytona vs Freestyle](https://www.anchorterminal.com/compare/daytona-vs-freestyle.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Daytona vs Modal Sandboxes](https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes.md)\n- [Daytona vs Morph Cloud](https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.md)\n- [Daytona vs Runloop Devboxes](https://www.anchorterminal.com/compare/daytona-vs-runloop.md)\n- [Daytona vs Sprites](https://www.anchorterminal.com/compare/daytona-vs-sprites.md)\n- [Daytona vs Together Code Sandbox](https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox.md)\n- [Daytona vs Vercel Sandbox](https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.md)\n- [Deno Sandbox vs E2B](https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.md)\n- [Deno Sandbox vs Freestyle](https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md)\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs Modal Sandboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.md)\n- [Deno Sandbox vs Morph Cloud](https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.md)\n- [Deno Sandbox vs Runloop Devboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.md)\n- [Deno Sandbox vs Sprites](https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.md)\n- [Deno Sandbox vs Together Code Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md)\n- [Deno Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Daytona](https://www.anchorterminal.com/compare/agent37-vs-daytona.md)\n- [Agent 37 Cloud vs Deno Sandbox](https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Daytona vs Deno Sandbox",
        "url": ""
      }
    ],
    "description": "Daytona scores 64.3 (B) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 5 of 7 scored categories. Deno Sandbox leads on agent ergonomics. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Daytona B 64.3",
      "Deno Sandbox D 50.3",
      "scores"
    ],
    "h1": "Daytona vs Deno Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/compare-daytona-vs-deno-sandbox.png",
    "path": "/compare/daytona-vs-deno-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Daytona vs Deno Sandbox for AI agents, B 64.3 vs D 50.3",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 680
  },
  "version": 1
}
