# Deno Sandbox (slim) > Deno Sandbox runs Linux microVMs on Deno Deploy for untrusted or AI-generated code. It is driven from the @deno/sandbox JavaScript SDK, the deno-sandbox Python SDK or the deno sandbox CLI, and launched in beta on 3 February 2026. - Full: https://www.anchorterminal.com/tools/deno-sandbox.md (~7,350 tokens) · this version ~1,630 tokens · JSON https://www.anchorterminal.com/tools/deno-sandbox.json · canonical https://www.anchorterminal.com/tools/deno-sandbox - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **D · 50.3/100 · rank #689 of 842 · #14 in Code execution sandboxes · not agent-ready · confidence medium** Assessment: Secrets stay outside the microVM and are substituted only on outbound requests to approved hosts, and an allowlist limits egress. The service is still in beta, sandboxes need the $20 Pro plan, lifetime is capped at 30 minutes, and no sandbox operation appears in the published OpenAPI document. ## Facts - Kind: HTTP API · vendor: Deno Land Inc. · category: Code execution sandboxes · legal entity: Deno Land Inc. · provenance 80/100 - Local only (HTTP): npm `@deno/sandbox`, pypi `deno-sandbox` - Auth: API key · pricing: Paid · x402: no · licence: Proprietary service under the Deno Deploy terms and conditions. The `@deno/sandbox` and `deno-sandbox` SDKs are MIT - Probe metrics: not measured yet (probes haven't run) - Release status: Beta since 3 February 2026. The docs call the present phase pre-release - Interfaces: `@deno/sandbox` on npm and JSR (0.13.2, 16 March 2026), `deno-sandbox` on PyPI (0.16.0, 22 July 2026, sync and async), and `deno sandbox` commands in the Deno CLI. No sandbox operations in the published OpenAPI document - Isolation: One Firecracker microVM per sandbox per the product page, with outbound traffic routed through a policy proxy - Resources: 2 vCPUs, 768 MB to 4,096 MB of memory (default about 1.2 GB), 10 GB of ephemeral disk - Lifetime: Ends with the client session by default. A duration timeout keeps it alive for reconnection, extendable, to a maximum of 30 minutes - Concurrency: 3 per region on Pro and 20 on Builder per the pricing table. The docs give 5 per organisation as the pre-release default - Regions: `ams` (Amsterdam) and `ord` (Chicago). Volumes only in `ord` - Persistence: Volumes of 300 MB to 20 GB, mountable read-only, removed 24 hours after deletion. Read-only snapshots made from bootable volumes, with `builtin:debian-13` the only base image - Network and secrets: `allowNet` allowlist by hostname, wildcard, port or IP address. Secrets substituted outside the VM for named hosts - Access from outside: `exposeHttp` gives a public URL without authentication, plus SSH and a browser editor - Observability: Commands, HTTP requests and SSH sessions traced in the Deploy dashboard, with an event log per sandbox. Logs and traces kept 1 week on Pro - Status: denostatus.com on Instatus, with Deno Deploy component groups and no component named for sandboxes - SLA and compliance: 99.95 per cent reliability SLA, SOC2 Type 1 and a DPA listed under Enterprise only - Prices: Active CPU beyond plan allowance $0.10 per vCPU-hour; Volume storage beyond plan allowance $0.20 per GB per month; Pro plan, the lowest that includes sandboxes $20 per month (plan) - Scores: Reliability 48, Performance pending, Schema & documentation 66, Agent ergonomics 60, Security & auth 61, Payments & pricing 20, Task success pending, Maintenance & community 45, Transparency & trust 58 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Hosted lines. · Schema & documentation, The published OpenAPI document has no sandbox operations, so the typed TypeScript SDK reference on JSR and the typed Python SDK count as 15… · Agent ergonomics, Sandbox and volume objects are small, and command output streams (15). · Security & auth, One organisation token with no scopes or expiry found, rotatable from the dashboard, which also manages the organisation's Deploy apps. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, `deno-sandbox` 0.16.0 on 22 July 2026, 78 days ago. · Transparency & trust, The SDKs are MIT and the platform is closed under terms last modified 30 September 2026 (18). - Sources: 27, open questions: 9, both in the full twin - Capabilities: sandbox.code, sandbox.fs, sandbox.persist - JSON: https://www.anchorterminal.com/api/v1/tools/deno-sandbox.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/deno-sandbox.svg` or a link to https://www.anchorterminal.com/tools/deno-sandbox from a page on deno.com or one of its subdomains, or the README of github.com/denoland/sandbox-py, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Set `DENO_DEPLOY_TOKEN` to an organisation token (prefix `ddo_`) from Settings in console.deno.com. The organisation must be on Pro or above 2. Pass `allowNet` on every `Sandbox.create()`. The Security page says outbound access is unrestricted when it is omitted 3. Pass credentials through `secrets` with a `hosts` list, not `env`, so code in the VM sees only a placeholder 4. The default timeout ends the VM when the client disconnects. Pass a duration such as `"10m"` and reconnect with `Sandbox.connect({ id })`, up to 30 minutes 5. Create volumes in `ord` and start the sandbox in `ord`. A volume mounts only in its own region 6. `exposeHttp` URLs are public with no authentication. Treat the random subdomain as a secret ## Connect ```bash npm install @deno/sandbox # or pip install deno-sandbox ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/deno-sandbox ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Microsoft Execution Containers | BB | 76.3 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md | | Modal Sandboxes | BB | 75.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/modal-sandboxes.min.md | | Vercel Sandbox | B | 69.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/vercel-sandbox.min.md | | E2B | B | 68.3 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/e2b.min.md | | Cloudflare Sandbox SDK | B | 67.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)