{
  "data": {
    "a": {
      "slug": "deno-sandbox",
      "name": "Deno Sandbox",
      "vendor": "Deno Land Inc.",
      "vendorUrl": "https://deno.com",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the `@deno/sandbox` JavaScript SDK, the `deno-sandbox` Python SDK or the `deno sandbox` CLI, and launched in beta on 3 February 2026.",
      "url": "https://www.anchorterminal.com/tools/deno-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json",
      "repo": "https://github.com/denoland/sandbox-py",
      "license": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@deno/sandbox"
        },
        {
          "registry": "pypi",
          "name": "deno-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "An organisation access token (prefix `ddo_`) created under Settings in console.deno.com, read by the SDKs from `DENO_DEPLOY_TOKEN` and sent as a Bearer token. The same token manages the organisation's Deno Deploy apps. No scopes or expiry were found in the reviewed docs, the docs say to rotate a leaked token from the dashboard, and all organisation members hold owner permissions. Signup is in a browser.",
      "pricing": "paid",
      "pricingNotes": "Sandboxes need the Pro plan ($20 a month) or above, and the Free plan does not include them. Compute bills through the Deploy meters at $0.10 a CPU-hour and $0.025 a GiB-hour of memory beyond the plan's allowance (50 CPU-hours and 750 GiB-hours on Pro), and volume storage at $0.20 a GiB-month beyond 5 GiB on Pro. Spend limits can be set on paid plans (https://deno.com/deploy/pricing, checked 2026-10-08).",
      "priceSummary": "$0.10 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the sandbox docs, the pricing page or the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 1971,
        "pypiWeekly": 31729,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.deno.com/sandbox/",
      "llmsTxt": "https://docs.deno.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "paid",
        "beta",
        "microvm",
        "typescript",
        "python",
        "cli",
        "llms-txt",
        "status-page",
        "enterprise"
      ],
      "lastRelease": "2026-07-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.3,
        "grade": "D",
        "agentReady": false,
        "rank": 689,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08: the Create page (last modified 28 January 2026) says a default sandbox has no outbound network access, while the Security page of the same date says outbound access is unrestricted unless `allowNet` is set. A reader of the first page would leave egress open. 2 points. https://docs.deno.com/sandbox/create/ and https://docs.deno.com/sandbox/security/"
        ],
        "verdict": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
        "bestFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "strengths": [
          "Secrets are held outside the VM. Code sees a placeholder, and the real value is substituted only on requests to hosts named for that secret",
          "`allowNet` restricts outbound traffic to listed hostnames, wildcard subdomains, ports or IP addresses",
          "Each sandbox is a Firecracker microVM per the product page, with 2 vCPUs, 768 MB to 4 GB of memory and 10 GB of disk",
          "Volumes of 300 MB to 20 GB persist between sandboxes, and read-only snapshots of a volume can boot new sandboxes",
          "Unit prices are public, $0.10 a CPU-hour, $0.025 a GiB-hour of memory and $0.20 a GiB-month of volume storage"
        ],
        "weaknesses": [
          "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found",
          "Sandboxes are not included in the Free plan. Access starts at Pro, $20 a month, after a browser signup",
          "The published OpenAPI document at `api.deno.com/v2/openapi.json` has 34 operations and none for sandboxes, volumes or snapshots",
          "The Create page says a default sandbox has no outbound network access, and the Security page says outbound access is unrestricted by default",
          "Maximum lifetime is 30 minutes, volumes exist only in `ord`, and no API rate limits or 429 guidance were found",
          "Organisation tokens carry no scopes in the reviewed docs, and every organisation member has owner permissions"
        ],
        "agentNotes": [
          "Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above",
          "Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted",
          "Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder",
          "The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes",
          "Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region",
          "`exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 35
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install @deno/sandbox  # or pip install deno-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/deno-sandbox"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active CPU beyond plan allowance",
          "unit": "vcpu-hour",
          "usd": 0.1,
          "note": "Memory extra at $0.025 a GiB-hour"
        },
        {
          "item": "Volume storage beyond plan allowance",
          "unit": "gb-month",
          "usd": 0.2,
          "note": "Priced per GiB"
        },
        {
          "item": "Pro plan, the lowest that includes sandboxes",
          "unit": "month",
          "usd": 20,
          "note": "Includes 50 CPU-hours, 750 GiB-hours of memory and 5 GiB of volume storage"
        }
      ],
      "provenance": {
        "legalEntity": "Deno Land Inc.",
        "domain": "deno.com",
        "domainRegistered": "1999-03-09",
        "endpointOnVendorDomain": false,
        "terms": "https://docs.deno.com/deploy/terms_and_conditions/",
        "privacy": "https://docs.deno.com/deploy/privacy_policy/",
        "statusPage": "https://denostatus.com",
        "changelog": "https://docs.deno.com/deploy/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Deno Deploy terms and conditions (last modified 30 September 2026) name Deno Land Inc. and govern the Deploy services, of which Sandbox is a part. No separate sandbox terms were found.",
          "The privacy policy (last modified 30 September 2026) gives Deno Land Inc., 1111 6th Ave Ste 550, PMB 702973, San Diego CA 92101. A DPA is listed under Enterprise only, and no public copy was found.",
          "The Python SDK's default sandbox endpoint is `\u003cregion\u003e.sandbox-api.deno.net`, a second domain of the vendor's, while listing and volumes go through console.deno.com.",
          "deno.com/.well-known/security.txt gives deploy@deno.com and a policy link and has no Expires field, which RFC 9116 requires. It is recorded as valid to match other listings with the same gap. The policy page gives security@deno.com.",
          "RDAP for deno.com gives a registration date of 1999-03-09.",
          "The Deploy changelog's newest entry is dated 12 March 2026."
        ],
        "score": 80
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/deno-sandbox.json",
      "live": {
        "slug": "deno-sandbox",
        "vendorStatus": {
          "page": "https://denostatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:48.013369722Z"
        },
        "updatedAt": "2026-10-09T07:57:48.013369722Z"
      }
    },
    "answer": "Together Code Sandbox scores 53.6 (D) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability and security \u0026 auth.",
    "b": {
      "slug": "together-code-sandbox",
      "name": "Together Code Sandbox",
      "vendor": "Together AI",
      "vendorUrl": "https://www.together.ai",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Together AI's hosted virtual machine sandboxes for running commands and code, built from Docker-image snapshots and driven from the `together-sandbox` Python SDK, TypeScript SDK or CLI. Access is by allowlist, on request to Together.",
      "url": "https://www.anchorterminal.com/tools/together-code-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json",
      "repo": "https://github.com/togethercomputer/together-sandbox",
      "license": "Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.bartender.codesandbox.io",
      "packages": [
        {
          "registry": "pypi",
          "name": "together-sandbox"
        },
        {
          "registry": "npm",
          "name": "together-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "Access is by allowlist. The docs say the `together-sandbox` SDK and CLI must be enabled for an organisation and to contact Together to request it. Once enabled, a project-scoped Together API key is sent as a Bearer token, read from `TOGETHER_API_KEY`. Keys are revocable, can carry an expiry date and have no finer scopes. Each running sandbox also has its own agent token for the in-VM API, which the SDKs handle.",
      "pricing": "usage",
      "pricingNotes": "The pricing page lists Code Sandbox compute at $0.0446 per vCPU-hour and $0.0149 per GiB of RAM per hour, and does not say whether that rate covers the new SDK as well as the legacy one. No free tier or sandbox lets an agent start without a contract. Together has no free trial, platform access needs a $15 first credit purchase, and the organisation must then be enabled on request (https://www.together.ai/pricing, https://docs.together.ai/docs/billing-credits).",
      "priceSummary": "$0.0446 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs page, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3,
        "npmWeekly": 1298,
        "pypiWeekly": 3387,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.together.ai/docs/together-code-sandbox",
      "llmsTxt": "https://docs.together.ai/llms.txt",
      "openapi": "https://togethercomputer.github.io/together-sandbox/api-openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "usage",
        "allowlist",
        "sales-led",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "cli",
        "security-txt"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.6,
        "grade": "D",
        "agentReady": false,
        "rank": 628,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 20,
          "reliability": 25,
          "schema": 86,
          "security": 47,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.",
        "bestFor": "Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.",
        "strengths": [
          "Public OpenAPI documents for the management API (17 operations) and the in-VM API (25), in the repository and on GitHub Pages",
          "Terminating with `memory: true` saves disk and memory, and a new sandbox created from that snapshot resumes its running processes",
          "List calls are cursor-paginated (1 to 100 a page) with filters for status, source snapshot and tags",
          "Both SDKs retry 408, 429 and 5xx three times with exponential backoff, and the docs warn that `snapshots.create` is not idempotent",
          "Releases on 30 September, 1 October and 7 October 2026, with a generated changelog that marks breaking changes"
        ],
        "weaknesses": [
          "The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access",
          "No rate limits, concurrency limits or SLA found, and neither status.together.ai nor status.codesandbox.io names the service",
          "Every sandbox port is public unless an experimental inbound policy is set, and no outbound controls exist yet",
          "Three major versions between 2 June and 28 July 2026, and memory snapshots were removed in 4.0.0 and restored in 4.0.4",
          "The management API answers at `api.bartender.codesandbox.io`, off Together's domain, and the privacy policy's data table has no sandbox row"
        ],
        "agentNotes": [
          "Confirm the organisation is on Together's allowlist before installing. A valid `TOGETHER_API_KEY` alone is not enough",
          "Build a snapshot first with `snapshots.create`. No default image exists, and every sandbox needs `snapshot_id` or `snapshot_alias`",
          "Set `ttl` at creation or call `terminate()`. Nothing stops a sandbox otherwise, and closing the Python client leaves it running",
          "Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at `sandbox:\u003cid\u003e`",
          "Exclude `snapshots.create` from retries with `should_retry`, and set `experimental.network_policy` before serving anything private on a port"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.6
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 20,
          "reliability": 25,
          "schema": 86,
          "security": 47,
          "transparency": 43
        },
        "provenanceScore": 77
      },
      "connect": {
        "install": "pip install together-sandbox  # or npm install together-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/together-code-sandbox"
      },
      "sameCompany": [
        "together-fine-tuning"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.0446,
          "note": "RAM extra at $0.0149 per GiB-hour. Listed under Code Sandbox on the pricing page, which doesn't name the SDK"
        },
        {
          "item": "Default sandbox (1 vCPU, 2 GiB)",
          "unit": "session-hour",
          "usd": 0.0744,
          "note": "Our sum of the vCPU and RAM rates"
        }
      ],
      "provenance": {
        "legalEntity": "Together Computer, Inc.",
        "domain": "together.ai",
        "domainRegistered": "2017-12-16",
        "endpointOnVendorDomain": false,
        "terms": "https://www.together.ai/terms-of-service",
        "privacy": "https://www.together.ai/privacy",
        "statusPage": "https://status.together.ai",
        "changelog": "https://github.com/togethercomputer/together-sandbox/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (updated 19 May 2026) name Together Computer, Inc., a Delaware corporation at 251 Rhode Island Street, San Francisco, and cover the website and the Services. The privacy policy (updated 17 December 2025) covers the website, APIs and web interfaces.",
          "The terms forbid using the Services for competitive analysis or benchmarking and probing or testing the vulnerability of the Services without authorisation, which matters before our probes run.",
          "The management API answers at api.bartender.codesandbox.io and sandbox URLs sit under csb.app. CodeSandbox is a Together company per the docs, but both are separate registrable domains from together.ai.",
          "status.together.ai has no sandbox component. status.codesandbox.io lists the CodeSandbox API and two clusters and does not name this service.",
          "security.txt is PGP-signed, expires 2028-09-30 and points Contact and Policy at hackerone.com/together_ai. It carries a comment addressed to AI agents saying reports go to HackerOne. Recorded as a fact, and we did not act on it.",
          "RDAP for together.ai gives a registration date of 2017-12-16.",
          "trust.together.ai is script-drawn and showed our reader only its title. No DPA or sub-processor page was found."
        ],
        "score": 77
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.json",
      "live": {
        "slug": "together-code-sandbox",
        "probe": {
          "target": "https://api.bartender.codesandbox.io",
          "method": "get",
          "lastAt": "2026-10-09T11:46:43.223654648Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 849,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 148,
          "p95ms24h": 182,
          "samples24h": 44,
          "samples30d": 44,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 44,
              "ok": 44
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.together.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:36.139351511Z"
        },
        "updatedAt": "2026-10-09T11:46:43.223654648Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Deno Land Inc.",
        "b": "Together AI",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.bartender.codesandbox.io",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
        "b": "Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-07-22",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "2026-09-30",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "2026-09-30",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "6 stars, 2k npm/wk, 32k PyPI/wk",
        "b": "3 stars, 1.3k npm/wk, 3.4k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Together Code Sandbox scores 53.6 (D) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability and security \u0026 auth.",
        "question": "Which is better for AI agents, Deno Sandbox or Together Code Sandbox?"
      },
      {
        "answer": "Both need an API key.",
        "question": "Do Deno Sandbox and Together Code Sandbox need an API key?"
      },
      {
        "answer": "No hosted endpoint is listed for Deno Sandbox. Together Code Sandbox has a hosted endpoint at https://api.bartender.codesandbox.io.",
        "question": "Can an agent call Deno Sandbox and Together Code Sandbox without installing anything?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 48 against 25",
          "Security \u0026 auth, 61 against 47"
        ],
        "also": null,
        "goodFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "slug": "deno-sandbox",
        "watchFor": "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 86 against 66",
          "Agent ergonomics, 70 against 60",
          "Maintenance \u0026 community, 83 against 45"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.",
        "slug": "together-code-sandbox",
        "watchFor": "The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.json",
        "title": "Blaxel Sandboxes vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-together-code-sandbox.json",
        "title": "Blaxel Sandboxes vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.json",
        "title": "Daytona vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox.json",
        "title": "Daytona vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.json",
        "title": "Deno Sandbox vs E2B",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.json",
        "title": "Deno Sandbox vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
        "title": "Deno Sandbox vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.json",
        "title": "Deno Sandbox vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.json",
        "title": "Deno Sandbox vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.json",
        "title": "Deno Sandbox vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.json",
        "title": "Deno Sandbox vs Sprites",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.json",
        "title": "Deno Sandbox vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-together-code-sandbox.json",
        "title": "E2B vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.json",
        "title": "Freestyle vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.json",
        "title": "Microsoft Execution Containers vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-together-code-sandbox.json",
        "title": "Modal Sandboxes vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-together-code-sandbox.json",
        "title": "Morph Cloud vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/runloop-vs-together-code-sandbox.json",
        "title": "Runloop Devboxes vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/runloop-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox.json",
        "title": "Sprites vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/together-code-sandbox-vs-vercel-sandbox.json",
        "title": "Together Code Sandbox vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/together-code-sandbox-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.json",
        "title": "Agent 37 Cloud vs Deno Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-together-code-sandbox.json",
        "title": "Agent 37 Cloud vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-together-code-sandbox"
      }
    ],
    "scores": [
      {
        "by": 23,
        "deno-sandbox": 48,
        "edge": "deno-sandbox",
        "key": "reliability",
        "name": "Reliability",
        "together-code-sandbox": 25,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 20,
        "deno-sandbox": 66,
        "edge": "together-code-sandbox",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "together-code-sandbox": 86,
        "weight": 13
      },
      {
        "by": 10,
        "deno-sandbox": 60,
        "edge": "together-code-sandbox",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "together-code-sandbox": 70,
        "weight": 13
      },
      {
        "by": 14,
        "deno-sandbox": 61,
        "edge": "deno-sandbox",
        "key": "security",
        "name": "Security \u0026 auth",
        "together-code-sandbox": 47,
        "weight": 14
      },
      {
        "by": 0,
        "deno-sandbox": 20,
        "edge": "",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "together-code-sandbox": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 38,
        "deno-sandbox": 45,
        "edge": "together-code-sandbox",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "together-code-sandbox": 83,
        "weight": 7
      },
      {
        "by": 2,
        "deno-sandbox": 58,
        "edge": "together-code-sandbox",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "together-code-sandbox": 60,
        "weight": 7
      }
    ],
    "summary": "Together Code Sandbox scores 53.6 (D) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability and security \u0026 auth. Both do sandbox code.",
    "verdicts": {
      "deno-sandbox": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
      "together-code-sandbox": "Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox",
    "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md",
    "slim": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.min.md"
  },
  "markdown": "Together Code Sandbox scores 53.6 (D) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability and security \u0026 auth. Both do sandbox code.\n\n- Deno Sandbox: grade D, 50.3/100, rank #689 of 842. Markdown https://www.anchorterminal.com/tools/deno-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json\n- Together Code Sandbox: grade D, 53.6/100, rank #628 of 842. Markdown https://www.anchorterminal.com/tools/together-code-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json\n\n## Which one, for what\n\n### Deno Sandbox (D)\n\nGood for: Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.\n\nAhead on:\n- Reliability, 48 against 25\n- Security \u0026 auth, 61 against 47\n\nWatch for: Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found\n\n### Together Code Sandbox (D)\n\nGood for: Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.\n\nAhead on:\n- Schema \u0026 documentation, 86 against 66\n- Agent ergonomics, 70 against 60\n- Maintenance \u0026 community, 83 against 45\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access\n\n\n## Score by category\n\n| Category | Weight | Deno Sandbox | Together Code Sandbox | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 48 | 25 | Deno Sandbox +23 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 66 | 86 | Together Code Sandbox +20 |\n| Agent ergonomics | 13% (16.2 this run) | 60 | 70 | Together Code Sandbox +10 |\n| Security \u0026 auth | 14% (17.5 this run) | 61 | 47 | Deno Sandbox +14 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 20 | 20 | even |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 45 | 83 | Together Code Sandbox +38 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 58 | 60 | Together Code Sandbox +2 |\n| Negative events | ≤15 | -2 | 0 | |\n| **Total** | | **50.3 · D** | **53.6 · D** | |\n\n## Facts side by side\n\n| Fact | Deno Sandbox | Together Code Sandbox |\n| --- | --- | --- |\n| Kind | HTTP API | HTTP API |\n| Vendor | Deno Land Inc. | Together AI |\n| Hosted endpoint | no (local only) | `https://api.bartender.codesandbox.io` |\n| Transports | HTTP | HTTP |\n| Auth | API key | API key |\n| Pricing | Paid | Pay per use |\n| x402 | no | no |\n| Licence | Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT | Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT |\n| Read-only variant documented | yes | no |\n| llms.txt | yes | yes |\n| Last release | 2026-07-22 | 2026-10-07 |\n| Terms last updated | 2026-09-30 | no date given |\n| Privacy policy last updated | 2026-09-30 | no date given |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | not found in the text | not found in the text |\n| Terms restrict benchmarking | yes | yes |\n| Terms or service can change without notice | yes | not found in the text |\n| Arbitration or class-action waiver | yes | not found in the text |\n| Popularity | 6 stars, 2k npm/wk, 32k PyPI/wk | 3 stars, 1.3k npm/wk, 3.4k PyPI/wk |\n\n## Verdicts\n\n**Deno Sandbox.** Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.\n\n**Together Code Sandbox.** Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.\n\n## Before you call either\n\n### Deno Sandbox\n\n1. Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above\n2. Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted\n3. Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder\n4. The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes\n5. Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region\n6. `exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret\n\n### Together Code Sandbox\n\n1. Confirm the organisation is on Together's allowlist before installing. A valid `TOGETHER_API_KEY` alone is not enough\n2. Build a snapshot first with `snapshots.create`. No default image exists, and every sandbox needs `snapshot_id` or `snapshot_alias`\n3. Set `ttl` at creation or call `terminate()`. Nothing stops a sandbox otherwise, and closing the Python client leaves it running\n4. Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at `sandbox:\u003cid\u003e`\n5. Exclude `snapshots.create` from retries with `should_retry`, and set `experimental.network_policy` before serving anything private on a port\n\n## Questions\n\n### Which is better for AI agents, Deno Sandbox or Together Code Sandbox?\n\nTogether Code Sandbox scores 53.6 (D) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability and security \u0026 auth.\n\n### Do Deno Sandbox and Together Code Sandbox need an API key?\n\nBoth need an API key.\n\n### Can an agent call Deno Sandbox and Together Code Sandbox without installing anything?\n\nNo hosted endpoint is listed for Deno Sandbox. Together Code Sandbox has a hosted endpoint at https://api.bartender.codesandbox.io.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.json, and with the fewest tokens: https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"deno-sandbox\", \"b\": \"together-code-sandbox\"}`. From a terminal: `anchor compare deno-sandbox together-code-sandbox`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json and https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json\n\n## Other comparisons with Deno Sandbox or Together Code Sandbox\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Together Code Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox.md)\n- [Blaxel Sandboxes vs Deno Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.md)\n- [Blaxel Sandboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-together-code-sandbox.md)\n- [Cloudflare Sandbox SDK vs Deno Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.md)\n- [Cloudflare Sandbox SDK vs Together Code Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox.md)\n- [Daytona vs Deno Sandbox](https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.md)\n- [Daytona vs Together Code Sandbox](https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox.md)\n- [Deno Sandbox vs E2B](https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.md)\n- [Deno Sandbox vs Freestyle](https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md)\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs Modal Sandboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.md)\n- [Deno Sandbox vs Morph Cloud](https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.md)\n- [Deno Sandbox vs Runloop Devboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.md)\n- [Deno Sandbox vs Sprites](https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.md)\n- [Deno Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.md)\n- [E2B vs Together Code Sandbox](https://www.anchorterminal.com/compare/e2b-vs-together-code-sandbox.md)\n- [Freestyle vs Together Code Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.md)\n- [Microsoft Execution Containers vs Together Code Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.md)\n- [Modal Sandboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/modal-sandboxes-vs-together-code-sandbox.md)\n- [Morph Cloud vs Together Code Sandbox](https://www.anchorterminal.com/compare/morph-cloud-vs-together-code-sandbox.md)\n- [Runloop Devboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/runloop-vs-together-code-sandbox.md)\n- [Sprites vs Together Code Sandbox](https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox.md)\n- [Together Code Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/together-code-sandbox-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Deno Sandbox](https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.md)\n- [Agent 37 Cloud vs Together Code Sandbox](https://www.anchorterminal.com/compare/agent37-vs-together-code-sandbox.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Deno Sandbox vs Together Code Sandbox",
        "url": ""
      }
    ],
    "description": "Together Code Sandbox scores 53.6 (D) on agent readiness against Deno Sandbox's 50.3 (D), and leads in 4 of 7 scored categories. Deno Sandbox leads on reliability and security \u0026 auth. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Deno Sandbox D 50.3",
      "Together Code Sandbox D 53.6",
      "scores"
    ],
    "h1": "Deno Sandbox vs Together Code Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/compare-deno-sandbox-vs-together-code-sandbox.png",
    "path": "/compare/deno-sandbox-vs-together-code-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Deno Sandbox vs Together Code Sandbox for AI agents, D 50.3 vs D 53.6",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox"
  },
  "tokens": {
    "markdown": 2700,
    "slim": 680
  },
  "version": 1
}
