{
  "data": {
    "a": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 34,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-translator",
        "microsoft-graph-calendar",
        "dynamics-365-sales",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category.",
    "b": {
      "slug": "morph-cloud",
      "name": "Morph Cloud",
      "vendor": "Morph Labs",
      "vendorUrl": "https://cloud.morph.so",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Cloud virtual machines for AI agents from Morph Labs. Instances boot from snapshots and can be paused with memory intact, branched into copies, and driven through a REST API, Python and TypeScript SDKs and a CLI.",
      "url": "https://www.anchorterminal.com/tools/morph-cloud",
      "markdownUrl": "https://www.anchorterminal.com/tools/morph-cloud.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/morph-cloud.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/morph-cloud.json",
      "repo": "https://github.com/morph-labs/morph-python-sdk",
      "license": "Proprietary hosted service with no published terms found. The Python and TypeScript SDKs are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://cloud.morph.so/api",
      "packages": [
        {
          "registry": "pypi",
          "name": "morphcloud"
        },
        {
          "registry": "npm",
          "name": "morphcloud"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key on https://cloud.morph.so/api, created in the dashboard at cloud.morph.so/web/keys after a browser signup. The SDKs and CLI read `MORPH_API_KEY`. Keys are bound to an organisation and can be listed and deleted through the API. An agent inside a devbox can use a devbox agent token limited to that devbox and to named scopes.",
      "pricing": "usage",
      "pricingNotes": "Billed in Morph Compute Units. 1 MCU is 1 vCPU-hour with 4 GB RAM-hours and 16 GB disk-hours, or 5 TB snapshot-hours, at a stated standard rate of $0.05. The Free plan is $0 a month with 0 MCUs, so compute needs a purchase. Developer is $40 a month with 1,000 MCUs and Team is $250 a month with 7,500, with more billed as used (https://cloud.morph.so/web/pricing, checked 2026-10-08). No sandbox or free credit was found that lets an agent start without paying.",
      "priceSummary": "$0.05 / unit",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3,
        "npmWeekly": 339,
        "pypiWeekly": 13199,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://cloud.morph.so/docs",
      "llmsTxt": "https://cloud.morph.so/docs/llms.txt",
      "openapi": "https://cloud.morph.so/api/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "cli",
        "status-page"
      ],
      "lastRelease": "2026-09-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.8,
        "grade": "D",
        "agentReady": false,
        "rank": 515,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 9,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 61,
          "maintenance": 58,
          "payments": 20,
          "reliability": 63,
          "schema": 72,
          "security": 39,
          "transparency": 25
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Pause and snapshot keep memory and running processes, and one call branches an instance into several copies. A public OpenAPI file covers 69 operations. No terms of service, privacy policy or security page was found, the free plan includes no compute credit, and the changelog holds one entry from November 2024.",
        "bestFor": "Agents that need to checkpoint and fork a running machine with memory intact, for parallel attempts, evaluations or reinforcement learning rollouts.",
        "strengths": [
          "Pause and snapshot preserve memory and running processes, and a paused instance is billed for its snapshot only",
          "Branch creates a snapshot and starts a chosen number of copies in one call",
          "Public OpenAPI 3.1 file with 69 operations, plus llms.txt and llms-full.txt",
          "Devbox agent tokens are bound to one devbox and carry named scopes",
          "Status page shows 90 days without downtime to 8 October 2026 and no incident since 5 December 2025"
        ],
        "weaknesses": [
          "No terms of service, privacy policy, DPA or subprocessor list found on morph.so or cloud.morph.so",
          "The Free plan starts with 0 MCUs, so compute needs a purchase, and signup is in a browser",
          "No request rate limits, SLA or error-code reference in the reviewed documentation",
          "The changelog has one entry, the beta release of 19 November 2024",
          "The TypeScript SDK's last release is 0.0.20 of 6 October 2025",
          "No security.txt, disclosure policy or certification found, and no isolation technology is named in the docs"
        ],
        "agentNotes": [
          "Set `ttl_seconds` and `ttl_action` when starting an instance. Nothing in the docs stops an instance with no TTL from billing MCUs",
          "Pass `auth_mode: api_key` when exposing an HTTP service. The default is `none`, which makes the URL public",
          "Enable `wake_on_ssh` before calling exec on an instance that may be paused. There is no separate exec wake setting",
          "Use `/api/instance/list` and `/api/snapshot/list` with `page` and `limit` (default 50, maximum 1,000). The plain list routes return everything",
          "On a 503 from snapshot, branch, pause or reboot, wait for the `Retry-After` value before repeating the call"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.8
          }
        ],
        "editorialScores": {
          "ergonomics": 61,
          "maintenance": 58,
          "payments": 20,
          "reliability": 63,
          "schema": 72,
          "security": 39,
          "transparency": 14
        },
        "provenanceScore": 35
      },
      "connect": {
        "install": "pip install morphcloud  # or npm install morphcloud@0.0.20",
        "http": "curl -sS -H \"Authorization: Bearer $MORPH_API_KEY\" \\\n  https://cloud.morph.so/api/snapshot/snapshot_your_snapshot_id"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/morph-cloud"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Morph Compute Unit",
          "unit": "compute-unit",
          "usd": 0.05,
          "note": "1 vCPU-hour with 4 GB RAM-hours and 16 GB disk-hours, or 5 TB snapshot-hours"
        },
        {
          "item": "Instance compute",
          "unit": "vcpu-hour",
          "usd": 0.05,
          "note": "Includes 4 GB RAM and 16 GB disk per vCPU. MCUs are the largest of the three ratios"
        },
        {
          "item": "Developer plan",
          "unit": "month",
          "usd": 40,
          "note": "1,000 MCUs included"
        },
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 250,
          "note": "7,500 MCUs included"
        }
      ],
      "provenance": {
        "legalEntity": "",
        "domain": "morph.so",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "",
        "privacy": "",
        "statusPage": "https://status.cloud.morph.so",
        "changelog": "https://cloud.morph.so/docs/changelog",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "No terms of service, service agreement or privacy policy was found. /terms and /privacy return 404 on cloud.morph.so and www.morph.so, and the morph.so site map lists only the home page, blog and careers, so both fields are left out.",
          "No registered legal entity was found. The SDK licence reads Copyright 2024 Morph Labs.",
          "The API answers at cloud.morph.so/api and exposed services at morphcloud.io addresses, per the docs.",
          "security.txt returns 404 on cloud.morph.so and www.morph.so.",
          "No RDAP service answers for the .so registry, so the registration date is blank.",
          "The status page's own data names Morph Labs, cloud.morph.so and support@morph.so. The page is not linked from the docs."
        ],
        "score": 35
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/morph-cloud.json",
      "live": {
        "slug": "morph-cloud",
        "probe": {
          "target": "https://cloud.morph.so/api",
          "method": "get",
          "lastAt": "2026-10-08T19:08:53.519030264Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 139,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 138,
          "p95ms24h": 272,
          "samples24h": 19,
          "samples30d": 19,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 19,
              "ok": 19
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.cloud.morph.so",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:50:53.2122056Z"
        },
        "pages": [
          {
            "url": "https://cloud.morph.so/docs/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:17.092678678Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a911488f7933"
          },
          {
            "url": "https://cloud.morph.so/web/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:16:19.269281319Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "4fc791aaa2ac"
          }
        ],
        "updatedAt": "2026-10-08T19:08:53.519030264Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Morph Labs",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://cloud.morph.so/api",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Proprietary hosted service with no published terms found. The Python and TypeScript SDKs are Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-09-01",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no document linked",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "no document linked",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 472k npm/wk",
        "b": "3 stars, 339 npm/wk, 13k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category.",
        "question": "Which is better for AI agents, Microsoft Execution Containers or Morph Cloud?"
      },
      {
        "answer": "No hosted endpoint is listed for Microsoft Execution Containers. Morph Cloud has a hosted endpoint at https://cloud.morph.so/api.",
        "question": "Can an agent call Microsoft Execution Containers and Morph Cloud without installing anything?"
      },
      {
        "answer": "Microsoft Execution Containers is open source (MIT). No open-source release is listed for Morph Cloud.",
        "question": "Are Microsoft Execution Containers and Morph Cloud open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 63",
          "Schema \u0026 documentation, 81 against 72",
          "Agent ergonomics, 74 against 61",
          "Security \u0026 auth, 69 against 39",
          "Payments \u0026 pricing, 60 against 20",
          "Maintenance \u0026 community, 92 against 58",
          "Transparency \u0026 trust, 83 against 25"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      },
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agents that need to checkpoint and fork a running machine with memory intact, for parallel attempts, evaluations or reinforcement learning rollouts.",
        "slug": "morph-cloud",
        "watchFor": "No terms of service, privacy policy, DPA or subprocessor list found on morph.so or cloud.morph.so"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-morph-cloud.json",
        "title": "Blaxel Sandboxes vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.json",
        "title": "Cloudflare Sandbox SDK vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.json",
        "title": "Daytona vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-morph-cloud.json",
        "title": "E2B vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud.json",
        "title": "Modal Sandboxes vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-runloop.json",
        "title": "Morph Cloud vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox.json",
        "title": "Morph Cloud vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-morph-cloud.json",
        "title": "Agent 37 Cloud vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-morph-cloud"
      }
    ],
    "scores": [
      {
        "by": 18,
        "edge": "microsoft-execution-containers",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "morph-cloud": 63,
        "name": "Reliability",
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "microsoft-execution-containers",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "morph-cloud": 72,
        "name": "Schema \u0026 documentation",
        "weight": 13
      },
      {
        "by": 13,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "morph-cloud": 61,
        "name": "Agent ergonomics",
        "weight": 13
      },
      {
        "by": 30,
        "edge": "microsoft-execution-containers",
        "key": "security",
        "microsoft-execution-containers": 69,
        "morph-cloud": 39,
        "name": "Security \u0026 auth",
        "weight": 14
      },
      {
        "by": 40,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "morph-cloud": 20,
        "name": "Payments \u0026 pricing",
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 34,
        "edge": "microsoft-execution-containers",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "morph-cloud": 58,
        "name": "Maintenance \u0026 community",
        "weight": 7
      },
      {
        "by": 58,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "morph-cloud": 25,
        "name": "Transparency \u0026 trust",
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category. Both do sandbox code.",
    "verdicts": {
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
      "morph-cloud": "Pause and snapshot keep memory and running processes, and one call branches an instance into several copies. A public OpenAPI file covers 69 operations. No terms of service, privacy policy or security page was found, the free plan includes no compute credit, and the changelog holds one entry from November 2024."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud",
    "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category. Both do sandbox code.\n\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #34 of 629. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n- Morph Cloud: grade D, 50.8/100, rank #515 of 629. Markdown https://www.anchorterminal.com/tools/morph-cloud.md · JSON https://www.anchorterminal.com/api/v1/tools/morph-cloud.json\n\n## Which one, for what\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 63\n- Schema \u0026 documentation, 81 against 72\n- Agent ergonomics, 74 against 61\n- Security \u0026 auth, 69 against 39\n- Payments \u0026 pricing, 60 against 20\n- Maintenance \u0026 community, 92 against 58\n- Transparency \u0026 trust, 83 against 25\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Free to start without a card\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n### Morph Cloud (D)\n\nGood for: Agents that need to checkpoint and fork a running machine with memory intact, for parallel attempts, evaluations or reinforcement learning rollouts.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: No terms of service, privacy policy, DPA or subprocessor list found on morph.so or cloud.morph.so\n\n\n## Score by category\n\n| Category | Weight | Microsoft Execution Containers | Morph Cloud | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 63 | Microsoft Execution Containers +18 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 72 | Microsoft Execution Containers +9 |\n| Agent ergonomics | 13% (16.2 this run) | 74 | 61 | Microsoft Execution Containers +13 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 39 | Microsoft Execution Containers +30 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 20 | Microsoft Execution Containers +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 92 | 58 | Microsoft Execution Containers +34 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 25 | Microsoft Execution Containers +58 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **76.3 · BB** | **50.8 · D** | |\n\n## Facts side by side\n\n| Fact | Microsoft Execution Containers | Morph Cloud |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Microsoft | Morph Labs |\n| Hosted endpoint | no (local only) | `https://cloud.morph.so/api` |\n| Transports |  | HTTP |\n| Auth | None | API key |\n| Pricing | Free | Pay per use |\n| x402 | no | no |\n| Licence | MIT | Proprietary hosted service with no published terms found. The Python and TypeScript SDKs are Apache-2.0 |\n| Read-only variant documented | yes | no |\n| llms.txt | no | yes |\n| Last release | 2026-10-06 | 2026-09-01 |\n| Terms last updated | no document linked | no document linked |\n| Privacy policy last updated | couldn't be read | no document linked |\n| Customer content may train models |  |  |\n| Terms restrict automated access |  |  |\n| Terms restrict benchmarking |  |  |\n| Terms or service can change without notice |  |  |\n| Arbitration or class-action waiver |  |  |\n| Popularity | 1.5k stars, 472k npm/wk | 3 stars, 339 npm/wk, 13k PyPI/wk |\n\n## Verdicts\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n**Morph Cloud.** Pause and snapshot keep memory and running processes, and one call branches an instance into several copies. A public OpenAPI file covers 69 operations. No terms of service, privacy policy or security page was found, the free plan includes no compute credit, and the changelog holds one entry from November 2024.\n\n## Before you call either\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n### Morph Cloud\n\n1. Set `ttl_seconds` and `ttl_action` when starting an instance. Nothing in the docs stops an instance with no TTL from billing MCUs\n2. Pass `auth_mode: api_key` when exposing an HTTP service. The default is `none`, which makes the URL public\n3. Enable `wake_on_ssh` before calling exec on an instance that may be paused. There is no separate exec wake setting\n4. Use `/api/instance/list` and `/api/snapshot/list` with `page` and `limit` (default 50, maximum 1,000). The plain list routes return everything\n5. On a 503 from snapshot, branch, pause or reboot, wait for the `Retry-After` value before repeating the call\n\n## Questions\n\n### Which is better for AI agents, Microsoft Execution Containers or Morph Cloud?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category.\n\n### Can an agent call Microsoft Execution Containers and Morph Cloud without installing anything?\n\nNo hosted endpoint is listed for Microsoft Execution Containers. Morph Cloud has a hosted endpoint at https://cloud.morph.so/api.\n\n### Are Microsoft Execution Containers and Morph Cloud open source?\n\nMicrosoft Execution Containers is open source (MIT). No open-source release is listed for Morph Cloud.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-execution-containers\", \"b\": \"morph-cloud\"}`. From a terminal: `anchor compare microsoft-execution-containers morph-cloud`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json and https://www.anchorterminal.com/api/v1/tools/morph-cloud.json\n\n## Other comparisons with Microsoft Execution Containers or Morph Cloud\n\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Morph Cloud](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-morph-cloud.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Morph Cloud](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-morph-cloud.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Daytona vs Morph Cloud](https://www.anchorterminal.com/compare/daytona-vs-morph-cloud.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [E2B vs Morph Cloud](https://www.anchorterminal.com/compare/e2b-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Modal Sandboxes vs Morph Cloud](https://www.anchorterminal.com/compare/modal-sandboxes-vs-morph-cloud.md)\n- [Morph Cloud vs Runloop Devboxes](https://www.anchorterminal.com/compare/morph-cloud-vs-runloop.md)\n- [Morph Cloud vs Vercel Sandbox](https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n- [Agent 37 Cloud vs Morph Cloud](https://www.anchorterminal.com/compare/agent37-vs-morph-cloud.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Execution Containers vs Morph Cloud",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Morph Cloud's 50.8 (D), and leads in every scored category. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Execution Containers BB 76.3",
      "Morph Cloud D 50.8",
      "scores"
    ],
    "h1": "Microsoft Execution Containers vs Morph Cloud",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-execution-containers-vs-morph-cloud.png",
    "path": "/compare/microsoft-execution-containers-vs-morph-cloud",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Execution Containers vs Morph Cloud for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
  },
  "tokens": {
    "markdown": 2450,
    "slim": 680
  },
  "version": 1
}
