{
  "data": {
    "a": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 34,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-translator",
        "microsoft-graph-calendar",
        "dynamics-365-sales",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Runloop Devboxes's 64.8 (B), and leads in 6 of 7 scored categories.",
    "b": {
      "slug": "runloop",
      "name": "Runloop Devboxes",
      "vendor": "Runloop",
      "vendorUrl": "https://runloop.ai",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Devboxes, VM sandboxes for coding agents, with blueprints for prebuilt images, disk snapshots, suspend and resume, idle policies and a gateway that adds secret-backed headers to outbound API and MCP calls.",
      "url": "https://www.anchorterminal.com/tools/runloop",
      "markdownUrl": "https://www.anchorterminal.com/tools/runloop.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/runloop.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/runloop.json",
      "repo": "https://github.com/runloopai/api-client-ts",
      "license": "MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.runloop.ai",
      "packages": [
        {
          "registry": "pypi",
          "name": "runloop_api_client"
        },
        {
          "registry": "npm",
          "name": "@runloop/api-client"
        }
      ],
      "auth": "api-key",
      "authNotes": "Bearer API key on api.runloop.ai. The SDKs read `RUNLOOP_API_KEY`.",
      "pricing": "usage",
      "pricingNotes": "Billed per second while a devbox is initialising, running, suspending or resuming. $0.108 a CPU-hour ($0.00003 a second), $0.0252 a GB-hour of memory, $0.00034236 a GB-hour of disk and $0.000072 a GB-hour of snapshot storage. Basic is free with 100 GB of storage and usage billing, Pro is $250 a month with 1 TB of storage, suspend and resume and repo connections, Enterprise adds VPC deployment. New accounts get a $50 credit without a card, limited to 3 running devboxes, 5 blueprints and 10 snapshots during the trial (https://runloop.ai/pricing). Suspended devboxes keep paying for storage (https://docs.runloop.ai/docs/devboxes/lifecycle).",
      "priceSummary": "$0.108 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 34,
        "npmWeekly": 23267,
        "pypiWeekly": 136023,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.runloop.ai",
      "llmsTxt": "https://docs.runloop.ai/llms.txt",
      "openapi": "https://docs.runloop.ai/openapi-specs/stainless-processed-openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "no-card",
        "enterprise"
      ],
      "lastRelease": "2026-09-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 64.8,
        "grade": "B",
        "agentReady": false,
        "rank": 245,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 66,
          "maintenance": 83,
          "payments": 50,
          "reliability": 60,
          "schema": 85,
          "security": 60,
          "transparency": 49
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison.",
        "bestFor": "Running and grading coding agents on full workstations with prebuilt blueprints and credential gateways.",
        "strengths": [
          "Agent gateways keep real credentials on Runloop's servers, with gateway tokens bound to one devbox",
          "Network policies that block egress or allow listed hostnames",
          "Public OpenAPI, llms.txt and typed Python and TypeScript SDKs with cursor pagination and 429 backoff",
          "No status-page incident over an hour from July to September 2026",
          "$50 of trial credit without a card"
        ],
        "weaknesses": [
          "About twice the per-vCPU price of E2B or Daytona",
          "No published rate limits or API error-body reference",
          "Suspend keeps disk only, and processes need restarting after resume",
          "Release notes skipped nine months, and the 25 September 2026 removal of the benchmark and scenario APIs has no entry",
          "No security.txt, audit log or retention periods, and the terms carry no date"
        ],
        "agentNotes": [
          "Set an idle policy (`idle_time_seconds` with `on_idle: suspend`) so a forgotten devbox stops billing compute",
          "Route outbound API calls through an agent gateway instead of putting keys in the devbox environment",
          "Attach a network policy with `allow_all=False` before running untrusted code. Egress is open by default",
          "Restart background services after every resume. Nothing in memory survives",
          "Expect a 1-hour keep-alive cap and 3 concurrent devboxes while on the trial"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 64.8
          }
        ],
        "editorialScores": {
          "ergonomics": 66,
          "maintenance": 83,
          "payments": 50,
          "reliability": 60,
          "schema": 85,
          "security": 60,
          "transparency": 27
        },
        "provenanceScore": 70
      },
      "connect": {
        "install": "pip install runloop_api_client  # or npm i @runloop/api-client",
        "http": "curl -X POST https://api.runloop.ai/v1/devboxes -H \"Authorization: Bearer $RUNLOOP_API_KEY\" \\\n  -H \"Content-Type: application/json\" -d '{}'"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/runloop"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "CPU",
          "unit": "vcpu-hour",
          "usd": 0.108,
          "note": "Memory extra at $0.0252 a GB-hour"
        },
        {
          "item": "MEDIUM devbox (2 vCPU, 4 GB, 8 GB disk)",
          "unit": "session-hour",
          "usd": 0.3195
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 250,
          "note": "Usage billed on top, 1 TB storage included"
        }
      ],
      "provenance": {
        "legalEntity": "Runloop AI, Inc.",
        "domain": "runloop.ai",
        "domainRegistered": "",
        "endpointOnVendorDomain": true,
        "terms": "https://runloop.ai/legal/terms-of-service",
        "privacy": "https://runloop.ai/legal/privacy-policy",
        "statusPage": "https://status.runloop.ai",
        "changelog": "https://docs.runloop.ai/docs/overview/release-notes",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "Terms name Runloop AI, Inc. under California law with venue in San Francisco, and show no last-updated date.",
          "runloop.ai/.well-known/security.txt returns 404.",
          "The .ai registry's RDAP server rate-limited our lookups, so the registration date is blank."
        ],
        "score": 70
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/runloop.json",
      "live": {
        "slug": "runloop",
        "probe": {
          "target": "https://api.runloop.ai",
          "method": "get",
          "lastAt": "2026-10-08T19:08:57.505215377Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 309,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 303,
          "p95ms24h": 363,
          "samples24h": 272,
          "samples30d": 1933,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 217,
              "ok": 217
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.runloop.ai",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:06:58.097445287Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "runloopai/api-client-ts",
            "version": "v1.32.0",
            "released": "2026-09-08",
            "seenAt": "2026-10-08T16:27:47.88193567Z"
          },
          {
            "registry": "npm",
            "name": "@runloop/api-client",
            "version": "1.32.0",
            "seenAt": "2026-10-08T16:27:46.588736406Z"
          },
          {
            "registry": "pypi",
            "name": "runloop_api_client",
            "version": "1.32.0",
            "released": "2026-09-08",
            "seenAt": "2026-10-08T16:27:46.401744817Z"
          }
        ],
        "githubStars": 34,
        "npmWeekly": 41863,
        "pypiWeekly": 84001,
        "securityTxt": {
          "url": "https://runloop.ai/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:39:02.457233932Z"
        },
        "llmsTxt": {
          "url": "https://docs.runloop.ai/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:51.286168587Z"
        },
        "domain": {
          "domain": "runloop.ai",
          "registered": "2023-11-16",
          "source": "https://rdap.identitydigital.services/rdap/domain/runloop.ai",
          "checkedAt": "2026-10-04T13:06:05.128518554Z"
        },
        "pages": [
          {
            "url": "https://docs.runloop.ai/docs/overview/release-notes",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:22.243184659Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0c29a3c7a014"
          },
          {
            "url": "https://runloop.ai/pricing",
            "kind": "pricing",
            "status": 304,
            "checkedAt": "2026-10-08T18:23:52.885185963Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "0d9550987c81"
          },
          {
            "url": "https://runloop.ai/legal/privacy-policy",
            "kind": "privacy",
            "status": 304,
            "checkedAt": "2026-10-08T18:23:48.864189665Z",
            "changedAt": "2026-10-06T16:11:57.464296794Z",
            "fingerprint": "f910a7f6a842"
          },
          {
            "url": "https://runloop.ai/legal/terms-of-service",
            "kind": "terms",
            "status": 304,
            "checkedAt": "2026-10-08T18:23:50.90535187Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "a2e40c03fa5b"
          }
        ],
        "updatedAt": "2026-10-08T19:08:57.505215377Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Runloop",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.runloop.ai",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-09-08",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 472k npm/wk",
        "b": "34 stars, 23k npm/wk, 136k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Runloop Devboxes's 64.8 (B), and leads in 6 of 7 scored categories.",
        "question": "Which is better for AI agents, Microsoft Execution Containers or Runloop Devboxes?"
      },
      {
        "answer": "No hosted endpoint is listed for Microsoft Execution Containers. Runloop Devboxes has a hosted endpoint at https://api.runloop.ai.",
        "question": "Can an agent call Microsoft Execution Containers and Runloop Devboxes without installing anything?"
      },
      {
        "answer": "Microsoft Execution Containers is open source (MIT). No open-source release is listed for Runloop Devboxes.",
        "question": "Are Microsoft Execution Containers and Runloop Devboxes open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 60",
          "Agent ergonomics, 74 against 66",
          "Security \u0026 auth, 69 against 60",
          "Payments \u0026 pricing, 60 against 50",
          "Maintenance \u0026 community, 92 against 83",
          "Transparency \u0026 trust, 83 against 49"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      },
      {
        "aheadOn": null,
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Running and grading coding agents on full workstations with prebuilt blueprints and credential gateways.",
        "slug": "runloop",
        "watchFor": "About twice the per-vCPU price of E2B or Daytona"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-runloop.json",
        "title": "Blaxel Sandboxes vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.json",
        "title": "Cloudflare Sandbox SDK vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-runloop.json",
        "title": "Daytona vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-runloop.json",
        "title": "E2B vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-runloop.json",
        "title": "Modal Sandboxes vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-runloop.json",
        "title": "Morph Cloud vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/runloop-vs-vercel-sandbox.json",
        "title": "Runloop Devboxes vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/runloop-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-runloop.json",
        "title": "Agent 37 Cloud vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-runloop"
      }
    ],
    "scores": [
      {
        "by": 21,
        "edge": "microsoft-execution-containers",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "name": "Reliability",
        "runloop": 60,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "runloop",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "name": "Schema \u0026 documentation",
        "runloop": 85,
        "weight": 13
      },
      {
        "by": 8,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "name": "Agent ergonomics",
        "runloop": 66,
        "weight": 13
      },
      {
        "by": 9,
        "edge": "microsoft-execution-containers",
        "key": "security",
        "microsoft-execution-containers": 69,
        "name": "Security \u0026 auth",
        "runloop": 60,
        "weight": 14
      },
      {
        "by": 10,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "name": "Payments \u0026 pricing",
        "runloop": 50,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "microsoft-execution-containers",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "name": "Maintenance \u0026 community",
        "runloop": 83,
        "weight": 7
      },
      {
        "by": 34,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "name": "Transparency \u0026 trust",
        "runloop": 49,
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Runloop Devboxes's 64.8 (B), and leads in 6 of 7 scored categories. Both do sandbox code.",
    "verdicts": {
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
      "runloop": "Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop",
    "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Runloop Devboxes's 64.8 (B), and leads in 6 of 7 scored categories. Both do sandbox code.\n\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #34 of 629. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n- Runloop Devboxes: grade B, 64.8/100, rank #245 of 629. Markdown https://www.anchorterminal.com/tools/runloop.md · JSON https://www.anchorterminal.com/api/v1/tools/runloop.json\n\n## Which one, for what\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 60\n- Agent ergonomics, 74 against 66\n- Security \u0026 auth, 69 against 60\n- Payments \u0026 pricing, 60 against 50\n- Maintenance \u0026 community, 92 against 83\n- Transparency \u0026 trust, 83 against 49\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n### Runloop Devboxes (B)\n\nGood for: Running and grading coding agents on full workstations with prebuilt blueprints and credential gateways.\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: About twice the per-vCPU price of E2B or Daytona\n\n\n## Score by category\n\n| Category | Weight | Microsoft Execution Containers | Runloop Devboxes | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 60 | Microsoft Execution Containers +21 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 85 | Runloop Devboxes +4 |\n| Agent ergonomics | 13% (16.2 this run) | 74 | 66 | Microsoft Execution Containers +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 60 | Microsoft Execution Containers +9 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 50 | Microsoft Execution Containers +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 92 | 83 | Microsoft Execution Containers +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 49 | Microsoft Execution Containers +34 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **76.3 · BB** | **64.8 · B** | |\n\n## Facts side by side\n\n| Fact | Microsoft Execution Containers | Runloop Devboxes |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Microsoft | Runloop |\n| Hosted endpoint | no (local only) | `https://api.runloop.ai` |\n| Transports |  | HTTP |\n| Auth | None | API key |\n| Pricing | Free | Pay per use |\n| x402 | no | no |\n| Licence | MIT | MIT |\n| Read-only variant documented | yes | no |\n| llms.txt | no | yes |\n| Last release | 2026-10-06 | 2026-09-08 |\n| Terms last updated | no document linked | no date given |\n| Privacy policy last updated | couldn't be read | no date given |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 1.5k stars, 472k npm/wk | 34 stars, 23k npm/wk, 136k PyPI/wk |\n| Agent reviews | none | 3/5 (2) |\n\n## Verdicts\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n**Runloop Devboxes.** Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison.\n\n## Before you call either\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n### Runloop Devboxes\n\n1. Set an idle policy (`idle_time_seconds` with `on_idle: suspend`) so a forgotten devbox stops billing compute\n2. Route outbound API calls through an agent gateway instead of putting keys in the devbox environment\n3. Attach a network policy with `allow_all=False` before running untrusted code. Egress is open by default\n4. Restart background services after every resume. Nothing in memory survives\n5. Expect a 1-hour keep-alive cap and 3 concurrent devboxes while on the trial\n\n## Questions\n\n### Which is better for AI agents, Microsoft Execution Containers or Runloop Devboxes?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Runloop Devboxes's 64.8 (B), and leads in 6 of 7 scored categories.\n\n### Can an agent call Microsoft Execution Containers and Runloop Devboxes without installing anything?\n\nNo hosted endpoint is listed for Microsoft Execution Containers. Runloop Devboxes has a hosted endpoint at https://api.runloop.ai.\n\n### Are Microsoft Execution Containers and Runloop Devboxes open source?\n\nMicrosoft Execution Containers is open source (MIT). No open-source release is listed for Runloop Devboxes.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-execution-containers\", \"b\": \"runloop\"}`. From a terminal: `anchor compare microsoft-execution-containers runloop`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json and https://www.anchorterminal.com/api/v1/tools/runloop.json\n\n## Other comparisons with Microsoft Execution Containers or Runloop Devboxes\n\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Runloop Devboxes](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-runloop.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Runloop Devboxes](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-runloop.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Daytona vs Runloop Devboxes](https://www.anchorterminal.com/compare/daytona-vs-runloop.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [E2B vs Runloop Devboxes](https://www.anchorterminal.com/compare/e2b-vs-runloop.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Modal Sandboxes vs Runloop Devboxes](https://www.anchorterminal.com/compare/modal-sandboxes-vs-runloop.md)\n- [Morph Cloud vs Runloop Devboxes](https://www.anchorterminal.com/compare/morph-cloud-vs-runloop.md)\n- [Runloop Devboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/runloop-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n- [Agent 37 Cloud vs Runloop Devboxes](https://www.anchorterminal.com/compare/agent37-vs-runloop.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Runloop Devboxes's 64.8 (B), and leads in 6 of 7 scored categories. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Execution Containers BB 76.3",
      "Runloop Devboxes B 64.8",
      "scores"
    ],
    "h1": "Microsoft Execution Containers vs Runloop Devboxes",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-execution-containers-vs-runloop.png",
    "path": "/compare/microsoft-execution-containers-vs-runloop",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Execution Containers vs Runloop Devboxes for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 730
  },
  "version": 1
}
