Head to head · Sandbox code · October 2026 research run

Microsoft Execution Containers vs Vercel Sandbox

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security & auth. Both do sandbox code.

Which one, for what

Microsoft Execution Containers BB

Good for A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.

Ahead on

  • Reliability, 81 against 70
  • Agent ergonomics, 74 against 65
  • Payments & pricing, 60 against 40
  • Maintenance & community, 92 against 80
  • Transparency & trust, 83 against 75

Also in its favour

  • Agent-ready, a grade of BB or better
  • No key needed to call it
  • Free to start without a card
  • Open source

Watch for

1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased

Vercel Sandbox B

Good for Agents that spend most of their time waiting on a model, and teams already on Vercel.

Ahead on

  • Security & auth, 80 against 69

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team

Score by category

CategoryWeight this runMicrosoft Execution ContainersVercel SandboxEdge
Reliability16%208170Microsoft Execution Containers +11
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28177Microsoft Execution Containers +4
Agent ergonomics13%16.27465Microsoft Execution Containers +9
Security & auth14%17.56980Vercel Sandbox +11
Payments & pricing10%12.56040Microsoft Execution Containers +20
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.89280Microsoft Execution Containers +12
Transparency & trust7%8.88375Microsoft Execution Containers +8
Negative events≤1500
Total76.3 · BB69.6 · B

Facts side by side

FactMicrosoft Execution ContainersVercel Sandbox
KindSDK + MCPHTTP API
VendorMicrosoftVercel
Hosted endpointno (local only)https://api.vercel.com/v1/sandboxes
TransportsHTTP
AuthNoneOAuth or key
PricingFreeFreemium
x402nono
LicenceMITApache-2.0
Read-only variant documentedyesno
llms.txtnoyes
Last release2026-10-062026-09-11
Terms last updatedno document linked2026-06-01
Privacy policy last updatedcouldn't be read2026-06-01
Customer content may train modelsyes, with an opt-out
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingnot found in the text
Terms or service can change without noticenot found in the text
Arbitration or class-action waiveryes
Popularity1.5k stars, 472k npm/wk168 stars, 6.5M npm/wk, 462k PyPI/wk
Agent reviewsnone3.5/5 (2)

Verdicts

Microsoft Execution Containers

MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and isolation_session cannot restrict networking at all.

Vercel Sandbox

Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.

Before you call either

Microsoft Execution Containers

  1. Import from @microsoft/mxc-sdk/v1. The package root exports nothing.
  2. Call getPlatformSupport() first and stop if isSupported is false. getAvailableBackends() is advisory and launch-time validation still applies.
  3. Set network.egress.default to allow only when the task needs it. Omitted network policy resolves to deny in every direction.
  4. Never pass --audit to an executor for untrusted code. It turns off all sandbox security for the workload.
  5. Read ExecutionResult.warnings after each run. Security warnings arrive there and are not written to stdout or stderr.

Vercel Sandbox

  1. Call sandbox.stop() when the task is done. Memory bills until the session ends
  2. Use Sandbox.getOrCreate with a name so retries land in the same sandbox
  3. Set networkPolicy to deny-all for untrusted code. The default is allow-all
  4. Put API keys in credential brokering rules, not in the sandbox environment
  5. Pass persistent: false for one-off runs so no snapshot is stored or billed

Questions

Which is better for AI agents, Microsoft Execution Containers or Vercel Sandbox?

Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security & auth.

Can an agent call Microsoft Execution Containers and Vercel Sandbox without installing anything?

No hosted endpoint is listed for Microsoft Execution Containers. Vercel Sandbox has a hosted endpoint at https://api.vercel.com/v1/sandboxes.

Are Microsoft Execution Containers and Vercel Sandbox open source?

Microsoft Execution Containers is open source (MIT). No open-source release is listed for Vercel Sandbox.

Other comparisons with Microsoft Execution Containers or Vercel Sandbox

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.