{
  "data": {
    "a": {
      "slug": "deno-sandbox",
      "name": "Deno Sandbox",
      "vendor": "Deno Land Inc.",
      "vendorUrl": "https://deno.com",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the `@deno/sandbox` JavaScript SDK, the `deno-sandbox` Python SDK or the `deno sandbox` CLI, and launched in beta on 3 February 2026.",
      "url": "https://www.anchorterminal.com/tools/deno-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json",
      "repo": "https://github.com/denoland/sandbox-py",
      "license": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@deno/sandbox"
        },
        {
          "registry": "pypi",
          "name": "deno-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "An organisation access token (prefix `ddo_`) created under Settings in console.deno.com, read by the SDKs from `DENO_DEPLOY_TOKEN` and sent as a Bearer token. The same token manages the organisation's Deno Deploy apps. No scopes or expiry were found in the reviewed docs, the docs say to rotate a leaked token from the dashboard, and all organisation members hold owner permissions. Signup is in a browser.",
      "pricing": "paid",
      "pricingNotes": "Sandboxes need the Pro plan ($20 a month) or above, and the Free plan does not include them. Compute bills through the Deploy meters at $0.10 a CPU-hour and $0.025 a GiB-hour of memory beyond the plan's allowance (50 CPU-hours and 750 GiB-hours on Pro), and volume storage at $0.20 a GiB-month beyond 5 GiB on Pro. Spend limits can be set on paid plans (https://deno.com/deploy/pricing, checked 2026-10-08).",
      "priceSummary": "$0.10 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the sandbox docs, the pricing page or the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 1971,
        "pypiWeekly": 31729,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.deno.com/sandbox/",
      "llmsTxt": "https://docs.deno.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "paid",
        "beta",
        "microvm",
        "typescript",
        "python",
        "cli",
        "llms-txt",
        "status-page",
        "enterprise"
      ],
      "lastRelease": "2026-07-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.3,
        "grade": "D",
        "agentReady": false,
        "rank": 689,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08: the Create page (last modified 28 January 2026) says a default sandbox has no outbound network access, while the Security page of the same date says outbound access is unrestricted unless `allowNet` is set. A reader of the first page would leave egress open. 2 points. https://docs.deno.com/sandbox/create/ and https://docs.deno.com/sandbox/security/"
        ],
        "verdict": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
        "bestFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "strengths": [
          "Secrets are held outside the VM. Code sees a placeholder, and the real value is substituted only on requests to hosts named for that secret",
          "`allowNet` restricts outbound traffic to listed hostnames, wildcard subdomains, ports or IP addresses",
          "Each sandbox is a Firecracker microVM per the product page, with 2 vCPUs, 768 MB to 4 GB of memory and 10 GB of disk",
          "Volumes of 300 MB to 20 GB persist between sandboxes, and read-only snapshots of a volume can boot new sandboxes",
          "Unit prices are public, $0.10 a CPU-hour, $0.025 a GiB-hour of memory and $0.20 a GiB-month of volume storage"
        ],
        "weaknesses": [
          "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found",
          "Sandboxes are not included in the Free plan. Access starts at Pro, $20 a month, after a browser signup",
          "The published OpenAPI document at `api.deno.com/v2/openapi.json` has 34 operations and none for sandboxes, volumes or snapshots",
          "The Create page says a default sandbox has no outbound network access, and the Security page says outbound access is unrestricted by default",
          "Maximum lifetime is 30 minutes, volumes exist only in `ord`, and no API rate limits or 429 guidance were found",
          "Organisation tokens carry no scopes in the reviewed docs, and every organisation member has owner permissions"
        ],
        "agentNotes": [
          "Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above",
          "Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted",
          "Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder",
          "The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes",
          "Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region",
          "`exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 35
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install @deno/sandbox  # or pip install deno-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/deno-sandbox"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active CPU beyond plan allowance",
          "unit": "vcpu-hour",
          "usd": 0.1,
          "note": "Memory extra at $0.025 a GiB-hour"
        },
        {
          "item": "Volume storage beyond plan allowance",
          "unit": "gb-month",
          "usd": 0.2,
          "note": "Priced per GiB"
        },
        {
          "item": "Pro plan, the lowest that includes sandboxes",
          "unit": "month",
          "usd": 20,
          "note": "Includes 50 CPU-hours, 750 GiB-hours of memory and 5 GiB of volume storage"
        }
      ],
      "provenance": {
        "legalEntity": "Deno Land Inc.",
        "domain": "deno.com",
        "domainRegistered": "1999-03-09",
        "endpointOnVendorDomain": false,
        "terms": "https://docs.deno.com/deploy/terms_and_conditions/",
        "privacy": "https://docs.deno.com/deploy/privacy_policy/",
        "statusPage": "https://denostatus.com",
        "changelog": "https://docs.deno.com/deploy/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Deno Deploy terms and conditions (last modified 30 September 2026) name Deno Land Inc. and govern the Deploy services, of which Sandbox is a part. No separate sandbox terms were found.",
          "The privacy policy (last modified 30 September 2026) gives Deno Land Inc., 1111 6th Ave Ste 550, PMB 702973, San Diego CA 92101. A DPA is listed under Enterprise only, and no public copy was found.",
          "The Python SDK's default sandbox endpoint is `\u003cregion\u003e.sandbox-api.deno.net`, a second domain of the vendor's, while listing and volumes go through console.deno.com.",
          "deno.com/.well-known/security.txt gives deploy@deno.com and a policy link and has no Expires field, which RFC 9116 requires. It is recorded as valid to match other listings with the same gap. The policy page gives security@deno.com.",
          "RDAP for deno.com gives a registration date of 1999-03-09.",
          "The Deploy changelog's newest entry is dated 12 March 2026."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/deno-sandbox.json",
      "live": {
        "slug": "deno-sandbox",
        "vendorStatus": {
          "page": "https://denostatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:48.013369722Z"
        },
        "updatedAt": "2026-10-09T07:57:48.013369722Z"
      }
    },
    "answer": "Freestyle scores 58.5 (C) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability, security \u0026 auth and transparency \u0026 trust.",
    "b": {
      "slug": "freestyle",
      "name": "Freestyle",
      "vendor": "Freestyle Cloud Inc.",
      "vendorUrl": "https://www.freestyle.sh",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Freestyle runs full Linux virtual machines for AI agents, with pause and resume that keeps memory, snapshots, private networks and domains. Agents drive it through a REST API, a TypeScript SDK and a CLI from one npm package.",
      "url": "https://www.anchorterminal.com/tools/freestyle",
      "markdownUrl": "https://www.anchorterminal.com/tools/freestyle.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/freestyle.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/freestyle.json",
      "license": "Proprietary service with no published terms of service found. The `freestyle` SDK and CLI package on npm is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.freestyle.sh/v5",
      "packages": [
        {
          "registry": "npm",
          "name": "freestyle"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key in the `Authorization` header, read by the SDK and CLI from `FREESTYLE_API_KEY`. Keys are created after a browser login with `freestyle tokens create`, shown once, and listed and revoked from the CLI. No scopes or expiry on account keys were found. For end users, an identity access token in the `x-freestyle-identity-access-token` header reaches only the VMs and Linux users granted to it, on the exec and terminal routes.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 200 vCPU-hours, 400 GiB-hours of memory, 60,000 GiB-hours of storage and 50 GB of transfer a month, up to 10 concurrent VMs, no card needed. Usage beyond that needs Hobby ($50 a month minimum, counted as usage) or Pro ($500). $0.04032 a vCPU-hour, $0.0129 a GiB-hour of memory, $0.000086 a GiB-hour of storage and $0.02 a GB of transfer, metered per second on allocated resources. Enterprise is priced by sales (https://www.freestyle.sh/pricing.md, checked 2026-10-08).",
      "priceSummary": "$0.0403 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 71758,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.freestyle.sh/docs",
      "llmsTxt": "https://www.freestyle.sh/llms.txt",
      "openapi": "https://www.freestyle.sh/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.browser"
      ],
      "tags": [
        "hosted",
        "no-card",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "vm",
        "snapshots",
        "enterprise"
      ],
      "lastRelease": "2026-09-27",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.5,
        "grade": "C",
        "agentReady": false,
        "rank": 520,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 71,
          "payments": 45,
          "reliability": 43,
          "schema": 86,
          "security": 53,
          "transparency": 41
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.",
        "bestFor": "Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.",
        "strengths": [
          "Public OpenAPI 3.1 file with 88 `/v5` operations, each with a description and named error codes per status",
          "A new VM has no inbound or outbound network access until firewall rules allow it",
          "Identity access tokens limited to granted VMs and Linux users, revocable without rotating the team API key",
          "Pausing keeps memory and disk, and a paused VM bills for storage only",
          "Free plan at $0 with 200 vCPU-hours a month, and per-unit prices published without a login"
        ],
        "weaknesses": [
          "No terms of service or service agreement found on the site, and the privacy policy covers the website only",
          "The status page shows three components with no incident history",
          "No request rate limit, Retry-After guidance or idempotency keys found in the docs or the OpenAPI file",
          "No security.txt, disclosure policy, bug bounty or SOC 2 statement found. Audit logs are Enterprise only",
          "TypeScript is the only SDK, and the CLI repository linked from the site last changed on 22 May 2025"
        ],
        "agentNotes": [
          "Send a `firewall` object on every `POST /v5/vms`. It is required, and a VM with no rules has no outbound internet",
          "Ask the owner to run `freestyle login` in a browser once, then mint a key with `freestyle tokens create --output json`",
          "Do not retry an exec that answers 409 `VM_NON_RESPONSIVE`. The command may already have run",
          "Keep `exec-await` under its 300,000 ms cap and use a PTY session or `x-freestyle-background-after-secs` for longer work",
          "Call the `/v5` paths. The unversioned duplicates in the OpenAPI file are marked deprecated"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.5
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 71,
          "payments": 45,
          "reliability": 43,
          "schema": 86,
          "security": 53,
          "transparency": 20
        },
        "provenanceScore": 62
      },
      "connect": {
        "install": "npm install freestyle@latest  # CLI without installing: npx freestyle@latest --help"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/freestyle"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.04032,
          "note": "Memory extra at $0.0129 a GiB-hour. 200 vCPU-hours a month included"
        },
        {
          "item": "Data transfer",
          "unit": "gb",
          "usd": 0.02,
          "note": "50 GB a month included on Free, 500 GB on Hobby and Pro"
        },
        {
          "item": "Hobby plan",
          "unit": "month",
          "usd": 50,
          "note": "Monthly minimum, counted as usage"
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 500,
          "note": "Monthly minimum, counted as usage"
        }
      ],
      "provenance": {
        "legalEntity": "Freestyle Cloud Inc.",
        "domain": "freestyle.sh",
        "domainRegistered": "2024-04-11",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "https://www.freestyle.sh/status",
        "changelog": "https://www.freestyle.sh/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 15 June 2025) names Freestyle Cloud Inc. and says it covers the website at freestyle.sh. It is not linked here because it does not govern the product.",
          "No terms of service or service agreement was found. `/terms`, `/tos` and `/legal` answer 404 and the sitemap lists no legal page other than the privacy policy.",
          "The API answers at https://api.freestyle.sh/v5, a freestyle.sh subdomain. One unauthenticated request returned 401 with a `code` and `message`.",
          "www.freestyle.sh/.well-known/security.txt returns 404.",
          "RDAP for freestyle.sh gives a registration date of 2024-04-11 and a transfer on 11 March 2026.",
          "The status page is the vendor's own, with three components and no incident history."
        ],
        "score": 62
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/freestyle.json",
      "live": {
        "slug": "freestyle",
        "probe": {
          "target": "https://api.freestyle.sh/v5",
          "method": "get",
          "lastAt": "2026-10-09T10:42:43.668932977Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 652,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 576,
          "p95ms24h": 652,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.freestyle.sh/status",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:56.720133529Z"
        },
        "updatedAt": "2026-10-09T10:42:43.668932977Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Deno Land Inc.",
        "b": "Freestyle Cloud Inc.",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.freestyle.sh/v5",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
        "b": "Proprietary service with no published terms of service found. The `freestyle` SDK and CLI package on npm is MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-07-22",
        "b": "2026-09-27",
        "name": "Last release"
      },
      {
        "a": "2026-09-30",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-30",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6 stars, 2k npm/wk, 32k PyPI/wk",
        "b": "72k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Freestyle scores 58.5 (C) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability, security \u0026 auth and transparency \u0026 trust.",
        "question": "Which is better for AI agents, Deno Sandbox or Freestyle?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Deno Sandbox and Freestyle need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Deno Sandbox. Freestyle has a hosted endpoint at https://api.freestyle.sh/v5.",
        "question": "Can an agent call Deno Sandbox and Freestyle without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 48 against 43",
          "Security \u0026 auth, 61 against 53",
          "Transparency \u0026 trust, 58 against 41"
        ],
        "also": null,
        "goodFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "slug": "deno-sandbox",
        "watchFor": "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 86 against 66",
          "Agent ergonomics, 69 against 60",
          "Payments \u0026 pricing, 45 against 20",
          "Maintenance \u0026 community, 71 against 45"
        ],
        "also": [
          "A hosted endpoint, with nothing to install",
          "Free to start without a card"
        ],
        "goodFor": "Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.",
        "slug": "freestyle",
        "watchFor": "No terms of service or service agreement found on the site, and the privacy policy covers the website only"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.json",
        "title": "Blaxel Sandboxes vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-freestyle.json",
        "title": "Blaxel Sandboxes vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle.json",
        "title": "Cloudflare Sandbox SDK vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.json",
        "title": "Daytona vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-freestyle.json",
        "title": "Daytona vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.json",
        "title": "Deno Sandbox vs E2B",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
        "title": "Deno Sandbox vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.json",
        "title": "Deno Sandbox vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.json",
        "title": "Deno Sandbox vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.json",
        "title": "Deno Sandbox vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.json",
        "title": "Deno Sandbox vs Sprites",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.json",
        "title": "Deno Sandbox vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.json",
        "title": "Deno Sandbox vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-freestyle.json",
        "title": "E2B vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.json",
        "title": "Freestyle vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-modal-sandboxes.json",
        "title": "Freestyle vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-morph-cloud.json",
        "title": "Freestyle vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-runloop.json",
        "title": "Freestyle vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-sprites.json",
        "title": "Freestyle vs Sprites",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.json",
        "title": "Freestyle vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-vercel-sandbox.json",
        "title": "Freestyle vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.json",
        "title": "Agent 37 Cloud vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-freestyle.json",
        "title": "Agent 37 Cloud vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-freestyle"
      }
    ],
    "scores": [
      {
        "by": 5,
        "deno-sandbox": 48,
        "edge": "deno-sandbox",
        "freestyle": 43,
        "key": "reliability",
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 20,
        "deno-sandbox": 66,
        "edge": "freestyle",
        "freestyle": 86,
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 9,
        "deno-sandbox": 60,
        "edge": "freestyle",
        "freestyle": 69,
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 8,
        "deno-sandbox": 61,
        "edge": "deno-sandbox",
        "freestyle": 53,
        "key": "security",
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 25,
        "deno-sandbox": 20,
        "edge": "freestyle",
        "freestyle": 45,
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 26,
        "deno-sandbox": 45,
        "edge": "freestyle",
        "freestyle": 71,
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 17,
        "deno-sandbox": 58,
        "edge": "deno-sandbox",
        "freestyle": 41,
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Freestyle scores 58.5 (C) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability, security \u0026 auth and transparency \u0026 trust. Both do sandbox code.",
    "verdicts": {
      "deno-sandbox": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
      "freestyle": "A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle",
    "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md",
    "slim": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.min.md"
  },
  "markdown": "Freestyle scores 58.5 (C) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability, security \u0026 auth and transparency \u0026 trust. Both do sandbox code.\n\n- Deno Sandbox: grade D, 50.3/100, rank #689 of 842. Markdown https://www.anchorterminal.com/tools/deno-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json\n- Freestyle: grade C, 58.5/100, rank #520 of 842. Markdown https://www.anchorterminal.com/tools/freestyle.md · JSON https://www.anchorterminal.com/api/v1/tools/freestyle.json\n\n## Which one, for what\n\n### Deno Sandbox (D)\n\nGood for: Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.\n\nAhead on:\n- Reliability, 48 against 43\n- Security \u0026 auth, 61 against 53\n- Transparency \u0026 trust, 58 against 41\n\nWatch for: Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found\n\n### Freestyle (C)\n\nGood for: Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.\n\nAhead on:\n- Schema \u0026 documentation, 86 against 66\n- Agent ergonomics, 69 against 60\n- Payments \u0026 pricing, 45 against 20\n- Maintenance \u0026 community, 71 against 45\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n- Free to start without a card\n\nWatch for: No terms of service or service agreement found on the site, and the privacy policy covers the website only\n\n\n## Score by category\n\n| Category | Weight | Deno Sandbox | Freestyle | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 48 | 43 | Deno Sandbox +5 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 66 | 86 | Freestyle +20 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 69 | Freestyle +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 61 | 53 | Deno Sandbox +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 45 | Freestyle +25 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 45 | 71 | Freestyle +26 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 58 | 41 | Deno Sandbox +17 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **50.3 · D** | **58.5 · C** | |\n\n## Facts side by side\n\n| Fact | Deno Sandbox | Freestyle |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Deno Land Inc. | Freestyle Cloud Inc. |\n| Hosted endpoint | no (local only) | `https://api.freestyle.sh/v5` |\n| Transports | HTTP | HTTP |\n| Auth | API key | API key |\n| Pricing | Paid | Freemium |\n| x402 | no | no |\n| Licence | Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT | Proprietary service with no published terms of service found. The `freestyle` SDK and CLI package on npm is MIT |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-07-22 | 2026-09-27 |\n| Terms last updated | 2026-09-30 | no document linked |\n| Privacy policy last updated | 2026-09-30 | no document linked |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 6 stars, 2k npm/wk, 32k PyPI/wk | 72k npm/wk |\n\n## Verdicts\n\n**Deno Sandbox.** Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.\n\n**Freestyle.** A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.\n\n## Before you call either\n\n### Deno Sandbox\n\n1. Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above\n2. Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted\n3. Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder\n4. The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes\n5. Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region\n6. `exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret\n\n### Freestyle\n\n1. Send a `firewall` object on every `POST /v5/vms`. It is required, and a VM with no rules has no outbound internet\n2. Ask the owner to run `freestyle login` in a browser once, then mint a key with `freestyle tokens create --output json`\n3. Do not retry an exec that answers 409 `VM_NON_RESPONSIVE`. The command may already have run\n4. Keep `exec-await` under its 300,000 ms cap and use a PTY session or `x-freestyle-background-after-secs` for longer work\n5. Call the `/v5` paths. The unversioned duplicates in the OpenAPI file are marked deprecated\n\n## Questions\n\n### Which is better for AI agents, Deno Sandbox or Freestyle?\n\nFreestyle scores 58.5 (C) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability, security \u0026 auth and transparency \u0026 trust.\n\n### Do Deno Sandbox and Freestyle need an API key?\n\nBoth need an API key.\n\n### Can an agent call Deno Sandbox and Freestyle without installing anything?\n\nNo hosted endpoint is listed for Deno Sandbox. Freestyle has a hosted endpoint at https://api.freestyle.sh/v5.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.json, and with the fewest tokens: https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"deno-sandbox\", \"b\": \"freestyle\"}`. From a terminal: `anchor compare deno-sandbox freestyle`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json and https://www.anchorterminal.com/api/v1/tools/freestyle.json\n\n## Other comparisons with Deno Sandbox or Freestyle\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Freestyle](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle.md)\n- [Blaxel Sandboxes vs Deno Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.md)\n- [Blaxel Sandboxes vs Freestyle](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-freestyle.md)\n- [Cloudflare Sandbox SDK vs Deno Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.md)\n- [Cloudflare Sandbox SDK vs Freestyle](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle.md)\n- [Daytona vs Deno Sandbox](https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.md)\n- [Daytona vs Freestyle](https://www.anchorterminal.com/compare/daytona-vs-freestyle.md)\n- [Deno Sandbox vs E2B](https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.md)\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs Modal Sandboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.md)\n- [Deno Sandbox vs Morph Cloud](https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.md)\n- [Deno Sandbox vs Runloop Devboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.md)\n- [Deno Sandbox vs Sprites](https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.md)\n- [Deno Sandbox vs Together Code Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md)\n- [Deno Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.md)\n- [E2B vs Freestyle](https://www.anchorterminal.com/compare/e2b-vs-freestyle.md)\n- [Freestyle vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.md)\n- [Freestyle vs Modal Sandboxes](https://www.anchorterminal.com/compare/freestyle-vs-modal-sandboxes.md)\n- [Freestyle vs Morph Cloud](https://www.anchorterminal.com/compare/freestyle-vs-morph-cloud.md)\n- [Freestyle vs Runloop Devboxes](https://www.anchorterminal.com/compare/freestyle-vs-runloop.md)\n- [Freestyle vs Sprites](https://www.anchorterminal.com/compare/freestyle-vs-sprites.md)\n- [Freestyle vs Together Code Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.md)\n- [Freestyle vs Vercel Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Deno Sandbox](https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.md)\n- [Agent 37 Cloud vs Freestyle](https://www.anchorterminal.com/compare/agent37-vs-freestyle.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Deno Sandbox vs Freestyle",
        "url": ""
      }
    ],
    "description": "Freestyle scores 58.5 (C) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability, security \u0026 auth and transparency \u0026 trust. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Deno Sandbox D 50.3",
      "Freestyle C 58.5",
      "scores"
    ],
    "h1": "Deno Sandbox vs Freestyle",
    "image": "https://www.anchorterminal.com/assets/og/compare-deno-sandbox-vs-freestyle.png",
    "path": "/compare/deno-sandbox-vs-freestyle",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Deno Sandbox vs Freestyle for AI agents, D 50.3 vs C 58.5",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle"
  },
  "tokens": {
    "markdown": 2550,
    "slim": 730
  },
  "version": 1
}
