Head to head · Sandbox code · October 2026 research run

Microsoft Execution Containers vs Sprites

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category. Both do sandbox code.

Which one, for what

Microsoft Execution Containers BB

Good for A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.

Ahead on

  • Reliability, 81 against 55
  • Schema & documentation, 81 against 74
  • Agent ergonomics, 74 against 68
  • Security & auth, 69 against 59
  • Payments & pricing, 60 against 30
  • Maintenance & community, 92 against 80
  • Transparency & trust, 83 against 59

Also in its favour

  • Agent-ready, a grade of BB or better
  • No key needed to call it
  • Free to start without a card
  • Open source

Watch for

1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased

Sprites C

Good for Agents that need a long-lived machine with installed tools and files kept between sessions, and rollback by checkpoint.

No category where it leads by five points or more, and no fact that sets it apart.

Watch for

Four Sprites incidents on the status page in 90 days, including a partial outage of 7 hours 28 minutes on 23 September 2026 and failed creates outside Europe for 28 minutes on 8 October

Score by category

CategoryWeight this runMicrosoft Execution ContainersSpritesEdge
Reliability16%208155Microsoft Execution Containers +26
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28174Microsoft Execution Containers +7
Agent ergonomics13%16.27468Microsoft Execution Containers +6
Security & auth14%17.56959Microsoft Execution Containers +10
Payments & pricing10%12.56030Microsoft Execution Containers +30
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89280Microsoft Execution Containers +12
Transparency & trust7%8.88359Microsoft Execution Containers +24
Negative events≤150-2
Total76.3 · BB58.3 · C

Facts side by side

FactMicrosoft Execution ContainersSprites
KindSDK + MCPHTTP API
VendorMicrosoftFly.io
Hosted endpointno (local only)no (local only)
TransportsHTTP
AuthNoneAPI key
PricingFreePay per use
x402nono
LicenceMITProprietary service under the Fly.io Terms of Service. The JavaScript, Go, Python and Elixir SDKs are MIT
Read-only variant documentedyesyes
llms.txtnoyes
Last release2026-10-062026-10-06
Terms last updatedno document linked2026-04-29
Privacy policy last updatedcouldn't be read2026-09-24
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity1.5k stars, 472k npm/wk158k npm/wk, 59k PyPI/wk

Verdicts

Microsoft Execution Containers

MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and isolation_session cannot restrict networking at all.

Sprites

A Sprite keeps a 100 GB ext4 disk between runs, bills compute only while active and can be checkpointed and restored through a published OpenAPI contract. The status page records four Sprites incidents in the last 90 days, one lasting over seven hours, and outbound network access is unrestricted until a policy is set.

Before you call either

Microsoft Execution Containers

  1. Import from @microsoft/mxc-sdk/v1. The package root exports nothing.
  2. Call getPlatformSupport() first and stop if isSupported is false. getAvailableBackends() is advisory and launch-time validation still applies.
  3. Set network.egress.default to allow only when the task needs it. Omitted network policy resolves to deny in every direction.
  4. Never pass --audit to an executor for untrusted code. It turns off all sandbox security for the workload.
  5. Read ExecutionResult.warnings after each run. Security warnings arrive there and are not written to stdout or stderr.

Sprites

  1. Create a token at sprites.dev/account after a browser signup, and send it as Authorization: Bearer <token> to https://api.sprites.dev
  2. Follow the OpenAPI document, not the product page example. Create with POST /v1/sprites and a JSON name, and run commands with POST /v1/sprites/{name}/exec using cmd query parameters
  3. Set a network policy with POST /v1/sprites/{name}/policy/network before running untrusted code. Egress is open until one is set
  4. Processes started by exec stop on a cold wake. Define a Service for anything that must answer the request that wakes the Sprite
  5. Create a checkpoint before a restore. Restoring replaces the filesystem, ends active sessions and keeps no copy of the replaced state
  6. Sprite creation is limited to 10 a minute on pay-as-you-go. The Go SDK reads Retry-After and the error code sprite_creation_rate_limited on a 429
  7. Delete Sprites you no longer need. An idle Sprite still bills cold storage for the bytes it holds

Questions

Which is better for AI agents, Microsoft Execution Containers or Sprites?

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category.

Can an agent call Microsoft Execution Containers and Sprites without installing anything?

No hosted endpoint is listed for Microsoft Execution Containers. No hosted endpoint is listed for Sprites.

Are Microsoft Execution Containers and Sprites open source?

Microsoft Execution Containers is open source (MIT). No open-source release is listed for Sprites.

Other comparisons with Microsoft Execution Containers or Sprites

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.