{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
        "name": "Microsoft Execution Containers",
        "score": 76.3,
        "shared": [
          "sandbox.code",
          "sandbox.fs"
        ],
        "slug": "microsoft-execution-containers"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/modal-sandboxes.json",
        "name": "Modal Sandboxes",
        "score": 75.5,
        "shared": [
          "sandbox.code",
          "sandbox.fs"
        ],
        "slug": "modal-sandboxes"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/vercel-sandbox.json",
        "name": "Vercel Sandbox",
        "score": 69.6,
        "shared": [
          "sandbox.code",
          "sandbox.fs"
        ],
        "slug": "vercel-sandbox"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/e2b.json",
        "name": "E2B",
        "score": 68.3,
        "shared": [
          "sandbox.code",
          "sandbox.fs"
        ],
        "slug": "e2b"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
        "name": "Cloudflare Sandbox SDK",
        "score": 67.5,
        "shared": [
          "sandbox.code",
          "sandbox.fs"
        ],
        "slug": "cloudflare-sandbox-sdk"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/runloop.json",
        "name": "Runloop Devboxes",
        "score": 64.8,
        "shared": [
          "sandbox.code",
          "sandbox.fs"
        ],
        "slug": "runloop"
      }
    ],
    "tool": {
      "slug": "agentcore-code-interpreter",
      "name": "Amazon Bedrock AgentCore Code Interpreter",
      "vendor": "Amazon Web Services",
      "vendorUrl": "https://aws.amazon.com/bedrock/agentcore/",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Amazon Bedrock AgentCore Code Interpreter is AWS's managed sandbox for running agent-written Python, JavaScript and TypeScript. Each session is a dedicated microVM, reached through the AWS API, the AgentCore SDKs or an MCP server.",
      "url": "https://www.anchorterminal.com/tools/agentcore-code-interpreter",
      "markdownUrl": "https://www.anchorterminal.com/tools/agentcore-code-interpreter.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/agentcore-code-interpreter.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/agentcore-code-interpreter.json",
      "repo": "https://github.com/aws/bedrock-agentcore-sdk-python",
      "license": "Proprietary service under the AWS Service Terms. The AgentCore SDKs for Python and TypeScript and the AgentCore MCP server are Apache-2.0",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://bedrock-agentcore.{region}.amazonaws.com/code-interpreters/{id}/tools/invoke",
      "packages": [
        {
          "registry": "pypi",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "npm",
          "name": "bedrock-agentcore"
        },
        {
          "registry": "pypi",
          "name": "boto3"
        },
        {
          "registry": "pypi",
          "name": "awslabs.amazon-bedrock-agentcore-mcp-server"
        }
      ],
      "auth": "api-key",
      "authNotes": "AWS Signature Version 4 with IAM access keys or a role, self-serve once an AWS account exists. A policy must allow `bedrock-agentcore:StartCodeInterpreterSession`, `bedrock-agentcore:InvokeCodeInterpreter` and `bedrock-agentcore:StopCodeInterpreterSession` on the interpreter's ARN. The managed interpreter `aws.codeinterpreter.v1` needs no resource of its own. A custom interpreter takes a network mode and an execution role, which bounds the AWS resources code in the sandbox can reach. No partner or sales approval.",
      "pricing": "usage",
      "pricingNotes": "$0.0895 a vCPU-hour and $0.00945 a GB-hour, billed per second on CPU used and peak memory, with a one-second minimum and 128 MB minimum memory. AWS says I/O wait and idle time are free when no background process is running. Network data transfer is extra at EC2 rates. No allowance specific to Code Interpreter. New AWS accounts get up to $200 in Free Tier credits, and AWS says most new customers sign up without a payment method, so an agent's owner can start without a contract (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/, checked 2026-10-08).",
      "priceSummary": "$0.0895 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 on the Code Interpreter endpoints, in the API reference or on the pricing page. AgentCore Payments, a separate component, lets a customer's agents pay third parties over x402 and MPP and is not a way to pay AWS (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 776,
        "npmWeekly": 334717,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-tool.html",
      "llmsTxt": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs"
      ],
      "tags": [
        "hosted",
        "usage-priced",
        "closed-source",
        "python",
        "typescript",
        "enterprise",
        "llms-txt",
        "mcp",
        "free-tier",
        "no-card",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 73.1,
        "grade": "BB",
        "agentReady": true,
        "rank": 89,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 75,
          "maintenance": 65,
          "payments": 30,
          "reliability": 85,
          "schema": 81,
          "security": 87,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 85,
            "points": 17,
            "reason": "Graded on the hosted lines, for the AWS API. AWS Health Dashboard with per-service, per-Region history (20). The dashboard history file, read on 8 October, names AgentCore in one event in the 90 days, elevated packet loss in one availability zone of Europe (Spain) for 2 hours 40 minutes on 4 October 2026, marked informational. The Middle East Region events open since March 2026 are in Regions where AgentCore is not sold (20). Rate limits published per API, 30 requests a second for starting sessions and invoking and 5 for creating or deleting interpreters, with 1,000 concurrent sessions (15). `ThrottlingException` is a 429 with advice to back off exponentially, `InternalServerException` is documented as retryable, and `StartCodeInterpreterSession` takes a `clientToken` so a retry does not open a second session (15). The AgentCore FAQ says the Bedrock SLA applies, but that SLA, last updated 4 October 2023, names only the Bedrock APIs for models (5 of 10, our call, as on the Bedrock Guardrails listing). Generally available since October 2025 (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 81,
            "points": 13.16,
            "reason": "The API model is public as Smithy JSON in aws/api-models-aws, version 2024-02-28, and the SDKs are generated from it (25). The developer guide has an llms.txt of 988 lines and serves every page as Markdown (10). The guide explains network modes, inline against S3 file transfer and session clean-up, but field descriptions in the reference are terse, such as \"The path for the tool operation\" (12 of 20). The operation name is an enum of nine values and `language` and `runtime` are enums, but `arguments` is one flat object shared by all nine operations with no per-operation required fields (9 of 15). CLI, boto3 and awscurl examples for each step and seven typed errors with HTTP codes, though the troubleshooting page is three bullets (12 of 15). A dated API version, a versioned system interpreter id and release notes with an RSS feed, whose entries carry a month and no day (13 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 75,
            "points": 12.19,
            "reason": "Results stream back as content blocks with stdout and stderr, and we found no control for truncating or sizing output. The MCP server registers 122 tools by default and `AGENTCORE_ENABLE_TOOLS` cuts that to the 10 for Code Interpreter (15 of 25). `ListCodeInterpreterSessions` pages with `maxResults` of 1 to 100 and `nextToken` and filters by status (15 of 20). Typed errors with HTTP codes, but a quota breach comes back as HTTP 402 and errors can also arrive inside the result stream (15 of 20). `clientToken` on session start and on interpreter create and delete. Running code has no idempotency key (15 of 20). The managed interpreter needs no set-up, `code_session` handles start and stop, and there are AgentCore SDKs for Python and TypeScript beside the AWS SDKs (15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 87,
            "points": 15.23,
            "reason": "IAM with SigV4, roles and short-lived credentials, and policies can name one interpreter ARN (30). Each of the nine operations is its own IAM action, system and custom interpreters have separate ARN types, a custom interpreter's execution role bounds what sandbox code can reach, and the default Sandbox network mode reaches only Amazon S3. No approval step for destructive calls (17 of 20). Each session is a dedicated microVM whose memory AWS says is sanitised at the end, and the docs flag Public network mode as a risk, but the Code Interpreter pages we read give no guidance on treating execution output as untrusted (11 of 15). CloudWatch metrics, spans and per-second usage logs per session, and the overview claims CloudTrail logging, but we found no page listing Code Interpreter's CloudTrail events, and console logs are not sent to CloudWatch (11 of 15). A vulnerability disclosure programme on HackerOne, public bulletins and AgentCore in SOC scope on the list of 11 August 2026. The security.txt expired on 24 September 2026 and no paid bounty was found, read as on the other AWS listings (18 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No x402, MPP or L402 on the Code Interpreter endpoints. AgentCore Payments is a separate component for an agent paying third parties (0). Per-unit prices published without a login, $0.0895 a vCPU-hour and $0.00945 a GB-hour (20). No allowance for Code Interpreter, but the pricing page says new AWS customers get up to $200 in Free Tier credits and the Free Tier FAQ says most new customers need no payment method, so half, as on the other AWS listings (10). A person signs up in a browser and sets up IAM (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 65,
            "points": 5.69,
            "reason": "The Python SDK that carries `code_session` shipped 1.24.1 on 7 October 2026, but the newest changes to Code Interpreter itself are from July 2026, the `ActiveSessionCount` metric and a fix to `install_packages` on 17 July, so 20 of 30 as a judgement call (20). The SDK had ten releases since 10 July and the release notes have entries every month, yet only two touch Code Interpreter (10 of 20). Public release notes with RSS, issues open on the SDK repository with an auto-triage workflow, and re:Post and AWS Support. Reply times were not checked (10 of 15). Current official SDKs, `bedrock-agentcore` 1.24.1 on PyPI and 0.4.5 on npm (15). The SDK repository runs CI, integration tests, security scanning and a breaking-change check, with a lock file (10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 70,
            "points": 6.13,
            "note": "editorial 51, provenance 88",
            "reason": "Closed service under the AWS Service Terms, with Apache-2.0 SDKs and MCP server (15). The docs say session files are cleaned up when a session ends and also give a 30-day retention period for session data without saying what is kept. Encryption at rest and TLS 1.2 are stated, the privacy notice excludes customer content, and we found no Code Interpreter statement on use of customer content (15 of 30). No deprecation policy for the interpreter or its language runtimes was found. The system interpreter id carries a version (3 of 20). AWS publishes a sub-processor list, updated 28 July 2026, and the guide lists the 22 Regions where built-in tools run (18 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Results stream back as content blocks with stdout and stderr, and we found no control for truncating or sizing output. The MCP server registers 122 tools by default and `AGENTCORE_ENABLE_TOOLS` cuts that to the 10 for Code Interpreter (15 of 25). `ListCodeInterpreterSessions` pages with `maxResults` of 1 to 100 and `nextToken` and filters by status (15 of 20). Typed errors with HTTP codes, but a quota breach comes back as HTTP 402 and errors can also arrive inside the result stream (15 of 20). `clientToken` on session start and on interpreter create and delete. Running code has no idempotency key (15 of 20). The managed interpreter needs no set-up, `code_session` handles start and stop, and there are AgentCore SDKs for Python and TypeScript beside the AWS SDKs (15).",
            "maintenance": "The Python SDK that carries `code_session` shipped 1.24.1 on 7 October 2026, but the newest changes to Code Interpreter itself are from July 2026, the `ActiveSessionCount` metric and a fix to `install_packages` on 17 July, so 20 of 30 as a judgement call (20). The SDK had ten releases since 10 July and the release notes have entries every month, yet only two touch Code Interpreter (10 of 20). Public release notes with RSS, issues open on the SDK repository with an auto-triage workflow, and re:Post and AWS Support. Reply times were not checked (10 of 15). Current official SDKs, `bedrock-agentcore` 1.24.1 on PyPI and 0.4.5 on npm (15). The SDK repository runs CI, integration tests, security scanning and a breaking-change check, with a lock file (10).",
            "payments": "No x402, MPP or L402 on the Code Interpreter endpoints. AgentCore Payments is a separate component for an agent paying third parties (0). Per-unit prices published without a login, $0.0895 a vCPU-hour and $0.00945 a GB-hour (20). No allowance for Code Interpreter, but the pricing page says new AWS customers get up to $200 in Free Tier credits and the Free Tier FAQ says most new customers need no payment method, so half, as on the other AWS listings (10). A person signs up in a browser and sets up IAM (0).",
            "reliability": "Graded on the hosted lines, for the AWS API. AWS Health Dashboard with per-service, per-Region history (20). The dashboard history file, read on 8 October, names AgentCore in one event in the 90 days, elevated packet loss in one availability zone of Europe (Spain) for 2 hours 40 minutes on 4 October 2026, marked informational. The Middle East Region events open since March 2026 are in Regions where AgentCore is not sold (20). Rate limits published per API, 30 requests a second for starting sessions and invoking and 5 for creating or deleting interpreters, with 1,000 concurrent sessions (15). `ThrottlingException` is a 429 with advice to back off exponentially, `InternalServerException` is documented as retryable, and `StartCodeInterpreterSession` takes a `clientToken` so a retry does not open a second session (15). The AgentCore FAQ says the Bedrock SLA applies, but that SLA, last updated 4 October 2023, names only the Bedrock APIs for models (5 of 10, our call, as on the Bedrock Guardrails listing). Generally available since October 2025 (10).",
            "schema": "The API model is public as Smithy JSON in aws/api-models-aws, version 2024-02-28, and the SDKs are generated from it (25). The developer guide has an llms.txt of 988 lines and serves every page as Markdown (10). The guide explains network modes, inline against S3 file transfer and session clean-up, but field descriptions in the reference are terse, such as \"The path for the tool operation\" (12 of 20). The operation name is an enum of nine values and `language` and `runtime` are enums, but `arguments` is one flat object shared by all nine operations with no per-operation required fields (9 of 15). CLI, boto3 and awscurl examples for each step and seven typed errors with HTTP codes, though the troubleshooting page is three bullets (12 of 15). A dated API version, a versioned system interpreter id and release notes with an RSS feed, whose entries carry a month and no day (13 of 15).",
            "security": "IAM with SigV4, roles and short-lived credentials, and policies can name one interpreter ARN (30). Each of the nine operations is its own IAM action, system and custom interpreters have separate ARN types, a custom interpreter's execution role bounds what sandbox code can reach, and the default Sandbox network mode reaches only Amazon S3. No approval step for destructive calls (17 of 20). Each session is a dedicated microVM whose memory AWS says is sanitised at the end, and the docs flag Public network mode as a risk, but the Code Interpreter pages we read give no guidance on treating execution output as untrusted (11 of 15). CloudWatch metrics, spans and per-second usage logs per session, and the overview claims CloudTrail logging, but we found no page listing Code Interpreter's CloudTrail events, and console logs are not sent to CloudWatch (11 of 15). A vulnerability disclosure programme on HackerOne, public bulletins and AgentCore in SOC scope on the list of 11 August 2026. The security.txt expired on 24 September 2026 and no paid bounty was found, read as on the other AWS listings (18 of 20).",
            "transparency": "Closed service under the AWS Service Terms, with Apache-2.0 SDKs and MCP server (15). The docs say session files are cleaned up when a session ends and also give a 30-day retention period for session data without saying what is kept. Encryption at rest and TLS 1.2 are stated, the privacy notice excludes customer content, and we found no Code Interpreter statement on use of customer content (15 of 30). No deprecation policy for the interpreter or its language runtimes was found. The system interpreter id carries a version (3 of 20). AWS publishes a sub-processor list, updated 28 July 2026, and the guide lists the 22 Regions where built-in tools run (18 of 20)."
          },
          "sources": [
            {
              "what": "Code Interpreter overview",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-tool.html",
              "seen": "2026-10-08"
            },
            {
              "what": "session characteristics and isolation",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-session-characteristics.html",
              "seen": "2026-10-08"
            },
            {
              "what": "resource management and network modes",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-resource-management.html",
              "seen": "2026-10-08"
            },
            {
              "what": "file system configurations",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-filesystem-configurations.html",
              "seen": "2026-10-08"
            },
            {
              "what": "runtime selection",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-runtime-selection.html",
              "seen": "2026-10-08"
            },
            {
              "what": "observability",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-observability.html",
              "seen": "2026-10-08"
            },
            {
              "what": "built-in tools observability data",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability-tool-metrics.html",
              "seen": "2026-10-08"
            },
            {
              "what": "troubleshooting",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-troubleshooting.html",
              "seen": "2026-10-08"
            },
            {
              "what": "getting started and IAM policy",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-getting-started.html",
              "seen": "2026-10-08"
            },
            {
              "what": "quotas",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html",
              "seen": "2026-10-08"
            },
            {
              "what": "release notes",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
              "seen": "2026-10-08"
            },
            {
              "what": "supported Regions",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-regions.html",
              "seen": "2026-10-08"
            },
            {
              "what": "data protection",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-protection.html",
              "seen": "2026-10-08"
            },
            {
              "what": "data encryption",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-encryption.html",
              "seen": "2026-10-08"
            },
            {
              "what": "developer guide llms.txt",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "InvokeCodeInterpreter API reference",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_InvokeCodeInterpreter.html",
              "seen": "2026-10-08"
            },
            {
              "what": "StartCodeInterpreterSession API reference",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_StartCodeInterpreterSession.html",
              "seen": "2026-10-08"
            },
            {
              "what": "ToolArguments API reference",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_ToolArguments.html",
              "seen": "2026-10-08"
            },
            {
              "what": "ListCodeInterpreterSessions API reference",
              "url": "https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_ListCodeInterpreterSessions.html",
              "seen": "2026-10-08"
            },
            {
              "what": "IAM service reference for AgentCore",
              "url": "https://servicereference.us-east-1.amazonaws.com/v1/bedrock-agentcore/bedrock-agentcore.json",
              "seen": "2026-10-08"
            },
            {
              "what": "Smithy API model",
              "url": "https://raw.githubusercontent.com/aws/api-models-aws/main/models/bedrock-agentcore/service/2024-02-28/bedrock-agentcore-2024-02-28.json",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://aws.amazon.com/bedrock/agentcore/pricing/",
              "seen": "2026-10-08"
            },
            {
              "what": "AgentCore FAQ",
              "url": "https://aws.amazon.com/bedrock/agentcore/faqs/",
              "seen": "2026-10-08"
            },
            {
              "what": "Bedrock SLA",
              "url": "https://aws.amazon.com/bedrock/sla/",
              "seen": "2026-10-08"
            },
            {
              "what": "Free Tier FAQ",
              "url": "https://aws.amazon.com/free/free-tier-faqs/",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS Service Terms",
              "url": "https://aws.amazon.com/service-terms/",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS Privacy Notice",
              "url": "https://aws.amazon.com/privacy/",
              "seen": "2026-10-08"
            },
            {
              "what": "sub-processor list",
              "url": "https://aws.amazon.com/compliance/sub-processors/",
              "seen": "2026-10-08"
            },
            {
              "what": "SOC scope",
              "url": "https://aws.amazon.com/compliance/services-in-scope/SOC/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://aws.amazon.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "AWS Health Dashboard history file",
              "url": "https://history-events-us-west-2-prod.s3.amazonaws.com/historyevents.json",
              "seen": "2026-10-08"
            },
            {
              "what": "Python SDK repository, changelog and workflows",
              "url": "https://github.com/aws/bedrock-agentcore-sdk-python",
              "seen": "2026-10-08"
            },
            {
              "what": "bedrock-agentcore on PyPI",
              "url": "https://pypi.org/project/bedrock-agentcore/",
              "seen": "2026-10-08"
            },
            {
              "what": "bedrock-agentcore on npm",
              "url": "https://registry.npmjs.org/bedrock-agentcore/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "npm weekly downloads",
              "url": "https://api.npmjs.org/downloads/point/last-week/bedrock-agentcore",
              "seen": "2026-10-08"
            },
            {
              "what": "AgentCore MCP server README",
              "url": "https://github.com/awslabs/mcp/blob/main/src/amazon-bedrock-agentcore-mcp-server/README.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server on PyPI",
              "url": "https://pypi.org/project/awslabs.amazon-bedrock-agentcore-mcp-server/",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP for amazonaws.com",
              "url": "https://rdap.verisign.com/com/v1/domain/amazonaws.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "Whether the Bedrock SLA's wording, the Bedrock APIs for models, covers Code Interpreter. The AgentCore FAQ says the SLA applies and the SLA text does not name AgentCore.",
            "What the 30-day retention period for session data covers, since the same page says session data is cleaned up when the session ends.",
            "Which Code Interpreter calls are recorded in CloudTrail, and whether `InvokeCodeInterpreter` is a data event. The overview claims CloudTrail logging and we found no event list.",
            "The day in July 2026 on which the `ActiveSessionCount` metric shipped. The release notes carry months only.",
            "`firstReleased` is the date of the first `bedrock-agentcore` release on PyPI, 8 July 2025. The preview announcement itself was not read.",
            "unchecked: weekly PyPI downloads for `bedrock-agentcore`. pypistats.org answered 429 on the first request and we did not retry.",
            "unchecked: the AWS Data Processing Addendum and the AWS Customer Agreement were not read this run.",
            "unchecked: the MCP server's tool definitions and annotations. Only its README was read.",
            "unchecked: reply times on the SDK repositories' issues. The GitHub API gave 776 stars and 135 open issues and pull requests for the Python SDK."
          ]
        },
        "negative": 0,
        "verdict": "Each session runs in its own microVM with 2 vCPU, 8 GB and a 10 GB disk for up to eight hours, and IAM can scope access to one interpreter. Sessions cannot be paused or resumed, and an AWS account with IAM set-up is needed before a first call.",
        "bestFor": "A team already on AWS that wants agent code to run under IAM, inside a VPC and beside S3 data, for sessions up to eight hours.",
        "strengths": [
          "Each session runs in a dedicated microVM, which AWS says is terminated and has its memory sanitised when the session ends",
          "Billing is per second on CPU used and peak memory, at $0.0895 a vCPU-hour and $0.00945 a GB-hour, with I/O wait and idle time free",
          "IAM actions cover each of the nine operations, with separate ARNs for the system interpreter and custom ones",
          "Rate limits are published per API, 30 requests a second for `StartCodeInterpreterSession` and `InvokeCodeInterpreter`, and 1,000 concurrent sessions per account",
          "The managed interpreter `aws.codeinterpreter.v1` needs no resource set-up, and `code_session` in the Python SDK starts and stops a session in one block"
        ],
        "weaknesses": [
          "No pause, resume or snapshot. Session files are removed when the session ends, and persistence needs a customer-owned S3 Files or EFS mount inside a VPC",
          "Every session is capped at 2 vCPU, 8 GB of memory and 10 GB of disk, and the cap is not adjustable",
          "`InvokeCodeInterpreter` takes one flat `arguments` object for nine operations, so the reference does not say which fields each operation requires",
          "The Bedrock SLA that AWS says applies to AgentCore dates from 4 October 2023 and names only the Bedrock APIs for models",
          "The troubleshooting page is three bullet points, and execution console logs are not sent to CloudWatch"
        ],
        "agentNotes": [
          "Start a session with `StartCodeInterpreterSession`, then pass its id in the `x-amzn-code-interpreter-session-id` header on every `InvokeCodeInterpreter` call",
          "Set `sessionTimeoutSeconds` when starting. The default is 900 seconds and the maximum is eight hours, and the session ends itself at the timeout",
          "Stop sessions when done. Billing runs per second while code is busy, and a session left open counts against the 1,000 concurrent-session quota",
          "Use `startCommandExecution`, `getTask` and `stopTask` for work longer than the 15-minute synchronous request limit",
          "Retry `ThrottlingException` (429) and `InternalServerException` (500) with exponential backoff, and treat `ServiceQuotaExceededException`, returned as HTTP 402, as a quota to raise"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 73.1
          }
        ],
        "editorialScores": {
          "ergonomics": 75,
          "maintenance": 65,
          "payments": 30,
          "reliability": 85,
          "schema": 81,
          "security": 87,
          "transparency": 51
        },
        "provenanceScore": 88
      },
      "connect": {
        "install": "pip install bedrock-agentcore   # or: npm i bedrock-agentcore",
        "http": "awscurl -X POST \\\n  \"https://bedrock-agentcore.us-west-2.amazonaws.com/code-interpreters/aws.codeinterpreter.v1/tools/invoke\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"x-amzn-code-interpreter-session-id: $SESSION_ID\" \\\n  --service bedrock-agentcore --region us-west-2 \\\n  -d '{\"name\":\"executeCode\",\"arguments\":{\"language\":\"python\",\"code\":\"print(\\\"Hello, world!\\\")\"}}'",
        "config": {
          "mcpServers": {
            "bedrock-agentcore-mcp-server": {
              "args": [
                "awslabs.amazon-bedrock-agentcore-mcp-server@latest"
              ],
              "command": "uvx",
              "env": {
                "AGENTCORE_ENABLE_TOOLS": "code_interpreter",
                "FASTMCP_LOG_LEVEL": "ERROR"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/agentcore-code-interpreter"
      },
      "sameCompany": [
        "amazon-bedrock-customization",
        "amazon-textract",
        "aws-end-user-messaging",
        "amazon-sns",
        "amazon-s3"
      ],
      "notable": [
        "Nine operations through one call, `executeCode`, `executeCommand`, `readFiles`, `listFiles`, `removeFiles`, `writeFiles`, `startCommandExecution`, `getTask` and `stopTask`, sent to `POST /code-interpreters/{id}/tools/invoke` (https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_InvokeCodeInterpreter.html)",
        "Languages are `python`, `javascript` and `typescript`, with runtimes `python`, `nodejs` and `deno`. JavaScript and TypeScript default to `deno` (https://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_ToolArguments.html, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-runtime-selection.html)",
        "Sessions default to 900 seconds and can be set up to eight hours. Each runs in a dedicated microVM, and files are cleaned up when the session ends (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-session-characteristics.html)",
        "Three network modes. Sandbox reaches Amazon S3 only, Public reaches the internet, and VPC connects to private resources (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-resource-management.html)",
        "Code Interpreter has no managed session storage. Persistent files need an Amazon S3 Files or Amazon EFS access point, which requires VPC connectivity (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-filesystem-configurations.html)",
        "Quotas are 1,000 concurrent sessions per account, 2 vCPU and 8 GB per session, 10 GB of disk, a 100 MB payload and a 15-minute synchronous request, with asynchronous commands up to eight hours (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html)",
        "The AgentCore MCP server in awslabs/mcp registers 122 tools by default, 10 of them for Code Interpreter. `AGENTCORE_ENABLE_TOOLS=code_interpreter` limits it to that set (https://github.com/awslabs/mcp/blob/main/src/amazon-bedrock-agentcore-mcp-server/README.md)",
        "The AWS Service Terms, updated 1 October 2026, allow benchmarks of the Services if the disclosure includes everything needed to replicate them, section 1.8 (https://aws.amazon.com/service-terms/)",
        "AgentCore has been generally available since October 2025 and in SOC 1, 2 and 3 scope since June 2026. Built-in tools are listed in 22 Regions (https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-regions.html)",
        "The API model is published as Smithy JSON, version 2024-02-28, in aws/api-models-aws (https://github.com/aws/api-models-aws/tree/main/models/bedrock-agentcore)"
      ],
      "area": "agent-runtime",
      "details": [
        {
          "label": "Free tier",
          "value": "No Code Interpreter allowance. New AWS accounts get up to $200 in Free Tier credits, and AWS says most new customers sign up without a payment method"
        },
        {
          "label": "Isolation",
          "value": "A dedicated microVM per session with its own CPU, memory and filesystem, terminated at session end"
        },
        {
          "label": "Languages",
          "value": "Python, JavaScript and TypeScript, on `python`, `nodejs` or `deno` runtimes, with pre-installed libraries"
        },
        {
          "label": "Session length",
          "value": "Default 15 minutes, up to 8 hours"
        },
        {
          "label": "Resources",
          "value": "2 vCPU, 8 GB of memory and 10 GB of disk per session, not adjustable"
        },
        {
          "label": "Persistence",
          "value": "None managed. No pause, resume or snapshot. Bring-your-own Amazon S3 Files or EFS mounts, VPC required"
        },
        {
          "label": "Network modes",
          "value": "Sandbox (Amazon S3 only), Public (internet) or VPC"
        },
        {
          "label": "Rate limits",
          "value": "30 requests a second per account for starting sessions and invoking, 5 a second for creating or deleting interpreters, 1,000 concurrent sessions, adjustable"
        },
        {
          "label": "File transfer",
          "value": "100 MB inline per request, up to 5 GB through Amazon S3 with an execution role"
        },
        {
          "label": "Regions",
          "value": "22, including AWS GovCloud (US-West)"
        },
        {
          "label": "MCP",
          "value": "`awslabs.amazon-bedrock-agentcore-mcp-server` 0.2.1, a local stdio server with 10 Code Interpreter tools"
        }
      ],
      "unitPrices": [
        {
          "item": "CPU",
          "unit": "vcpu-hour",
          "usd": 0.0895,
          "note": "Billed per second on CPU used. Memory extra at $0.00945 a GB-hour on peak use"
        },
        {
          "item": "Session at the 2 vCPU, 8 GB cap, fully busy",
          "unit": "session-hour",
          "usd": 0.2546,
          "note": "Our sum of 2 x $0.0895 and 8 x $0.00945. I/O wait and idle time are not billed"
        }
      ],
      "provenance": {
        "legalEntity": "Amazon Web Services, Inc.",
        "domain": "amazonaws.com",
        "domainRegistered": "2005-08-18",
        "endpointOnVendorDomain": true,
        "terms": "https://aws.amazon.com/service-terms/",
        "privacy": "https://aws.amazon.com/privacy/",
        "statusPage": "https://health.aws.amazon.com/health/status",
        "changelog": "https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The endpoints are `bedrock-agentcore.\u003cregion\u003e.amazonaws.com`. RDAP gives 2005-08-18 for amazonaws.com and 1994-11-01 for amazon.com, where the product, pricing and legal pages sit.",
          "The AWS Service Terms were last updated on 1 October 2026. Section 50 covers Amazon Bedrock. No clause naming Code Interpreter was found.",
          "The AWS Privacy Notice, last updated 18 May 2026, names Amazon Web Services, Inc. and says it does not apply to content customers process in AWS services, which the customer agreement governs.",
          "aws.amazon.com/.well-known/security.txt has Contact and Policy fields, and its Expires date of 2026-09-24 had passed on 8 October 2026.",
          "AgentCore release notes carry a month for each entry, not a day."
        ],
        "score": 88,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Amazon Web Services, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "amazonaws.com, registered 2005-08-18 (21 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "bedrock-agentcore.{region}.amazonaws.com",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 3.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "health.aws.amazon.com/health/status",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "published but past its Expires date",
            "points": 5,
            "max": 10,
            "state": "part"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://aws.amazon.com/service-terms/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-10-01",
            "words": 47585,
            "points": 3.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: October 1, 2026",
                "says": "Last updated 2026-10-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": false
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "AWS’S AND ITS AFFILIATES’ AND LICENSORS’ AGGREGATE LIABILITY FOR ANY BETA SERVICES AND BETA REGIONS WILL BE LIMITED TO THE AMOUNT YOU ACTUALLY PAY US UNDER THIS AGREEMENT FOR THE BETA SERVICES OR BETA REGIONS THAT GAVE RISE TO THE CLAIM DURING THE 12 MONTHS PRECEDING THE CLAIM."
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "If you do not remove or disable access to the Prohibited Content within 2 business days of our notice, we may remove or disable access to the Prohibited Content or suspend the Services to the extent we are not able to remove or disable access to the Prohibited Content."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "If during the previous 6 months you have incurred no fees for Amazon SimpleDB and have registered no usage of Your Content stored in Amazon SimpleDB, we may delete Your Content that is stored in Simple DB upon 30 days prior notice to you.",
                "says": "Gives 30 days of notice before a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You may not transfer outside the Services any software (including related documentation) you obtain from us or third party licensors in connection with the Services without specific authorization to do so."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "If you have been charged for a Service for a period when that Service was unavailable (as defined in the applicable Service Level Agreement for each Service), you may request a Service credit equal to any charged amounts for such period."
              }
            ],
            "toKnow": [
              {
                "key": "training.optout",
                "label": "Says it may use customer content to train or improve models, and gives an opt-out",
                "found": true,
                "quote": "You may instruct AWS not to use and store Amazon WorkSpaces AI Content processed by Amazon WorkSpaces AI Features to develop and improve the Service or technologies of AWS or its affiliates by configuring an AI services opt-out policy using AWS Organizations."
              },
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Reverse engineer, decompile, attempt to reconstruct, scrape, systematically collect, or duplicate Address Validation Data.",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "You may not, and may not allow any third party to, use Amazon CloudWatch Network Monitoring, or any data or information made available through Amazon CloudWatch Network Monitoring, to, directly or indirectly, develop, improve, or offer a similar or competing product or service.",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We may change, discontinue, or deprecate support for any third-party software development services at any time without prior notice.",
                "costsPoints": true
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://aws.amazon.com/privacy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-05-18",
            "words": 8790,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last Updated: May 18, 2026",
                "says": "Last updated 2026-05-18"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Notice describes how we collect and use your personal information in relation to AWS websites, applications, products, services, events, and experiences that reference this Privacy Notice (together, “AWS Offerings”)."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We keep your personal information to enable your continued use of AWS Offerings, for as long as it is required in order to fulfill the relevant purposes described in this Privacy Notice, as may be required by law (including for tax and accounting purposes), or as otherwise communicated to you.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Information from Other Sources: We might collect information about you from other sources, including service providers, partners, and publicly available sources."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Information about our customers is an important part of our business and we are not in the business of selling our customers’ personal information to others."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "Additionally, you may have the right to opt out of the processing of your personal data for cross-context behavioral advertising (also referred to as targeted advertising under certain state privacy laws)."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "We provide additional information about our controllers and data protection officers (as applicable), the privacy, collection, and use of personal information of prospective and current customers of AWS Offerings located in certain jurisdictions.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "EU-US Data Privacy Framework, UK Extension, and Swiss-US Data Privacy Framework",
                "says": "Relies on the Data Privacy Framework"
              }
            ],
            "toKnow": [
              {
                "key": "privacy.sells",
                "label": "Says it sells personal data or shares it for advertising",
                "found": true,
                "quote": "To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled.",
                "quote": "This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/agentcore-code-interpreter.json",
      "live": {
        "slug": "agentcore-code-interpreter",
        "probe": {
          "target": "https://bedrock-agentcore.{region}.amazonaws.com/code-interpreters/{id}/tools/invoke",
          "method": "get",
          "lastAt": "2026-10-09T09:26:41.522149204Z",
          "lastOk": false,
          "lastStatus": 0,
          "lastMs": 0,
          "lastNote": "invalid character \"{\" in host name",
          "authRequired": false,
          "uptime24h": 0,
          "uptime30d": 0,
          "p50ms24h": 0,
          "p95ms24h": 0,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 0
            }
          ],
          "outages": [
            {
              "start": "2026-10-09T07:40:18.24415355Z",
              "end": "0001-01-01T00:00:00Z",
              "note": "invalid character \"{\" in host name"
            }
          ]
        },
        "vendorStatus": {
          "page": "https://health.aws.amazon.com/health/status",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:35.17007236Z"
        },
        "updatedAt": "2026-10-09T09:26:41.522149204Z"
      }
    },
    "verify": {
      "accepts": "a page on aws.amazon.com or one of its subdomains, or the README of github.com/aws/bedrock-agentcore-sdk-python",
      "badgeUrl": "https://www.anchorterminal.com/badges/agentcore-code-interpreter.svg",
      "body": {
        "slug": "agentcore-code-interpreter",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/agentcore-code-interpreter",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/agentcore-code-interpreter\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/agentcore-code-interpreter.svg\" alt=\"Amazon Bedrock AgentCore Code Interpreter on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Amazon Bedrock AgentCore Code Interpreter on Anchor Terminal](https://www.anchorterminal.com/badges/agentcore-code-interpreter.svg)](https://www.anchorterminal.com/tools/agentcore-code-interpreter)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/agentcore-code-interpreter\"\u003eAmazon Bedrock AgentCore Code Interpreter on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/agentcore-code-interpreter",
    "json": "https://www.anchorterminal.com/tools/agentcore-code-interpreter.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/agentcore-code-interpreter.md",
    "slim": "https://www.anchorterminal.com/tools/agentcore-code-interpreter.min.md"
  },
  "markdown": "## Overview\n\n**Grade BB · 73.1/100 · rank #89 of 842 · #3 in Code execution sandboxes · agent-ready · confidence medium**\n\n\nMore from Amazon Web Services, listed separately because each is its own product: [Amazon Bedrock model customisation](https://www.anchorterminal.com/tools/amazon-bedrock-customization.md) (Fine-tuning), [Amazon Textract](https://www.anchorterminal.com/tools/amazon-textract.md) (Document parsing \u0026 extraction), [AWS End User Messaging](https://www.anchorterminal.com/tools/aws-end-user-messaging.md) (Messaging APIs), [Amazon SNS](https://www.anchorterminal.com/tools/amazon-sns.md) (Notifications), [Amazon S3](https://www.anchorterminal.com/tools/amazon-s3.md) (File storage \u0026 sharing).\n\n## Assessment\n\nEach session runs in its own microVM with 2 vCPU, 8 GB and a 10 GB disk for up to eight hours, and IAM can scope access to one interpreter. Sessions cannot be paused or resumed, and an AWS account with IAM set-up is needed before a first call.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Amazon Web Services (https://aws.amazon.com/bedrock/agentcore/) |\n| Kind | HTTP API |\n| Category | Code execution sandboxes (https://www.anchorterminal.com/categories/code-sandboxes) |\n| Transport | HTTP |\n| Endpoint | `https://bedrock-agentcore.{region}.amazonaws.com/code-interpreters/{id}/tools/invoke` |\n| Auth | API key · AWS Signature Version 4 with IAM access keys or a role, self-serve once an AWS account exists. A policy must allow `bedrock-agentcore:StartCodeInterpreterSession`, `bedrock-agentcore:InvokeCodeInterpreter` and `bedrock-agentcore:StopCodeInterpreterSession` on the interpreter's ARN. The managed interpreter `aws.codeinterpreter.v1` needs no resource of its own. A custom interpreter takes a network mode and an execution role, which bounds the AWS resources code in the sandbox can reach. No partner or sales approval. |\n| Pricing | Pay per use ($0.0895 / vCPU-hr) · $0.0895 a vCPU-hour and $0.00945 a GB-hour, billed per second on CPU used and peak memory, with a one-second minimum and 128 MB minimum memory. AWS says I/O wait and idle time are free when no background process is running. Network data transfer is extra at EC2 rates. No allowance specific to Code Interpreter. New AWS accounts get up to $200 in Free Tier credits, and AWS says most new customers sign up without a payment method, so an agent's owner can start without a contract (https://aws.amazon.com/bedrock/agentcore/pricing/, https://aws.amazon.com/free/free-tier-faqs/, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 on the Code Interpreter endpoints, in the API reference or on the pricing page. AgentCore Payments, a separate component, lets a customer's agents pay third parties over x402 and MPP and is not a way to pay AWS (checked 2026-10-08). |\n| Licence | Proprietary service under the AWS Service Terms. The AgentCore SDKs for Python and TypeScript and the AgentCore MCP server are Apache-2.0 |\n| Packages | pypi: `bedrock-agentcore`; npm: `bedrock-agentcore`; pypi: `boto3`; pypi: `awslabs.amazon-bedrock-agentcore-mcp-server` |\n| Source | https://github.com/aws/bedrock-agentcore-sdk-python |\n| Docs | https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-tool.html |\n| llms.txt | https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt |\n| Last release | 2026-10-07 |\n| GitHub stars | 776 (as of 2026-10-08) |\n| npm downloads / week | 334,717 |\n| Free tier | No Code Interpreter allowance. New AWS accounts get up to $200 in Free Tier credits, and AWS says most new customers sign up without a payment method |\n| Isolation | A dedicated microVM per session with its own CPU, memory and filesystem, terminated at session end |\n| Languages | Python, JavaScript and TypeScript, on `python`, `nodejs` or `deno` runtimes, with pre-installed libraries |\n| Session length | Default 15 minutes, up to 8 hours |\n| Resources | 2 vCPU, 8 GB of memory and 10 GB of disk per session, not adjustable |\n| Persistence | None managed. No pause, resume or snapshot. Bring-your-own Amazon S3 Files or EFS mounts, VPC required |\n| Network modes | Sandbox (Amazon S3 only), Public (internet) or VPC |\n| Rate limits | 30 requests a second per account for starting sessions and invoking, 5 a second for creating or deleting interpreters, 1,000 concurrent sessions, adjustable |\n| File transfer | 100 MB inline per request, up to 5 GB through Amazon S3 with an execution role |\n| Regions | 22, including AWS GovCloud (US-West) |\n| MCP | `awslabs.amazon-bedrock-agentcore-mcp-server` 0.2.1, a local stdio server with 10 Code Interpreter tools |\n| Capabilities | sandbox.code, sandbox.fs |\n| Tags | hosted, usage-priced, closed-source, python, typescript, enterprise, llms-txt, mcp, free-tier, no-card, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/agentcore-code-interpreter.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 85 | 17.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 81 | 13.2 |\n| Agent ergonomics | 13% | 16.2 | 75 | 12.2 |\n| Security \u0026 auth | 14% | 17.5 | 87 | 15.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 65 | 5.7 |\n| Transparency \u0026 trust (editorial 51, provenance 88) | 7% | 8.8 | 70 | 6.1 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **73.1 → BB** |\n\n### Why each score\n\n- Reliability 85: Graded on the hosted lines, for the AWS API. AWS Health Dashboard with per-service, per-Region history (20). The dashboard history file, read on 8 October, names AgentCore in one event in the 90 days, elevated packet loss in one availability zone of Europe (Spain) for 2 hours 40 minutes on 4 October 2026, marked informational. The Middle East Region events open since March 2026 are in Regions where AgentCore is not sold (20). Rate limits published per API, 30 requests a second for starting sessions and invoking and 5 for creating or deleting interpreters, with 1,000 concurrent sessions (15). `ThrottlingException` is a 429 with advice to back off exponentially, `InternalServerException` is documented as retryable, and `StartCodeInterpreterSession` takes a `clientToken` so a retry does not open a second session (15). The AgentCore FAQ says the Bedrock SLA applies, but that SLA, last updated 4 October 2023, names only the Bedrock APIs for models (5 of 10, our call, as on the Bedrock Guardrails listing). Generally available since October 2025 (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 81: The API model is public as Smithy JSON in aws/api-models-aws, version 2024-02-28, and the SDKs are generated from it (25). The developer guide has an llms.txt of 988 lines and serves every page as Markdown (10). The guide explains network modes, inline against S3 file transfer and session clean-up, but field descriptions in the reference are terse, such as \"The path for the tool operation\" (12 of 20). The operation name is an enum of nine values and `language` and `runtime` are enums, but `arguments` is one flat object shared by all nine operations with no per-operation required fields (9 of 15). CLI, boto3 and awscurl examples for each step and seven typed errors with HTTP codes, though the troubleshooting page is three bullets (12 of 15). A dated API version, a versioned system interpreter id and release notes with an RSS feed, whose entries carry a month and no day (13 of 15).\n- Agent ergonomics 75: Results stream back as content blocks with stdout and stderr, and we found no control for truncating or sizing output. The MCP server registers 122 tools by default and `AGENTCORE_ENABLE_TOOLS` cuts that to the 10 for Code Interpreter (15 of 25). `ListCodeInterpreterSessions` pages with `maxResults` of 1 to 100 and `nextToken` and filters by status (15 of 20). Typed errors with HTTP codes, but a quota breach comes back as HTTP 402 and errors can also arrive inside the result stream (15 of 20). `clientToken` on session start and on interpreter create and delete. Running code has no idempotency key (15 of 20). The managed interpreter needs no set-up, `code_session` handles start and stop, and there are AgentCore SDKs for Python and TypeScript beside the AWS SDKs (15).\n- Security \u0026 auth 87: IAM with SigV4, roles and short-lived credentials, and policies can name one interpreter ARN (30). Each of the nine operations is its own IAM action, system and custom interpreters have separate ARN types, a custom interpreter's execution role bounds what sandbox code can reach, and the default Sandbox network mode reaches only Amazon S3. No approval step for destructive calls (17 of 20). Each session is a dedicated microVM whose memory AWS says is sanitised at the end, and the docs flag Public network mode as a risk, but the Code Interpreter pages we read give no guidance on treating execution output as untrusted (11 of 15). CloudWatch metrics, spans and per-second usage logs per session, and the overview claims CloudTrail logging, but we found no page listing Code Interpreter's CloudTrail events, and console logs are not sent to CloudWatch (11 of 15). A vulnerability disclosure programme on HackerOne, public bulletins and AgentCore in SOC scope on the list of 11 August 2026. The security.txt expired on 24 September 2026 and no paid bounty was found, read as on the other AWS listings (18 of 20).\n- Payments \u0026 pricing 30: No x402, MPP or L402 on the Code Interpreter endpoints. AgentCore Payments is a separate component for an agent paying third parties (0). Per-unit prices published without a login, $0.0895 a vCPU-hour and $0.00945 a GB-hour (20). No allowance for Code Interpreter, but the pricing page says new AWS customers get up to $200 in Free Tier credits and the Free Tier FAQ says most new customers need no payment method, so half, as on the other AWS listings (10). A person signs up in a browser and sets up IAM (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 65: The Python SDK that carries `code_session` shipped 1.24.1 on 7 October 2026, but the newest changes to Code Interpreter itself are from July 2026, the `ActiveSessionCount` metric and a fix to `install_packages` on 17 July, so 20 of 30 as a judgement call (20). The SDK had ten releases since 10 July and the release notes have entries every month, yet only two touch Code Interpreter (10 of 20). Public release notes with RSS, issues open on the SDK repository with an auto-triage workflow, and re:Post and AWS Support. Reply times were not checked (10 of 15). Current official SDKs, `bedrock-agentcore` 1.24.1 on PyPI and 0.4.5 on npm (15). The SDK repository runs CI, integration tests, security scanning and a breaking-change check, with a lock file (10).\n- Transparency \u0026 trust 70: Closed service under the AWS Service Terms, with Apache-2.0 SDKs and MCP server (15). The docs say session files are cleaned up when a session ends and also give a 30-day retention period for session data without saying what is kept. Encryption at rest and TLS 1.2 are stated, the privacy notice excludes customer content, and we found no Code Interpreter statement on use of customer content (15 of 30). No deprecation policy for the interpreter or its language runtimes was found. The system interpreter id carries a version (3 of 20). AWS publishes a sub-processor list, updated 28 July 2026, and the guide lists the 22 Regions where built-in tools run (18 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/agentcore-code-interpreter.md (JSON https://www.anchorterminal.com/fixes/agentcore-code-interpreter.json)\n\n### What we couldn't check\n\n- Whether the Bedrock SLA's wording, the Bedrock APIs for models, covers Code Interpreter. The AgentCore FAQ says the SLA applies and the SLA text does not name AgentCore.\n- What the 30-day retention period for session data covers, since the same page says session data is cleaned up when the session ends.\n- Which Code Interpreter calls are recorded in CloudTrail, and whether `InvokeCodeInterpreter` is a data event. The overview claims CloudTrail logging and we found no event list.\n- The day in July 2026 on which the `ActiveSessionCount` metric shipped. The release notes carry months only.\n- `firstReleased` is the date of the first `bedrock-agentcore` release on PyPI, 8 July 2025. The preview announcement itself was not read.\n- unchecked: weekly PyPI downloads for `bedrock-agentcore`. pypistats.org answered 429 on the first request and we did not retry.\n- unchecked: the AWS Data Processing Addendum and the AWS Customer Agreement were not read this run.\n- unchecked: the MCP server's tool definitions and annotations. Only its README was read.\n- unchecked: reply times on the SDK repositories' issues. The GitHub API gave 776 stars and 135 open issues and pull requests for the Python SDK.\n\n### Sources\n\n- Code Interpreter overview: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-tool.html\u003e (seen 2026-10-08)\n- session characteristics and isolation: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-session-characteristics.html\u003e (seen 2026-10-08)\n- resource management and network modes: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-resource-management.html\u003e (seen 2026-10-08)\n- file system configurations: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-filesystem-configurations.html\u003e (seen 2026-10-08)\n- runtime selection: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-runtime-selection.html\u003e (seen 2026-10-08)\n- observability: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-observability.html\u003e (seen 2026-10-08)\n- built-in tools observability data: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/observability-tool-metrics.html\u003e (seen 2026-10-08)\n- troubleshooting: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-troubleshooting.html\u003e (seen 2026-10-08)\n- getting started and IAM policy: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-getting-started.html\u003e (seen 2026-10-08)\n- quotas: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html\u003e (seen 2026-10-08)\n- release notes: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html\u003e (seen 2026-10-08)\n- supported Regions: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-regions.html\u003e (seen 2026-10-08)\n- data protection: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-protection.html\u003e (seen 2026-10-08)\n- data encryption: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/data-encryption.html\u003e (seen 2026-10-08)\n- developer guide llms.txt: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/llms.txt\u003e (seen 2026-10-08)\n- InvokeCodeInterpreter API reference: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_InvokeCodeInterpreter.html\u003e (seen 2026-10-08)\n- StartCodeInterpreterSession API reference: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_StartCodeInterpreterSession.html\u003e (seen 2026-10-08)\n- ToolArguments API reference: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_ToolArguments.html\u003e (seen 2026-10-08)\n- ListCodeInterpreterSessions API reference: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_ListCodeInterpreterSessions.html\u003e (seen 2026-10-08)\n- IAM service reference for AgentCore: \u003chttps://servicereference.us-east-1.amazonaws.com/v1/bedrock-agentcore/bedrock-agentcore.json\u003e (seen 2026-10-08)\n- Smithy API model: \u003chttps://raw.githubusercontent.com/aws/api-models-aws/main/models/bedrock-agentcore/service/2024-02-28/bedrock-agentcore-2024-02-28.json\u003e (seen 2026-10-08)\n- pricing: \u003chttps://aws.amazon.com/bedrock/agentcore/pricing/\u003e (seen 2026-10-08)\n- AgentCore FAQ: \u003chttps://aws.amazon.com/bedrock/agentcore/faqs/\u003e (seen 2026-10-08)\n- Bedrock SLA: \u003chttps://aws.amazon.com/bedrock/sla/\u003e (seen 2026-10-08)\n- Free Tier FAQ: \u003chttps://aws.amazon.com/free/free-tier-faqs/\u003e (seen 2026-10-08)\n- AWS Service Terms: \u003chttps://aws.amazon.com/service-terms/\u003e (seen 2026-10-08)\n- AWS Privacy Notice: \u003chttps://aws.amazon.com/privacy/\u003e (seen 2026-10-08)\n- sub-processor list: \u003chttps://aws.amazon.com/compliance/sub-processors/\u003e (seen 2026-10-08)\n- SOC scope: \u003chttps://aws.amazon.com/compliance/services-in-scope/SOC/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://aws.amazon.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- AWS Health Dashboard history file: \u003chttps://history-events-us-west-2-prod.s3.amazonaws.com/historyevents.json\u003e (seen 2026-10-08)\n- Python SDK repository, changelog and workflows: \u003chttps://github.com/aws/bedrock-agentcore-sdk-python\u003e (seen 2026-10-08)\n- bedrock-agentcore on PyPI: \u003chttps://pypi.org/project/bedrock-agentcore/\u003e (seen 2026-10-08)\n- bedrock-agentcore on npm: \u003chttps://registry.npmjs.org/bedrock-agentcore/latest\u003e (seen 2026-10-08)\n- npm weekly downloads: \u003chttps://api.npmjs.org/downloads/point/last-week/bedrock-agentcore\u003e (seen 2026-10-08)\n- AgentCore MCP server README: \u003chttps://github.com/awslabs/mcp/blob/main/src/amazon-bedrock-agentcore-mcp-server/README.md\u003e (seen 2026-10-08)\n- MCP server on PyPI: \u003chttps://pypi.org/project/awslabs.amazon-bedrock-agentcore-mcp-server/\u003e (seen 2026-10-08)\n- RDAP for amazonaws.com: \u003chttps://rdap.verisign.com/com/v1/domain/amazonaws.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 88/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Amazon Web Services, Inc. | 20/20 |\n| Domain age | amazonaws.com, registered 2005-08-18 (21 years) | 15/15 |\n| Endpoint on the vendor's domain | bedrock-agentcore.{region}.amazonaws.com | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points | 3.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | health.aws.amazon.com/health/status | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | published but past its Expires date | 5/10 |\n\nThe endpoints are `bedrock-agentcore.\u003cregion\u003e.amazonaws.com`. RDAP gives 2005-08-18 for amazonaws.com and 1994-11-01 for amazon.com, where the product, pricing and legal pages sit.\n\nThe AWS Service Terms were last updated on 1 October 2026. Section 50 covers Amazon Bedrock. No clause naming Code Interpreter was found.\n\nThe AWS Privacy Notice, last updated 18 May 2026, names Amazon Web Services, Inc. and says it does not apply to content customers process in AWS services, which the customer agreement governs.\n\naws.amazon.com/.well-known/security.txt has Contact and Policy fields, and its Expires date of 2026-09-24 had passed on 8 October 2026.\n\nAgentCore release notes carry a month for each entry, not a day.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://aws.amazon.com/service-terms/), read 2026-10-08, dated 2026-10-01, states 6 of the 7 things a reader expects.\n\n- To know. Says it may use customer content to train or improve models, and gives an opt-out. \"You may instruct AWS not to use and store Amazon WorkSpaces AI Content processed by Amazon WorkSpaces AI Features to develop and improve the Service or technologies of AWS or its affiliates by configuring an AI services opt-out policy using AWS Organizations.\"\n- To know. Restricts automated access (costs points). \"Reverse engineer, decompile, attempt to reconstruct, scrape, systematically collect, or duplicate Address Validation Data.\"\n- To know. Restricts benchmarking or competitive use (costs points). \"You may not, and may not allow any third party to, use Amazon CloudWatch Network Monitoring, or any data or information made available through Amazon CloudWatch Network Monitoring, to, directly or indirectly, develop, improve, or offer a similar or competing product or service.\"\n- To know. Says the terms or the service can change without notice (costs points). \"We may change, discontinue, or deprecate support for any third-party software development services at any time without prior notice.\"\n- Gives the date it was last updated. Last updated 2026-10-01.\n- Not found in the text. Names the governing law or courts.\n- Says how changes to the terms are announced. Gives 30 days of notice before a change.\n\n**Privacy policy** (https://aws.amazon.com/privacy/), read 2026-10-08, dated 2026-05-18, states 8 of the 8 things a reader expects.\n\n- To know. Says it sells personal data or shares it for advertising. \"To help you receive more useful and relevant ads on other sites and services and to measure their effectiveness, AWS shares limited personal information with our advertising partners.\"\n- Gives the date it was last updated. Last updated 2026-05-18.\n- Says how long data is kept. For as long as needed, with no period named.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on the Data Privacy Framework.\n- Also in the text (2026-10-08). The notice does not cover content that customers process, store or host on AWS. It refers to the customer agreement for how that content is handled. \"This Privacy Notice does not apply to the “content” processed, stored, or hosted by our customers using AWS Offerings in connection with an AWS account.\"\n\n## Live (updated 2026-10-09 09:26 UTC)\n\n- Right now: down, n/a, checked 2026-10-09 09:26 UTC (get on `https://bedrock-agentcore.{region}.amazonaws.com/code-interpreters/{id}/tools/invoke`)\n- Uptime 24h 0.0% (20 probes) · 30 days 0.0% (20 probes) · p50 n/a · p95 n/a\n- Vendor status page: unknown, no machine-readable status found\n- Always current: https://www.anchorterminal.com/api/v1/live/agentcore-code-interpreter.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| CPU | $0.0895 | per vCPU-hour | Billed per second on CPU used. Memory extra at $0.00945 a GB-hour on peak use |\n| Session at the 2 vCPU, 8 GB cap, fully busy | $0.2546 | per session-hour | Our sum of 2 x $0.0895 and 8 x $0.00945. I/O wait and idle time are not billed |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Each session runs in a dedicated microVM, which AWS says is terminated and has its memory sanitised when the session ends\n- Billing is per second on CPU used and peak memory, at $0.0895 a vCPU-hour and $0.00945 a GB-hour, with I/O wait and idle time free\n- IAM actions cover each of the nine operations, with separate ARNs for the system interpreter and custom ones\n- Rate limits are published per API, 30 requests a second for `StartCodeInterpreterSession` and `InvokeCodeInterpreter`, and 1,000 concurrent sessions per account\n- The managed interpreter `aws.codeinterpreter.v1` needs no resource set-up, and `code_session` in the Python SDK starts and stops a session in one block\n\n## Weaknesses\n\n- No pause, resume or snapshot. Session files are removed when the session ends, and persistence needs a customer-owned S3 Files or EFS mount inside a VPC\n- Every session is capped at 2 vCPU, 8 GB of memory and 10 GB of disk, and the cap is not adjustable\n- `InvokeCodeInterpreter` takes one flat `arguments` object for nine operations, so the reference does not say which fields each operation requires\n- The Bedrock SLA that AWS says applies to AgentCore dates from 4 October 2023 and names only the Bedrock APIs for models\n- The troubleshooting page is three bullet points, and execution console logs are not sent to CloudWatch\n\n## Before you call it (notes for agents)\n\n1. Start a session with `StartCodeInterpreterSession`, then pass its id in the `x-amzn-code-interpreter-session-id` header on every `InvokeCodeInterpreter` call\n2. Set `sessionTimeoutSeconds` when starting. The default is 900 seconds and the maximum is eight hours, and the session ends itself at the timeout\n3. Stop sessions when done. Billing runs per second while code is busy, and a session left open counts against the 1,000 concurrent-session quota\n4. Use `startCommandExecution`, `getTask` and `stopTask` for work longer than the 15-minute synchronous request limit\n5. Retry `ThrottlingException` (429) and `InternalServerException` (500) with exponential backoff, and treat `ServiceQuotaExceededException`, returned as HTTP 402, as a quota to raise\n\n## Connect\n\nInstall:\n\n```bash\npip install bedrock-agentcore   # or: npm i bedrock-agentcore\n```\n\nFirst request:\n\n```bash\nawscurl -X POST \\\n  \"https://bedrock-agentcore.us-west-2.amazonaws.com/code-interpreters/aws.codeinterpreter.v1/tools/invoke\" \\\n  -H \"Content-Type: application/json\" \\\n  -H \"x-amzn-code-interpreter-session-id: $SESSION_ID\" \\\n  --service bedrock-agentcore --region us-west-2 \\\n  -d '{\"name\":\"executeCode\",\"arguments\":{\"language\":\"python\",\"code\":\"print(\\\"Hello, world!\\\")\"}}'\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"bedrock-agentcore-mcp-server\": {\n      \"args\": [\n        \"awslabs.amazon-bedrock-agentcore-mcp-server@latest\"\n      ],\n      \"command\": \"uvx\",\n      \"env\": {\n        \"AGENTCORE_ENABLE_TOOLS\": \"code_interpreter\",\n        \"FASTMCP_LOG_LEVEL\": \"ERROR\"\n      }\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/agentcore-code-interpreter. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Microsoft Execution Containers | BB | 76.3 | 35 | sandbox.code, sandbox.fs | no | https://www.anchorterminal.com/tools/microsoft-execution-containers.md |\n| Modal Sandboxes | BB | 75.5 | 45 | sandbox.code, sandbox.fs | no | https://www.anchorterminal.com/tools/modal-sandboxes.md |\n| Vercel Sandbox | B | 69.6 | 168 | sandbox.code, sandbox.fs | no | https://www.anchorterminal.com/tools/vercel-sandbox.md |\n| E2B | B | 68.3 | 207 | sandbox.code, sandbox.fs | no | https://www.anchorterminal.com/tools/e2b.md |\n| Cloudflare Sandbox SDK | B | 67.5 | 231 | sandbox.code, sandbox.fs | no | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md |\n| Runloop Devboxes | B | 64.8 | 305 | sandbox.code, sandbox.fs | no | https://www.anchorterminal.com/tools/runloop.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Nine operations through one call, `executeCode`, `executeCommand`, `readFiles`, `listFiles`, `removeFiles`, `writeFiles`, `startCommandExecution`, `getTask` and `stopTask`, sent to `POST /code-interpreters/{id}/tools/invoke` (source: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_InvokeCodeInterpreter.html\u003e)\n- Languages are `python`, `javascript` and `typescript`, with runtimes `python`, `nodejs` and `deno`. JavaScript and TypeScript default to `deno` (source: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/APIReference/API_ToolArguments.html, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-runtime-selection.html\u003e)\n- Sessions default to 900 seconds and can be set up to eight hours. Each runs in a dedicated microVM, and files are cleaned up when the session ends (source: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-session-characteristics.html\u003e)\n- Three network modes. Sandbox reaches Amazon S3 only, Public reaches the internet, and VPC connects to private resources (source: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-resource-management.html\u003e)\n- Code Interpreter has no managed session storage. Persistent files need an Amazon S3 Files or Amazon EFS access point, which requires VPC connectivity (source: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/code-interpreter-filesystem-configurations.html\u003e)\n- Quotas are 1,000 concurrent sessions per account, 2 vCPU and 8 GB per session, 10 GB of disk, a 100 MB payload and a 15-minute synchronous request, with asynchronous commands up to eight hours (source: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/bedrock-agentcore-limits.html\u003e)\n- The AgentCore MCP server in awslabs/mcp registers 122 tools by default, 10 of them for Code Interpreter. `AGENTCORE_ENABLE_TOOLS=code_interpreter` limits it to that set (source: \u003chttps://github.com/awslabs/mcp/blob/main/src/amazon-bedrock-agentcore-mcp-server/README.md\u003e)\n- The AWS Service Terms, updated 1 October 2026, allow benchmarks of the Services if the disclosure includes everything needed to replicate them, section 1.8 (source: \u003chttps://aws.amazon.com/service-terms/\u003e)\n- AgentCore has been generally available since October 2025 and in SOC 1, 2 and 3 scope since June 2026. Built-in tools are listed in 22 Regions (source: \u003chttps://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/release-notes.html, https://docs.aws.amazon.com/bedrock-agentcore/latest/devguide/agentcore-regions.html\u003e)\n- The API model is published as Smithy JSON, version 2024-02-28, in aws/api-models-aws (source: \u003chttps://github.com/aws/api-models-aws/tree/main/models/bedrock-agentcore\u003e)\n\n## Compare\n\n- [Agent 37 Cloud vs Amazon Bedrock AgentCore Code Interpreter](https://www.anchorterminal.com/compare/agent37-vs-agentcore-code-interpreter.md): D 46.1 vs BB 73.1\n- [Amazon Bedrock AgentCore Code Interpreter vs Blaxel Sandboxes](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-blaxel-sandboxes.md): BB 73.1 vs C 60.7\n- [Amazon Bedrock AgentCore Code Interpreter vs Cloudflare Sandbox SDK](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-cloudflare-sandbox-sdk.md): BB 73.1 vs B 67.5\n- [Amazon Bedrock AgentCore Code Interpreter vs Daytona](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-daytona.md): BB 73.1 vs B 64.3\n- [Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.md): BB 73.1 vs D 50.3\n- [Amazon Bedrock AgentCore Code Interpreter vs E2B](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-e2b.md): BB 73.1 vs B 68.3\n- [Amazon Bedrock AgentCore Code Interpreter vs Freestyle](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle.md): BB 73.1 vs C 58.5\n- [Amazon Bedrock AgentCore Code Interpreter vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-microsoft-execution-containers.md): BB 73.1 vs BB 76.3\n- [Amazon Bedrock AgentCore Code Interpreter vs Modal Sandboxes](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-modal-sandboxes.md): BB 73.1 vs BB 75.5\n- [Amazon Bedrock AgentCore Code Interpreter vs Morph Cloud](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-morph-cloud.md): BB 73.1 vs D 50.8\n- [Amazon Bedrock AgentCore Code Interpreter vs Runloop Devboxes](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-runloop.md): BB 73.1 vs B 64.8\n- [Amazon Bedrock AgentCore Code Interpreter vs Sprites](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-sprites.md): BB 73.1 vs C 58.3\n- [Amazon Bedrock AgentCore Code Interpreter vs Together Code Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox.md): BB 73.1 vs D 53.6\n- [Amazon Bedrock AgentCore Code Interpreter vs Vercel Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-vercel-sandbox.md): BB 73.1 vs B 69.6\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on aws.amazon.com or one of its subdomains, or the README of github.com/aws/bedrock-agentcore-sdk-python. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"agentcore-code-interpreter\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/agentcore-code-interpreter\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/agentcore-code-interpreter.svg\" alt=\"Amazon Bedrock AgentCore Code Interpreter on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Amazon Bedrock AgentCore Code Interpreter on Anchor Terminal](https://www.anchorterminal.com/badges/agentcore-code-interpreter.svg)](https://www.anchorterminal.com/tools/agentcore-code-interpreter)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/agentcore-code-interpreter\"\u003eAmazon Bedrock AgentCore Code Interpreter on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Amazon Bedrock AgentCore Code Interpreter is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/agentcore-code-interpreter-dark.png\n- Light: https://www.anchorterminal.com/assets/share/agentcore-code-interpreter-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Code execution sandboxes",
        "url": "https://www.anchorterminal.com/categories/code-sandboxes"
      },
      {
        "name": "Amazon Bedrock AgentCore Code Interpreter",
        "url": ""
      }
    ],
    "description": "Amazon Bedrock AgentCore Code Interpreter is AWS's managed sandbox for running agent-written Python, JavaScript and TypeScript. Each session is a dedicated microVM, reached through the AWS API, the AgentCore SDKs or an MCP server.",
    "facts": [
      "rank #89 of 842",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Amazon Bedrock AgentCore Code Interpreter",
    "image": "https://www.anchorterminal.com/assets/og/tools-agentcore-code-interpreter.png",
    "path": "/tools/agentcore-code-interpreter",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Amazon Bedrock AgentCore Code Interpreter review, grade BB (73.1/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/agentcore-code-interpreter"
  },
  "tokens": {
    "markdown": 9050,
    "slim": 1630
  },
  "version": 1
}
