{
  "data": {
    "a": {
      "slug": "daytona",
      "name": "Daytona",
      "vendor": "Daytona",
      "vendorUrl": "https://www.daytona.io",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Sandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API.",
      "url": "https://www.anchorterminal.com/tools/daytona",
      "markdownUrl": "https://www.anchorterminal.com/tools/daytona.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/daytona.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/daytona.json",
      "repo": "https://github.com/daytona/clients",
      "license": "Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI)",
      "transports": [
        "http",
        "stdio"
      ],
      "remoteUrl": "https://app.daytona.io/api",
      "packages": [
        {
          "registry": "pypi",
          "name": "daytona"
        },
        {
          "registry": "npm",
          "name": "@daytona/sdk"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key in the `Authorization` header. The SDKs read `DAYTONA_API_KEY`, `DAYTONA_API_URL` (default https://app.daytona.io/api) and `DAYTONA_TARGET` (us or eu). Keys take scopes, so an agent's key can have `write:sandboxes` without `delete:sandboxes`. The MCP server uses the CLI session from `daytona login`.",
      "pricing": "usage",
      "pricingNotes": "Billed per second. $0.0504 a vCPU-hour, $0.0162 a GiB-hour of memory and $0.000108 a GiB-hour of storage after the first 5 GiB, Windows $0.0858 a vCPU-hour. GPUs from $0.57 an hour (RTX 4090, preemptible) to $6.25 (B300 or B200, on demand), with H100 at $2.27 preemptible or $3.95 on demand. $200 of free compute without a card, and up to $50,000 in startup credits (https://www.daytona.io/pricing). Higher limits unlock with a linked card and a $25 top-up (Tier 2), a $500 top-up (Tier 3) or $2,000 every 30 days (Tier 4) (https://www.daytona.io/docs/en/limits.md).",
      "priceSummary": "$0.0504 / vCPU-hr",
      "where": "both",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 705790,
        "pypiWeekly": 1406178,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://www.daytona.io/docs",
      "llmsTxt": "https://www.daytona.io/docs/llms.txt",
      "openapi": "https://www.daytona.io/docs/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.browser",
        "sandbox.gpu"
      ],
      "tags": [
        "hosted",
        "no-card",
        "mcp",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "go",
        "eu",
        "enterprise"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.3,
        "grade": "B",
        "agentReady": false,
        "rank": 256,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 55,
          "maintenance": 80,
          "payments": 50,
          "reliability": 60,
          "schema": 87,
          "security": 63,
          "transparency": 56
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.",
        "bestFor": "Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.",
        "strengths": [
          "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them",
          "Container, Linux VM, Windows and GPU sandbox classes behind one API",
          "Three public OpenAPI files, llms.txt and SDKs in five languages",
          "Rate limits published per tier, with Retry-After and rate-limit headers on 429s",
          "$200 of compute without a card, billed per second"
        ],
        "weaknesses": [
          "The container class shares the host kernel. Only the VM classes get their own",
          "Full internet access and per-sandbox allow lists need Tier 3",
          "Platform code went private in June 2026, and the old repository's 311 open issues won't be answered",
          "Two Windows runner outages over an hour in July and August 2026",
          "No security.txt, SOC 2 report or bug bounty found"
        ],
        "agentNotes": [
          "Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead",
          "Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking",
          "Give the agent a key without `delete:sandboxes` if it shouldn't destroy work",
          "Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation",
          "Check the organisation's tier before relying on outbound calls from inside the sandbox"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.3
          }
        ],
        "editorialScores": {
          "ergonomics": 55,
          "maintenance": 80,
          "payments": 50,
          "reliability": 60,
          "schema": 87,
          "security": 63,
          "transparency": 40
        },
        "provenanceScore": 72
      },
      "connect": {
        "install": "pip install daytona  # or npm i @daytona/sdk",
        "http": "curl -X POST https://app.daytona.io/api/sandbox -H \"Authorization: Bearer $DAYTONA_API_KEY\" \\\n  -H \"Content-Type: application/json\" -d '{}'",
        "claudeCode": "claude mcp add daytona -- daytona mcp start",
        "config": {
          "mcpServers": {
            "daytona": {
              "args": [
                "mcp",
                "start"
              ],
              "command": "daytona"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/daytona"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.0504,
          "note": "Memory extra at $0.0162 a GiB-hour"
        },
        {
          "item": "Nvidia H100, on demand",
          "unit": "gpu-hour",
          "usd": 3.95
        },
        {
          "item": "Nvidia H100, preemptible",
          "unit": "gpu-hour",
          "usd": 2.27
        },
        {
          "item": "Nvidia RTX 4090, preemptible",
          "unit": "gpu-hour",
          "usd": 0.57
        }
      ],
      "provenance": {
        "legalEntity": "Daytona Platforms Inc.",
        "domain": "daytona.io",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://www.daytona.io/terms-of-service",
        "privacy": "https://www.daytona.io/privacy-policy",
        "statusPage": "https://status.app.daytona.io",
        "changelog": "https://www.daytona.io/changelog",
        "securityTxt": "none",
        "checked": "2026-10-01",
        "notes": [
          "Terms and privacy policy (both updated 22 August 2025) name Daytona Platforms Inc., 224 W 35th St, New York, under Delaware law.",
          "The status page lists Windows runner outages on 31 July (3 hours 50 minutes) and 1 August 2026 (1 hour 40 minutes), a 17.5-hour regional degradation on 11 August, short incidents in July and September, and a 2-hour degradation of sandbox listing on 1 October 2026.",
          "www.daytona.io/.well-known/security.txt returns 404. daytona/clients has a SECURITY.md.",
          "The .io registry's RDAP server rate-limited our lookups, so the registration date is blank."
        ],
        "score": 72
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/daytona.json",
      "live": {
        "slug": "daytona",
        "probe": {
          "target": "https://app.daytona.io/api",
          "method": "get",
          "lastAt": "2026-10-08T18:20:28.516014403Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 114,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 109,
          "p95ms24h": 265,
          "samples24h": 272,
          "samples30d": 1924,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 208,
              "ok": 208
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.app.daytona.io",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:50:33.039839811Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "daytona/clients",
            "version": "v0.223.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:07:59.235643031Z"
          },
          {
            "registry": "npm",
            "name": "@daytona/sdk",
            "version": "0.223.0",
            "seenAt": "2026-10-08T16:07:56.298006682Z"
          },
          {
            "registry": "pypi",
            "name": "daytona",
            "version": "0.223.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:07:56.168303679Z"
          }
        ],
        "githubStars": 13,
        "npmWeekly": 754322,
        "pypiWeekly": 1558208,
        "securityTxt": {
          "url": "https://daytona.io/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:36.850747632Z"
        },
        "llmsTxt": {
          "url": "https://www.daytona.io/docs/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:18.273054429Z"
        },
        "domain": {
          "domain": "daytona.io",
          "checkedAt": "2026-10-04T13:04:31.91436109Z"
        },
        "pages": [
          {
            "url": "https://www.daytona.io/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-07T18:11:34.123095103Z",
            "changedAt": "2026-10-07T18:11:34.123095103Z",
            "fingerprint": "e3e95e827d6a"
          },
          {
            "url": "https://www.daytona.io/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-07T18:11:37.337416924Z",
            "changedAt": "2026-10-03T15:37:58.260333039Z",
            "fingerprint": "8c2c3fd83e7e"
          },
          {
            "url": "https://www.daytona.io/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-07T18:11:38.495642224Z",
            "changedAt": "2026-10-03T15:37:59.162897733Z",
            "fingerprint": "c712b184a1f3"
          },
          {
            "url": "https://www.daytona.io/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-07T18:11:40.485358765Z",
            "changedAt": "2026-10-03T15:38:01.284671381Z",
            "fingerprint": "c42adfc2b432"
          }
        ],
        "updatedAt": "2026-10-08T18:20:28.516014403Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Daytona's 64.3 (B), and leads in 6 of 7 scored categories. Daytona leads on schema \u0026 documentation.",
    "b": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 34,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-translator",
        "microsoft-graph-calendar",
        "dynamics-365-sales",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Daytona",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://app.daytona.io/api",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, stdio",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Pay per use",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI)",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-29",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "2025-08-22",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2025-08-22",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6 stars, 706k npm/wk, 1.4M PyPI/wk",
        "b": "1.5k stars, 472k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Daytona's 64.3 (B), and leads in 6 of 7 scored categories. Daytona leads on schema \u0026 documentation.",
        "question": "Which is better for AI agents, Daytona or Microsoft Execution Containers?"
      },
      {
        "answer": "Daytona has a hosted endpoint at https://app.daytona.io/api. No hosted endpoint is listed for Microsoft Execution Containers.",
        "question": "Can an agent call Daytona and Microsoft Execution Containers without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Daytona. Microsoft Execution Containers is open source (MIT).",
        "question": "Are Daytona and Microsoft Execution Containers open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 87 against 81"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Runs on your own machine"
        ],
        "goodFor": "Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.",
        "slug": "daytona",
        "watchFor": "The container class shares the host kernel. Only the VM classes get their own"
      },
      {
        "aheadOn": [
          "Reliability, 81 against 60",
          "Agent ergonomics, 74 against 55",
          "Security \u0026 auth, 69 against 63",
          "Payments \u0026 pricing, 60 against 50",
          "Maintenance \u0026 community, 92 against 80",
          "Transparency \u0026 trust, 83 against 56"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-daytona.json",
        "title": "Blaxel Sandboxes vs Daytona",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.json",
        "title": "Cloudflare Sandbox SDK vs Daytona",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-e2b.json",
        "title": "Daytona vs E2B",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes.json",
        "title": "Daytona vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.json",
        "title": "Daytona vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-runloop.json",
        "title": "Daytona vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.json",
        "title": "Daytona vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-daytona.json",
        "title": "Agent 37 Cloud vs Daytona",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-daytona"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      }
    ],
    "scores": [
      {
        "by": 21,
        "daytona": 60,
        "edge": "microsoft-execution-containers",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 6,
        "daytona": 87,
        "edge": "daytona",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 19,
        "daytona": 55,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 6,
        "daytona": 63,
        "edge": "microsoft-execution-containers",
        "key": "security",
        "microsoft-execution-containers": 69,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 10,
        "daytona": 50,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "daytona": 80,
        "edge": "microsoft-execution-containers",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 27,
        "daytona": 56,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Daytona's 64.3 (B), and leads in 6 of 7 scored categories. Daytona leads on schema \u0026 documentation. Both do sandbox code.",
    "verdicts": {
      "daytona": "API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.",
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers",
    "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md",
    "slim": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Daytona's 64.3 (B), and leads in 6 of 7 scored categories. Daytona leads on schema \u0026 documentation. Both do sandbox code.\n\n- Daytona: grade B, 64.3/100, rank #256 of 629. Markdown https://www.anchorterminal.com/tools/daytona.md · JSON https://www.anchorterminal.com/api/v1/tools/daytona.json\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #34 of 629. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n\n## Which one, for what\n\n### Daytona (B)\n\nGood for: Agents that need a choice of machine, including Windows desktops and GPUs, and operators who want least-privilege keys.\n\nAhead on:\n- Schema \u0026 documentation, 87 against 81\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Runs on your own machine\n\nWatch for: The container class shares the host kernel. Only the VM classes get their own\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 60\n- Agent ergonomics, 74 against 55\n- Security \u0026 auth, 69 against 63\n- Payments \u0026 pricing, 60 against 50\n- Maintenance \u0026 community, 92 against 80\n- Transparency \u0026 trust, 83 against 56\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n\n## Score by category\n\n| Category | Weight | Daytona | Microsoft Execution Containers | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 60 | 81 | Microsoft Execution Containers +21 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 87 | 81 | Daytona +6 |\n| Agent ergonomics | 13% (16.2 this run) | 55 | 74 | Microsoft Execution Containers +19 |\n| Security \u0026 auth | 14% (17.5 this run) | 63 | 69 | Microsoft Execution Containers +6 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 50 | 60 | Microsoft Execution Containers +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 80 | 92 | Microsoft Execution Containers +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 56 | 83 | Microsoft Execution Containers +27 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **64.3 · B** | **76.3 · BB** | |\n\n## Facts side by side\n\n| Fact | Daytona | Microsoft Execution Containers |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Daytona | Microsoft |\n| Hosted endpoint | `https://app.daytona.io/api` | no (local only) |\n| Transports | HTTP, stdio |  |\n| Auth | API key | None |\n| Pricing | Pay per use | Free |\n| x402 | no | no |\n| Licence | Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI) | MIT |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | no |\n| Last release | 2026-09-29 | 2026-10-06 |\n| Terms last updated | 2025-08-22 | no document linked |\n| Privacy policy last updated | 2025-08-22 | couldn't be read |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | not found in the text |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 6 stars, 706k npm/wk, 1.4M PyPI/wk | 1.5k stars, 472k npm/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Daytona.** API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own.\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n## Before you call either\n\n### Daytona\n\n1. Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead\n2. Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking\n3. Give the agent a key without `delete:sandboxes` if it shouldn't destroy work\n4. Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation\n5. Check the organisation's tier before relying on outbound calls from inside the sandbox\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n## Questions\n\n### Which is better for AI agents, Daytona or Microsoft Execution Containers?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Daytona's 64.3 (B), and leads in 6 of 7 scored categories. Daytona leads on schema \u0026 documentation.\n\n### Can an agent call Daytona and Microsoft Execution Containers without installing anything?\n\nDaytona has a hosted endpoint at https://app.daytona.io/api. No hosted endpoint is listed for Microsoft Execution Containers.\n\n### Are Daytona and Microsoft Execution Containers open source?\n\nNo open-source release is listed for Daytona. Microsoft Execution Containers is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json, and with the fewest tokens: https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"daytona\", \"b\": \"microsoft-execution-containers\"}`. From a terminal: `anchor compare daytona microsoft-execution-containers`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/daytona.json and https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n\n## Other comparisons with Daytona or Microsoft Execution Containers\n\n- [Blaxel Sandboxes vs Daytona](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-daytona.md)\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Daytona](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-daytona.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Daytona vs E2B](https://www.anchorterminal.com/compare/daytona-vs-e2b.md)\n- [Daytona vs Modal Sandboxes](https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes.md)\n- [Daytona vs Morph Cloud](https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.md)\n- [Daytona vs Runloop Devboxes](https://www.anchorterminal.com/compare/daytona-vs-runloop.md)\n- [Daytona vs Vercel Sandbox](https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Daytona](https://www.anchorterminal.com/compare/agent37-vs-daytona.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Daytona vs Microsoft Execution Containers",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Daytona's 64.3 (B), and leads in 6 of 7 scored categories. Daytona leads on schema \u0026 documentation. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Daytona B 64.3",
      "Microsoft Execution Containers BB 76.3",
      "scores"
    ],
    "h1": "Daytona vs Microsoft Execution Containers",
    "image": "https://www.anchorterminal.com/assets/og/compare-daytona-vs-microsoft-execution-containers.png",
    "path": "/compare/daytona-vs-microsoft-execution-containers",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Daytona vs Microsoft Execution Containers for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 780
  },
  "version": 1
}
