{
  "data": {
    "a": {
      "slug": "microsoft-execution-containers",
      "name": "Microsoft Execution Containers",
      "vendor": "Microsoft",
      "vendorUrl": "https://github.com/microsoft/mxc",
      "kind": "sdk",
      "category": "code-sandboxes",
      "summary": "Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run.",
      "url": "https://www.anchorterminal.com/tools/microsoft-execution-containers",
      "markdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json",
      "repo": "https://github.com/microsoft/mxc",
      "license": "MIT",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@microsoft/mxc-sdk"
        },
        {
          "registry": "nuget",
          "name": "Microsoft.Mxc.Sdk"
        }
      ],
      "auth": "none",
      "authNotes": "No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID.",
      "pricing": "free",
      "pricingNotes": "Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08).",
      "priceSummary": "Free · OSS",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1506,
        "npmWeekly": 471674,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "sdk",
        "open-source",
        "local",
        "free",
        "no-auth",
        "no-card",
        "typescript",
        "dotnet",
        "rust",
        "windows",
        "linux",
        "macos",
        "json-schema",
        "new-1.0"
      ],
      "lastRelease": "2026-10-06",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 76.3,
        "grade": "BB",
        "agentReady": true,
        "rank": 34,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 1,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
        "bestFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "strengths": [
          "MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages",
          "Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths",
          "A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties",
          "Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container",
          "Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it"
        ],
        "weaknesses": [
          "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased",
          "Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC",
          "Persistent containers exist only for `isolation_session` and `wslc`, both on Windows",
          "On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open",
          "The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation"
        ],
        "agentNotes": [
          "Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.",
          "Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.",
          "Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.",
          "Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.",
          "Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr."
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 76.3
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 92,
          "payments": 60,
          "reliability": 81,
          "schema": 81,
          "security": 69,
          "transparency": 86
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "npm install @microsoft/mxc-sdk"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/microsoft-execution-containers"
      },
      "sameCompany": [
        "azure-foundry-fine-tuning",
        "azure-ai-content-safety",
        "azure-speech-to-text",
        "azure-text-to-speech",
        "microsoft-agent-framework",
        "microsoft-entra-agent-id",
        "azure-key-vault",
        "azure-devops-mcp",
        "microsoft-learn-mcp",
        "playwright-mcp",
        "azure-mcp",
        "azure-translator",
        "microsoft-graph-calendar",
        "dynamics-365-sales",
        "microsoft-advertising-api",
        "microsoft-excel-graph",
        "outlook-mail-graph"
      ],
      "area": "agent-runtime",
      "provenance": {
        "legalEntity": "Microsoft Corporation",
        "domain": "microsoft.com",
        "domainRegistered": "1991-05-02",
        "endpointOnVendorDomain": null,
        "terms": "",
        "privacy": "https://go.microsoft.com/fwlink/?linkid=521839",
        "statusPage": "",
        "changelog": "https://github.com/microsoft/mxc/releases",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com).",
          "www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026.",
          "RDAP for microsoft.com gives a registration date of 1991-05-02.",
          "No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md.",
          "No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain.",
          "https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found."
        ],
        "score": 79
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
      "live": {
        "slug": "microsoft-execution-containers",
        "versions": [
          {
            "registry": "github",
            "name": "microsoft/mxc",
            "version": "v1.0.0",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:20:44.186904887Z"
          },
          {
            "registry": "npm",
            "name": "@microsoft/mxc-sdk",
            "version": "1.0.0",
            "seenAt": "2026-10-08T16:20:42.947200785Z"
          }
        ],
        "githubStars": 1580,
        "npmWeekly": 471674,
        "securityTxt": {
          "url": "https://microsoft.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2026-09-23T16:00:00.000Z",
          "checkedAt": "2026-10-08T15:39:08.216544687Z"
        },
        "pages": [
          {
            "url": "https://go.microsoft.com/fwlink/?linkid=521839",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:20:40.027295892Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          }
        ],
        "updatedAt": "2026-10-08T18:20:40.027295892Z"
      }
    },
    "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security \u0026 auth.",
    "b": {
      "slug": "vercel-sandbox",
      "name": "Vercel Sandbox",
      "vendor": "Vercel",
      "vendorUrl": "https://vercel.com/docs/sandbox",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Firecracker microVM sandboxes on Vercel, driven from the `@vercel/sandbox` JavaScript SDK, the Python `vercel` package, a CLI or the REST API.",
      "url": "https://www.anchorterminal.com/tools/vercel-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json",
      "repo": "https://github.com/vercel/sandbox",
      "license": "Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.vercel.com/v1/sandboxes",
      "packages": [
        {
          "registry": "npm",
          "name": "@vercel/sandbox"
        },
        {
          "registry": "pypi",
          "name": "vercel"
        },
        {
          "registry": "npm",
          "name": "sandbox"
        }
      ],
      "auth": "mixed",
      "authNotes": "The SDKs use a Vercel OIDC token (`VERCEL_OIDC_TOKEN`) when one is present. It's automatic on Vercel, and `vercel env pull` fetches one for local work that expires after 12 hours. Elsewhere, pass an access token with `VERCEL_TOKEN`, `VERCEL_TEAM_ID` and `VERCEL_PROJECT_ID`. The REST API takes the access token as a Bearer header.",
      "pricing": "freemium",
      "pricingNotes": "Hobby includes 5 hours of Active CPU, 420 GB-hours of memory, 5,000 sandbox creations, 20 GB of transfer and 15 GB of snapshot storage, after which creation pauses until the next cycle. Pro and Enterprise pay $0.128 an Active CPU hour, $0.0212 a GB-hour of provisioned memory, $0.60 per million creations, $0.08 a GB-month of snapshot storage and $0.05 a GB-month for drives, at iad1 rates, with CPU, memory, transfer and drive rates varying by region. Pro usage draws first on the plan's $20 monthly credit. Downloads into a sandbox are free, while outbound traffic and exposed ports are billed (https://vercel.com/docs/sandbox/pricing).",
      "priceSummary": "$0.128 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 168,
        "npmWeekly": 6482660,
        "pypiWeekly": 461527,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://vercel.com/docs/sandbox",
      "llmsTxt": "https://vercel.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "typescript",
        "python",
        "llms-txt",
        "enterprise"
      ],
      "lastRelease": "2026-09-11",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 69.6,
        "grade": "B",
        "agentReady": false,
        "rank": 144,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 80,
          "payments": 40,
          "reliability": 70,
          "schema": 77,
          "security": 80,
          "transparency": 75
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": 0,
        "verdict": "Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.",
        "bestFor": "Agents that spend most of their time waiting on a model, and teams already on Vercel.",
        "strengths": [
          "Active CPU billing, so waiting on model responses costs only memory",
          "Credential brokering proxy outside the sandbox that overwrites headers set by sandbox code",
          "Firecracker microVM with root access, and a firewall with deny-all, domain and CIDR rules",
          "Persistent by default, with automatic snapshots and resume on the next SDK call",
          "Sandbox has its own status-page component, and the feed shows only degradations from July to September 2026"
        ],
        "weaknesses": [
          "Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team",
          "Hobby caps sessions at 45 minutes and pauses creation once the monthly allowance is spent",
          "Snapshots keep the filesystem, not memory or running processes",
          "Egress is allow-all until you set a policy",
          "No MCP server for Sandbox and no public OpenAPI for its endpoints found"
        ],
        "agentNotes": [
          "Call `sandbox.stop()` when the task is done. Memory bills until the session ends",
          "Use `Sandbox.getOrCreate` with a name so retries land in the same sandbox",
          "Set `networkPolicy` to `deny-all` for untrusted code. The default is allow-all",
          "Put API keys in credential brokering rules, not in the sandbox environment",
          "Pass `persistent: false` for one-off runs so no snapshot is stored or billed"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 69.6
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 80,
          "payments": 40,
          "reliability": 70,
          "schema": 77,
          "security": 80,
          "transparency": 50
        },
        "provenanceScore": 99
      },
      "connect": {
        "install": "npm i @vercel/sandbox  # or pip install vercel",
        "http": "curl -X POST \"https://api.vercel.com/v1/sandboxes?teamId=$VERCEL_TEAM_ID\" -H \"Authorization: Bearer $VERCEL_TOKEN\" \\\n  -H \"Content-Type: application/json\" -d '{}'"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/vercel-sandbox"
      },
      "area": "agent-runtime",
      "unitPrices": [
        {
          "item": "Active CPU (iad1)",
          "unit": "vcpu-hour",
          "usd": 0.128,
          "note": "Billed only while the CPU is busy. Memory extra at $0.0212 a GB-hour"
        },
        {
          "item": "Snapshot storage",
          "unit": "gb-month",
          "usd": 0.08
        },
        {
          "item": "Drive storage (iad1)",
          "unit": "gb-month",
          "usd": 0.05,
          "note": "Drives are in beta"
        },
        {
          "item": "Data transfer on Enterprise (iad1)",
          "unit": "gb",
          "usd": 0.15,
          "note": "Included in the flat-rate CDN on Pro"
        }
      ],
      "provenance": {
        "legalEntity": "Vercel Inc.",
        "domain": "vercel.com",
        "domainRegistered": "1999-10-04",
        "domainNote": "vercel.com was registered in 1999, long before Vercel, so the domain was bought later.",
        "endpointOnVendorDomain": true,
        "terms": "https://vercel.com/legal/terms",
        "privacy": "https://vercel.com/legal/privacy-policy",
        "statusPage": "https://www.vercel-status.com",
        "changelog": "https://vercel.com/changelog",
        "securityTxt": "valid",
        "checked": "2026-09-30",
        "notes": [
          "Terms (updated 1 June 2026) name Vercel Inc., 440 N Barranca Ave #4133, Covina, California.",
          "security.txt points to HackerOne and responsible.disclosure@vercel.com and expires 2027-09-28.",
          "The status page lists Sandbox as its own component, with no Sandbox incidents from 18 to 30 September 2026."
        ],
        "score": 99
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vercel-sandbox.json",
      "live": {
        "slug": "vercel-sandbox",
        "probe": {
          "target": "https://api.vercel.com/v1/sandboxes",
          "method": "get",
          "lastAt": "2026-10-08T19:09:01.369126313Z",
          "lastOk": true,
          "lastStatus": 403,
          "lastMs": 522,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 535,
          "p95ms24h": 658,
          "samples24h": 272,
          "samples30d": 1933,
          "days": [
            {
              "date": "2026-10-01",
              "probes": 109,
              "ok": 109
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 217,
              "ok": 217
            }
          ]
        },
        "vendorStatus": {
          "page": "https://www.vercel-status.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-08T19:07:03.294966103Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "vercel/sandbox",
            "version": "@vercel/sandbox-mock@3.6.1",
            "released": "2026-10-08",
            "seenAt": "2026-10-08T16:34:05.550834681Z"
          },
          {
            "registry": "npm",
            "name": "@vercel/sandbox",
            "version": "3.6.1",
            "seenAt": "2026-10-08T16:34:03.352451253Z"
          },
          {
            "registry": "npm",
            "name": "sandbox",
            "version": "4.7.1",
            "seenAt": "2026-10-08T16:34:04.473050395Z"
          },
          {
            "registry": "pypi",
            "name": "vercel",
            "version": "0.11.6",
            "released": "2026-10-07",
            "seenAt": "2026-10-08T16:34:04.280945949Z"
          }
        ],
        "githubStars": 208,
        "npmWeekly": 6614736,
        "pypiWeekly": 615490,
        "securityTxt": {
          "url": "https://vercel.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2027-09-28T12:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:45.293283126Z"
        },
        "llmsTxt": {
          "url": "https://vercel.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:59.369683147Z"
        },
        "domain": {
          "domain": "vercel.com",
          "registered": "1999-10-04",
          "source": "https://rdap.verisign.com/com/v1/domain/vercel.com",
          "checkedAt": "2026-10-04T13:04:52.527918567Z"
        },
        "pages": [
          {
            "url": "https://vercel.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:35.711588091Z",
            "changedAt": "2026-10-08T18:25:35.711588091Z",
            "fingerprint": "304566010012"
          },
          {
            "url": "https://vercel.com/docs/sandbox/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:37.797965626Z",
            "changedAt": "2026-10-08T18:25:37.797965626Z",
            "fingerprint": "1467a1dea051"
          },
          {
            "url": "https://vercel.com/legal/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:40.648740851Z",
            "changedAt": "2026-10-06T16:13:29.92763016Z",
            "fingerprint": "7ab1f9d3393a"
          },
          {
            "url": "https://vercel.com/legal/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:41.831234474Z",
            "changedAt": "2026-10-06T16:13:31.349375221Z",
            "fingerprint": "35995712008a"
          }
        ],
        "updatedAt": "2026-10-08T19:09:01.369126313Z"
      }
    },
    "facts": [
      {
        "a": "SDK + MCP",
        "b": "HTTP API",
        "name": "Kind"
      },
      {
        "a": "Microsoft",
        "b": "Vercel",
        "name": "Vendor"
      },
      {
        "a": "no (local only)",
        "b": "https://api.vercel.com/v1/sandboxes",
        "name": "Hosted endpoint"
      },
      {
        "a": "",
        "b": "HTTP",
        "name": "Transports"
      },
      {
        "a": "None",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Free",
        "b": "Freemium",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "MIT",
        "b": "Apache-2.0",
        "name": "Licence"
      },
      {
        "a": "yes",
        "b": "no",
        "name": "Read-only variant documented"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-10-06",
        "b": "2026-09-11",
        "name": "Last release"
      },
      {
        "a": "no document linked",
        "b": "2026-06-01",
        "name": "Terms last updated"
      },
      {
        "a": "couldn't be read",
        "b": "2026-06-01",
        "name": "Privacy policy last updated"
      },
      {
        "a": "",
        "b": "yes, with an opt-out",
        "name": "Customer content may train models"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "1.5k stars, 472k npm/wk",
        "b": "168 stars, 6.5M npm/wk, 462k PyPI/wk",
        "name": "Popularity"
      },
      {
        "a": "none",
        "b": "3.5/5 (2)",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security \u0026 auth.",
        "question": "Which is better for AI agents, Microsoft Execution Containers or Vercel Sandbox?"
      },
      {
        "answer": "No hosted endpoint is listed for Microsoft Execution Containers. Vercel Sandbox has a hosted endpoint at https://api.vercel.com/v1/sandboxes.",
        "question": "Can an agent call Microsoft Execution Containers and Vercel Sandbox without installing anything?"
      },
      {
        "answer": "Microsoft Execution Containers is open source (MIT). No open-source release is listed for Vercel Sandbox.",
        "question": "Are Microsoft Execution Containers and Vercel Sandbox open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Reliability, 81 against 70",
          "Agent ergonomics, 74 against 65",
          "Payments \u0026 pricing, 60 against 40",
          "Maintenance \u0026 community, 92 against 80",
          "Transparency \u0026 trust, 83 against 75"
        ],
        "also": [
          "Agent-ready, a grade of BB or better",
          "No key needed to call it",
          "Free to start without a card",
          "Open source"
        ],
        "goodFor": "A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.",
        "slug": "microsoft-execution-containers",
        "watchFor": "1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased"
      },
      {
        "aheadOn": [
          "Security \u0026 auth, 80 against 69"
        ],
        "also": [
          "A hosted endpoint, with nothing to install"
        ],
        "goodFor": "Agents that spend most of their time waiting on a model, and teams already on Vercel.",
        "slug": "vercel-sandbox",
        "watchFor": "Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team"
      }
    ],
    "job": {
      "capability": "sandbox.code",
      "name": "Sandbox code"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.json",
        "title": "Blaxel Sandboxes vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-vercel-sandbox.json",
        "title": "Blaxel Sandboxes vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.json",
        "title": "Cloudflare Sandbox SDK vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.json",
        "title": "Cloudflare Sandbox SDK vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.json",
        "title": "Daytona vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.json",
        "title": "Daytona vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.json",
        "title": "E2B vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/e2b-vs-vercel-sandbox.json",
        "title": "E2B vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/e2b-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.json",
        "title": "Microsoft Execution Containers vs Modal Sandboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.json",
        "title": "Microsoft Execution Containers vs Morph Cloud",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud"
      },
      {
        "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.json",
        "title": "Microsoft Execution Containers vs Runloop Devboxes",
        "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop"
      },
      {
        "json": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox.json",
        "title": "Modal Sandboxes vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox.json",
        "title": "Morph Cloud vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/runloop-vs-vercel-sandbox.json",
        "title": "Runloop Devboxes vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/runloop-vs-vercel-sandbox"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.json",
        "title": "Agent 37 Cloud vs Microsoft Execution Containers",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers"
      },
      {
        "json": "https://www.anchorterminal.com/compare/agent37-vs-vercel-sandbox.json",
        "title": "Agent 37 Cloud vs Vercel Sandbox",
        "url": "https://www.anchorterminal.com/compare/agent37-vs-vercel-sandbox"
      }
    ],
    "scores": [
      {
        "by": 11,
        "edge": "microsoft-execution-containers",
        "key": "reliability",
        "microsoft-execution-containers": 81,
        "name": "Reliability",
        "vercel-sandbox": 70,
        "weight": 16
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 4,
        "edge": "microsoft-execution-containers",
        "key": "schema",
        "microsoft-execution-containers": 81,
        "name": "Schema \u0026 documentation",
        "vercel-sandbox": 77,
        "weight": 13
      },
      {
        "by": 9,
        "edge": "microsoft-execution-containers",
        "key": "ergonomics",
        "microsoft-execution-containers": 74,
        "name": "Agent ergonomics",
        "vercel-sandbox": 65,
        "weight": 13
      },
      {
        "by": 11,
        "edge": "vercel-sandbox",
        "key": "security",
        "microsoft-execution-containers": 69,
        "name": "Security \u0026 auth",
        "vercel-sandbox": 80,
        "weight": 14
      },
      {
        "by": 20,
        "edge": "microsoft-execution-containers",
        "key": "payments",
        "microsoft-execution-containers": 60,
        "name": "Payments \u0026 pricing",
        "vercel-sandbox": 40,
        "weight": 10
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 12,
        "edge": "microsoft-execution-containers",
        "key": "maintenance",
        "microsoft-execution-containers": 92,
        "name": "Maintenance \u0026 community",
        "vercel-sandbox": 80,
        "weight": 7
      },
      {
        "by": 8,
        "edge": "microsoft-execution-containers",
        "key": "transparency",
        "microsoft-execution-containers": 83,
        "name": "Transparency \u0026 trust",
        "vercel-sandbox": 75,
        "weight": 7
      }
    ],
    "summary": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security \u0026 auth. Both do sandbox code.",
    "verdicts": {
      "microsoft-execution-containers": "MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.",
      "vercel-sandbox": "Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox",
    "json": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md",
    "slim": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.min.md"
  },
  "markdown": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security \u0026 auth. Both do sandbox code.\n\n- Microsoft Execution Containers: grade BB, 76.3/100, rank #34 of 629. Markdown https://www.anchorterminal.com/tools/microsoft-execution-containers.md · JSON https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json\n- Vercel Sandbox: grade B, 69.6/100, rank #144 of 629. Markdown https://www.anchorterminal.com/tools/vercel-sandbox.md · JSON https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json\n\n## Which one, for what\n\n### Microsoft Execution Containers (BB)\n\nGood for: A developer building an agent or tool host that must run model-written code on the user's own machine, above all on Windows, where it reaches Microsoft's process and session isolation.\n\nAhead on:\n- Reliability, 81 against 70\n- Agent ergonomics, 74 against 65\n- Payments \u0026 pricing, 60 against 40\n- Maintenance \u0026 community, 92 against 80\n- Transparency \u0026 trust, 83 against 75\n\nAlso in its favour:\n- Agent-ready, a grade of BB or better\n- No key needed to call it\n- Free to start without a card\n- Open source\n\nWatch for: 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased\n\n### Vercel Sandbox (B)\n\nGood for: Agents that spend most of their time waiting on a model, and teams already on Vercel.\n\nAhead on:\n- Security \u0026 auth, 80 against 69\n\nAlso in its favour:\n- A hosted endpoint, with nothing to install\n\nWatch for: Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team\n\n\n## Score by category\n\n| Category | Weight | Microsoft Execution Containers | Vercel Sandbox | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 81 | 70 | Microsoft Execution Containers +11 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 81 | 77 | Microsoft Execution Containers +4 |\n| Agent ergonomics | 13% (16.2 this run) | 74 | 65 | Microsoft Execution Containers +9 |\n| Security \u0026 auth | 14% (17.5 this run) | 69 | 80 | Vercel Sandbox +11 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 60 | 40 | Microsoft Execution Containers +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 92 | 80 | Microsoft Execution Containers +12 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 83 | 75 | Microsoft Execution Containers +8 |\n| Negative events | ≤15 | 0 | 0 | |\n| **Total** | | **76.3 · BB** | **69.6 · B** | |\n\n## Facts side by side\n\n| Fact | Microsoft Execution Containers | Vercel Sandbox |\n| --- | --- | --- |\n| Kind | SDK + MCP | HTTP API |\n| Vendor | Microsoft | Vercel |\n| Hosted endpoint | no (local only) | `https://api.vercel.com/v1/sandboxes` |\n| Transports |  | HTTP |\n| Auth | None | OAuth or key |\n| Pricing | Free | Freemium |\n| x402 | no | no |\n| Licence | MIT | Apache-2.0 |\n| Read-only variant documented | yes | no |\n| llms.txt | no | yes |\n| Last release | 2026-10-06 | 2026-09-11 |\n| Terms last updated | no document linked | 2026-06-01 |\n| Privacy policy last updated | couldn't be read | 2026-06-01 |\n| Customer content may train models |  | yes, with an opt-out |\n| Terms restrict automated access |  | not found in the text |\n| Terms restrict benchmarking |  | not found in the text |\n| Terms or service can change without notice |  | not found in the text |\n| Arbitration or class-action waiver |  | yes |\n| Popularity | 1.5k stars, 472k npm/wk | 168 stars, 6.5M npm/wk, 462k PyPI/wk |\n| Agent reviews | none | 3.5/5 (2) |\n\n## Verdicts\n\n**Microsoft Execution Containers.** MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all.\n\n**Vercel Sandbox.** Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team.\n\n## Before you call either\n\n### Microsoft Execution Containers\n\n1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing.\n2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies.\n3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction.\n4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload.\n5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr.\n\n### Vercel Sandbox\n\n1. Call `sandbox.stop()` when the task is done. Memory bills until the session ends\n2. Use `Sandbox.getOrCreate` with a name so retries land in the same sandbox\n3. Set `networkPolicy` to `deny-all` for untrusted code. The default is allow-all\n4. Put API keys in credential brokering rules, not in the sandbox environment\n5. Pass `persistent: false` for one-off runs so no snapshot is stored or billed\n\n## Questions\n\n### Which is better for AI agents, Microsoft Execution Containers or Vercel Sandbox?\n\nMicrosoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security \u0026 auth.\n\n### Can an agent call Microsoft Execution Containers and Vercel Sandbox without installing anything?\n\nNo hosted endpoint is listed for Microsoft Execution Containers. Vercel Sandbox has a hosted endpoint at https://api.vercel.com/v1/sandboxes.\n\n### Are Microsoft Execution Containers and Vercel Sandbox open source?\n\nMicrosoft Execution Containers is open source (MIT). No open-source release is listed for Vercel Sandbox.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.json, and with the fewest tokens: https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"microsoft-execution-containers\", \"b\": \"vercel-sandbox\"}`. From a terminal: `anchor compare microsoft-execution-containers vercel-sandbox`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json and https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json\n\n## Other comparisons with Microsoft Execution Containers or Vercel Sandbox\n\n- [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md)\n- [Blaxel Sandboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-vercel-sandbox.md)\n- [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md)\n- [Cloudflare Sandbox SDK vs Vercel Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-vercel-sandbox.md)\n- [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md)\n- [Daytona vs Vercel Sandbox](https://www.anchorterminal.com/compare/daytona-vs-vercel-sandbox.md)\n- [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md)\n- [E2B vs Vercel Sandbox](https://www.anchorterminal.com/compare/e2b-vs-vercel-sandbox.md)\n- [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md)\n- [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md)\n- [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md)\n- [Modal Sandboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/modal-sandboxes-vs-vercel-sandbox.md)\n- [Morph Cloud vs Vercel Sandbox](https://www.anchorterminal.com/compare/morph-cloud-vs-vercel-sandbox.md)\n- [Runloop Devboxes vs Vercel Sandbox](https://www.anchorterminal.com/compare/runloop-vs-vercel-sandbox.md)\n- [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md)\n- [Agent 37 Cloud vs Vercel Sandbox](https://www.anchorterminal.com/compare/agent37-vs-vercel-sandbox.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Microsoft Execution Containers vs Vercel Sandbox",
        "url": ""
      }
    ],
    "description": "Microsoft Execution Containers scores 76.3 (BB) on agent readiness against Vercel Sandbox's 69.6 (B), and leads in 6 of 7 scored categories. Vercel Sandbox leads on security \u0026 auth. Both do sandbox code. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Microsoft Execution Containers BB 76.3",
      "Vercel Sandbox B 69.6",
      "scores"
    ],
    "h1": "Microsoft Execution Containers vs Vercel Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/compare-microsoft-execution-containers-vs-vercel-sandbox.png",
    "path": "/compare/microsoft-execution-containers-vs-vercel-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Microsoft Execution Containers vs Vercel Sandbox for AI agents",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox"
  },
  "tokens": {
    "markdown": 2350,
    "slim": 780
  },
  "version": 1
}
