{
  "data": {
    "a": {
      "slug": "freestyle",
      "name": "Freestyle",
      "vendor": "Freestyle Cloud Inc.",
      "vendorUrl": "https://www.freestyle.sh",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Freestyle runs full Linux virtual machines for AI agents, with pause and resume that keeps memory, snapshots, private networks and domains. Agents drive it through a REST API, a TypeScript SDK and a CLI from one npm package.",
      "url": "https://www.anchorterminal.com/tools/freestyle",
      "markdownUrl": "https://www.anchorterminal.com/tools/freestyle.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/freestyle.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/freestyle.json",
      "license": "Proprietary service with no published terms of service found. The `freestyle` SDK and CLI package on npm is MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.freestyle.sh/v5",
      "packages": [
        {
          "registry": "npm",
          "name": "freestyle"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key in the `Authorization` header, read by the SDK and CLI from `FREESTYLE_API_KEY`. Keys are created after a browser login with `freestyle tokens create`, shown once, and listed and revoked from the CLI. No scopes or expiry on account keys were found. For end users, an identity access token in the `x-freestyle-identity-access-token` header reaches only the VMs and Linux users granted to it, on the exec and terminal routes.",
      "pricing": "freemium",
      "pricingNotes": "Free plan at $0 with 200 vCPU-hours, 400 GiB-hours of memory, 60,000 GiB-hours of storage and 50 GB of transfer a month, up to 10 concurrent VMs, no card needed. Usage beyond that needs Hobby ($50 a month minimum, counted as usage) or Pro ($500). $0.04032 a vCPU-hour, $0.0129 a GiB-hour of memory, $0.000086 a GiB-hour of storage and $0.02 a GB of transfer, metered per second on allocated resources. Enterprise is priced by sales (https://www.freestyle.sh/pricing.md, checked 2026-10-08).",
      "priceSummary": "$0.0403 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 71758,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://www.freestyle.sh/docs",
      "llmsTxt": "https://www.freestyle.sh/llms.txt",
      "openapi": "https://www.freestyle.sh/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.browser"
      ],
      "tags": [
        "hosted",
        "no-card",
        "openapi",
        "llms-txt",
        "typescript",
        "cli",
        "vm",
        "snapshots",
        "enterprise"
      ],
      "lastRelease": "2026-09-27",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.5,
        "grade": "C",
        "agentReady": false,
        "rank": 520,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 10,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 69,
          "maintenance": 71,
          "payments": 45,
          "reliability": 43,
          "schema": 86,
          "security": 53,
          "transparency": 41
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.",
        "bestFor": "Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.",
        "strengths": [
          "Public OpenAPI 3.1 file with 88 `/v5` operations, each with a description and named error codes per status",
          "A new VM has no inbound or outbound network access until firewall rules allow it",
          "Identity access tokens limited to granted VMs and Linux users, revocable without rotating the team API key",
          "Pausing keeps memory and disk, and a paused VM bills for storage only",
          "Free plan at $0 with 200 vCPU-hours a month, and per-unit prices published without a login"
        ],
        "weaknesses": [
          "No terms of service or service agreement found on the site, and the privacy policy covers the website only",
          "The status page shows three components with no incident history",
          "No request rate limit, Retry-After guidance or idempotency keys found in the docs or the OpenAPI file",
          "No security.txt, disclosure policy, bug bounty or SOC 2 statement found. Audit logs are Enterprise only",
          "TypeScript is the only SDK, and the CLI repository linked from the site last changed on 22 May 2025"
        ],
        "agentNotes": [
          "Send a `firewall` object on every `POST /v5/vms`. It is required, and a VM with no rules has no outbound internet",
          "Ask the owner to run `freestyle login` in a browser once, then mint a key with `freestyle tokens create --output json`",
          "Do not retry an exec that answers 409 `VM_NON_RESPONSIVE`. The command may already have run",
          "Keep `exec-await` under its 300,000 ms cap and use a PTY session or `x-freestyle-background-after-secs` for longer work",
          "Call the `/v5` paths. The unversioned duplicates in the OpenAPI file are marked deprecated"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.5
          }
        ],
        "editorialScores": {
          "ergonomics": 69,
          "maintenance": 71,
          "payments": 45,
          "reliability": 43,
          "schema": 86,
          "security": 53,
          "transparency": 20
        },
        "provenanceScore": 62
      },
      "connect": {
        "install": "npm install freestyle@latest  # CLI without installing: npx freestyle@latest --help"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/freestyle"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.04032,
          "note": "Memory extra at $0.0129 a GiB-hour. 200 vCPU-hours a month included"
        },
        {
          "item": "Data transfer",
          "unit": "gb",
          "usd": 0.02,
          "note": "50 GB a month included on Free, 500 GB on Hobby and Pro"
        },
        {
          "item": "Hobby plan",
          "unit": "month",
          "usd": 50,
          "note": "Monthly minimum, counted as usage"
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 500,
          "note": "Monthly minimum, counted as usage"
        }
      ],
      "provenance": {
        "legalEntity": "Freestyle Cloud Inc.",
        "domain": "freestyle.sh",
        "domainRegistered": "2024-04-11",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "https://www.freestyle.sh/status",
        "changelog": "https://www.freestyle.sh/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The privacy policy (last updated 15 June 2025) names Freestyle Cloud Inc. and says it covers the website at freestyle.sh. It is not linked here because it does not govern the product.",
          "No terms of service or service agreement was found. `/terms`, `/tos` and `/legal` answer 404 and the sitemap lists no legal page other than the privacy policy.",
          "The API answers at https://api.freestyle.sh/v5, a freestyle.sh subdomain. One unauthenticated request returned 401 with a `code` and `message`.",
          "www.freestyle.sh/.well-known/security.txt returns 404.",
          "RDAP for freestyle.sh gives a registration date of 2024-04-11 and a transfer on 11 March 2026.",
          "The status page is the vendor's own, with three components and no incident history."
        ],
        "score": 62
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/freestyle.json",
      "live": {
        "slug": "freestyle",
        "probe": {
          "target": "https://api.freestyle.sh/v5",
          "method": "get",
          "lastAt": "2026-10-09T10:42:43.668932977Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 652,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 576,
          "p95ms24h": 652,
          "samples24h": 33,
          "samples30d": 33,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 33,
              "ok": 33
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.freestyle.sh/status",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:56.720133529Z"
        },
        "updatedAt": "2026-10-09T10:42:43.668932977Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema \u0026 documentation.",
    "b": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 35,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Freestyle Cloud Inc.",
        "b": "Microsoft",
        "name": "Vendor"
      },
      {
        "a": "https://api.freestyle.sh/v5",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "API key",
        "b": "None",
        "name": "Auth"
      },
      {
        "a": "Freemium",
        "b": "Free",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "Proprietary service with no published terms of service found. The `freestyle` SDK and CLI package on npm is MIT",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-27",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "no document linked",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "72k npm/wk",
        "b": "1.5k stars, 472k npm/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema \u0026 documentation.",
        "question": "Which is better for AI agents, Freestyle or Microsoft Execution Containers?"
      },
      {
        "answer": "Freestyle has a hosted endpoint at https://api.freestyle.sh/v5. No hosted endpoint is listed for Microsoft Execution Containers.",
        "question": "Can an agent call Freestyle and Microsoft Execution Containers without installing anything?"
      },
      {
        "answer": "No open-source release is listed for Freestyle. Microsoft Execution Containers is open source (MIT).",
        "question": "Are Freestyle and Microsoft Execution Containers open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 86 against 81"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.",
        "slug": "freestyle",
        "watchFor": "No terms of service or service agreement found on the site, and the privacy policy covers the website only"
      },
      {
        "aheadOn": [
          "Reliability, 81 against 43",
          "Agent ergonomics, 74 against 69",
          "Security \u0026 auth, 69 against 53",
          "Payments \u0026 pricing, 60 against 45",
          "Maintenance \u0026 community, 92 against 71",
          "Transparency \u0026 trust, 83 against 41"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-freestyle.json",
        "title": "Blaxel Sandboxes vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle.json",
        "title": "Cloudflare Sandbox SDK vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-freestyle.json",
        "title": "Daytona vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.json",
        "title": "Deno Sandbox vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
        "title": "Deno Sandbox vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-freestyle.json",
        "title": "E2B vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-modal-sandboxes.json",
        "title": "Freestyle vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-morph-cloud.json",
        "title": "Freestyle vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-runloop.json",
        "title": "Freestyle vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-sprites.json",
        "title": "Freestyle vs Sprites",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.json",
        "title": "Freestyle vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-vercel-sandbox.json",
        "title": "Freestyle vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.json",
        "title": "Microsoft Execution Containers vs Sprites",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.json",
        "title": "Microsoft Execution Containers vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-freestyle.json",
        "title": "Agent 37 Cloud vs Freestyle",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-freestyle"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      }
    ],
    "scores": [
      {
        "by": 38,
        "edge": "microsoft-execution-containers",
        "freestyle": 43,
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "freestyle",
        "freestyle": 86,
        "key": "schema",
        "microsoft-execution-containers": 81,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 5,
        "edge": "microsoft-execution-containers",
        "freestyle": 69,
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 16,
        "edge": "microsoft-execution-containers",
        "freestyle": 53,
        "key": "security",
        "microsoft-execution-containers": 69,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 15,
        "edge": "microsoft-execution-containers",
        "freestyle": 45,
        "key": "payments",
        "microsoft-execution-containers": 60,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 21,
        "edge": "microsoft-execution-containers",
        "freestyle": 71,
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 42,
        "edge": "microsoft-execution-containers",
        "freestyle": 41,
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema \u0026 documentation. Both do sandbox code.",
    "verdicts": {
      "freestyle": "A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.",
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers",
    "json": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.md",
    "slim": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema \u0026 documentation. Both do sandbox code.\n\n- Freestyle: grade C, 58.5/100, rank #520 of 842. Markdown https://www.anchorterminal.com/tools/freestyle.md · JSON https://www.anchorterminal.com/api/v1/tools/freestyle.json\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #35 of 842. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n\n## Which one, for what\n\n### Freestyle (C)\n\nGood for: Suited to long-running agent work that needs a full Linux VM, memory-preserving pause, snapshots to branch from and private networking.\n\nAhead on:\n- Schema \u0026 documentation, 86 against 81\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: No terms of service or service agreement found on the site, and the privacy policy covers the website only\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 43\n- Agent ergonomics, 74 against 69\n- Security \u0026 auth, 69 against 53\n- Payments \u0026 pricing, 60 against 45\n- Maintenance \u0026 community, 92 against 71\n- Transparency \u0026 trust, 83 against 41\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n\n## Score by category\n\n| Category | Weight | Freestyle | Microsoft Execution Containers | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 43 | 81 | Microsoft Execution Containers +38 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 86 | 81 | Freestyle +5 |\n| Agent ergonomics | 13% (16.2 this run) | 69 | 74 | Microsoft Execution Containers +5 |\n| Security \u0026 auth | 14% (17.5 this run) | 53 | 69 | Microsoft Execution Containers +16 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 45 | 60 | Microsoft Execution Containers +15 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 71 | 92 | Microsoft Execution Containers +21 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 41 | 83 | Microsoft Execution Containers +42 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **58.5 · C** | **76.3 · BB** | |\n\n## Facts side by side\n\n| Fact | Freestyle | Microsoft Execution Containers |\n| --- | --- | --- |\n| Kind | HTTP API | SDK + MCP |\n| Vendor | Freestyle Cloud Inc. | Microsoft |\n| Hosted endpoint | `https://api.freestyle.sh/v5` | no (local only) |\n| Transports | HTTP |  |\n| Auth | API key | None |\n| Pricing | Freemium | Free |\n| x402 | no | no |\n| Licence | Proprietary service with no published terms of service found. The `freestyle` SDK and CLI package on npm is MIT | MIT |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | no |\n| Last release | 2026-09-27 | 2026-10-06 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | no document linked | couldn't be read |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 72k npm/wk | 1.5k stars, 472k npm/wk |\n\n## Verdicts\n\n**Freestyle.** A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript.\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n## Before you call either\n\n### Freestyle\n\n1. Send a `firewall` object on every `POST /v5/vms`. It is required, and a VM with no rules has no outbound internet\n2. Ask the owner to run `freestyle login` in a browser once, then mint a key with `freestyle tokens create --output json`\n3. Do not retry an exec that answers 409 `VM_NON_RESPONSIVE`. The command may already have run\n4. Keep `exec-await` under its 300,000 ms cap and use a PTY session or `x-freestyle-background-after-secs` for longer work\n5. Call the `/v5` paths. The unversioned duplicates in the OpenAPI file are marked deprecated\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n## Questions\n\n### Which is better for AI agents, Freestyle or Microsoft Execution Containers?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema \u0026 documentation.\n\n### Can an agent call Freestyle and Microsoft Execution Containers without installing anything?\n\nFreestyle has a hosted endpoint at https://api.freestyle.sh/v5. No hosted endpoint is listed for Microsoft Execution Containers.\n\n### Are Freestyle and Microsoft Execution Containers open source?\n\nNo open-source release is listed for Freestyle. Microsoft Execution Containers is open source (MIT).\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.json, and with the fewest tokens: https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"freestyle\", \"b\": \"microsoft-execution-containers\"}`. From a terminal: `anchor compare freestyle microsoft-execution-containers`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/freestyle.json and https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n\n## Other comparisons with Freestyle or Microsoft Execution Containers\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Freestyle](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Freestyle](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-freestyle.md)\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Freestyle](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Daytona vs Freestyle](https://www.anchorterminal.com/compare/daytona-vs-freestyle.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs Freestyle](https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md)\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md)\n- [E2B vs Freestyle](https://www.anchorterminal.com/compare/e2b-vs-freestyle.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [Freestyle vs Modal Sandboxes](https://www.anchorterminal.com/compare/freestyle-vs-modal-sandboxes.md)\n- [Freestyle vs Morph Cloud](https://www.anchorterminal.com/compare/freestyle-vs-morph-cloud.md)\n- [Freestyle vs Runloop Devboxes](https://www.anchorterminal.com/compare/freestyle-vs-runloop.md)\n- [Freestyle vs Sprites](https://www.anchorterminal.com/compare/freestyle-vs-sprites.md)\n- [Freestyle vs Together Code Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.md)\n- [Freestyle vs Vercel Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-vercel-sandbox.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Microsoft Execution Containers vs Sprites](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.md)\n- [Microsoft Execution Containers vs Together Code Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Freestyle](https://www.anchorterminal.com/compare/agent37-vs-freestyle.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Freestyle vs Microsoft Execution Containers",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Freestyle's 58.5 (C), and leads in 6 of 7 scored categories. Freestyle leads on schema \u0026 documentation. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Freestyle C 58.5",
      "Microsoft Execution Containers BB 76.3",
      "scores"
    ],
    "h1": "Freestyle vs Microsoft Execution Containers",
    "image": "https://www.anchorterminal.com/assets/og/compare-freestyle-vs-microsoft-execution-containers.png",
    "path": "/compare/freestyle-vs-microsoft-execution-containers",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Freestyle vs Microsoft Execution Containers for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers"
  },
  "tokens": {
    "markdown": 2700,
    "slim": 680
  },
  "version": 1
}
