# Freestyle > Freestyle runs full Linux virtual machines for AI agents, with pause and resume that keeps memory, snapshots, private networks and domains. Agents drive it through a REST API, a TypeScript SDK and a CLI from one npm package. - Canonical: https://www.anchorterminal.com/tools/freestyle - Markdown: https://www.anchorterminal.com/tools/freestyle.md (~6,500 tokens) - Slim: https://www.anchorterminal.com/tools/freestyle.min.md (~1,580 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/freestyle.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-09 ## Overview **Grade C · 58.5/100 · rank #520 of 842 · #10 in Code execution sandboxes · not agent-ready · confidence medium** ## Assessment A public OpenAPI 3.1 file describes 88 operations with a stable error code on every failure, and per-VM identity tokens keep the team API key away from end users. No terms of service, product privacy policy, request rate limit or incident history was found, and the only SDK is TypeScript. ## Facts | Field | Value | | --- | --- | | Vendor | Freestyle Cloud Inc. (https://www.freestyle.sh) | | Kind | HTTP API | | Category | Code execution sandboxes (https://www.anchorterminal.com/categories/code-sandboxes) | | Transport | HTTP | | Endpoint | `https://api.freestyle.sh/v5` | | Auth | API key · Bearer API key in the `Authorization` header, read by the SDK and CLI from `FREESTYLE_API_KEY`. Keys are created after a browser login with `freestyle tokens create`, shown once, and listed and revoked from the CLI. No scopes or expiry on account keys were found. For end users, an identity access token in the `x-freestyle-identity-access-token` header reaches only the VMs and Linux users granted to it, on the exec and terminal routes. | | Pricing | Freemium ($0.0403 / vCPU-hr) · Free plan at $0 with 200 vCPU-hours, 400 GiB-hours of memory, 60,000 GiB-hours of storage and 50 GB of transfer a month, up to 10 concurrent VMs, no card needed. Usage beyond that needs Hobby ($50 a month minimum, counted as usage) or Pro ($500). $0.04032 a vCPU-hour, $0.0129 a GiB-hour of memory, $0.000086 a GiB-hour of storage and $0.02 a GB of transfer, metered per second on allocated resources. Enterprise is priced by sales (https://www.freestyle.sh/pricing.md, checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the docs, the OpenAPI file or the pricing page (checked 2026-10-08). | | Licence | Proprietary service with no published terms of service found. The `freestyle` SDK and CLI package on npm is MIT | | Packages | npm: `freestyle` | | Docs | https://www.freestyle.sh/docs | | llms.txt | https://www.freestyle.sh/llms.txt | | Last release | 2026-09-27 | | npm downloads / week | 71,758 | | API | REST at https://api.freestyle.sh/v5, OpenAPI 3.1 with 88 operations for VMs, files, PTY sessions, snapshots, VPCs, firewall, TLS rules, tunnels, domains and identities. The same paths without `/v5` are marked deprecated | | Free plan | $0, no card. 200 vCPU-hours, 400 GiB-hours of memory, 60,000 GiB-hours of storage and 50 GB of transfer a month, as hard allowances. Adding a card charges $1 and refunds it | | Plan limits | Free 10 concurrent VMs, 10 saved VMs, 10 snapshots, 4 vCPU and 8 GiB a VM. Hobby 40, 200, 1,000, 8 vCPU and 16 GiB. Pro 400, 4,000, 12,000, 32 vCPU and 64 GiB | | Default VM | 4 vCPU, 8 GiB memory, 32 GB disk. Resizing is grow-only and live | | Lifecycle | States starting, running, pausing, paused and stopped. `idleTimeoutSeconds`, `ttlSeconds`, `maxRunSeconds`, `maxRunTotalSeconds` and `autoDeleteSeconds` set pause and delete policy. No idle pause unless set | | Exec | `POST /v5/vms/{vmIdOrSlug}/exec-await`, default timeout 30 s, maximum 300 s, stdin up to 1 MiB. PTY sessions over WebSocket can be named and reattached | | Files | Read, write, stat, list and remove over the API, byte-range reads, and resumable uploads up to 16 GiB | | Errors | One body shape with a stable `code` and a `message`. 429 `LIMIT_EXCEEDED` names the plan limit reached | | SDK and CLI | TypeScript only, npm package `freestyle` 0.2.16 (27 September 2026), MIT. The CLI covers VMs, snapshots, VPCs, tunnels, firewall, TLS, domains, identities and API keys, with `--output json` | | Status | www.freestyle.sh/status, three components (Freestyle VMs, API, Dashboard), no incident history | | Enterprise | Custom limits, SAML SSO and SCIM, audit logs, a stated 99.99% SLA, GPU sandboxes and dedicated hardware, all through sales | | Capabilities | sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser | | Tags | hosted, no-card, openapi, llms-txt, typescript, cli, vm, snapshots, enterprise | | JSON | https://www.anchorterminal.com/api/v1/tools/freestyle.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 43 | 8.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 86 | 14.0 | | Agent ergonomics | 13% | 16.2 | 69 | 11.2 | | Security & auth | 14% | 17.5 | 53 | 9.3 | | Payments & pricing | 10% | 12.5 | 45 | 5.6 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 71 | 6.2 | | Transparency & trust (editorial 20, provenance 62) | 7% | 8.8 | 41 | 3.6 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **58.5 → C** | ### Why each score - Reliability 43: Graded on the hosted lines. www.freestyle.sh/status is the vendor's own page with three components (Freestyle VMs, API, Dashboard), all operational, last updated 4 October 2026, with no incident list or component history (10 of 20). No readable history (5). Plan limits are published with numbers (10, 40 and 400 concurrent VMs, per-VM and total resource budgets), but no request rate limit for the API was found in the reviewed documentation (5 of 15). The OpenAPI file documents 429 `LIMIT_EXCEEDED` on VM creation and resize and marks which 409s are safe to retry, resumable uploads take retryable chunks, and a `x-freestyle-background-after-secs` header turns a long call into a polled request. No Retry-After or backoff guidance and no idempotency keys found (8 of 15). The pricing page lists a 99.99% SLA for Enterprise with no SLA document published (5 of 10). The API is served under `/v5` with no beta label (10). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 86: A public OpenAPI 3.1 file at www.freestyle.sh/openapi.json with 88 operations under `/v5` and 128 schemas (25). llms.txt, llms-full.txt, a Markdown twin of every docs page and a read-only shell over the docs at `/docs/bash` (10). Every `/v5` operation has a description, and the about page states when to use the product and when not to (18 of 20). Request bodies are typed with enums, required fields and `additionalProperties: false`, with free-form objects only for metadata and environment variables (13 of 15). Each operation lists its error statuses with a named code and cause, on one `PublicErrorBody` shape, and the docs carry TypeScript and CLI examples but few raw HTTP examples (12 of 15). Paths are versioned at `/v5`, but the changelog has three entries in 2026 (11 April, 17 April, 9 September) and the npm package ships no changelog across 25 releases since 10 July (8 of 15). - Agent ergonomics 69: List calls take `limit` and `offset`, file reads take byte ranges, and paused VMs can be read without starting compute. `exec-await` returns whole stdout and stderr with no documented size control (15 of 25). VM lists filter by state, slug, search, snapshot, VPC and metadata, and snapshot lists by source VM and search (18 of 20). Every error has a stable `code` in SCREAMING_SNAKE_CASE and a message, and limit errors name the limit reached (18 of 20). No idempotency keys. A slug is unique per account and a repeated create answers 409, and the spec says which failures are safe to retry and warns against retrying an exec that returned `VM_NON_RESPONSIVE` (10 of 20). A create call needs only `firewall`, with defaults of 4 vCPU, 8 GiB and 32 GB. The only SDK is TypeScript, shipped with the CLI in one npm package (8 of 15). - Security & auth 53: Account API keys are named, shown once, listed and revoked from the CLI, with no scopes or expiry found. Identity access tokens are separate, limited to granted VMs and named Linux users and to the exec and terminal routes, and revocable one by one (22 of 30). No documented option carries a secret in a URL query string. A new VM has no inbound or outbound network until firewall rules allow it, and identity tokens cannot create team resources. Deleting a VM takes one call with no confirmation step (14 of 20). Credential injection at the edge puts API keys, Postgres passwords and Git tokens on outbound requests without storing them in the VM, and forward auth keeps session cookies out of the guest (12 of 15). Audit logs are listed for Enterprise only, and the April 2026 changelog describes a logs dashboard (5 of 15). `/.well-known/security.txt` answers 404, and no disclosure policy, bug bounty, SOC 2 or ISO 27001 statement was found (0 of 20). - Payments & pricing 45: No x402, MPP or L402 found in the docs, the OpenAPI file or the pricing page (0). Per-unit prices are public, $0.04032 a vCPU-hour, $0.0129 a GiB-hour of memory, $0.000086 a GiB-hour of storage and $0.02 a GB of data transfer (20). The Free plan costs $0 with 200 vCPU-hours and 400 GiB-hours of memory a month and needs no card (20). A person has to sign in through a browser first. After that an agent can mint its own key with `freestyle tokens create --output json`, so 5 of 20 (5). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 71: `freestyle` 0.2.16 was published to npm on 27 September 2026 (30). 25 versions were published between 13 August and 27 September 2026 (20). Closed service with a public changelog of three entries in 2026 and a Discord server, whose response times we did not check (8 of 15). One current official SDK, TypeScript, with the CLI in the same package (10 of 15). The package has three dependencies and no `repository` field, no public CI was found, and the CLI repository linked from the site footer (freestyle-sh/freestyle-sh) last changed on 22 May 2025 (3 of 10). - Transparency & trust 41: The platform is closed. The SDK and CLI are MIT on npm, and no terms of service or service agreement was found on www.freestyle.sh (`/terms`, `/tos` and `/legal` answer 404, and the sitemap lists none), so the terms of use are unclear (8 of 30). The privacy policy, last updated 15 June 2025, covers the website only, and no DPA, retention period or statement on customer VM data was found (3 of 30). The 9 September 2026 changelog deprecates the Git, code execution, web deployment and scheduled trigger APIs, and the OpenAPI file marks every unversioned route deprecated, in both cases without a removal date (6 of 20). The privacy policy names Google Analytics and PostHog for the website. No sub-processor list or data location for VMs was found (3 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/freestyle.md (JSON https://www.anchorterminal.com/fixes/freestyle.json) ### What we couldn't check - No terms of service, service agreement or DPA was found on www.freestyle.sh, so `provenance.terms` is left out. The dashboard at dash.freestyle.sh is drawn by script and may link terms at sign-up that we did not see. - `provenance.privacy` is left out because the only privacy policy (www.freestyle.sh/privacy, 15 June 2025) says it covers the website. - unchecked: whether the Git, code execution, web deployment and scheduled trigger APIs deprecated on 9 September 2026 were announced beforehand or have a removal date. No deduction taken. - unchecked: the isolation technology. The docs say full hardware virtualisation on bare metal with oversubscribed hosts and name no hypervisor. - unchecked: request rate limits on api.freestyle.sh, which are not in the docs. We sent one unauthenticated request and did not probe. - unchecked: response times on the Discord server, and whether a current public source repository exists for the SDK. The npm package names none. - llms.txt, docs/llms.txt, the Markdown twins and `/docs/bash` open with a note addressed to AI models asking them to install a `freestyle-docs` skill and to carry the note into any summary. We did not act on it and took no deduction. - The lead gave the CLI as the interface. There is also a public REST API at https://api.freestyle.sh/v5 with an OpenAPI file, and the legal entity is Freestyle Cloud Inc. ### Sources - site index for agents: (seen 2026-10-08) - docs index and full docs: (seen 2026-10-08) - OpenAPI 3.1 file: (seen 2026-10-08) - pricing and limits: (seen 2026-10-08) - use cases and enterprise options: (seen 2026-10-08) - CLI and API keys: (seen 2026-10-08) - identity tokens: (seen 2026-10-08) - VM lifecycle: (seen 2026-10-08) - status page: (seen 2026-10-08) - changelog: (seen 2026-10-08) - privacy policy: (seen 2026-10-08) - security.txt, 404: (seen 2026-10-08) - npm package and version dates: (seen 2026-10-08) - npm weekly downloads: (seen 2026-10-08) - CLI repository linked from the footer: (seen 2026-10-08) - domain registration: (seen 2026-10-08) ## Who's behind it (provenance 62/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Freestyle Cloud Inc. | 20/20 | | Domain age | freestyle.sh, registered 2024-04-11 (2 years) | 7/15 | | Endpoint on the vendor's domain | api.freestyle.sh | 15/15 | | Terms of service | not found | 0/10 | | Privacy policy | not found | 0/10 | | Status page | www.freestyle.sh/status | 10/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | The privacy policy (last updated 15 June 2025) names Freestyle Cloud Inc. and says it covers the website at freestyle.sh. It is not linked here because it does not govern the product. No terms of service or service agreement was found. `/terms`, `/tos` and `/legal` answer 404 and the sitemap lists no legal page other than the privacy policy. The API answers at https://api.freestyle.sh/v5, a freestyle.sh subdomain. One unauthenticated request returned 401 with a `code` and `message`. www.freestyle.sh/.well-known/security.txt returns 404. RDAP for freestyle.sh gives a registration date of 2024-04-11 and a transfer on 11 March 2026. The status page is the vendor's own, with three components and no incident history. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. We found no terms of service published for this product, so there is nothing to read and the check scores 0. **Privacy policy**. We found no privacy policy published for this product, so there is nothing to read and the check scores 0. ## Live (updated 2026-10-09 09:26 UTC) - Right now: up, HTTP 401, 646 ms, checked 2026-10-09 09:26 UTC (get on `https://api.freestyle.sh/v5`, asks for auth) - Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 574 ms · p95 596 ms - Vendor status page: unknown, no machine-readable status found - Always current: https://www.anchorterminal.com/api/v1/live/freestyle.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Prices | Item | Price | Unit | Note | | --- | --- | --- | --- | | vCPU | $0.0403 | per vCPU-hour | Memory extra at $0.0129 a GiB-hour. 200 vCPU-hours a month included | | Data transfer | $0.02 | per GB of traffic | 50 GB a month included on Free, 500 GB on Hobby and Pro | | Hobby plan | $50 | per month (plan) | Monthly minimum, counted as usage | | Pro plan | $500 | per month (plan) | Monthly minimum, counted as usage | Across all listings: https://www.anchorterminal.com/prices/index.md ## Strengths - Public OpenAPI 3.1 file with 88 `/v5` operations, each with a description and named error codes per status - A new VM has no inbound or outbound network access until firewall rules allow it - Identity access tokens limited to granted VMs and Linux users, revocable without rotating the team API key - Pausing keeps memory and disk, and a paused VM bills for storage only - Free plan at $0 with 200 vCPU-hours a month, and per-unit prices published without a login ## Weaknesses - No terms of service or service agreement found on the site, and the privacy policy covers the website only - The status page shows three components with no incident history - No request rate limit, Retry-After guidance or idempotency keys found in the docs or the OpenAPI file - No security.txt, disclosure policy, bug bounty or SOC 2 statement found. Audit logs are Enterprise only - TypeScript is the only SDK, and the CLI repository linked from the site last changed on 22 May 2025 ## Before you call it (notes for agents) 1. Send a `firewall` object on every `POST /v5/vms`. It is required, and a VM with no rules has no outbound internet 2. Ask the owner to run `freestyle login` in a browser once, then mint a key with `freestyle tokens create --output json` 3. Do not retry an exec that answers 409 `VM_NON_RESPONSIVE`. The command may already have run 4. Keep `exec-await` under its 300,000 ms cap and use a PTY session or `x-freestyle-background-after-secs` for longer work 5. Call the `/v5` paths. The unversioned duplicates in the OpenAPI file are marked deprecated ## Connect Install: ```bash npm install freestyle@latest # CLI without installing: npx freestyle@latest --help ``` Through letme (picks today, calling later): https://letme.dev/freestyle. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | E2B | B | 68.3 | 207 | sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser | no | https://www.anchorterminal.com/tools/e2b.md | | Daytona | B | 64.3 | 320 | sandbox.code, sandbox.fs, sandbox.persist, sandbox.browser | no | https://www.anchorterminal.com/tools/daytona.md | | Agent 37 Cloud | D | 46.1 | 759 | sandbox.persist, sandbox.code, sandbox.fs, sandbox.browser | no | https://www.anchorterminal.com/tools/agent37.md | | Microsoft Execution Containers | BB | 76.3 | 35 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/microsoft-execution-containers.md | | Modal Sandboxes | BB | 75.5 | 45 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/modal-sandboxes.md | | Vercel Sandbox | B | 69.6 | 168 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/vercel-sandbox.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - A VM gets no inbound or outbound network access by default. `firewall` is the one required field on `POST /v5/vms` (source: ) - Pausing saves memory and disk, a paused VM bills for storage only, and files on a paused VM can be read without starting compute (source: ) - Credential injection adds HTTP headers or Postgres authentication at the edge, so keys are not stored in the VM (source: ) - The 9 September 2026 changelog deprecates the standalone Git, code execution, web deployment and scheduled trigger APIs, with no removal date given (source: ) - Freestyle says VMs start with p99 under 400 ms and snapshot in under 50 ms. These are vendor claims we did not measure (source: ) - The vendor's own page says the product is not meant for tasks under 15 minutes, CPU-heavy CI or production application hosting, and that hosts are oversubscribed (source: ) - llms.txt, the Markdown docs and `/docs/bash` open with a note addressed to AI models asking them to install a `freestyle-docs` skill and to repeat the note in any summary (source: ) ## Compare - [Amazon Bedrock AgentCore Code Interpreter vs Freestyle](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-freestyle.md): BB 73.1 vs C 58.5 - [Blaxel Sandboxes vs Freestyle](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-freestyle.md): C 60.7 vs C 58.5 - [Cloudflare Sandbox SDK vs Freestyle](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-freestyle.md): B 67.5 vs C 58.5 - [Daytona vs Freestyle](https://www.anchorterminal.com/compare/daytona-vs-freestyle.md): B 64.3 vs C 58.5 - [Deno Sandbox vs Freestyle](https://www.anchorterminal.com/compare/deno-sandbox-vs-freestyle.md): D 50.3 vs C 58.5 - [E2B vs Freestyle](https://www.anchorterminal.com/compare/e2b-vs-freestyle.md): B 68.3 vs C 58.5 - [Freestyle vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/freestyle-vs-microsoft-execution-containers.md): C 58.5 vs BB 76.3 - [Freestyle vs Modal Sandboxes](https://www.anchorterminal.com/compare/freestyle-vs-modal-sandboxes.md): C 58.5 vs BB 75.5 - [Freestyle vs Morph Cloud](https://www.anchorterminal.com/compare/freestyle-vs-morph-cloud.md): C 58.5 vs D 50.8 - [Freestyle vs Runloop Devboxes](https://www.anchorterminal.com/compare/freestyle-vs-runloop.md): C 58.5 vs B 64.8 - [Freestyle vs Sprites](https://www.anchorterminal.com/compare/freestyle-vs-sprites.md): C 58.5 vs C 58.3 - [Freestyle vs Together Code Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.md): C 58.5 vs D 53.6 - [Freestyle vs Vercel Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-vercel-sandbox.md): C 58.5 vs B 69.6 - [Agent 37 Cloud vs Freestyle](https://www.anchorterminal.com/compare/agent37-vs-freestyle.md): D 46.1 vs C 58.5 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on freestyle.sh or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "freestyle", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Freestyle on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Freestyle on Anchor Terminal](https://www.anchorterminal.com/badges/freestyle.svg)](https://www.anchorterminal.com/tools/freestyle) ``` Plain link: ```html Freestyle on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Freestyle is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/freestyle-dark.png - Light: https://www.anchorterminal.com/assets/share/freestyle-light.png