{
  "data": {
    "a": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 35,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category.",
    "b": {
      "slug": "sprites",
      "name": "Sprites",
      "vendor": "Fly.io",
      "vendorUrl": "https://fly.io",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Sprites are hosted Linux microVMs from Fly.io that keep their disk between runs, pause when idle and wake on request. They are driven through a REST API, a CLI, four SDKs or a hosted MCP server.",
      "url": "https://www.anchorterminal.com/tools/sprites",
      "markdownUrl": "https://www.anchorterminal.com/tools/sprites.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sprites.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sprites.json",
      "repo": "https://github.com/superfly/sprites-js",
      "license": "Proprietary service under the Fly.io Terms of Service. The JavaScript, Go, Python and Elixir SDKs are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@fly/sprites"
        },
        {
          "registry": "pypi",
          "name": "sprites-py"
        }
      ],
      "auth": "api-key",
      "authNotes": "A bearer token created at sprites.dev/account after signing in with a Fly.io account, sent as `Authorization: Bearer \u003ctoken\u003e` to `https://api.sprites.dev`. Tokens belong to an organisation, and no scopes or expiry were found in the reviewed docs. The CLI signs in through a browser with `sprite org auth` or takes a token with `sprite auth setup --token`. The hosted MCP server uses OAuth with a token restricted by default to a name prefix and a capped number of Sprites.",
      "pricing": "usage",
      "pricingNotes": "$0.0385 a CPU-hour and $0.021875 a GB-hour of memory while a Sprite is active, hot storage at $0.000683 a GB-hour while awake and cold storage at $0.000027 a GB-hour while data is kept. Nothing is charged per Sprite or for bandwidth. New organisations get a $30 trial credit, and whether it needs a card was not established. The product page also describes monthly plans with allowances, of which Hero ($100) and Mythic ($2,000) are priced (https://fly.io/sprites/, https://fly.io/pricing/, checked 2026-10-08).",
      "priceSummary": "$0.0385 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the Sprites docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": 157565,
        "pypiWeekly": 58695,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.fly.io/sprites",
      "llmsTxt": "https://docs.fly.io/llms.txt",
      "openapi": "https://docs.fly.io/sprites/api/openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "usage-priced",
        "microvm",
        "persistent",
        "checkpoints",
        "openapi",
        "cli",
        "typescript",
        "python",
        "go",
        "elixir",
        "mcp",
        "llms-txt",
        "status-page"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 58.3,
        "grade": "C",
        "agentReady": false,
        "rank": 528,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 11,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 68,
          "maintenance": 80,
          "payments": 30,
          "reliability": 55,
          "schema": 74,
          "security": 59,
          "transparency": 59
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08: the Fly.io pricing page says of Sprites \"No plans and no tiers\", while the Sprites product page read the same day describes paid plans (Hero at $100 a month, Mythic at $2,000) that carry usage allowances and set concurrency and creation-rate limits. Prices for the other named plans were not found. 2 points. https://fly.io/pricing/ and https://fly.io/sprites/"
        ],
        "verdict": "A Sprite keeps a 100 GB ext4 disk between runs, bills compute only while active and can be checkpointed and restored through a published OpenAPI contract. The status page records four Sprites incidents in the last 90 days, one lasting over seven hours, and outbound network access is unrestricted until a policy is set.",
        "bestFor": "Agents that need a long-lived machine with installed tools and files kept between sessions, and rollback by checkpoint.",
        "strengths": [
          "The filesystem persists across pauses, and compute billing stops about 30 seconds after activity ends, per the lifecycle docs",
          "A public OpenAPI 3.1 document covers 44 operations on sprites, exec, files, checkpoints, services and policies, with an AsyncAPI file for the WebSocket calls",
          "Connectors hold third-party credentials outside the Sprite, deny access by default and can limit which provider paths a Sprite may call",
          "Checkpoints are copy-on-write snapshots of the writable filesystem, and the last five are mounted read-only inside the Sprite",
          "Unit prices are public, $0.0385 a CPU-hour, $0.021875 a GB-hour of memory and about $0.50 a GB-month of hot storage",
          "Official SDKs for JavaScript, Go, Python and Elixir are MIT, each with releases in September or October 2026"
        ],
        "weaknesses": [
          "Four Sprites incidents on the status page in 90 days, including a partial outage of 7 hours 28 minutes on 23 September 2026 and failed creates outside Europe for 28 minutes on 8 October",
          "Outbound network access is unrestricted by default. The DNS allowlist is opt-in and set from outside the Sprite",
          "The product page creates a Sprite with `PUT /v1/sprites/my-sprite` and a JSON `command` body, while the OpenAPI document creates with `POST /v1/sprites` and passes `cmd` as a query parameter",
          "No API changelog, deprecation policy or error-code reference was found in the reviewed documentation",
          "The pricing page says Sprites have no plans and no tiers, while the product page describes paid plans that set concurrency and creation-rate limits",
          "No scopes were found for API tokens created at sprites.dev/account. Only the MCP connector's OAuth token is restricted by default"
        ],
        "agentNotes": [
          "Create a token at sprites.dev/account after a browser signup, and send it as `Authorization: Bearer \u003ctoken\u003e` to `https://api.sprites.dev`",
          "Follow the OpenAPI document, not the product page example. Create with `POST /v1/sprites` and a JSON `name`, and run commands with `POST /v1/sprites/{name}/exec` using `cmd` query parameters",
          "Set a network policy with `POST /v1/sprites/{name}/policy/network` before running untrusted code. Egress is open until one is set",
          "Processes started by exec stop on a cold wake. Define a Service for anything that must answer the request that wakes the Sprite",
          "Create a checkpoint before a restore. Restoring replaces the filesystem, ends active sessions and keeps no copy of the replaced state",
          "Sprite creation is limited to 10 a minute on pay-as-you-go. The Go SDK reads `Retry-After` and the error code `sprite_creation_rate_limited` on a 429",
          "Delete Sprites you no longer need. An idle Sprite still bills cold storage for the bytes it holds"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 58.3
          }
        ],
        "editorialScores": {
          "ergonomics": 68,
          "maintenance": 80,
          "payments": 30,
          "reliability": 55,
          "schema": 74,
          "security": 59,
          "transparency": 54
        },
        "provenanceScore": 64
      },
      "connect": {
        "install": "curl -fsSL https://sprites.dev/install.sh | sh  # CLI. SDKs: npm install @fly/sprites, pip install sprites-py",
        "http": "curl -X POST https://api.sprites.dev/v1/sprites -H \"Authorization: Bearer $SPRITES_TOKEN\" -H \"Content-Type: application/json\" -d '{\"name\": \"my-sprite\"}'"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/sprites"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "CPU time while active",
          "unit": "vcpu-hour",
          "usd": 0.0385,
          "note": "Memory extra at $0.021875 a GB-hour"
        },
        {
          "item": "Hot storage while the Sprite is awake",
          "unit": "gb-month",
          "usd": 0.5,
          "note": "Billed at $0.000683 a GB-hour, on bytes written"
        },
        {
          "item": "Cold storage while data is kept",
          "unit": "gb-month",
          "usd": 0.02,
          "note": "Billed at $0.000027 a GB-hour"
        }
      ],
      "provenance": {
        "legalEntity": "Fly.io, Inc.",
        "domain": "fly.io",
        "domainRegistered": "2004-07-15",
        "endpointOnVendorDomain": false,
        "terms": "https://fly.io/legal/terms-of-service/",
        "privacy": "https://fly.io/legal/privacy-policy/",
        "statusPage": "https://status.flyio.net",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Service (effective 29 April 2026) name Fly.io, Inc. and cover the website and all products and services reached through it. No separate Sprites terms were found.",
          "The Privacy Statement is effective 24 September 2026. The sub-processor list was last updated the same day.",
          "The API is at api.sprites.dev and Sprite URLs are on sprites.app, second domains of the vendor's. sprites.dev redirects to fly.io/sprites, and RDAP gives its registration date as 2025-06-03.",
          "RDAP for fly.io gives a registration date of 2004-07-15.",
          "fly.io/.well-known/security.txt returned 404. The security docs give security@fly.io for reports.",
          "No changelog for the Sprites API or environment was found. The Python SDK repository keeps a CHANGELOG.md."
        ],
        "score": 64
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/sprites.json",
      "live": {
        "slug": "sprites",
        "vendorStatus": {
          "page": "https://status.flyio.net",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-09T09:25:33.929738149Z"
        },
        "updatedAt": "2026-10-09T09:25:33.929738149Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Fly.io",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "no (local only)",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Proprietary service under the Fly.io Terms of Service. The JavaScript, Go, Python and Elixir SDKs are MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-10-06",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-04-29",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-09-24",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 472k npm/wk",
        "b": "158k npm/wk, 59k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category.",
        "question": "Which is better for AI agents, Microsoft Execution Containers or Sprites?"
      },
      {
        "answer": "No hosted endpoint is listed for Microsoft Execution Containers. No hosted endpoint is listed for Sprites.",
        "question": "Can an agent call Microsoft Execution Containers and Sprites without installing anything?"
      },
      {
        "answer": "Microsoft Execution Containers is open source (MIT). No open-source release is listed for Sprites.",
        "question": "Are Microsoft Execution Containers and Sprites open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 55",
          "Schema \u0026 documentation, 81 against 74",
          "Agent ergonomics, 74 against 68",
          "Security \u0026 auth, 69 against 59",
          "Payments \u0026 pricing, 60 against 30",
          "Maintenance \u0026 community, 92 against 80",
          "Transparency \u0026 trust, 83 against 59"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      },
      {
        "aheadOn": null,
        "also": null,
        "goodFor": "Agents that need a long-lived machine with installed tools and files kept between sessions, and rollback by checkpoint.",
        "slug": "sprites",
        "watchFor": "Four Sprites incidents on the status page in 90 days, including a partial outage of 7 hours 28 minutes on 23 September 2026 and failed creates outside Europe for 28 minutes on 8 October"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-sprites.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Sprites",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-sprites.json",
        "title": "Blaxel Sandboxes vs Sprites",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-sprites.json",
        "title": "Cloudflare Sandbox SDK vs Sprites",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-sprites.json",
        "title": "Daytona vs Sprites",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
        "title": "Deno Sandbox vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.json",
        "title": "Deno Sandbox vs Sprites",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-sprites.json",
        "title": "E2B vs Sprites",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.json",
        "title": "Freestyle vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-sprites.json",
        "title": "Freestyle vs Sprites",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.json",
        "title": "Microsoft Execution Containers vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-sprites.json",
        "title": "Modal Sandboxes vs Sprites",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-sprites.json",
        "title": "Morph Cloud vs Sprites",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/runloop-vs-sprites.json",
        "title": "Runloop Devboxes vs Sprites",
        "url": "https://www.anchorterminal.com/compare/runloop-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox.json",
        "title": "Sprites vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sprites-vs-vercel-sandbox.json",
        "title": "Sprites vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/sprites-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-sprites.json",
        "title": "Agent 37 Cloud vs Sprites",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-sprites"
      }
    ],
    "scores": [
      {
        "by": 26,
        "edge": "microsoft-execution-containers",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "name": "Reliability",
        "sprites": 55,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 7,
        "edge": "microsoft-execution-containers",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "name": "Schema \u0026 documentation",
        "sprites": 74,
        "weight": 13
      },
      {
        "by": 6,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "name": "Agent ergonomics",
        "sprites": 68,
        "weight": 13
      },
      {
        "by": 10,
        "edge": "microsoft-execution-containers",
        "key": "security",
        "microsoft-execution-containers": 69,
        "name": "Security \u0026 auth",
        "sprites": 59,
        "weight": 14
      },
      {
        "by": 30,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "name": "Payments \u0026 pricing",
        "sprites": 30,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "microsoft-execution-containers",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "name": "Maintenance \u0026 community",
        "sprites": 80,
        "weight": 7
      },
      {
        "by": 24,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "name": "Transparency \u0026 trust",
        "sprites": 59,
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category. Both do sandbox code.",
    "verdicts": {
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
      "sprites": "A Sprite keeps a 100 GB ext4 disk between runs, bills compute only while active and can be checkpointed and restored through a published OpenAPI contract. The status page records four Sprites incidents in the last 90 days, one lasting over seven hours, and outbound network access is unrestricted until a policy is set."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites",
    "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category. Both do sandbox code.\n\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #35 of 842. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n- Sprites: grade C, 58.3/100, rank #528 of 842. Markdown https://www.anchorterminal.com/tools/sprites.md · JSON https://www.anchorterminal.com/api/v1/tools/sprites.json\n\n## Which one, for what\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 55\n- Schema \u0026 documentation, 81 against 74\n- Agent ergonomics, 74 against 68\n- Security \u0026 auth, 69 against 59\n- Payments \u0026 pricing, 60 against 30\n- Maintenance \u0026 community, 92 against 80\n- Transparency \u0026 trust, 83 against 59\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Free to start without a card\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n### Sprites (C)\n\nGood for: Agents that need a long-lived machine with installed tools and files kept between sessions, and rollback by checkpoint.\n\nWatch for: Four Sprites incidents on the status page in 90 days, including a partial outage of 7 hours 28 minutes on 23 September 2026 and failed creates outside Europe for 28 minutes on 8 October\n\n\n## Score by category\n\n| Category | Weight | Microsoft Execution Containers | Sprites | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 55 | Microsoft Execution Containers +26 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 74 | Microsoft Execution Containers +7 |\n| Agent ergonomics | 13% (16.2 this run) | 74 | 68 | Microsoft Execution Containers +6 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 59 | Microsoft Execution Containers +10 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 30 | Microsoft Execution Containers +30 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 92 | 80 | Microsoft Execution Containers +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 59 | Microsoft Execution Containers +24 |\n| Negative events | ≤15 | 0 | -2 | |\n| **Total** | | **76.3 · BB** | **58.3 · C** | |\n\n## Facts side by side\n\n| Fact | Microsoft Execution Containers | Sprites |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Microsoft | Fly.io |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  | HTTP |\n| Auth | None | API key |\n| Pricing | Free | Pay per use |\n| x402 | no | no |\n| Licence | MIT | Proprietary service under the Fly.io Terms of Service. The JavaScript, Go, Python and Elixir SDKs are MIT |\n| Read-only variant documented | yes | yes |\n| llms.txt | no | yes |\n| Last release | 2026-10-06 | 2026-10-06 |\n| Terms last updated | no document linked | 2026-04-29 |\n| Privacy policy last updated | couldn't be read | 2026-09-24 |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 1.5k stars, 472k npm/wk | 158k npm/wk, 59k PyPI/wk |\n\n## Verdicts\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n**Sprites.** A Sprite keeps a 100 GB ext4 disk between runs, bills compute only while active and can be checkpointed and restored through a published OpenAPI contract. The status page records four Sprites incidents in the last 90 days, one lasting over seven hours, and outbound network access is unrestricted until a policy is set.\n\n## Before you call either\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n### Sprites\n\n1. Create a token at sprites.dev/account after a browser signup, and send it as `Authorization: Bearer \u003ctoken\u003e` to `https://api.sprites.dev`\n2. Follow the OpenAPI document, not the product page example. Create with `POST /v1/sprites` and a JSON `name`, and run commands with `POST /v1/sprites/{name}/exec` using `cmd` query parameters\n3. Set a network policy with `POST /v1/sprites/{name}/policy/network` before running untrusted code. Egress is open until one is set\n4. Processes started by exec stop on a cold wake. Define a Service for anything that must answer the request that wakes the Sprite\n5. Create a checkpoint before a restore. Restoring replaces the filesystem, ends active sessions and keeps no copy of the replaced state\n6. Sprite creation is limited to 10 a minute on pay-as-you-go. The Go SDK reads `Retry-After` and the error code `sprite_creation_rate_limited` on a 429\n7. Delete Sprites you no longer need. An idle Sprite still bills cold storage for the bytes it holds\n\n## Questions\n\n### Which is better for AI agents, Microsoft Execution Containers or Sprites?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category.\n\n### Can an agent call Microsoft Execution Containers and Sprites without installing anything?\n\nNo hosted endpoint is listed for Microsoft Execution Containers. No hosted endpoint is listed for Sprites.\n\n### Are Microsoft Execution Containers and Sprites open source?\n\nMicrosoft Execution Containers is open source (MIT). No open-source release is listed for Sprites.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-execution-containers\", \"b\": \"sprites\"}`. From a terminal: `anchor compare microsoft-execution-containers sprites`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json and https://www.anchorterminal.com/api/v1/tools/sprites.json\n\n## Other comparisons with Microsoft Execution Containers or Sprites\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Sprites](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-sprites.md)\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Sprites](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-sprites.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Sprites](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-sprites.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Daytona vs Sprites](https://www.anchorterminal.com/compare/daytona-vs-sprites.md)\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs Sprites](https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [E2B vs Sprites](https://www.anchorterminal.com/compare/e2b-vs-sprites.md)\n- [Freestyle vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.md)\n- [Freestyle vs Sprites](https://www.anchorterminal.com/compare/freestyle-vs-sprites.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Microsoft Execution Containers vs Together Code Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Modal Sandboxes vs Sprites](https://www.anchorterminal.com/compare/modal-sandboxes-vs-sprites.md)\n- [Morph Cloud vs Sprites](https://www.anchorterminal.com/compare/morph-cloud-vs-sprites.md)\n- [Runloop Devboxes vs Sprites](https://www.anchorterminal.com/compare/runloop-vs-sprites.md)\n- [Sprites vs Together Code Sandbox](https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox.md)\n- [Sprites vs Vercel Sandbox](https://www.anchorterminal.com/compare/sprites-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n- [Agent 37 Cloud vs Sprites](https://www.anchorterminal.com/compare/agent37-vs-sprites.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Execution Containers vs Sprites",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Sprites's 58.3 (C), and leads in every scored category. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Execution Containers BB 76.3",
      "Sprites C 58.3",
      "scores"
    ],
    "h1": "Microsoft Execution Containers vs Sprites",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-execution-containers-vs-sprites.png",
    "path": "/compare/microsoft-execution-containers-vs-sprites",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Execution Containers vs Sprites for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites"
  },
  "tokens": {
    "markdown": 2800,
    "slim": 730
  },
  "version": 1
}
