{
  "data": {
    "a": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 35,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-document-intelligence",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-maps",
        "azure-translator",
        "microsoft-graph-calendar",
        "azure-blob-storage",
        "onedrive-sharepoint",
        "microsoft-teams",
        "dynamics-365-sales",
        "power-automate",
        "foundry-local",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema \u0026 documentation.",
    "b": {
      "slug": "together-code-sandbox",
      "name": "Together Code Sandbox",
      "vendor": "Together AI",
      "vendorUrl": "https://www.together.ai",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Together AI's hosted virtual machine sandboxes for running commands and code, built from Docker-image snapshots and driven from the `together-sandbox` Python SDK, TypeScript SDK or CLI. Access is by allowlist, on request to Together.",
      "url": "https://www.anchorterminal.com/tools/together-code-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json",
      "repo": "https://github.com/togethercomputer/together-sandbox",
      "license": "Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.bartender.codesandbox.io",
      "packages": [
        {
          "registry": "pypi",
          "name": "together-sandbox"
        },
        {
          "registry": "npm",
          "name": "together-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "Access is by allowlist. The docs say the `together-sandbox` SDK and CLI must be enabled for an organisation and to contact Together to request it. Once enabled, a project-scoped Together API key is sent as a Bearer token, read from `TOGETHER_API_KEY`. Keys are revocable, can carry an expiry date and have no finer scopes. Each running sandbox also has its own agent token for the in-VM API, which the SDKs handle.",
      "pricing": "usage",
      "pricingNotes": "The pricing page lists Code Sandbox compute at $0.0446 per vCPU-hour and $0.0149 per GiB of RAM per hour, and does not say whether that rate covers the new SDK as well as the legacy one. No free tier or sandbox lets an agent start without a contract. Together has no free trial, platform access needs a $15 first credit purchase, and the organisation must then be enabled on request (https://www.together.ai/pricing, https://docs.together.ai/docs/billing-credits).",
      "priceSummary": "$0.0446 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs page, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3,
        "npmWeekly": 1298,
        "pypiWeekly": 3387,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.together.ai/docs/together-code-sandbox",
      "llmsTxt": "https://docs.together.ai/llms.txt",
      "openapi": "https://togethercomputer.github.io/together-sandbox/api-openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "usage",
        "allowlist",
        "sales-led",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "cli",
        "security-txt"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.6,
        "grade": "D",
        "agentReady": false,
        "rank": 628,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 20,
          "reliability": 25,
          "schema": 86,
          "security": 47,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.",
        "bestFor": "Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.",
        "strengths": [
          "Public OpenAPI documents for the management API (17 operations) and the in-VM API (25), in the repository and on GitHub Pages",
          "Terminating with `memory: true` saves disk and memory, and a new sandbox created from that snapshot resumes its running processes",
          "List calls are cursor-paginated (1 to 100 a page) with filters for status, source snapshot and tags",
          "Both SDKs retry 408, 429 and 5xx three times with exponential backoff, and the docs warn that `snapshots.create` is not idempotent",
          "Releases on 30 September, 1 October and 7 October 2026, with a generated changelog that marks breaking changes"
        ],
        "weaknesses": [
          "The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access",
          "No rate limits, concurrency limits or SLA found, and neither status.together.ai nor status.codesandbox.io names the service",
          "Every sandbox port is public unless an experimental inbound policy is set, and no outbound controls exist yet",
          "Three major versions between 2 June and 28 July 2026, and memory snapshots were removed in 4.0.0 and restored in 4.0.4",
          "The management API answers at `api.bartender.codesandbox.io`, off Together's domain, and the privacy policy's data table has no sandbox row"
        ],
        "agentNotes": [
          "Confirm the organisation is on Together's allowlist before installing. A valid `TOGETHER_API_KEY` alone is not enough",
          "Build a snapshot first with `snapshots.create`. No default image exists, and every sandbox needs `snapshot_id` or `snapshot_alias`",
          "Set `ttl` at creation or call `terminate()`. Nothing stops a sandbox otherwise, and closing the Python client leaves it running",
          "Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at `sandbox:\u003cid\u003e`",
          "Exclude `snapshots.create` from retries with `should_retry`, and set `experimental.network_policy` before serving anything private on a port"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.6
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 20,
          "reliability": 25,
          "schema": 86,
          "security": 47,
          "transparency": 43
        },
        "provenanceScore": 77
      },
      "connect": {
        "install": "pip install together-sandbox  # or npm install together-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/together-code-sandbox"
      },
      "sameCompany": [
        "together-fine-tuning"
      ],
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.0446,
          "note": "RAM extra at $0.0149 per GiB-hour. Listed under Code Sandbox on the pricing page, which doesn't name the SDK"
        },
        {
          "item": "Default sandbox (1 vCPU, 2 GiB)",
          "unit": "session-hour",
          "usd": 0.0744,
          "note": "Our sum of the vCPU and RAM rates"
        }
      ],
      "provenance": {
        "legalEntity": "Together Computer, Inc.",
        "domain": "together.ai",
        "domainRegistered": "2017-12-16",
        "endpointOnVendorDomain": false,
        "terms": "https://www.together.ai/terms-of-service",
        "privacy": "https://www.together.ai/privacy",
        "statusPage": "https://status.together.ai",
        "changelog": "https://github.com/togethercomputer/together-sandbox/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (updated 19 May 2026) name Together Computer, Inc., a Delaware corporation at 251 Rhode Island Street, San Francisco, and cover the website and the Services. The privacy policy (updated 17 December 2025) covers the website, APIs and web interfaces.",
          "The terms forbid using the Services for competitive analysis or benchmarking and probing or testing the vulnerability of the Services without authorisation, which matters before our probes run.",
          "The management API answers at api.bartender.codesandbox.io and sandbox URLs sit under csb.app. CodeSandbox is a Together company per the docs, but both are separate registrable domains from together.ai.",
          "status.together.ai has no sandbox component. status.codesandbox.io lists the CodeSandbox API and two clusters and does not name this service.",
          "security.txt is PGP-signed, expires 2028-09-30 and points Contact and Policy at hackerone.com/together_ai. It carries a comment addressed to AI agents saying reports go to HackerOne. Recorded as a fact, and we did not act on it.",
          "RDAP for together.ai gives a registration date of 2017-12-16.",
          "trust.together.ai is script-drawn and showed our reader only its title. No DPA or sub-processor page was found."
        ],
        "score": 77
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.json",
      "live": {
        "slug": "together-code-sandbox",
        "probe": {
          "target": "https://api.bartender.codesandbox.io",
          "method": "get",
          "lastAt": "2026-10-09T10:14:30.155277956Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 143,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 146,
          "p95ms24h": 181,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.together.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:36.139351511Z"
        },
        "updatedAt": "2026-10-09T10:14:30.155277956Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Together AI",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.bartender.codesandbox.io",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "API key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-10-07",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "no date given",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "no date given",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 472k npm/wk",
        "b": "3 stars, 1.3k npm/wk, 3.4k PyPI/wk",
        "name": "Popularity"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema \u0026 documentation.",
        "question": "Which is better for AI agents, Microsoft Execution Containers or Together Code Sandbox?"
      },
      {
        "answer": "No hosted endpoint is listed for Microsoft Execution Containers. Together Code Sandbox has a hosted endpoint at https://api.bartender.codesandbox.io.",
        "question": "Can an agent call Microsoft Execution Containers and Together Code Sandbox without installing anything?"
      },
      {
        "answer": "Microsoft Execution Containers is open source (MIT). No open-source release is listed for Together Code Sandbox.",
        "question": "Are Microsoft Execution Containers and Together Code Sandbox open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 25",
          "Security \u0026 auth, 69 against 47",
          "Payments \u0026 pricing, 60 against 20",
          "Maintenance \u0026 community, 92 against 83",
          "Transparency \u0026 trust, 83 against 60"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      },
      {
        "aheadOn": [
          "Schema \u0026 documentation, 86 against 81"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.",
        "slug": "together-code-sandbox",
        "watchFor": "The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox.json",
        "title": "Amazon Bedrock AgentCore Code Interpreter vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-together-code-sandbox.json",
        "title": "Blaxel Sandboxes vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox.json",
        "title": "Daytona vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.json",
        "title": "Deno Sandbox vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.json",
        "title": "Deno Sandbox vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-together-code-sandbox.json",
        "title": "E2B vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.json",
        "title": "Freestyle vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.json",
        "title": "Freestyle vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.json",
        "title": "Microsoft Execution Containers vs Sprites",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
        "title": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-together-code-sandbox.json",
        "title": "Modal Sandboxes vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-together-code-sandbox.json",
        "title": "Morph Cloud vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/runloop-vs-together-code-sandbox.json",
        "title": "Runloop Devboxes vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/runloop-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox.json",
        "title": "Sprites vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/together-code-sandbox-vs-vercel-sandbox.json",
        "title": "Together Code Sandbox vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/together-code-sandbox-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-together-code-sandbox.json",
        "title": "Agent 37 Cloud vs Together Code Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-together-code-sandbox"
      }
    ],
    "scores": [
      {
        "by": 56,
        "edge": "microsoft-execution-containers",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "name": "Reliability",
        "together-code-sandbox": 25,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 5,
        "edge": "together-code-sandbox",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "name": "Schema \u0026 documentation",
        "together-code-sandbox": 86,
        "weight": 13
      },
      {
        "by": 4,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "name": "Agent ergonomics",
        "together-code-sandbox": 70,
        "weight": 13
      },
      {
        "by": 22,
        "edge": "microsoft-execution-containers",
        "key": "security",
        "microsoft-execution-containers": 69,
        "name": "Security \u0026 auth",
        "together-code-sandbox": 47,
        "weight": 14
      },
      {
        "by": 40,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "name": "Payments \u0026 pricing",
        "together-code-sandbox": 20,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 9,
        "edge": "microsoft-execution-containers",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "name": "Maintenance \u0026 community",
        "together-code-sandbox": 83,
        "weight": 7
      },
      {
        "by": 23,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "name": "Transparency \u0026 trust",
        "together-code-sandbox": 60,
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema \u0026 documentation. Both do sandbox code.",
    "verdicts": {
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
      "together-code-sandbox": "Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox",
    "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema \u0026 documentation. Both do sandbox code.\n\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #35 of 842. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n- Together Code Sandbox: grade D, 53.6/100, rank #628 of 842. Markdown https://www.anchorterminal.com/tools/together-code-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json\n\n## Which one, for what\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 25\n- Security \u0026 auth, 69 against 47\n- Payments \u0026 pricing, 60 against 20\n- Maintenance \u0026 community, 92 against 83\n- Transparency \u0026 trust, 83 against 60\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Free to start without a card\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n### Together Code Sandbox (D)\n\nGood for: Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.\n\nAhead on:\n- Schema \u0026 documentation, 86 against 81\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access\n\n\n## Score by category\n\n| Category | Weight | Microsoft Execution Containers | Together Code Sandbox | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 25 | Microsoft Execution Containers +56 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 86 | Together Code Sandbox +5 |\n| Agent ergonomics | 13% (16.2 this run) | 74 | 70 | Microsoft Execution Containers +4 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 47 | Microsoft Execution Containers +22 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 20 | Microsoft Execution Containers +40 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 92 | 83 | Microsoft Execution Containers +9 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 60 | Microsoft Execution Containers +23 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **76.3 · BB** | **53.6 · D** | |\n\n## Facts side by side\n\n| Fact | Microsoft Execution Containers | Together Code Sandbox |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Microsoft | Together AI |\n| Hosted endpoint | no (local only) | `https://api.bartender.codesandbox.io` |\n| Transports |  | HTTP |\n| Auth | None | API key |\n| Pricing | Free | Pay per use |\n| x402 | no | no |\n| Licence | MIT | Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT |\n| Read-only variant documented | yes | no |\n| llms.txt | no | yes |\n| Last release | 2026-10-06 | 2026-10-07 |\n| Terms last updated | no document linked | no date given |\n| Privacy policy last updated | couldn't be read | no date given |\n| Customer content may train models |  | not found in the text |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | yes |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | not found in the text |\n| Popularity | 1.5k stars, 472k npm/wk | 3 stars, 1.3k npm/wk, 3.4k PyPI/wk |\n\n## Verdicts\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n**Together Code Sandbox.** Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.\n\n## Before you call either\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n### Together Code Sandbox\n\n1. Confirm the organisation is on Together's allowlist before installing. A valid `TOGETHER_API_KEY` alone is not enough\n2. Build a snapshot first with `snapshots.create`. No default image exists, and every sandbox needs `snapshot_id` or `snapshot_alias`\n3. Set `ttl` at creation or call `terminate()`. Nothing stops a sandbox otherwise, and closing the Python client leaves it running\n4. Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at `sandbox:\u003cid\u003e`\n5. Exclude `snapshots.create` from retries with `should_retry`, and set `experimental.network_policy` before serving anything private on a port\n\n## Questions\n\n### Which is better for AI agents, Microsoft Execution Containers or Together Code Sandbox?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema \u0026 documentation.\n\n### Can an agent call Microsoft Execution Containers and Together Code Sandbox without installing anything?\n\nNo hosted endpoint is listed for Microsoft Execution Containers. Together Code Sandbox has a hosted endpoint at https://api.bartender.codesandbox.io.\n\n### Are Microsoft Execution Containers and Together Code Sandbox open source?\n\nMicrosoft Execution Containers is open source (MIT). No open-source release is listed for Together Code Sandbox.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-execution-containers\", \"b\": \"together-code-sandbox\"}`. From a terminal: `anchor compare microsoft-execution-containers together-code-sandbox`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json and https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json\n\n## Other comparisons with Microsoft Execution Containers or Together Code Sandbox\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.md)\n- [Amazon Bedrock AgentCore Code Interpreter vs Together Code Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox.md)\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-together-code-sandbox.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Together Code Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Daytona vs Together Code Sandbox](https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox.md)\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md)\n- [Deno Sandbox vs Together Code Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [E2B vs Together Code Sandbox](https://www.anchorterminal.com/compare/e2b-vs-together-code-sandbox.md)\n- [Freestyle vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.md)\n- [Freestyle vs Together Code Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Microsoft Execution Containers vs Sprites](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-sprites.md)\n- [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md)\n- [Modal Sandboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/modal-sandboxes-vs-together-code-sandbox.md)\n- [Morph Cloud vs Together Code Sandbox](https://www.anchorterminal.com/compare/morph-cloud-vs-together-code-sandbox.md)\n- [Runloop Devboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/runloop-vs-together-code-sandbox.md)\n- [Sprites vs Together Code Sandbox](https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox.md)\n- [Together Code Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/together-code-sandbox-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n- [Agent 37 Cloud vs Together Code Sandbox](https://www.anchorterminal.com/compare/agent37-vs-together-code-sandbox.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Execution Containers vs Together Code Sandbox",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Together Code Sandbox's 53.6 (D), and leads in 6 of 7 scored categories. Together Code Sandbox leads on schema \u0026 documentation. Both do sandbox code. Category scores, facts, verdicts and agent notes side…",
    "facts": [
      "Microsoft Execution Containers BB 76.3",
      "Together Code Sandbox D 53.6",
      "scores"
    ],
    "h1": "Microsoft Execution Containers vs Together Code Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-execution-containers-vs-together-code-sandbox.png",
    "path": "/compare/microsoft-execution-containers-vs-together-code-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Execution Containers vs Together Code Sandbox for AI agents",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox"
  },
  "tokens": {
    "markdown": 2950,
    "slim": 830
  },
  "version": 1
}
