Head to head · Sandbox code · October 2026 research run

Morph Cloud vs Together Code Sandbox

Together Code Sandbox scores 53.6 (D) on agent readiness against Morph Cloud's 50.8 (D), and leads in 5 of 7 scored categories. Morph Cloud leads on reliability. Both do sandbox code.

Which one, for what

Morph Cloud D

Good for Agents that need to checkpoint and fork a running machine with memory intact, for parallel attempts, evaluations or reinforcement learning rollouts.

Ahead on

  • Reliability, 63 against 25

Watch for

No terms of service, privacy policy, DPA or subprocessor list found on morph.so or cloud.morph.so

Together Code Sandbox D

Good for Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.

Ahead on

  • Schema & documentation, 86 against 72
  • Agent ergonomics, 70 against 61
  • Security & auth, 47 against 39
  • Maintenance & community, 83 against 58
  • Transparency & trust, 60 against 25

Watch for

The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access

Score by category

CategoryWeight this runMorph CloudTogether Code SandboxEdge
Reliability16%206325Morph Cloud +38
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.27286Together Code Sandbox +14
Agent ergonomics13%16.26170Together Code Sandbox +9
Security & auth14%17.53947Together Code Sandbox +8
Payments & pricing10%12.52020even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.85883Together Code Sandbox +25
Transparency & trust7%8.82560Together Code Sandbox +35
Negative events≤1500
Total50.8 · D53.6 · D

Facts side by side

FactMorph CloudTogether Code Sandbox
KindHTTP APIHTTP API
VendorMorph LabsTogether AI
Hosted endpointhttps://cloud.morph.so/apihttps://api.bartender.codesandbox.io
TransportsHTTPHTTP
AuthAPI keyAPI key
PricingPay per usePay per use
x402nono
LicenceProprietary hosted service with no published terms found. The Python and TypeScript SDKs are Apache-2.0Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT
Read-only variant documentednono
llms.txtyesyes
Last release2026-09-012026-10-07
Terms last updatedno document linkedno date given
Privacy policy last updatedno document linkedno date given
Customer content may train modelsnot found in the text
Terms restrict automated accessnot found in the text
Terms restrict benchmarkingyes
Terms or service can change without noticenot found in the text
Arbitration or class-action waivernot found in the text
Popularity3 stars, 339 npm/wk, 13k PyPI/wk3 stars, 1.3k npm/wk, 3.4k PyPI/wk

Verdicts

Morph Cloud

Pause and snapshot keep memory and running processes, and one call branches an instance into several copies. A public OpenAPI file covers 69 operations. No terms of service, privacy policy or security page was found, the free plan includes no compute credit, and the changelog holds one entry from November 2024.

Together Code Sandbox

Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.

Before you call either

Morph Cloud

  1. Set ttl_seconds and ttl_action when starting an instance. Nothing in the docs stops an instance with no TTL from billing MCUs
  2. Pass auth_mode: api_key when exposing an HTTP service. The default is none, which makes the URL public
  3. Enable wake_on_ssh before calling exec on an instance that may be paused. There is no separate exec wake setting
  4. Use /api/instance/list and /api/snapshot/list with page and limit (default 50, maximum 1,000). The plain list routes return everything
  5. On a 503 from snapshot, branch, pause or reboot, wait for the Retry-After value before repeating the call

Together Code Sandbox

  1. Confirm the organisation is on Together's allowlist before installing. A valid TOGETHER_API_KEY alone is not enough
  2. Build a snapshot first with snapshots.create. No default image exists, and every sandbox needs snapshot_id or snapshot_alias
  3. Set ttl at creation or call terminate(). Nothing stops a sandbox otherwise, and closing the Python client leaves it running
  4. Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at sandbox:<id>
  5. Exclude snapshots.create from retries with should_retry, and set experimental.network_policy before serving anything private on a port

Questions

Which is better for AI agents, Morph Cloud or Together Code Sandbox?

Together Code Sandbox scores 53.6 (D) on agent readiness against Morph Cloud's 50.8 (D), and leads in 5 of 7 scored categories. Morph Cloud leads on reliability.

Do Morph Cloud and Together Code Sandbox need an API key?

Both need an API key.

Can an agent call Morph Cloud and Together Code Sandbox without installing anything?

Yes. Morph Cloud has a hosted endpoint at https://cloud.morph.so/api and Together Code Sandbox at https://api.bartender.codesandbox.io.

Other comparisons with Morph Cloud or Together Code Sandbox

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.