{
  "data": {
    "a": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 34,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "answer": "Microsoft Execution Containers and Modal Sandboxes score within a point of each other on agent readiness, 76.3 (BB) and 75.5 (BB). Modal Sandboxes leads on reliability and security \u0026 auth.",
    "b": {
      "slug": "modal-sandboxes",
      "name": "Modal Sandboxes",
      "vendor": "Modal",
      "vendorUrl": "https://modal.com",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Modal's sandboxed compute environments for running code, with SDK access, GPU support and filesystem snapshots.",
      "url": "https://www.anchorterminal.com/tools/modal-sandboxes",
      "markdownUrl": "https://www.anchorterminal.com/tools/modal-sandboxes.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/modal-sandboxes.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/modal-sandboxes.json",
      "repo": "https://github.com/modal-labs/modal-client",
      "license": "Apache-2.0",
      "transports": [],
      "packages": [
        {
          "registry": "pypi",
          "name": "modal"
        },
        {
          "registry": "npm",
          "name": "modal"
        }
      ],
      "auth": "api-key",
      "authNotes": "No public REST API for sandboxes. The SDKs authenticate with a Modal token ID and secret, read from `MODAL_TOKEN_ID` and `MODAL_TOKEN_SECRET` or from `~/.modal.toml` (written by `modal token set`). Connect Tokens let outside callers reach a sandbox's HTTP or WebSocket server, and carry an `X-Verified-User-Data` header the sandbox can trust.",
      "pricing": "freemium",
      "pricingNotes": "Sandboxes cost $0.00003942 a physical core-second (one core is 2 vCPU, minimum 0.125 cores) and $0.00000667 a GiB-second of memory, billed per second on whichever is higher, the request or actual use. GPUs bill at Modal's standard per-second GPU rates. Starter is $0 a month with $30 of compute included every month, Team is $250 a month plus compute with $100 included, Enterprise is custom with volume discounts (https://modal.com/pricing, https://modal.com/docs/guide/sandbox-resources.md).",
      "priceSummary": "$0.071 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 514,
        "npmWeekly": 940973,
        "pypiWeekly": 10146778,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://modal.com/docs/guide/sandboxes",
      "llmsTxt": "https://modal.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist",
        "sandbox.gpu"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "python",
        "typescript",
        "go",
        "llms-txt",
        "enterprise"
      ],
      "lastRelease": "2026-09-28",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 75.5,
        "grade": "BB",
        "agentReady": true,
        "rank": 41,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 2,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 67,
          "maintenance": 93,
          "payments": 40,
          "reliability": 95,
          "schema": 79,
          "security": 76,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta.",
        "bestFor": "GPU work inside a sandbox, or agents already running on Modal.",
        "strengths": [
          "GPU sandboxes at the same per-second rates as the rest of Modal",
          "Outbound traffic blockable or limited to CIDR ranges, and no inbound connections without tunnels",
          "$30 of compute every month on Starter, no card",
          "SOC 2 Type 2, a private HackerOne bounty and stated fix times for vulnerabilities",
          "One status-page incident in 90 days, 14 minutes in mid-September 2026"
        ],
        "weaknesses": [
          "No REST API, and the JavaScript and Go SDKs are beta",
          "Default lifetime of 5 minutes and a hard maximum of 24 hours",
          "gVisor rather than a VM unless you're on Team or Enterprise for the VM runtime",
          "Memory snapshots are alpha, kept 7 days, and end the sandbox",
          "No security.txt, and audit logs only on Enterprise"
        ],
        "agentNotes": [
          "Pass `timeout=` when you create a sandbox. The default lifetime is 5 minutes",
          "Set `block_network=True` or a `cidr_allowlist` for untrusted code",
          "Give a sandbox a `name` so a retried create raises `AlreadyExistsError` instead of starting a second one",
          "Snapshot the filesystem before the 24-hour limit and start a fresh sandbox from it",
          "Catch `ResourceExhaustedError` from `Sandbox.create()` on SDK 1.6.0 and later"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 8,
        "avgRating": 3.3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 75.5
          }
        ],
        "editorialScores": {
          "ergonomics": 67,
          "maintenance": 93,
          "payments": 40,
          "reliability": 95,
          "schema": 79,
          "security": 76,
          "transparency": 60
        },
        "provenanceScore": 84
      },
      "connect": {
        "install": "pip install modal  # or npm i modal"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/modal-sandboxes"
      },
      "sameCompany": [
        "modal"
      ],
      "alsoIn": [
        "gpu-compute"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Sandbox CPU",
          "unit": "vcpu-hour",
          "usd": 0.071,
          "note": "$0.00003942 a physical core-second, one core is 2 vCPU. Memory extra at $0.00000667 a GiB-second"
        },
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 250,
          "note": "Plus compute, $100 included"
        }
      ],
      "provenance": {
        "legalEntity": "Modal Labs, Inc.",
        "domain": "modal.com",
        "domainRegistered": "1999-03-18",
        "domainNote": "modal.com was registered in 1999, long before Modal Labs, so the domain was bought later.",
        "endpointOnVendorDomain": null,
        "terms": "https://modal.com/legal/terms",
        "privacy": "https://modal.com/legal/privacy-policy",
        "statusPage": "https://status.modal.com",
        "changelog": "https://modal.com/docs/sdk/py/releases",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "Terms (May 2026) name Modal Labs, Inc., a Delaware corporation, under California law.",
          "Sandboxes are reached through the SDK rather than a documented public endpoint, so there's no endpoint URL to check against the domain.",
          "modal.com/.well-known/security.txt returns 404. The security guide gives security@modal.com and a private HackerOne programme."
        ],
        "score": 84
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/modal-sandboxes.json",
      "live": {
        "slug": "modal-sandboxes",
        "vendorStatus": {
          "page": "https://status.modal.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:38:48.35497294Z"
        },
        "versions": [
          {
            "registry": "npm",
            "name": "modal",
            "version": "0.11.0",
            "seenAt": "2026-10-08T16:21:39.611509889Z"
          },
          {
            "registry": "pypi",
            "name": "modal",
            "version": "1.6.1",
            "released": "2026-10-03",
            "seenAt": "2026-10-08T16:21:39.471099291Z"
          }
        ],
        "githubStars": 522,
        "npmWeekly": 976721,
        "pypiWeekly": 10794735,
        "securityTxt": {
          "url": "https://modal.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:35.387911158Z"
        },
        "llmsTxt": {
          "url": "https://modal.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:39.602992362Z"
        },
        "domain": {
          "domain": "modal.com",
          "registered": "1999-03-18",
          "source": "https://rdap.verisign.com/com/v1/domain/modal.com",
          "checkedAt": "2026-10-04T13:03:51.14581991Z"
        },
        "pages": [
          {
            "url": "https://modal.com/docs/sdk/py/releases",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:08.619124868Z",
            "changedAt": "2026-10-04T15:46:02.530693875Z",
            "fingerprint": "2d8a24963498"
          },
          {
            "url": "https://modal.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:15.105990601Z",
            "changedAt": "2026-10-07T18:07:40.290186482Z",
            "fingerprint": "2bebc792cd5e"
          },
          {
            "url": "https://modal.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:11.552613672Z",
            "changedAt": "2026-10-07T18:07:37.098211707Z",
            "fingerprint": "602809288e68"
          },
          {
            "url": "https://modal.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:22:13.03355875Z",
            "changedAt": "2026-10-07T18:07:38.590004865Z",
            "fingerprint": "d2254dcf3a27"
          }
        ],
        "updatedAt": "2026-10-08T19:38:48.35497294Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "SDK + MCP",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Modal",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-09-28",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-05-01",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2023-05-17",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 472k npm/wk",
        "b": "514 stars, 941k npm/wk, 10.1M PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3.3/5 (8)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers and Modal Sandboxes score within a point of each other on agent readiness, 76.3 (BB) and 75.5 (BB). Modal Sandboxes leads on reliability and security \u0026 auth.",
        "question": "Which is better for AI agents, Microsoft Execution Containers or Modal Sandboxes?"
      },
      {
        "answer": "Microsoft Execution Containers is open source (MIT). No open-source release is listed for Modal Sandboxes.",
        "question": "Are Microsoft Execution Containers and Modal Sandboxes open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Agent ergonomics, 74 against 67",
          "Payments \u0026 pricing, 60 against 40",
          "Transparency \u0026 trust, 83 against 72"
        ],
        "also": [
          "No key needed to call it",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      },
      {
        "aheadOn": [
          "Reliability, 95 against 81",
          "Security \u0026 auth, 76 against 69"
        ],
        "also": null,
        "goodFor": "GPU work inside a sandbox, or agents already running on Modal.",
        "slug": "modal-sandboxes",
        "watchFor": "No REST API, and the JavaScript and Go SDKs are beta"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-modal-sandboxes.json",
        "title": "Blaxel Sandboxes vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.json",
        "title": "Cloudflare Sandbox SDK vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes.json",
        "title": "Daytona vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-modal-sandboxes.json",
        "title": "E2B vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud.json",
        "title": "Modal Sandboxes vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-runloop.json",
        "title": "Modal Sandboxes vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox.json",
        "title": "Modal Sandboxes vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-modal-sandboxes.json",
        "title": "Agent 37 Cloud vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-modal-sandboxes"
      }
    ],
    "scores": [
      {
        "by": 14,
        "edge": "modal-sandboxes",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "modal-sandboxes": 95,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 2,
        "edge": "microsoft-execution-containers",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "modal-sandboxes": 79,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 7,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "modal-sandboxes": 67,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 7,
        "edge": "modal-sandboxes",
        "key": "security",
        "microsoft-execution-containers": 69,
        "modal-sandboxes": 76,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 20,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "modal-sandboxes": 40,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 1,
        "edge": "modal-sandboxes",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "modal-sandboxes": 93,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 11,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "modal-sandboxes": 72,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers and Modal Sandboxes score within a point of each other on agent readiness, 76.3 (BB) and 75.5 (BB). Modal Sandboxes leads on reliability and security \u0026 auth. Both do sandbox code.",
    "verdicts": {
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
      "modal-sandboxes": "GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes",
    "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.min.md"
  },
  "markdown": "Microsoft Execution Containers and Modal Sandboxes score within a point of each other on agent readiness, 76.3 (BB) and 75.5 (BB). Modal Sandboxes leads on reliability and security \u0026 auth. Both do sandbox code.\n\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #34 of 722. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n- Modal Sandboxes: grade BB, 75.5/100, rank #41 of 722. Markdown https://www.anchorterminal.com/tools/modal-sandboxes.md · JSON https://www.anchorterminal.com/api/v1/tools/modal-sandboxes.json\n\n## Which one, for what\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Agent ergonomics, 74 against 67\n- Payments \u0026 pricing, 60 against 40\n- Transparency \u0026 trust, 83 against 72\n\nAlso in its favour:\n- No key needed to call it\n- Free to start without a card\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n### Modal Sandboxes (BB)\n\nGood for: GPU work inside a sandbox, or agents already running on Modal.\n\nAhead on:\n- Reliability, 95 against 81\n- Security \u0026 auth, 76 against 69\n\nWatch for: No REST API, and the JavaScript and Go SDKs are beta\n\n\n## Score by category\n\n| Category | Weight | Microsoft Execution Containers | Modal Sandboxes | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 95 | Modal Sandboxes +14 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 79 | Microsoft Execution Containers +2 |\n| Agent ergonomics | 13% (16.2 this run) | 74 | 67 | Microsoft Execution Containers +7 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 76 | Modal Sandboxes +7 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 40 | Microsoft Execution Containers +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 92 | 93 | Modal Sandboxes +1 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 72 | Microsoft Execution Containers +11 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **76.3 · BB** | **75.5 · BB** | |\n\n## Facts side by side\n\n| Fact | Microsoft Execution Containers | Modal Sandboxes |\n| --- | --- | --- |\n| Kind | SDK + MCP | SDK + MCP |\n| Vendor | Microsoft | Modal |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | None | API key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT | Apache-2.0 |\n| Read-only variant documented | yes | no |\n| llms.txt | no | yes |\n| Last release | 2026-10-06 | 2026-09-28 |\n| Terms last updated | no document linked | 2026-05-01 |\n| Privacy policy last updated | couldn't be read | 2023-05-17 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 1.5k stars, 472k npm/wk | 514 stars, 941k npm/wk, 10.1M PyPI/wk |\n| Agent reviews | none | 3.3/5 (8) |\n\n## Verdicts\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n**Modal Sandboxes.** GPU sandboxes at the same per-second rates as the rest of Modal. No REST API, and the JavaScript and Go SDKs are beta.\n\n## Before you call either\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n### Modal Sandboxes\n\n1. Pass `timeout=` when you create a sandbox. The default lifetime is 5 minutes\n2. Set `block_network=True` or a `cidr_allowlist` for untrusted code\n3. Give a sandbox a `name` so a retried create raises `AlreadyExistsError` instead of starting a second one\n4. Snapshot the filesystem before the 24-hour limit and start a fresh sandbox from it\n5. Catch `ResourceExhaustedError` from `Sandbox.create()` on SDK 1.6.0 and later\n\n## Questions\n\n### Which is better for AI agents, Microsoft Execution Containers or Modal Sandboxes?\n\nMicrosoft Execution Containers and Modal Sandboxes score within a point of each other on agent readiness, 76.3 (BB) and 75.5 (BB). Modal Sandboxes leads on reliability and security \u0026 auth.\n\n### Are Microsoft Execution Containers and Modal Sandboxes open source?\n\nMicrosoft Execution Containers is open source (MIT). No open-source release is listed for Modal Sandboxes.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-execution-containers\", \"b\": \"modal-sandboxes\"}`. From a terminal: `anchor compare microsoft-execution-containers modal-sandboxes`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json and https://www.anchorterminal.com/api/v1/tools/modal-sandboxes.json\n\n## Other comparisons with Microsoft Execution Containers or Modal Sandboxes\n\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Modal Sandboxes](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-modal-sandboxes.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Modal Sandboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-modal-sandboxes.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Daytona vs Modal Sandboxes](https://www.anchorterminal.com/compare/daytona-vs-modal-sandboxes.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [E2B vs Modal Sandboxes](https://www.anchorterminal.com/compare/e2b-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Modal Sandboxes vs Morph Cloud](https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud.md)\n- [Modal Sandboxes vs Runloop Devboxes](https://www.anchorterminal.com/compare/modal-sandboxes-vs-runloop.md)\n- [Modal Sandboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n- [Agent 37 Cloud vs Modal Sandboxes](https://www.anchorterminal.com/compare/agent37-vs-modal-sandboxes.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers and Modal Sandboxes score within a point of each other on agent readiness, 76.3 (BB) and 75.5 (BB). Modal Sandboxes leads on reliability and security \u0026 auth. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Execution Containers BB 76.3",
      "Modal Sandboxes BB 75.5",
      "scores"
    ],
    "h1": "Microsoft Execution Containers vs Modal Sandboxes",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-execution-containers-vs-modal-sandboxes.png",
    "path": "/compare/microsoft-execution-containers-vs-modal-sandboxes",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Execution Containers vs Modal Sandboxes for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
  },
  "tokens": {
    "markdown": 2250,
    "slim": 680
  },
  "version": 1
}
