# Daytona (slim) > Sandboxes for agent code in container, Linux VM, Windows and GPU classes, driven by SDKs for Python, TypeScript, Ruby, Go and Java or a REST API. - Full: https://www.anchorterminal.com/tools/daytona.md (~6,100 tokens) · this version ~1,430 tokens · JSON https://www.anchorterminal.com/tools/daytona.json · canonical https://www.anchorterminal.com/tools/daytona - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-05 **B · 64.4/100 · rank #183 of 452 · #6 in Code execution sandboxes · not agent-ready · confidence medium** Assessment: API keys with per-action scopes, so an agent can create sandboxes without being able to delete them. The container class shares the host kernel. Only the VM classes get their own. ## Facts - Kind: HTTP API · vendor: Daytona · category: Code execution sandboxes · legal entity: Daytona Platforms Inc. · provenance 75/100 - Endpoint: `https://app.daytona.io/api` (HTTP, stdio) - Auth: API key · pricing: Pay per use · x402: no · licence: Apache-2.0 (SDKs and API clients), AGPL-3.0 (CLI) - Probe metrics: not measured yet (probes haven't run) - Free credit: $200 of compute, no card - Default sandbox: 1 vCPU, 1 GiB RAM, 3 GiB disk. Up to 4 vCPU, 8 GiB and 10 GiB per sandbox by default - Lifecycle: Auto-stop after 15 minutes idle, auto-archive after 7 days, VM classes auto-pause after 60 minutes - Tiers: Tier 1 email verified (10 vCPU), Tier 2 card and $25 (100 vCPU), Tier 3 $500 (250 vCPU), Tier 4 $2,000 every 30 days (500 vCPU) - Rate limits: Sandbox creation 300 a minute on Tier 1 up to 600 on Tier 4 - Regions: Shared us and eu, dedicated regions on request, custom regions on your own compute. GPUs run in a global region - MCP server: Local over stdio with `daytona mcp start`, covering sandboxes, files, git, processes, computer use and previews - Prices: vCPU $0.0504 per vCPU-hour; Nvidia H100, on demand $3.95 per GPU-hour; Nvidia H100, preemptible $2.27 per GPU-hour; Nvidia RTX 4090, preemptible $0.57 per GPU-hour - Scores: Reliability 60, Performance pending, Schema & documentation 87, Agent ergonomics 55, Security & auth 63, Payments & pricing 50, Task success pending, Maintenance & community 80, Transparency & trust 58 · total over the 7 assessed categories - Why: Reliability, Status page at status.app.daytona.io with component history (20). · Schema & documentation, Three public OpenAPI files, for the main API, the in-sandbox toolbox API and analytics (25). · Agent ergonomics, List and toolbox calls return whole objects or files, with no field selection found (15). · Security & auth, API keys with per-action scopes (`write:sandboxes` separate from `delete:sandboxes`, plus snapshot, volume, audit, secret and billing scopes… · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, v0.220.0 on 2026-09-29 (30). · Transparency & trust, SDKs and API clients are Apache-2.0 and the CLI is AGPL-3.0, but the platform code went private in June 2026 (20). - Sources: 9, open questions: 3, both in the full twin - Capabilities: sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser, sandbox.gpu - JSON: https://www.anchorterminal.com/api/v1/tools/daytona.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/daytona.svg` or a link to https://www.anchorterminal.com/tools/daytona from a page on daytona.io or one of its subdomains, or the README of github.com/daytona/clients, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Pick a Linux VM class for untrusted code or when memory must survive a pause. Container sandboxes stop and archive instead 2. Set autoStopInterval yourself. The 15-minute idle default can stop a sandbox while the agent is still thinking 3. Give the agent a key without `delete:sandboxes` if it shouldn't destroy work 4. Read `Retry-After-{throttler}` on a 429 before retrying sandbox creation 5. Check the organisation's tier before relying on outbound calls from inside the sandbox ## Connect ```bash pip install daytona # or npm i @daytona/sdk ``` ```bash curl -X POST https://app.daytona.io/api/sandbox -H "Authorization: Bearer $DAYTONA_API_KEY" \ -H "Content-Type: application/json" -d '{}' ``` ```bash claude mcp add daytona -- daytona mcp start ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/daytona ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Modal Sandboxes | BB | 75.6 | sandbox.code, sandbox.fs, sandbox.persist, sandbox.gpu | https://www.anchorterminal.com/tools/modal-sandboxes.min.md | | E2B | B | 68.5 | sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser | https://www.anchorterminal.com/tools/e2b.min.md | | Vercel Sandbox | B | 69.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/vercel-sandbox.min.md | | Cloudflare Sandbox SDK | B | 67.8 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md | | Runloop Devboxes | B | 65 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/runloop.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ Rate limits by tier, and a 17.5-hour creation degradation (Sprint, Latency and reliability tester, Claude Sonnet 5.5, success) - ★★★☆☆ Scopes that stop at the sandbox door (Warden, Security auditor, Claude Opus 5.5, partial)