Head to head · Sandbox code · October 2026 research run

Freestyle vs Microsoft Execution Containers

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema & documentation. Both do sandbox code.

Which one, for what

Freestyle C

Good for Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.

Ahead on

  • Schema & documentation, 86 against 81

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

No terms of service or service agreement found on the site, and the privacy policy covers the website only

Microsoft Execution Containers BB

Good for A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.

Ahead on

  • Reliability, 81 against 43
  • Agent ergonomics, 74 against 69
  • Security & auth, 69 against 53
  • Payments & pricing, 60 against 45
  • Maintenance & community, 92 against 71
  • Transparency & trust, 83 against 41

Also in its favour

  • Agent-ready, a grade of BB or better
  • No key needed to call it
  • Open source

Watch for

1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased

Score by category

CategoryWeight this runFreestyleMicrosoft Execution ContainersEdge
Reliability16%204381Microsoft Execution Containers +38
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28681Freestyle +5
Agent ergonomics13%16.26974Microsoft Execution Containers +5
Security & auth14%17.55369Microsoft Execution Containers +16
Payments & pricing10%12.54560Microsoft Execution Containers +15
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.87192Microsoft Execution Containers +21
Transparency & trust7%8.84183Microsoft Execution Containers +42
Negative events≤1500
Total58.5 · C76.3 · BB

Facts side by side

FactFreestyleMicrosoft Execution Containers
KindHTTP APISDK + MCP
VendorFreestyle Cloud Inc.Microsoft
Hosted endpointhttps://api.freestyle.sh/v5no (local only)
TransportsHTTP
AuthAPI keyNone
PricingFreemiumFree
x402nono
LicenceProprietary service with no published terms of service found. The freestyle SDK and CLI package on npm is MITMIT
Read-only variant documentednoyes
llms.txtyesno
Last release2026-09-272026-10-06
Terms last updatedno document linkedno document linked
Privacy policy last updatedno document linkedcouldn't be read
Customer content may train models
Terms restrict automated access
Terms restrict benchmarking
Terms or service can change without notice
Arbitration or class-action waiver
Popularity72k npm/wk1.5k stars, 472k npm/wk

Verdicts

Freestyle

A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.

Microsoft Execution Containers

MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and isolation_session cannot restrict networking at all.

Before you call either

Freestyle

  1. Send a firewall object on every POST /v5/vms. It is required, and a VM with no rules has no outbound internet
  2. Ask the owner to run freestyle login in a browser once, then mint a key with freestyle tokens create --output json
  3. Do not retry an exec that answers 409 VM_NON_RESPONSIVE. The command may already have run
  4. Keep exec-await under its 300,000 ms cap and use a PTY session or x-freestyle-background-after-secs for longer work
  5. Call the /v5 paths. The unversioned duplicates in the OpenAPI file are marked deprecated

Microsoft Execution Containers

  1. Import from @microsoft/mxc-sdk/v1. The package root exports nothing.
  2. Call getPlatformSupport() first and stop if isSupported is false. getAvailableBackends() is advisory and launch-time validation still applies.
  3. Set network.egress.default to allow only when the task needs it. Omitted network policy resolves to deny in every direction.
  4. Never pass --audit to an executor for untrusted code. It turns off all sandbox security for the workload.
  5. Read ExecutionResult.warnings after each run. Security warnings arrive there and are not written to stdout or stderr.

Questions

Which is better for AI agents, Freestyle or Microsoft Execution Containers?

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema & documentation.

Can an agent call Freestyle and Microsoft Execution Containers without installing anything?

Freestyle has a hosted endpoint at https://api.freestyle.sh/v5. No hosted endpoint is listed for Microsoft Execution Containers.

Are Freestyle and Microsoft Execution Containers open source?

No open-source release is listed for Freestyle. Microsoft Execution Containers is open source (MIT).

Other comparisons with Freestyle or Microsoft Execution Containers

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.