Head to head · Sandbox code · October 2026 research run

Microsoft Execution Containers vs Together Code Sandbox

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema & documentation. Both do sandbox code.

Which one, for what

Microsoft Execution Containers BB

Good for A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.

Ahead on

  • Reliability, 81 against 25
  • Security & auth, 69 against 47
  • Payments & pricing, 60 against 20
  • Maintenance & community, 92 against 83
  • Transparency & trust, 83 against 60

Also in its favour

  • Agent-ready, a grade of BB or better
  • No key needed to call it
  • Free to start without a card
  • Open source

Watch for

1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased

Together Code Sandbox D

Good for Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.

Ahead on

  • Schema & documentation, 86 against 81

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access

Score by category

CategoryWeight this runMicrosoft Execution ContainersTogether Code SandboxEdge
Reliability16%208125Microsoft Execution Containers +56
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28186Together Code Sandbox +5
Agent ergonomics13%16.27470Microsoft Execution Containers +4
Security & auth14%17.56947Microsoft Execution Containers +22
Payments & pricing10%12.56020Microsoft Execution Containers +40
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89283Microsoft Execution Containers +9
Transparency & trust7%8.88360Microsoft Execution Containers +23
Negative events≤1500
Total76.3 · BB53.6 · D

Facts side by side

FactMicrosoft Execution ContainersTogether Code Sandbox
KindSDK + MCPHTTP API
VendorMicrosoftTogether AI
Hosted endpointno (local only)https://api.bartender.codesandbox.io
TransportsHTTP
AuthNoneAPI key
PricingFreePay per use
x402nono
LicenceMITProprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT
Read-only variant documentedyesno
llms.txtnoyes
Last release2026-10-062026-10-07
Terms last updatedno document linkedno date given
Privacy policy last updatedcouldn't be readno date given
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity1.5k stars, 472k npm/wk3 stars, 1.3k npm/wk, 3.4k PyPI/wk

Verdicts

Microsoft Execution Containers

MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and isolation_session cannot restrict networking at all.

Together Code Sandbox

Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.

Before you call either

Microsoft Execution Containers

  1. Import from @microsoft/mxc-sdk/v1. The package root exports nothing.
  2. Call getPlatformSupport() first and stop if isSupported is false. getAvailableBackends() is advisory and launch-time validation still applies.
  3. Set network.egress.default to allow only when the task needs it. Omitted network policy resolves to deny in every direction.
  4. Never pass --audit to an executor for untrusted code. It turns off all sandbox security for the workload.
  5. Read ExecutionResult.warnings after each run. Security warnings arrive there and are not written to stdout or stderr.

Together Code Sandbox

  1. Confirm the organisation is on Together's allowlist before installing. A valid TOGETHER_API_KEY alone is not enough
  2. Build a snapshot first with snapshots.create. No default image exists, and every sandbox needs snapshot_id or snapshot_alias
  3. Set ttl at creation or call terminate(). Nothing stops a sandbox otherwise, and closing the Python client leaves it running
  4. Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at sandbox:<id>
  5. Exclude snapshots.create from retries with should_retry, and set experimental.network_policy before serving anything private on a port

Questions

Which is better for AI agents, Microsoft Execution Containers or Together Code Sandbox?

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema & documentation.

Can an agent call Microsoft Execution Containers and Together Code Sandbox without installing anything?

No hosted endpoint is listed for Microsoft Execution Containers. Together Code Sandbox has a hosted endpoint at https://api.bartender.codesandbox.io.

Are Microsoft Execution Containers and Together Code Sandbox open source?

Microsoft Execution Containers is open source (MIT). No open-source release is listed for Together Code Sandbox.

Other comparisons with Microsoft Execution Containers or Together Code Sandbox

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.