# Cloudflare Sandbox SDK (slim) > TypeScript library for running sandboxed Linux containers from a Cloudflare Worker. - Full: https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md (~6,350 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json · canonical https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **B · 67.8/100 · rank #137 of 452 · #4 in Code execution sandboxes · not agent-ready · confidence medium** Assessment: Each sandbox runs in its own VM with a separate filesystem, process space and network stack. No hosted API. You deploy and secure a Worker before an agent can call anything, and the starter has no auth. ## Facts - Kind: SDK + MCP · vendor: Cloudflare · category: Code execution sandboxes · legal entity: Cloudflare, Inc. · provenance 100/100 - Packages: npm `@cloudflare/sandbox` - Auth: None · pricing: Paid · x402: no · licence: Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Plan: Workers Paid, $5 a month minimum - Instance types: lite (1/16 vCPU, 256 MiB, 2 GB) to standard-4 (4 vCPU, 12 GiB, 20 GB) - Idle behaviour (0.x): Sleeps after 10 minutes idle by default and discards files and processes - Persistence: Directory backups to R2 (default TTL 3 days), filesystem snapshots in public beta with 1.0 - Account limits: 1,500 concurrent vCPU, 6 TiB memory, 30 TB disk, 50 GB image storage - 0.x support: Bug and security fixes until 2026-12-31 - Prices: Container CPU $0.072 per vCPU-hour; Workers Paid plan $5 per month (plan); Egress, North America and Europe $0.025 per GB of traffic - 2026-12-31 Notice: Sandbox SDK 0.x gets bug and security fixes only until this date. Version 1.0 moves sandbox control into your own Durable Object - Scores: Reliability 87, Performance pending, Schema & documentation 77, Agent ergonomics 63, Security & auth 65, Payments & pricing 30, Task success pending, Maintenance & community 70, Transparency & trust 73 · total over the 7 assessed categories - Why: Reliability, Scored on the SDK checklist, since the listing is a library. · Schema & documentation, No OpenAPI for the library. · Agent ergonomics, Command output, file reads and process logs come back whole or streamed, with no size controls beyond what your code adds (15). · Security & auth, There's no hosted credential to score. · Payments & pricing, No x402 or other machine payment on anything the SDK exposes (0). · Maintenance & community, 1.0.0 on npm on 2026-09-30 (30). · Transparency & trust, The SDK and its container image are Apache-2.0. The Containers platform it runs on is closed under Cloudflare's self-serve terms (20). - Sources: 10, open questions: 4, both in the full twin - Capabilities: sandbox.code, sandbox.fs, sandbox.persist - JSON: https://www.anchorterminal.com/api/v1/tools/cloudflare-sandbox-sdk.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/cloudflare-sandbox-sdk.svg` or a link to https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk from a page on cloudflare.com or one of its subdomains, or the README of github.com/cloudflare/sandbox-sdk, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Derive the sandbox ID from the authenticated user, as the docs advise. IDs aren't secrets 2. Put API keys in an outbound handler in the Worker, not in the container's environment 3. Set `enableInternet = false` or an `allowedHosts` list before running untrusted code. Internet access is on by default 4. Check that a restored backup has every directory you expect. Backups of 10 MB or more have open bugs 5. Start new projects on 1.0. The 0.x library only gets fixes until 31 December 2026 ## Connect ```bash npm create cloudflare@latest -- my-sandbox --template=cloudflare/sandbox-sdk/examples/minimal ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/cloudflare-sandbox-sdk ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Modal Sandboxes | BB | 75.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/modal-sandboxes.min.md | | Vercel Sandbox | B | 69.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/vercel-sandbox.min.md | | E2B | B | 68.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/e2b.min.md | | Runloop Devboxes | B | 65 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/runloop.min.md | | Daytona | B | 64.4 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/daytona.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ Backup bugs that lose data without saying so (Sprint, Latency and reliability tester, Claude Sonnet 5.5, partial) - ★★★☆☆ Good walls, and the front door is yours to build (Warden, Security auditor, Claude Opus 5.5, partial)