{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
        "name": "Microsoft Execution Containers",
        "score": 76.3,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "microsoft-execution-containers"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/modal-sandboxes.json",
        "name": "Modal Sandboxes",
        "score": 75.5,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "modal-sandboxes"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/vercel-sandbox.json",
        "name": "Vercel Sandbox",
        "score": 69.6,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "vercel-sandbox"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/e2b.json",
        "name": "E2B",
        "score": 68.3,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "e2b"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
        "name": "Cloudflare Sandbox SDK",
        "score": 67.5,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "cloudflare-sandbox-sdk"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/runloop.json",
        "name": "Runloop Devboxes",
        "score": 64.8,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "runloop"
      }
    ],
    "tool": {
      "slug": "deno-sandbox",
      "name": "Deno Sandbox",
      "vendor": "Deno Land Inc.",
      "vendorUrl": "https://deno.com",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the `@deno/sandbox` JavaScript SDK, the `deno-sandbox` Python SDK or the `deno sandbox` CLI, and launched in beta on 3 February 2026.",
      "url": "https://www.anchorterminal.com/tools/deno-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/deno-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json",
      "repo": "https://github.com/denoland/sandbox-py",
      "license": "Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT",
      "transports": [
        "http"
      ],
      "packages": [
        {
          "registry": "npm",
          "name": "@deno/sandbox"
        },
        {
          "registry": "pypi",
          "name": "deno-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "An organisation access token (prefix `ddo_`) created under Settings in console.deno.com, read by the SDKs from `DENO_DEPLOY_TOKEN` and sent as a Bearer token. The same token manages the organisation's Deno Deploy apps. No scopes or expiry were found in the reviewed docs, the docs say to rotate a leaked token from the dashboard, and all organisation members hold owner permissions. Signup is in a browser.",
      "pricing": "paid",
      "pricingNotes": "Sandboxes need the Pro plan ($20 a month) or above, and the Free plan does not include them. Compute bills through the Deploy meters at $0.10 a CPU-hour and $0.025 a GiB-hour of memory beyond the plan's allowance (50 CPU-hours and 750 GiB-hours on Pro), and volume storage at $0.20 a GiB-month beyond 5 GiB on Pro. Spend limits can be set on paid plans (https://deno.com/deploy/pricing, checked 2026-10-08).",
      "priceSummary": "$0.10 / vCPU-hr",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the sandbox docs, the pricing page or the OpenAPI document (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 6,
        "npmWeekly": 1971,
        "pypiWeekly": 31729,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.deno.com/sandbox/",
      "llmsTxt": "https://docs.deno.com/llms.txt",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "paid",
        "beta",
        "microvm",
        "typescript",
        "python",
        "cli",
        "llms-txt",
        "status-page",
        "enterprise"
      ],
      "lastRelease": "2026-07-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 50.3,
        "grade": "D",
        "agentReady": false,
        "rank": 689,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 14,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 58
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 48,
            "points": 9.6,
            "reason": "Hosted lines. denostatus.com runs on Instatus with history, but has no component for sandboxes (15 of 20). The last 90 days show one incident, increased request failures in `ord` on 7 September 2026, 1 hour 9 minutes to resolution with recovery reported after 11 minutes. Its effect on sandboxes is not stated (20). Concurrency and resource limits are published, though the docs (5 per organisation) and the pricing table (3 per region on Pro) differ, and no API request limits were found (8). No 429 or retry guidance and no idempotency keys found (0). A 99.95 per cent SLA is listed for Enterprise without saying whether it covers a beta product (5). Beta, pre-release per the docs (0)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 66,
            "points": 10.73,
            "reason": "The published OpenAPI document has no sandbox operations, so the typed TypeScript SDK reference on JSR and the typed Python SDK count as 15 of 25 (15). llms.txt and every docs page as Markdown (10). The docs state use cases, when to choose a duration timeout and when to move work to a Deploy app (13). Typed options with stated ranges for memory, capacity and timeout (12). Examples in JavaScript, sync and async Python and the CLI. No error reference was found, and two pages disagree on the default network policy (8). SDKs are versioned at 0.x, and the Deploy changelog's newest entry is 12 March 2026 (8)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 60,
            "points": 9.75,
            "reason": "Sandbox and volume objects are small, and command output streams (15). Lists use cursor pagination with search, label and status filters (15). The Python SDK raises errors with a status, code, message and trace id, and validation errors with a field path, but the codes are not documented (10). No idempotency keys. A duration sandbox can be rejoined by id, and volume slugs are unique per organisation (5). `Sandbox.create()` needs no parameters, with JavaScript and Python SDKs and a CLI (15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 61,
            "points": 10.68,
            "reason": "One organisation token with no scopes or expiry found, rotatable from the dashboard, which also manages the organisation's Deploy apps. All members hold owner permissions (15). An outbound allowlist and read-only volume mounts exist, but outbound access is open unless `allowNet` is set, per the Security page (13). Secret substitution outside the VM is documented as a defence against prompt injection followed by exfiltration (13). Commands, HTTP requests and SSH sessions are traced in the dashboard with an event log (10). A disclosure policy with safe harbour at security@deno.com and a security.txt without an Expires field. The product page claims SOC2 and ISO27001 while the pricing table lists SOC2 Type 1 under Enterprise. No bug bounty found (10). `exposeHttp` URLs are public without authentication, which the docs state in capitals."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 (0). Unit prices are public without a login, $0.10 a CPU-hour, $0.025 a GiB-hour and $0.20 a GiB-month (20). The Free plan does not include sandboxes, and no trial was found (0). A person signs up at console.deno.com in a browser and creates the token (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 45,
            "points": 3.94,
            "reason": "`deno-sandbox` 0.16.0 on 22 July 2026, 78 days ago. `@deno/sandbox` last shipped 0.13.2 on 16 March 2026 (20). One release in the last 90 days (0). The Deploy changelog stops at 12 March 2026. Support is by Discord, and by email on paid plans. The Python repository shows one open issue or pull request (7). Official JavaScript and Python SDKs, the JavaScript one unchanged for over six months (12). The Python repository runs formatting, lint, type checks and offline tests in CI. The JavaScript SDK's source repository was not found in public (6)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 58,
            "points": 5.08,
            "note": "editorial 35, provenance 80",
            "reason": "The SDKs are MIT and the platform is closed under terms last modified 30 September 2026 (18). The privacy policy states no retention periods. The docs state that a deleted volume's storage is removed after 24 hours and the pricing table gives log retention of 1 day to 1 week. The terms grant Deno a licence over user data for internal business purposes including benchmarking. A DPA is listed for Enterprise only (10). No deprecation policy found, and the terms allow changes or discontinuation without notice (0). Two regions are named. No sub-processor list found (7)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "Sandbox and volume objects are small, and command output streams (15). Lists use cursor pagination with search, label and status filters (15). The Python SDK raises errors with a status, code, message and trace id, and validation errors with a field path, but the codes are not documented (10). No idempotency keys. A duration sandbox can be rejoined by id, and volume slugs are unique per organisation (5). `Sandbox.create()` needs no parameters, with JavaScript and Python SDKs and a CLI (15).",
            "maintenance": "`deno-sandbox` 0.16.0 on 22 July 2026, 78 days ago. `@deno/sandbox` last shipped 0.13.2 on 16 March 2026 (20). One release in the last 90 days (0). The Deploy changelog stops at 12 March 2026. Support is by Discord, and by email on paid plans. The Python repository shows one open issue or pull request (7). Official JavaScript and Python SDKs, the JavaScript one unchanged for over six months (12). The Python repository runs formatting, lint, type checks and offline tests in CI. The JavaScript SDK's source repository was not found in public (6).",
            "payments": "No x402, MPP or L402 (0). Unit prices are public without a login, $0.10 a CPU-hour, $0.025 a GiB-hour and $0.20 a GiB-month (20). The Free plan does not include sandboxes, and no trial was found (0). A person signs up at console.deno.com in a browser and creates the token (0).",
            "reliability": "Hosted lines. denostatus.com runs on Instatus with history, but has no component for sandboxes (15 of 20). The last 90 days show one incident, increased request failures in `ord` on 7 September 2026, 1 hour 9 minutes to resolution with recovery reported after 11 minutes. Its effect on sandboxes is not stated (20). Concurrency and resource limits are published, though the docs (5 per organisation) and the pricing table (3 per region on Pro) differ, and no API request limits were found (8). No 429 or retry guidance and no idempotency keys found (0). A 99.95 per cent SLA is listed for Enterprise without saying whether it covers a beta product (5). Beta, pre-release per the docs (0).",
            "schema": "The published OpenAPI document has no sandbox operations, so the typed TypeScript SDK reference on JSR and the typed Python SDK count as 15 of 25 (15). llms.txt and every docs page as Markdown (10). The docs state use cases, when to choose a duration timeout and when to move work to a Deploy app (13). Typed options with stated ranges for memory, capacity and timeout (12). Examples in JavaScript, sync and async Python and the CLI. No error reference was found, and two pages disagree on the default network policy (8). SDKs are versioned at 0.x, and the Deploy changelog's newest entry is 12 March 2026 (8).",
            "security": "One organisation token with no scopes or expiry found, rotatable from the dashboard, which also manages the organisation's Deploy apps. All members hold owner permissions (15). An outbound allowlist and read-only volume mounts exist, but outbound access is open unless `allowNet` is set, per the Security page (13). Secret substitution outside the VM is documented as a defence against prompt injection followed by exfiltration (13). Commands, HTTP requests and SSH sessions are traced in the dashboard with an event log (10). A disclosure policy with safe harbour at security@deno.com and a security.txt without an Expires field. The product page claims SOC2 and ISO27001 while the pricing table lists SOC2 Type 1 under Enterprise. No bug bounty found (10). `exposeHttp` URLs are public without authentication, which the docs state in capitals.",
            "transparency": "The SDKs are MIT and the platform is closed under terms last modified 30 September 2026 (18). The privacy policy states no retention periods. The docs state that a deleted volume's storage is removed after 24 hours and the pricing table gives log retention of 1 day to 1 week. The terms grant Deno a licence over user data for internal business purposes including benchmarking. A DPA is listed for Enterprise only (10). No deprecation policy found, and the terms allow changes or discontinuation without notice (0). Two regions are named. No sub-processor list found (7)."
          },
          "sources": [
            {
              "what": "Sandbox docs overview, limits and regions",
              "url": "https://docs.deno.com/sandbox/",
              "seen": "2026-10-08"
            },
            {
              "what": "Getting started, organisation tokens and options",
              "url": "https://docs.deno.com/sandbox/getting_started/",
              "seen": "2026-10-08"
            },
            {
              "what": "Create a sandbox, options and stated defaults",
              "url": "https://docs.deno.com/sandbox/create/",
              "seen": "2026-10-08"
            },
            {
              "what": "Security page, secrets, network allowlist and auditing",
              "url": "https://docs.deno.com/sandbox/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "Timeouts",
              "url": "https://docs.deno.com/sandbox/timeouts/",
              "seen": "2026-10-08"
            },
            {
              "what": "Volumes and snapshots",
              "url": "https://docs.deno.com/sandbox/volumes/",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI management",
              "url": "https://docs.deno.com/sandbox/cli/",
              "seen": "2026-10-08"
            },
            {
              "what": "Expose HTTP, public URLs",
              "url": "https://docs.deno.com/sandbox/expose_http/",
              "seen": "2026-10-08"
            },
            {
              "what": "Product page, prices, Firecracker and certification claims",
              "url": "https://deno.com/deploy/sandbox",
              "seen": "2026-10-08"
            },
            {
              "what": "Deploy pricing, plan table, SLA and compliance rows",
              "url": "https://deno.com/deploy/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "Launch post, 3 February 2026, beta",
              "url": "https://deno.com/blog/introducing-deno-sandbox",
              "seen": "2026-10-08"
            },
            {
              "what": "Deno Deploy REST API OpenAPI document",
              "url": "https://api.deno.com/v2/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "Status page",
              "url": "https://denostatus.com/",
              "seen": "2026-10-08"
            },
            {
              "what": "Status history feed",
              "url": "https://denostatus.com/history.rss",
              "seen": "2026-10-08"
            },
            {
              "what": "Deploy changelog",
              "url": "https://docs.deno.com/deploy/changelog/",
              "seen": "2026-10-08"
            },
            {
              "what": "Terms and conditions",
              "url": "https://docs.deno.com/deploy/terms_and_conditions/",
              "seen": "2026-10-08"
            },
            {
              "what": "Privacy policy",
              "url": "https://docs.deno.com/deploy/privacy_policy/",
              "seen": "2026-10-08"
            },
            {
              "what": "Acceptable use policy",
              "url": "https://docs.deno.com/deploy/acceptable_use_policy/",
              "seen": "2026-10-08"
            },
            {
              "what": "Security and responsible disclosure",
              "url": "https://docs.deno.com/deploy/security/",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://deno.com/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Organisations reference, member permissions",
              "url": "https://docs.deno.com/deploy/reference/organizations/",
              "seen": "2026-10-08"
            },
            {
              "what": "Python SDK repository, cloned",
              "url": "https://github.com/denoland/sandbox-py",
              "seen": "2026-10-08"
            },
            {
              "what": "npm registry, @deno/sandbox versions and dates",
              "url": "https://registry.npmjs.org/@deno/sandbox",
              "seen": "2026-10-08"
            },
            {
              "what": "JSR, @deno/sandbox versions",
              "url": "https://jsr.io/@deno/sandbox/meta.json",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI, deno-sandbox releases",
              "url": "https://pypi.org/pypi/deno-sandbox/json",
              "seen": "2026-10-08"
            },
            {
              "what": "llms.txt",
              "url": "https://docs.deno.com/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "RDAP record for deno.com",
              "url": "https://rdap.verisign.com/com/v1/domain/deno.com",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "The lead named a REST API for sandboxes. The docs link one, but its OpenAPI document has no sandbox, volume or snapshot operations. The Python SDK calls `/api/v3/sandboxes` paths that are not in any published contract we found.",
            "Which default applies to outbound network access. The Create and Security pages disagree, and we did not run a sandbox to test it.",
            "Whether the concurrency limit is 5 per organisation (docs) or 3 per region on Pro (pricing table).",
            "Whether the Enterprise 99.95 per cent SLA covers sandboxes while they are in beta.",
            "Which certification is current. The product page says SOC2 and ISO27001, the pricing table says SOC2 Type 1 under Enterprise, and no report or trust centre was found.",
            "unchecked: the source repository and changelog for `@deno/sandbox`. github.com/denoland/sandbox asked for credentials, so it is private or absent.",
            "unchecked: whether organisation tokens can be scoped or given an expiry in the console, which needs a login.",
            "unchecked: issue response times on denoland/sandbox-py. Only the open count (1) was read.",
            "No DPA or sub-processor list was found in public. deno.com/deploy/dpa returned 404."
          ]
        },
        "negative": -2,
        "negativeNotes": [
          "2026-10-08: the Create page (last modified 28 January 2026) says a default sandbox has no outbound network access, while the Security page of the same date says outbound access is unrestricted unless `allowNet` is set. A reader of the first page would leave egress open. 2 points. https://docs.deno.com/sandbox/create/ and https://docs.deno.com/sandbox/security/"
        ],
        "verdict": "Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.",
        "bestFor": "Short runs of untrusted or generated code that need outside API keys kept out of reach, and teams already on Deno Deploy who want to promote a sandbox to an app.",
        "strengths": [
          "Secrets are held outside the VM. Code sees a placeholder, and the real value is substituted only on requests to hosts named for that secret",
          "`allowNet` restricts outbound traffic to listed hostnames, wildcard subdomains, ports or IP addresses",
          "Each sandbox is a Firecracker microVM per the product page, with 2 vCPUs, 768 MB to 4 GB of memory and 10 GB of disk",
          "Volumes of 300 MB to 20 GB persist between sandboxes, and read-only snapshots of a volume can boot new sandboxes",
          "Unit prices are public, $0.10 a CPU-hour, $0.025 a GiB-hour of memory and $0.20 a GiB-month of volume storage"
        ],
        "weaknesses": [
          "Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found",
          "Sandboxes are not included in the Free plan. Access starts at Pro, $20 a month, after a browser signup",
          "The published OpenAPI document at `api.deno.com/v2/openapi.json` has 34 operations and none for sandboxes, volumes or snapshots",
          "The Create page says a default sandbox has no outbound network access, and the Security page says outbound access is unrestricted by default",
          "Maximum lifetime is 30 minutes, volumes exist only in `ord`, and no API rate limits or 429 guidance were found",
          "Organisation tokens carry no scopes in the reviewed docs, and every organisation member has owner permissions"
        ],
        "agentNotes": [
          "Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above",
          "Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted",
          "Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder",
          "The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes",
          "Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region",
          "`exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 50.3
          }
        ],
        "editorialScores": {
          "ergonomics": 60,
          "maintenance": 45,
          "payments": 20,
          "reliability": 48,
          "schema": 66,
          "security": 61,
          "transparency": 35
        },
        "provenanceScore": 80
      },
      "connect": {
        "install": "npm install @deno/sandbox  # or pip install deno-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/deno-sandbox"
      },
      "notable": [
        "Launched in beta on 3 February 2026 alongside general availability of Deno Deploy, and the docs still describe a pre-release phase (https://deno.com/blog/introducing-deno-sandbox, https://docs.deno.com/sandbox/)",
        "Secrets are replaced by placeholders inside the VM and substituted only on outbound requests to the hosts named for each secret (https://docs.deno.com/sandbox/security/)",
        "The pricing table lists sandboxes as not included on Free, with 3 concurrent per region on Pro and 20 on Builder, while the docs give 5 concurrent per organisation as the pre-release default (https://deno.com/deploy/pricing, https://docs.deno.com/sandbox/)",
        "The docs point to the REST API at api.deno.com/v2/docs for direct access, and its OpenAPI document has 34 operations on apps, revisions, layers, domains and database instances, with none for sandboxes (https://api.deno.com/v2/openapi.json)",
        "The Python SDK creates sandboxes over a WebSocket to `wss://\u003cregion\u003e.sandbox-api.deno.net/api/v3/sandboxes/create` and lists them through console.deno.com (https://github.com/denoland/sandbox-py)",
        "The Create page says a default sandbox has no outbound network access and the Security page says outbound access is unrestricted by default (https://docs.deno.com/sandbox/create/, https://docs.deno.com/sandbox/security/)",
        "The product page says Deno Deploy is SOC2 and ISO27001 certified, and the pricing table lists SOC2 Type 1 and a DPA under Enterprise only (https://deno.com/deploy/sandbox, https://deno.com/deploy/pricing)"
      ],
      "area": "agent-runtime",
      "details": [
        {
          "label": "Release status",
          "value": "Beta since 3 February 2026. The docs call the present phase pre-release"
        },
        {
          "label": "Interfaces",
          "value": "`@deno/sandbox` on npm and JSR (0.13.2, 16 March 2026), `deno-sandbox` on PyPI (0.16.0, 22 July 2026, sync and async), and `deno sandbox` commands in the Deno CLI. No sandbox operations in the published OpenAPI document"
        },
        {
          "label": "Isolation",
          "value": "One Firecracker microVM per sandbox per the product page, with outbound traffic routed through a policy proxy"
        },
        {
          "label": "Resources",
          "value": "2 vCPUs, 768 MB to 4,096 MB of memory (default about 1.2 GB), 10 GB of ephemeral disk"
        },
        {
          "label": "Lifetime",
          "value": "Ends with the client session by default. A duration timeout keeps it alive for reconnection, extendable, to a maximum of 30 minutes"
        },
        {
          "label": "Concurrency",
          "value": "3 per region on Pro and 20 on Builder per the pricing table. The docs give 5 per organisation as the pre-release default"
        },
        {
          "label": "Regions",
          "value": "`ams` (Amsterdam) and `ord` (Chicago). Volumes only in `ord`"
        },
        {
          "label": "Persistence",
          "value": "Volumes of 300 MB to 20 GB, mountable read-only, removed 24 hours after deletion. Read-only snapshots made from bootable volumes, with `builtin:debian-13` the only base image"
        },
        {
          "label": "Network and secrets",
          "value": "`allowNet` allowlist by hostname, wildcard, port or IP address. Secrets substituted outside the VM for named hosts"
        },
        {
          "label": "Access from outside",
          "value": "`exposeHttp` gives a public URL without authentication, plus SSH and a browser editor"
        },
        {
          "label": "Observability",
          "value": "Commands, HTTP requests and SSH sessions traced in the Deploy dashboard, with an event log per sandbox. Logs and traces kept 1 week on Pro"
        },
        {
          "label": "Status",
          "value": "denostatus.com on Instatus, with Deno Deploy component groups and no component named for sandboxes"
        },
        {
          "label": "SLA and compliance",
          "value": "99.95 per cent reliability SLA, SOC2 Type 1 and a DPA listed under Enterprise only"
        }
      ],
      "unitPrices": [
        {
          "item": "Active CPU beyond plan allowance",
          "unit": "vcpu-hour",
          "usd": 0.1,
          "note": "Memory extra at $0.025 a GiB-hour"
        },
        {
          "item": "Volume storage beyond plan allowance",
          "unit": "gb-month",
          "usd": 0.2,
          "note": "Priced per GiB"
        },
        {
          "item": "Pro plan, the lowest that includes sandboxes",
          "unit": "month",
          "usd": 20,
          "note": "Includes 50 CPU-hours, 750 GiB-hours of memory and 5 GiB of volume storage"
        }
      ],
      "provenance": {
        "legalEntity": "Deno Land Inc.",
        "domain": "deno.com",
        "domainRegistered": "1999-03-09",
        "endpointOnVendorDomain": false,
        "terms": "https://docs.deno.com/deploy/terms_and_conditions/",
        "privacy": "https://docs.deno.com/deploy/privacy_policy/",
        "statusPage": "https://denostatus.com",
        "changelog": "https://docs.deno.com/deploy/changelog/",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The Deno Deploy terms and conditions (last modified 30 September 2026) name Deno Land Inc. and govern the Deploy services, of which Sandbox is a part. No separate sandbox terms were found.",
          "The privacy policy (last modified 30 September 2026) gives Deno Land Inc., 1111 6th Ave Ste 550, PMB 702973, San Diego CA 92101. A DPA is listed under Enterprise only, and no public copy was found.",
          "The Python SDK's default sandbox endpoint is `\u003cregion\u003e.sandbox-api.deno.net`, a second domain of the vendor's, while listing and volumes go through console.deno.com.",
          "deno.com/.well-known/security.txt gives deploy@deno.com and a policy link and has no Expires field, which RFC 9116 requires. It is recorded as valid to match other listings with the same gap. The policy page gives security@deno.com.",
          "RDAP for deno.com gives a registration date of 1999-03-09.",
          "The Deploy changelog's newest entry is dated 12 March 2026."
        ],
        "score": 80,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Deno Land Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "deno.com, registered 1999-03-09 (27 years)",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": " is not on deno.com",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points",
            "points": 5.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "denostatus.com",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://docs.deno.com/deploy/terms_and_conditions/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-30",
            "words": 4897,
            "points": 5.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on September 30, 2026",
                "says": "Last updated 2026-09-30"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "The Agreement and any action related thereto will be governed by the laws of the State of New York without regard to its conflict of laws provisions.",
                "says": "The law of the State of New York"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "Limitation of Liability,” “Indemnification,” “Compliance with Applicable Laws,” “Term;"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "You may change or terminate your Subscription by emailing us at support@deno.com."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "We reserve the right, at our sole discretion, to modify, discontinue, or terminate the availability of any Services, or modify this Agreement, at any time and without prior notice.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You have no rights in or to the Content, and you will not use the Content except as permitted under this Agreement."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "You will not use the Services, or any portion or component thereof in violation of any applicable law, in order to build a competitive product or service, or for any purpose not specifically permitted in these Terms;",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "We reserve the right, at our sole discretion, to modify, discontinue, or terminate the availability of any Services, or modify this Agreement, at any time and without prior notice.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "We reserve the right, at our sole discretion, to modify, discontinue, or terminate the availability of any Services, or modify this Agreement, at any time and without prior notice."
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "THE SECTIONS BELOW TITLED “BINDING ARBITRATION” AND “CLASS ACTION WAIVER” CONTAIN A BINDING ARBITRATION AGREEMENT AND CLASS ACTION WAIVER."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Customers grant Deno a sublicensable licence to use their data for its internal business purposes, including improving the services and benchmarking.",
                "quote": "(ii) for Deno’s internal business purposes, including using such data to analyze, update, and improve the Services and Deno’s analytics capabilities and for benchmarking purposes."
              },
              {
                "date": "2026-10-08",
                "text": "Deno may add or change fees at any time at its sole discretion.",
                "quote": "Deno may add new fees and charges, or amend fees and charges, at any time in its sole discretion."
              },
              {
                "date": "2026-10-08",
                "text": "Each party may use the other's name and logo for marketing, and Deno may name the customer on its website.",
                "quote": "each party may during the term of this Agreement, use the other party’s name and/or logo for marketing and promotional purposes, including, without limitation, identifying Authorized Users as a customer of Deno on Deno’s website or elsewhere."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://docs.deno.com/deploy/privacy_policy/",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-30",
            "words": 2805,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Last updated on September 30, 2026",
                "says": "Last updated 2026-09-30"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This Privacy Policy (the “Policy”) describes the personal information we collect, the purposes for which we use it, the parties with whom we may share it, and your choices with respect to such information."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Deno determines the retention period for all Information based on the purposes for which we collect and/or receive the Information and/or tax, legal and regulatory requirements."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Information Obtained From Third Parties We may receive certain information about you from other sources, including publicly available sources (such as public records and social media platforms), as well as our service providers and marketing partners."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "Please note, however, that we do not sell any personal information to third parties.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If you are a resident of Nevada, you have the right to opt-out of the sale of personal information to third parties."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "Please reach out to support@deno.com for any questions, complaints, or requests regarding this Privacy Policy, and include in the subject line “Privacy Policy\", or contact us by mail at:",
                "says": "support@deno.com"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "If you are located outside of the United States, please be aware that any information you provide to us may be transferred to the United States or other countries where the privacy laws may not be as protective as those in your country of origin.",
                "says": "Data goes to the United States"
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/deno-sandbox.json",
      "live": {
        "slug": "deno-sandbox",
        "vendorStatus": {
          "page": "https://denostatus.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:57:48.013369722Z"
        },
        "updatedAt": "2026-10-09T07:57:48.013369722Z"
      }
    },
    "verify": {
      "accepts": "a page on deno.com or one of its subdomains, or the README of github.com/denoland/sandbox-py",
      "badgeUrl": "https://www.anchorterminal.com/badges/deno-sandbox.svg",
      "body": {
        "slug": "deno-sandbox",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/deno-sandbox",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/deno-sandbox\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/deno-sandbox.svg\" alt=\"Deno Sandbox on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Deno Sandbox on Anchor Terminal](https://www.anchorterminal.com/badges/deno-sandbox.svg)](https://www.anchorterminal.com/tools/deno-sandbox)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/deno-sandbox\"\u003eDeno Sandbox on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/deno-sandbox",
    "json": "https://www.anchorterminal.com/tools/deno-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/deno-sandbox.md",
    "slim": "https://www.anchorterminal.com/tools/deno-sandbox.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 50.3/100 · rank #689 of 842 · #14 in Code execution sandboxes · not agent-ready · confidence medium**\n\n\n## Assessment\n\nSecrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Deno Land Inc. (https://deno.com) |\n| Kind | HTTP API |\n| Category | Code execution sandboxes (https://www.anchorterminal.com/categories/code-sandboxes) |\n| Transport | HTTP |\n| Auth | API key · An organisation access token (prefix `ddo_`) created under Settings in console.deno.com, read by the SDKs from `DENO_DEPLOY_TOKEN` and sent as a Bearer token. The same token manages the organisation's Deno Deploy apps. No scopes or expiry were found in the reviewed docs, the docs say to rotate a leaked token from the dashboard, and all organisation members hold owner permissions. Signup is in a browser. |\n| Pricing | Paid ($0.10 / vCPU-hr) · Sandboxes need the Pro plan ($20 a month) or above, and the Free plan does not include them. Compute bills through the Deploy meters at $0.10 a CPU-hour and $0.025 a GiB-hour of memory beyond the plan's allowance (50 CPU-hours and 750 GiB-hours on Pro), and volume storage at $0.20 a GiB-month beyond 5 GiB on Pro. Spend limits can be set on paid plans (https://deno.com/deploy/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the sandbox docs, the pricing page or the OpenAPI document (checked 2026-10-08). |\n| Licence | Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT |\n| Packages | npm: `@deno/sandbox`; pypi: `deno-sandbox` |\n| Source | https://github.com/denoland/sandbox-py |\n| Docs | https://docs.deno.com/sandbox/ |\n| llms.txt | https://docs.deno.com/llms.txt |\n| Last release | 2026-07-22 |\n| GitHub stars | 6 (as of 2026-10-08) |\n| npm downloads / week | 1,971 |\n| PyPI downloads / week | 31,729 |\n| Release status | Beta since 3 February 2026. The docs call the present phase pre-release |\n| Interfaces | `@deno/sandbox` on npm and JSR (0.13.2, 16 March 2026), `deno-sandbox` on PyPI (0.16.0, 22 July 2026, sync and async), and `deno sandbox` commands in the Deno CLI. No sandbox operations in the published OpenAPI document |\n| Isolation | One Firecracker microVM per sandbox per the product page, with outbound traffic routed through a policy proxy |\n| Resources | 2 vCPUs, 768 MB to 4,096 MB of memory (default about 1.2 GB), 10 GB of ephemeral disk |\n| Lifetime | Ends with the client session by default. A duration timeout keeps it alive for reconnection, extendable, to a maximum of 30 minutes |\n| Concurrency | 3 per region on Pro and 20 on Builder per the pricing table. The docs give 5 per organisation as the pre-release default |\n| Regions | `ams` (Amsterdam) and `ord` (Chicago). Volumes only in `ord` |\n| Persistence | Volumes of 300 MB to 20 GB, mountable read-only, removed 24 hours after deletion. Read-only snapshots made from bootable volumes, with `builtin:debian-13` the only base image |\n| Network and secrets | `allowNet` allowlist by hostname, wildcard, port or IP address. Secrets substituted outside the VM for named hosts |\n| Access from outside | `exposeHttp` gives a public URL without authentication, plus SSH and a browser editor |\n| Observability | Commands, HTTP requests and SSH sessions traced in the Deploy dashboard, with an event log per sandbox. Logs and traces kept 1 week on Pro |\n| Status | denostatus.com on Instatus, with Deno Deploy component groups and no component named for sandboxes |\n| SLA and compliance | 99.95 per cent reliability SLA, SOC2 Type 1 and a DPA listed under Enterprise only |\n| Capabilities | sandbox.code, sandbox.fs, sandbox.persist |\n| Tags | hosted, paid, beta, microvm, typescript, python, cli, llms-txt, status-page, enterprise |\n| JSON | https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 48 | 9.6 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 66 | 10.7 |\n| Agent ergonomics | 13% | 16.2 | 60 | 9.8 |\n| Security \u0026 auth | 14% | 17.5 | 61 | 10.7 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 45 | 3.9 |\n| Transparency \u0026 trust (editorial 35, provenance 80) | 7% | 8.8 | 58 | 5.1 |\n| Negative events | up to −15 | up to −15 | 2026-10-08: the Create page (last modified 28 January 2026) says a default sandbox has no outbound network access, while the Security page of the same date says outbound access is unrestricted unless `allowNet` is set. A reader of the first page would leave egress open. 2 points. https://docs.deno.com/sandbox/create/ and https://docs.deno.com/sandbox/security/  | -2 |\n| **Total** | | | | **50.3 → D** |\n\n### Why each score\n\n- Reliability 48: Hosted lines. denostatus.com runs on Instatus with history, but has no component for sandboxes (15 of 20). The last 90 days show one incident, increased request failures in `ord` on 7 September 2026, 1 hour 9 minutes to resolution with recovery reported after 11 minutes. Its effect on sandboxes is not stated (20). Concurrency and resource limits are published, though the docs (5 per organisation) and the pricing table (3 per region on Pro) differ, and no API request limits were found (8). No 429 or retry guidance and no idempotency keys found (0). A 99.95 per cent SLA is listed for Enterprise without saying whether it covers a beta product (5). Beta, pre-release per the docs (0).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 66: The published OpenAPI document has no sandbox operations, so the typed TypeScript SDK reference on JSR and the typed Python SDK count as 15 of 25 (15). llms.txt and every docs page as Markdown (10). The docs state use cases, when to choose a duration timeout and when to move work to a Deploy app (13). Typed options with stated ranges for memory, capacity and timeout (12). Examples in JavaScript, sync and async Python and the CLI. No error reference was found, and two pages disagree on the default network policy (8). SDKs are versioned at 0.x, and the Deploy changelog's newest entry is 12 March 2026 (8).\n- Agent ergonomics 60: Sandbox and volume objects are small, and command output streams (15). Lists use cursor pagination with search, label and status filters (15). The Python SDK raises errors with a status, code, message and trace id, and validation errors with a field path, but the codes are not documented (10). No idempotency keys. A duration sandbox can be rejoined by id, and volume slugs are unique per organisation (5). `Sandbox.create()` needs no parameters, with JavaScript and Python SDKs and a CLI (15).\n- Security \u0026 auth 61: One organisation token with no scopes or expiry found, rotatable from the dashboard, which also manages the organisation's Deploy apps. All members hold owner permissions (15). An outbound allowlist and read-only volume mounts exist, but outbound access is open unless `allowNet` is set, per the Security page (13). Secret substitution outside the VM is documented as a defence against prompt injection followed by exfiltration (13). Commands, HTTP requests and SSH sessions are traced in the dashboard with an event log (10). A disclosure policy with safe harbour at security@deno.com and a security.txt without an Expires field. The product page claims SOC2 and ISO27001 while the pricing table lists SOC2 Type 1 under Enterprise. No bug bounty found (10). `exposeHttp` URLs are public without authentication, which the docs state in capitals.\n- Payments \u0026 pricing 20: No x402, MPP or L402 (0). Unit prices are public without a login, $0.10 a CPU-hour, $0.025 a GiB-hour and $0.20 a GiB-month (20). The Free plan does not include sandboxes, and no trial was found (0). A person signs up at console.deno.com in a browser and creates the token (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 45: `deno-sandbox` 0.16.0 on 22 July 2026, 78 days ago. `@deno/sandbox` last shipped 0.13.2 on 16 March 2026 (20). One release in the last 90 days (0). The Deploy changelog stops at 12 March 2026. Support is by Discord, and by email on paid plans. The Python repository shows one open issue or pull request (7). Official JavaScript and Python SDKs, the JavaScript one unchanged for over six months (12). The Python repository runs formatting, lint, type checks and offline tests in CI. The JavaScript SDK's source repository was not found in public (6).\n- Transparency \u0026 trust 58: The SDKs are MIT and the platform is closed under terms last modified 30 September 2026 (18). The privacy policy states no retention periods. The docs state that a deleted volume's storage is removed after 24 hours and the pricing table gives log retention of 1 day to 1 week. The terms grant Deno a licence over user data for internal business purposes including benchmarking. A DPA is listed for Enterprise only (10). No deprecation policy found, and the terms allow changes or discontinuation without notice (0). Two regions are named. No sub-processor list found (7).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/deno-sandbox.md (JSON https://www.anchorterminal.com/fixes/deno-sandbox.json)\n\n### What we couldn't check\n\n- The lead named a REST API for sandboxes. The docs link one, but its OpenAPI document has no sandbox, volume or snapshot operations. The Python SDK calls `/api/v3/sandboxes` paths that are not in any published contract we found.\n- Which default applies to outbound network access. The Create and Security pages disagree, and we did not run a sandbox to test it.\n- Whether the concurrency limit is 5 per organisation (docs) or 3 per region on Pro (pricing table).\n- Whether the Enterprise 99.95 per cent SLA covers sandboxes while they are in beta.\n- Which certification is current. The product page says SOC2 and ISO27001, the pricing table says SOC2 Type 1 under Enterprise, and no report or trust centre was found.\n- unchecked: the source repository and changelog for `@deno/sandbox`. github.com/denoland/sandbox asked for credentials, so it is private or absent.\n- unchecked: whether organisation tokens can be scoped or given an expiry in the console, which needs a login.\n- unchecked: issue response times on denoland/sandbox-py. Only the open count (1) was read.\n- No DPA or sub-processor list was found in public. deno.com/deploy/dpa returned 404.\n\n### Sources\n\n- Sandbox docs overview, limits and regions: \u003chttps://docs.deno.com/sandbox/\u003e (seen 2026-10-08)\n- Getting started, organisation tokens and options: \u003chttps://docs.deno.com/sandbox/getting_started/\u003e (seen 2026-10-08)\n- Create a sandbox, options and stated defaults: \u003chttps://docs.deno.com/sandbox/create/\u003e (seen 2026-10-08)\n- Security page, secrets, network allowlist and auditing: \u003chttps://docs.deno.com/sandbox/security/\u003e (seen 2026-10-08)\n- Timeouts: \u003chttps://docs.deno.com/sandbox/timeouts/\u003e (seen 2026-10-08)\n- Volumes and snapshots: \u003chttps://docs.deno.com/sandbox/volumes/\u003e (seen 2026-10-08)\n- CLI management: \u003chttps://docs.deno.com/sandbox/cli/\u003e (seen 2026-10-08)\n- Expose HTTP, public URLs: \u003chttps://docs.deno.com/sandbox/expose_http/\u003e (seen 2026-10-08)\n- Product page, prices, Firecracker and certification claims: \u003chttps://deno.com/deploy/sandbox\u003e (seen 2026-10-08)\n- Deploy pricing, plan table, SLA and compliance rows: \u003chttps://deno.com/deploy/pricing\u003e (seen 2026-10-08)\n- Launch post, 3 February 2026, beta: \u003chttps://deno.com/blog/introducing-deno-sandbox\u003e (seen 2026-10-08)\n- Deno Deploy REST API OpenAPI document: \u003chttps://api.deno.com/v2/openapi.json\u003e (seen 2026-10-08)\n- Status page: \u003chttps://denostatus.com/\u003e (seen 2026-10-08)\n- Status history feed: \u003chttps://denostatus.com/history.rss\u003e (seen 2026-10-08)\n- Deploy changelog: \u003chttps://docs.deno.com/deploy/changelog/\u003e (seen 2026-10-08)\n- Terms and conditions: \u003chttps://docs.deno.com/deploy/terms_and_conditions/\u003e (seen 2026-10-08)\n- Privacy policy: \u003chttps://docs.deno.com/deploy/privacy_policy/\u003e (seen 2026-10-08)\n- Acceptable use policy: \u003chttps://docs.deno.com/deploy/acceptable_use_policy/\u003e (seen 2026-10-08)\n- Security and responsible disclosure: \u003chttps://docs.deno.com/deploy/security/\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://deno.com/.well-known/security.txt\u003e (seen 2026-10-08)\n- Organisations reference, member permissions: \u003chttps://docs.deno.com/deploy/reference/organizations/\u003e (seen 2026-10-08)\n- Python SDK repository, cloned: \u003chttps://github.com/denoland/sandbox-py\u003e (seen 2026-10-08)\n- npm registry, @deno/sandbox versions and dates: \u003chttps://registry.npmjs.org/@deno/sandbox\u003e (seen 2026-10-08)\n- JSR, @deno/sandbox versions: \u003chttps://jsr.io/@deno/sandbox/meta.json\u003e (seen 2026-10-08)\n- PyPI, deno-sandbox releases: \u003chttps://pypi.org/pypi/deno-sandbox/json\u003e (seen 2026-10-08)\n- llms.txt: \u003chttps://docs.deno.com/llms.txt\u003e (seen 2026-10-08)\n- RDAP record for deno.com: \u003chttps://rdap.verisign.com/com/v1/domain/deno.com\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 80/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Deno Land Inc. | 20/20 |\n| Domain age | deno.com, registered 1999-03-09 (27 years) | 15/15 |\n| Endpoint on the vendor's domain |  is not on deno.com | 0/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 2 clauses that cost points | 5.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | denostatus.com | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe Deno Deploy terms and conditions (last modified 30 September 2026) name Deno Land Inc. and govern the Deploy services, of which Sandbox is a part. No separate sandbox terms were found.\n\nThe privacy policy (last modified 30 September 2026) gives Deno Land Inc., 1111 6th Ave Ste 550, PMB 702973, San Diego CA 92101. A DPA is listed under Enterprise only, and no public copy was found.\n\nThe Python SDK's default sandbox endpoint is `\u003cregion\u003e.sandbox-api.deno.net`, a second domain of the vendor's, while listing and volumes go through console.deno.com.\n\ndeno.com/.well-known/security.txt gives deploy@deno.com and a policy link and has no Expires field, which RFC 9116 requires. It is recorded as valid to match other listings with the same gap. The policy page gives security@deno.com.\n\nRDAP for deno.com gives a registration date of 1999-03-09.\n\nThe Deploy changelog's newest entry is dated 12 March 2026.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://docs.deno.com/deploy/terms_and_conditions/), read 2026-10-08, dated 2026-09-30, states 6 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"You will not use the Services, or any portion or component thereof in violation of any applicable law, in order to build a competitive product or service, or for any purpose not specifically permitted in these Terms;\"\n- To know. Says the terms or the service can change without notice (costs points). \"We reserve the right, at our sole discretion, to modify, discontinue, or terminate the availability of any Services, or modify this Agreement, at any time and without prior notice.\"\n- To know. Says access can be ended without notice or for any reason. \"We reserve the right, at our sole discretion, to modify, discontinue, or terminate the availability of any Services, or modify this Agreement, at any time and without prior notice.\"\n- To know. Requires arbitration or waives class actions. \"THE SECTIONS BELOW TITLED “BINDING ARBITRATION” AND “CLASS ACTION WAIVER” CONTAIN A BINDING ARBITRATION AGREEMENT AND CLASS ACTION WAIVER.\"\n- Gives the date it was last updated. Last updated 2026-09-30.\n- Names the governing law or courts. The law of the State of New York.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Customers grant Deno a sublicensable licence to use their data for its internal business purposes, including improving the services and benchmarking. \"(ii) for Deno’s internal business purposes, including using such data to analyze, update, and improve the Services and Deno’s analytics capabilities and for benchmarking purposes.\"\n- Also in the text (2026-10-08). Deno may add or change fees at any time at its sole discretion. \"Deno may add new fees and charges, or amend fees and charges, at any time in its sole discretion.\"\n- Also in the text (2026-10-08). Each party may use the other's name and logo for marketing, and Deno may name the customer on its website. \"each party may during the term of this Agreement, use the other party’s name and/or logo for marketing and promotional purposes, including, without limitation, identifying Authorized Users as a customer of Deno on Deno’s website or elsewhere.\"\n\n**Privacy policy** (https://docs.deno.com/deploy/privacy_policy/), read 2026-10-08, dated 2026-09-30, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-09-30.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. support@deno.com.\n- Says where data is transferred or stored. Data goes to the United States.\n\n## Live (updated 2026-10-09 07:57 UTC)\n\n- Vendor status page: unknown, no machine-readable status found\n- Always current: https://www.anchorterminal.com/api/v1/live/deno-sandbox.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Active CPU beyond plan allowance | $0.10 | per vCPU-hour | Memory extra at $0.025 a GiB-hour |\n| Volume storage beyond plan allowance | $0.20 | per GB per month | Priced per GiB |\n| Pro plan, the lowest that includes sandboxes | $20 | per month (plan) | Includes 50 CPU-hours, 750 GiB-hours of memory and 5 GiB of volume storage |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Secrets are held outside the VM. Code sees a placeholder, and the real value is substituted only on requests to hosts named for that secret\n- `allowNet` restricts outbound traffic to listed hostnames, wildcard subdomains, ports or IP addresses\n- Each sandbox is a Firecracker microVM per the product page, with 2 vCPUs, 768 MB to 4 GB of memory and 10 GB of disk\n- Volumes of 300 MB to 20 GB persist between sandboxes, and read-only snapshots of a volume can boot new sandboxes\n- Unit prices are public, $0.10 a CPU-hour, $0.025 a GiB-hour of memory and $0.20 a GiB-month of volume storage\n\n## Weaknesses\n\n- Beta since 3 February 2026. The docs call the present phase pre-release, and no general availability date was found\n- Sandboxes are not included in the Free plan. Access starts at Pro, $20 a month, after a browser signup\n- The published OpenAPI document at `api.deno.com/v2/openapi.json` has 34 operations and none for sandboxes, volumes or snapshots\n- The Create page says a default sandbox has no outbound network access, and the Security page says outbound access is unrestricted by default\n- Maximum lifetime is 30 minutes, volumes exist only in `ord`, and no API rate limits or 429 guidance were found\n- Organisation tokens carry no scopes in the reviewed docs, and every organisation member has owner permissions\n\n## Before you call it (notes for agents)\n\n1. Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above\n2. Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted\n3. Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder\n4. The default timeout ends the VM when the client disconnects. Pass a duration such as `\"10m\"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes\n5. Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region\n6. `exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret\n\n## Connect\n\nInstall:\n\n```bash\nnpm install @deno/sandbox  # or pip install deno-sandbox\n```\n\nThrough letme (picks today, calling later): https://letme.dev/deno-sandbox. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Microsoft Execution Containers | BB | 76.3 | 35 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/microsoft-execution-containers.md |\n| Modal Sandboxes | BB | 75.5 | 45 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/modal-sandboxes.md |\n| Vercel Sandbox | B | 69.6 | 168 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/vercel-sandbox.md |\n| E2B | B | 68.3 | 207 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/e2b.md |\n| Cloudflare Sandbox SDK | B | 67.5 | 231 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md |\n| Runloop Devboxes | B | 64.8 | 305 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/runloop.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Launched in beta on 3 February 2026 alongside general availability of Deno Deploy, and the docs still describe a pre-release phase (source: \u003chttps://deno.com/blog/introducing-deno-sandbox, https://docs.deno.com/sandbox/\u003e)\n- Secrets are replaced by placeholders inside the VM and substituted only on outbound requests to the hosts named for each secret (source: \u003chttps://docs.deno.com/sandbox/security/\u003e)\n- The pricing table lists sandboxes as not included on Free, with 3 concurrent per region on Pro and 20 on Builder, while the docs give 5 concurrent per organisation as the pre-release default (source: \u003chttps://deno.com/deploy/pricing, https://docs.deno.com/sandbox/\u003e)\n- The docs point to the REST API at api.deno.com/v2/docs for direct access, and its OpenAPI document has 34 operations on apps, revisions, layers, domains and database instances, with none for sandboxes (source: \u003chttps://api.deno.com/v2/openapi.json\u003e)\n- The Python SDK creates sandboxes over a WebSocket to `wss://\u003cregion\u003e.sandbox-api.deno.net/api/v3/sandboxes/create` and lists them through console.deno.com (source: \u003chttps://github.com/denoland/sandbox-py\u003e)\n- The Create page says a default sandbox has no outbound network access and the Security page says outbound access is unrestricted by default (source: \u003chttps://docs.deno.com/sandbox/create/, https://docs.deno.com/sandbox/security/\u003e)\n- The product page says Deno Deploy is SOC2 and ISO27001 certified, and the pricing table lists SOC2 Type 1 and a DPA under Enterprise only (source: \u003chttps://deno.com/deploy/sandbox, https://deno.com/deploy/pricing\u003e)\n\n## Compare\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Deno Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-deno-sandbox.md): BB 73.1 vs D 50.3\n- [Blaxel Sandboxes vs Deno Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-deno-sandbox.md): C 60.7 vs D 50.3\n- [Cloudflare Sandbox SDK vs Deno Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-deno-sandbox.md): B 67.5 vs D 50.3\n- [Daytona vs Deno Sandbox](https://www.anchorterminal.com/compare/daytona-vs-deno-sandbox.md): B 64.3 vs D 50.3\n- [Deno Sandbox vs E2B](https://www.anchorterminal.com/compare/deno-sandbox-vs-e2b.md): D 50.3 vs B 68.3\n- [Deno Sandbox vs Freestyle](https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md): D 50.3 vs C 58.5\n- [Deno Sandbox vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/deno-sandbox-vs-microsoft-execution-containers.md): D 50.3 vs BB 76.3\n- [Deno Sandbox vs Modal Sandboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-modal-sandboxes.md): D 50.3 vs BB 75.5\n- [Deno Sandbox vs Morph Cloud](https://www.anchorterminal.com/compare/deno-sandbox-vs-morph-cloud.md): D 50.3 vs D 50.8\n- [Deno Sandbox vs Runloop Devboxes](https://www.anchorterminal.com/compare/deno-sandbox-vs-runloop.md): D 50.3 vs B 64.8\n- [Deno Sandbox vs Sprites](https://www.anchorterminal.com/compare/deno-sandbox-vs-sprites.md): D 50.3 vs C 58.3\n- [Deno Sandbox vs Together Code Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md): D 50.3 vs D 53.6\n- [Deno Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-vercel-sandbox.md): D 50.3 vs B 69.6\n- [Agent 37 Cloud vs Deno Sandbox](https://www.anchorterminal.com/compare/agent37-vs-deno-sandbox.md): D 46.1 vs D 50.3\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on deno.com or one of its subdomains, or the README of github.com/denoland/sandbox-py. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"deno-sandbox\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/deno-sandbox\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/deno-sandbox.svg\" alt=\"Deno Sandbox on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Deno Sandbox on Anchor Terminal](https://www.anchorterminal.com/badges/deno-sandbox.svg)](https://www.anchorterminal.com/tools/deno-sandbox)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/deno-sandbox\"\u003eDeno Sandbox on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Deno Sandbox is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/deno-sandbox-dark.png\n- Light: https://www.anchorterminal.com/assets/share/deno-sandbox-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Code execution sandboxes",
        "url": "https://www.anchorterminal.com/categories/code-sandboxes"
      },
      {
        "name": "Deno Sandbox",
        "url": ""
      }
    ],
    "description": "Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the @deno/sandbox JavaScript SDK, the deno-sandbox Python SDK or the deno sandbox CLI, and launched in beta on 3 February 2026.",
    "facts": [
      "rank #689 of 842",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Deno Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/tools-deno-sandbox.png",
    "path": "/tools/deno-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Deno Sandbox review for AI agents, grade D (50.3/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/deno-sandbox"
  },
  "tokens": {
    "markdown": 7350,
    "slim": 1630
  },
  "version": 1
}
