{
  "data": {
    "a": {
      "slug": "deno-sandbox",
      "name": "Deno Sandbox",
      "vendor": "Deno Land Inc.",
      "vendorUrl": "https://deno.com",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the `@deno/sandbox` JavaScript SDK, the `deno-sandbox` Python SDK or the `deno sandbox` CLI, and launched in beta on 3 February 2026.",
      "url": "https://www.anchorterminal.com/tools/deno-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json",
      "repo": "https://github.com/denoland/sandbox-py",
      "license": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@deno/sandbox"
        },
        {
          "registry": "pypi",
          "name": "deno-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "An organisation access token (prefix `ddo_`) created under Settings in console.deno.com, read by the SDKs from `DENO_DEPLOY_TOKEN` and sent as a Bearer token. The same token manages the organisation's Deno Deploy apps. No scopes or expiry were found in the reviewed docs, the docs say to rotate a leaked token from the dashboard, and all organisation members hold owner permissions. Signup is in a browser.",
      "pricing": "paid",
      "pricingNotes": "Sandboxes need the Pro plan ($20 a month) or above, and the Free plan does not include them. Compute bills through the Deploy meters at $0.10 a CPU-hour and $0.025 a GiB-hour of memory beyond the plan's allowance (50 CPU-hours and 750 GiB-hours on Pro), and volume storage at $0.20 a GiB-month beyond 5 GiB on Pro. Spend limits can be set on paid plans (https://deno.com/deploy/pricing, checked 2026-10-08).",
      "priceSummary": "$0.10 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the sandbox docs, the pricing page or the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 1971,
        "pypiWeekly": 31729,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.deno.com/sandbox/",
      "llmsTxt": "https://docs.deno.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "paid",
        "beta",
        "microvm",
        "typescript",
        "python",
        "cli",
        "llms-txt",
        "status-page",
        "enterprise"
      ],
      "lastRelease": "2026-07-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.3,
        "grade": "D",
        "agentReady": false,
        "rank": 689,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08: the Create page (last modified 28 January 2026) says a default sandbox has no outbound network access, while the Security page of the same date says outbound access is unrestricted unless `allowNet` is set. A reader of the first page would leave egress open. 2 points. https://docs.deno.com/sandbox/create/ and https://docs.deno.com/sandbox/security/"
        ],
        "verdict": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
        "bestFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "strengths": [
          "Secrets are held outside the VM. Code sees a placeholder, and the real value is substituted only on requests to hosts named for that secret",
          "`allowNet` restricts outbound traffic to listed hostnames, wildcard subdomains, ports or IP addresses",
          "Each sandbox is a Firecracker microVM per the product page, with 2 vCPUs, 768 MB to 4 GB of memory and 10 GB of disk",
          "Volumes of 300 MB to 20 GB persist between sandboxes, and read-only snapshots of a volume can boot new sandboxes",
          "Unit prices are public, $0.10 a CPU-hour, $0.025 a GiB-hour of memory and $0.20 a GiB-month of volume storage"
        ],
        "weaknesses": [
          "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found",
          "Sandboxes are not included in the Free plan. Access starts at Pro, $20 a month, after a browser signup",
          "The published OpenAPI document at `api.deno.com/v2/openapi.json` has 34 operations and none for sandboxes, volumes or snapshots",
          "The Create page says a default sandbox has no outbound network access, and the Security page says outbound access is unrestricted by default",
          "Maximum lifetime is 30 minutes, volumes exist only in `ord`, and no API rate limits or 429 guidance were found",
          "Organisation tokens carry no scopes in the reviewed docs, and every organisation member has owner permissions"
        ],
        "agentNotes": [
          "Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above",
          "Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted",
          "Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder",
          "The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes",
          "Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region",
          "`exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 35
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install @deno/sandbox  # or pip install deno-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/deno-sandbox"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active CPU beyond plan allowance",
          "unit": "vcpu-hour",
          "usd": 0.1,
          "note": "Memory extra at $0.025 a GiB-hour"
        },
        {
          "item": "Volume storage beyond plan allowance",
          "unit": "gb-month",
          "usd": 0.2,
          "note": "Priced per GiB"
        },
        {
          "item": "Pro plan, the lowest that includes sandboxes",
          "unit": "month",
          "usd": 20,
          "note": "Includes 50 CPU-hours, 750 GiB-hours of memory and 5 GiB of volume storage"
        }
      ],
      "provenance": {
        "legalEntity": "Deno Land Inc.",
        "domain": "deno.com",
        "domainRegistered": "1999-03-09",
        "endpointOnVendorDomain": false,
        "terms": "https://docs.deno.com/deploy/terms_and_conditions/",
        "privacy": "https://docs.deno.com/deploy/privacy_policy/",
        "statusPage": "https://denostatus.com",
        "changelog": "https://docs.deno.com/deploy/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Deno Deploy terms and conditions (last modified 30 September 2026) name Deno Land Inc. and govern the Deploy services, of which Sandbox is a part. No separate sandbox terms were found.",
          "The privacy policy (last modified 30 September 2026) gives Deno Land Inc., 1111 6th Ave Ste 550, PMB 702973, San Diego CA 92101. A DPA is listed under Enterprise only, and no public copy was found.",
          "The Python SDK's default sandbox endpoint is `\u003cregion\u003e.sandbox-api.deno.net`, a second domain of the vendor's, while listing and volumes go through console.deno.com.",
          "deno.com/.well-known/security.txt gives deploy@deno.com and a policy link and has no Expires field, which RFC 9116 requires. It is recorded as valid to match other listings with the same gap. The policy page gives security@deno.com.",
          "RDAP for deno.com gives a registration date of 1999-03-09.",
          "The Deploy changelog's newest entry is dated 12 March 2026."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/deno-sandbox.json",
      "live": {
        "slug": "deno-sandbox",
        "vendorStatus": {
          "page": "https://denostatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:48.013369722Z"
        },
        "updatedAt": "2026-10-09T07:57:48.013369722Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category.",
    "b": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 35,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Deno Land Inc.",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-07-22",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "2026-09-30",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-30",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6 stars, 2k npm/wk, 32k PyPI/wk",
        "b": "1.5k stars, 472k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category.",
        "question": "Which is better for AI agents, Deno Sandbox or Microsoft Execution Containers?"
      },
      {
        "answer": "No hosted endpoint is listed for Deno Sandbox. No hosted endpoint is listed for Microsoft Execution Containers.",
        "question": "Can an agent call Deno Sandbox and Microsoft Execution Containers without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Deno Sandbox. Microsoft Execution Containers is open source (MIT).",
        "question": "Are Deno Sandbox and Microsoft Execution Containers open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "slug": "deno-sandbox",
        "watchFor": "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found"
      },
      {
        "aheadOn": [
          "Reliability, 81 against 48",
          "Schema \u0026 documentation, 81 against 66",
          "Agent ergonomics, 74 against 60",
          "Security \u0026 auth, 69 against 61",
          "Payments \u0026 pricing, 60 against 20",
          "Maintenance \u0026 community, 92 against 45",
          "Transparency \u0026 trust, 83 against 58"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.json",
        "title": "Blaxel Sandboxes vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.json",
        "title": "Daytona vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.json",
        "title": "Deno Sandbox vs E2B",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.json",
        "title": "Deno Sandbox vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.json",
        "title": "Deno Sandbox vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.json",
        "title": "Deno Sandbox vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.json",
        "title": "Deno Sandbox vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.json",
        "title": "Deno Sandbox vs Sprites",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.json",
        "title": "Deno Sandbox vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.json",
        "title": "Deno Sandbox vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.json",
        "title": "Freestyle vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.json",
        "title": "Microsoft Execution Containers vs Sprites",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.json",
        "title": "Microsoft Execution Containers vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.json",
        "title": "Agent 37 Cloud vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      }
    ],
    "scores": [
      {
        "by": 33,
        "deno-sandbox": 48,
        "edge": "microsoft-execution-containers",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "deno-sandbox": 66,
        "edge": "microsoft-execution-containers",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 14,
        "deno-sandbox": 60,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 8,
        "deno-sandbox": 61,
        "edge": "microsoft-execution-containers",
        "key": "security",
        "microsoft-execution-containers": 69,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 40,
        "deno-sandbox": 20,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 47,
        "deno-sandbox": 45,
        "edge": "microsoft-execution-containers",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 25,
        "deno-sandbox": 58,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category. Both do sandbox code.",
    "verdicts": {
      "deno-sandbox": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers",
    "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md",
    "slim": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category. Both do sandbox code.\n\n- Deno Sandbox: grade D, 50.3/100, rank #689 of 842. Markdown https://www.anchorterminal.com/tools/deno-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #35 of 842. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n\n## Which one, for what\n\n### Deno Sandbox (D)\n\nGood for: Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.\n\nWatch for: Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 48\n- Schema \u0026 documentation, 81 against 66\n- Agent ergonomics, 74 against 60\n- Security \u0026 auth, 69 against 61\n- Payments \u0026 pricing, 60 against 20\n- Maintenance \u0026 community, 92 against 45\n- Transparency \u0026 trust, 83 against 58\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Free to start without a card\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n\n## Score by category\n\n| Category | Weight | Deno Sandbox | Microsoft Execution Containers | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 48 | 81 | Microsoft Execution Containers +33 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 66 | 81 | Microsoft Execution Containers +15 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 74 | Microsoft Execution Containers +14 |\n| Security \u0026 auth | 14% (17.5 this run) | 61 | 69 | Microsoft Execution Containers +8 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 60 | Microsoft Execution Containers +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 45 | 92 | Microsoft Execution Containers +47 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 58 | 83 | Microsoft Execution Containers +25 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **50.3 · D** | **76.3 · BB** | |\n\n## Facts side by side\n\n| Fact | Deno Sandbox | Microsoft Execution Containers |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Deno Land Inc. | Microsoft |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports | HTTP |  |\n| Auth | API key | None |\n| Pricing | Paid | Free |\n| x402 | no | no |\n| Licence | Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT | MIT |\n| Read-only variant documented | yes | yes |\n| llms.txt | yes | no |\n| Last release | 2026-07-22 | 2026-10-06 |\n| Terms last updated | 2026-09-30 | no document linked |\n| Privacy policy last updated | 2026-09-30 | couldn't be read |\n| Customer content may train models | not found in the text |  |\n| Terms restrict automated access | not found in the text |  |\n| Terms restrict benchmarking | yes |  |\n| Terms or service can change without notice | yes |  |\n| Arbitration or class-action waiver | yes |  |\n| Popularity | 6 stars, 2k npm/wk, 32k PyPI/wk | 1.5k stars, 472k npm/wk |\n\n## Verdicts\n\n**Deno Sandbox.** Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n## Before you call either\n\n### Deno Sandbox\n\n1. Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above\n2. Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted\n3. Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder\n4. The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes\n5. Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region\n6. `exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n## Questions\n\n### Which is better for AI agents, Deno Sandbox or Microsoft Execution Containers?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category.\n\n### Can an agent call Deno Sandbox and Microsoft Execution Containers without installing anything?\n\nNo hosted endpoint is listed for Deno Sandbox. No hosted endpoint is listed for Microsoft Execution Containers.\n\n### Are Deno Sandbox and Microsoft Execution Containers open source?\n\nNo open-source release is listed for Deno Sandbox. Microsoft Execution Containers is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json, and with the fewest tokens: https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"deno-sandbox\", \"b\": \"microsoft-execution-containers\"}`. From a terminal: `anchor compare deno-sandbox microsoft-execution-containers`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json and https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n\n## Other comparisons with Deno Sandbox or Microsoft Execution Containers\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Deno Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.md)\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Deno Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Daytona vs Deno Sandbox](https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs E2B](https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.md)\n- [Deno Sandbox vs Freestyle](https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md)\n- [Deno Sandbox vs Modal Sandboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.md)\n- [Deno Sandbox vs Morph Cloud](https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.md)\n- [Deno Sandbox vs Runloop Devboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.md)\n- [Deno Sandbox vs Sprites](https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.md)\n- [Deno Sandbox vs Together Code Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md)\n- [Deno Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [Freestyle vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Microsoft Execution Containers vs Sprites](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.md)\n- [Microsoft Execution Containers vs Together Code Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Deno Sandbox](https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Deno Sandbox vs Microsoft Execution Containers",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Deno Sandbox's 50.3 (D), and leads in every scored category. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Deno Sandbox D 50.3",
      "Microsoft Execution Containers BB 76.3",
      "scores"
    ],
    "h1": "Deno Sandbox vs Microsoft Execution Containers",
    "image": "https://www.anchorterminal.com/assets/og/compare-deno-sandbox-vs-microsoft-execution-containers.png",
    "path": "/compare/deno-sandbox-vs-microsoft-execution-containers",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Deno Sandbox vs Microsoft Execution Containers for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
  },
  "tokens": {
    "markdown": 2800,
    "slim": 730
  },
  "version": 1
}
