# Microsoft Execution Containers > Microsoft Execution Containers (MXC) is an open-source SDK for running untrusted code in a local sandbox on Windows, Linux and macOS. An application embeds it through Node.js, .NET or Rust and sets filesystem, network and UI policy for each run. - Canonical: https://www.anchorterminal.com/tools/microsoft-execution-containers - Markdown: https://www.anchorterminal.com/tools/microsoft-execution-containers.md (~8,200 tokens) - Slim: https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md (~1,980 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/microsoft-execution-containers.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade BB · 76.3/100 · rank #34 of 629 · #1 in Code execution sandboxes · agent-ready · confidence medium** More from Microsoft, listed separately because each is its own product: [Microsoft Foundry fine-tuning (Azure OpenAI)](https://www.anchorterminal.com/tools/azure-foundry-fine-tuning.md) (Fine-tuning), [Azure AI Content Safety (Prompt Shields)](https://www.anchorterminal.com/tools/azure-ai-content-safety.md) (Guardrails & safety filters), [Azure AI Speech speech-to-text](https://www.anchorterminal.com/tools/azure-speech-to-text.md) (Speech-to-text), [Azure AI Speech text-to-speech](https://www.anchorterminal.com/tools/azure-text-to-speech.md) (Text-to-speech), [Microsoft Agent Framework](https://www.anchorterminal.com/tools/microsoft-agent-framework.md) (Agent frameworks & SDKs), [Microsoft Entra Agent ID](https://www.anchorterminal.com/tools/microsoft-entra-agent-id.md) (Agent auth & delegated access), [Azure Key Vault](https://www.anchorterminal.com/tools/azure-key-vault.md) (Secrets & credential vaults), [Azure DevOps MCP Server](https://www.anchorterminal.com/tools/azure-devops-mcp.md) (Code & developer platforms), [Microsoft Learn MCP Server](https://www.anchorterminal.com/tools/microsoft-learn-mcp.md) (Code & developer platforms), [Playwright MCP](https://www.anchorterminal.com/tools/playwright-mcp.md) (Browser automation), [Azure MCP Server](https://www.anchorterminal.com/tools/azure-mcp.md) (Cloud & infrastructure), [Azure Translator](https://www.anchorterminal.com/tools/azure-translator.md) (Translation), [Microsoft Graph Calendar API](https://www.anchorterminal.com/tools/microsoft-graph-calendar.md) (Calendars & scheduling), [Microsoft Dynamics 365 Sales](https://www.anchorterminal.com/tools/dynamics-365-sales.md) (CRM & customer platforms), [Microsoft Advertising API](https://www.anchorterminal.com/tools/microsoft-advertising-api.md) (Advertising & campaign operations), [Microsoft Excel (Microsoft Graph workbook API)](https://www.anchorterminal.com/tools/microsoft-excel-graph.md) (Spreadsheets & operational tables), [Outlook Mail (Microsoft Graph)](https://www.anchorterminal.com/tools/outlook-mail-graph.md) (Mailbox access). ## Assessment MXC puts nine operating-system sandbox backends behind one typed request, with network access denied by default and a JSON Schema for the stable 1.0.0 contract. Version 1.0.0 is two days old as of 8 October 2026. Enforcement varies by backend, and `isolation_session` cannot restrict networking at all. ## Facts | Field | Value | | --- | --- | | Vendor | Microsoft (https://github.com/microsoft/mxc) | | Kind | SDK + MCP | | Category | Code execution sandboxes (https://www.anchorterminal.com/categories/code-sandboxes) | | Auth | None · No account, key or sign-in. MXC is a library the host application loads in its own process, so it holds no credential of its own. The workload runs with whatever the request grants. Network egress, ingress and host loopback resolve to `deny` when omitted, and filesystem access is limited to the `readonlyPaths` and `readwritePaths` the caller lists. On Windows the `isolation_session` backend creates a separate agent user account for each container and returns its name and SID. | | Pricing | Free (Free · OSS) · Free. The SDKs and native runtime are MIT and install from npm, NuGet and crates.io with no account or card. There is no hosted service and nothing to buy. Compute is the owner's own machine. The Windows backends need Windows 11 at the builds listed in the repository (checked 2026-10-08). | | x402 | No · No x402, MPP or L402 in the README, the docs or the SDK source. Local open-source software with no paid endpoint (checked 2026-10-08). | | Licence | MIT | | Packages | npm: `@microsoft/mxc-sdk`; nuget: `Microsoft.Mxc.Sdk` | | Source | https://github.com/microsoft/mxc | | Docs | https://github.com/microsoft/mxc/blob/main/docs/api-reference/README.md | | llms.txt | not found | | Last release | 2026-10-06 | | GitHub stars | 1,506 (as of 2026-10-08) | | npm downloads / week | 471,674 | | Interfaces | Node.js `@microsoft/mxc-sdk/v1`, .NET `Microsoft.Mxc.Sdk.V1` and Rust `mxc_sdk::v1`, loaded in the host application's process. Executor binaries such as `wxc-exec.exe` take a JSON request for testing or where the SDK can't be embedded. No MCP server and no HTTP API (https://github.com/microsoft/mxc/blob/main/README.md) | | Backends | Windows 11 x64 and ARM64 with `processcontainer` (default), `isolation_session`, `wslc`, and experimental `windows_sandbox`, `microvm` and `hyperlight`. Linux x64 and ARM64 with `bubblewrap` (default), `lxc`, `microvm` and `hyperlight`. macOS ARM64 and x64 with `seatbelt` | | V1 creation choices | The Node V1 `Containment` union accepts `process` (the default intent), `processcontainer`, `wslc`, `lxc`, `seatbelt`, `isolation_session` and `bubblewrap` (https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/types.md) | | Operations | `run` for captured output, `spawn` for live pipes, `spawnWithPty` for a terminal, then `provisionContainer`, `startContainer`, `runInContainer`, `stopContainer` and `deprovisionContainer` for persistent containers, and `validate*` dry-runs (https://github.com/microsoft/mxc/blob/main/docs/api-reference/node/v1/api.md) | | Policy | Filesystem lists (`readonlyPaths`, `readwritePaths`, `deniedPaths`), directional network rules by CIDR, protocol and port or a caller-managed proxy, and UI controls for clipboard and input injection. Network defaults to deny in every direction | | Persistence | Provision, start, execute, stop and deprovision for `isolation_session` and `wslc` only in V1. No snapshot or pause and resume was found in the reviewed documentation | | Request schema | Draft-07 JSON Schema for the stable 1.0.0 contract at schemas/stable/mxc-config.schema.1.0.0.json. 0.9.0-alpha is the minimum supported contract and 1.1.0-alpha is the development contract (https://github.com/microsoft/mxc/blob/main/docs/schema.md) | | Errors | `MxcError` with 12 codes (`malformed_request`, `unsupported_containment`, `backend_unavailable`, `stale_id`, `policy_validation`, `backend_error` and others), plus optional `operation`, `nativeCode` and `remediation` | | Runtimes | Node.js 24 or later, and on Windows 24.21.0 or 26.8.0 for native stdio. Rust is pinned to 1.93 for source builds. Windows 11 24H2 needs build 26100.9278 for process isolation and 26100.9550 for session isolation (https://github.com/microsoft/mxc/blob/main/docs/backends/process-container/os-version-support.md) | | Packages | npm @microsoft/mxc-sdk 1.0.0 (6 October 2026, 37.7 MB tarball with native binaries for every platform), crates.io mxc-sdk 1.0.0 (6 October), NuGet Microsoft.Mxc.Sdk 1.0.0 (7 October) | | Telemetry | Off by default. Official builds can send ETW diagnostic events on Windows only when the run opts in, the user has consented and policy under HKLM\SOFTWARE\Policies\Mxc permits. The docs say events hold no commands, file paths or credentials | | Diagnostics | `--debug` output, a deny-and-record capture of blocked accesses on ProcessContainer, and local JSON audit records through `--log-file` on the executors. `--audit` disables the sandbox and is for trusted tools only | | Security reporting | SECURITY.md sends reports to MSRC, Microsoft's security response team. No advisories are published on the repository (https://github.com/microsoft/mxc/security/advisories) | | Capabilities | sandbox.code, sandbox.fs, sandbox.persist | | Tags | sdk, open-source, local, free, no-auth, no-card, typescript, dotnet, rust, windows, linux, macos, json-schema, new-1.0 | | JSON | https://www.anchorterminal.com/api/v1/tools/microsoft-execution-containers.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 81 | 16.2 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 81 | 13.2 | | Agent ergonomics | 13% | 16.2 | 74 | 12.0 | | Security & auth | 14% | 17.5 | 69 | 12.1 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 92 | 8.1 | | Transparency & trust (editorial 86, provenance 79) | 7% | 8.8 | 83 | 7.3 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **76.3 → BB** | ### Why each score - Reliability 81: Read with the local-software lines, because MXC is a library the owner runs. Official packages on npm, NuGet and crates.io. Node.js 24 or later is stated and Windows 11 builds are listed per release, but the README gives no minimum host version for Linux or macOS (18 of 20). The Build workflow runs lint, Windows, Linux and macOS builds and SDK unit and integration tests on every push to main. Of the last 14 completed runs on main, 10 passed and 4 failed, and the newest (7 October 2026) passed. A flaky test is tracked in issue #1365 (18 of 25). 38 open issues against 261 closed. Ten open issues carry the bug label, seven of them filed since 15 September, and three outside reports from 24 September to 2 October have no reply (19 of 25). The changelogs follow Keep a Changelog with breaking changes marked, and the v1.0.0 release notes have a breaking-changes section. The Node and .NET changelogs still list the V1 changes under Unreleased with no 1.0.0 heading (11 of 15). Version 1.0.0, which the release notes call the first stable release (15). It was published on 6 October 2026, two days before this check, and three backends are marked experimental. - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 81: Read as an SDK with a published request contract. A draft-07 JSON Schema for the stable 1.0.0 request sits in the repository, and the Node SDK ships TypeScript declarations (25). No llms.txt. The docs are Markdown files in the repository (5 of 10). The API reference states what each operation does and has a table for choosing between captured, piped and terminal execution, and the backend guides say which policies each backend enforces and which are cooperative (15 of 20). Containment is a closed union, network actions and clipboard levels are enums, the schema has 33 enums and 39 objects closed to extra properties, and 135 of 150 properties carry a description. `command` is one free string (13 of 15). Ten sample scenarios, each in Rust, .NET and Node. The 12 error codes are a closed type, but we found no page that explains each one (11 of 15). A versioned `/v1` entry point, a schema version table with retired contracts, a changelog for each SDK and GitHub release notes. The Node changelog has no 1.0.0 entry (12 of 15). - Agent ergonomics 74: One request type with `command` as the only required field, and `run` returns stdout, stderr, the exit code, a timeout flag and warnings. We found no documented cap on captured output, and the npm package is a 37.7 MB tarball (18 of 25). `spawn` streams output and `timeoutMs` bounds a run, but there is no truncation or size control on captured output (10 of 20). `MxcError` carries one of 12 codes with optional operation, native code and remediation, and a deny-and-record mode lists blocked accesses on ProcessContainer (18 of 20). `validate*` calls dry-run every lifecycle step, and lifecycle state errors are typed (`already_started`, `stale_id`). Issue #1429, open since 6 October, reports a second deprovision returning success. Not an MCP server, so no tool annotations apply (13 of 20). Network, filesystem and UI policy default to deny, and official SDKs exist for Node.js, .NET and Rust (15). - Security & auth 69: No credentials to issue or leak, because the library runs in the caller's process, so the middle band (20 of 30). Least privilege is the product's job. Egress, ingress and host loopback default to deny, filesystem access is limited to listed paths, UI access is denied when omitted, and validation rejects a policy the chosen backend can't enforce. The limits are documented. `isolation_session` cannot restrict networking, proxy routing is cooperative on Seatbelt and WSLC, the Windows DACL fallback that edits host file permissions is allowed by default, and `--audit` turns the sandbox off (17 of 20). The workload's output is untrusted content. The SDK keeps warnings and denial metadata out of stdout and stderr, but we found no guidance for an agent reading that output (8 of 15). Local JSON audit records for process exits, tier fallbacks, teardown and rejected configs through `--log-file` on the executors, and the deny-and-record capture. We found no equivalent switch documented for the in-process SDKs (10 of 15). SECURITY.md sends reports to MSRC, CodeQL runs in CI and the repository has a fuzzing pipeline. No advisories are published, although at least 20 enforcement gaps were fixed through public issues between August and October 2026. The security.txt on microsoft.com expired on 23 September 2026, and the Node SDK's PATH-resolved `whoami` at import (issue #1265) has had no reply since 24 September (14 of 20). - Payments & pricing 60: Read with the self-hosted rule. No x402, MPP or L402 (0 of 40). MIT software with nothing to buy and no hosted option, so 20 for pricing, 20 for free use with no card and 20 because an agent can install it from npm with no account. - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 92: v1.0.0 on 6 October 2026 (30). Three npm releases in the last 90 days, 0.8.0 on 22 August, 0.9.0 on 28 September and 1.0.0 on 6 October (20). 261 issues closed against 38 open, with issue forms, triage labels and fixes that land within days (issue #1430 was opened on 6 October and closed on 7 October). Three outside bug reports filed between 24 September and 2 October have no comment (19 of 25). Official SDKs for Node.js, .NET and Rust, all at 1.0.0 (15). A package-lock check, CodeQL and Dependabot for GitHub Actions in CI. The npm package has no `repository` field and no provenance attestation (8 of 10). - Transparency & trust 83: MIT for the repository and for the published npm package, whose `LICENSE.md` we compared with the repository's (30). Local software with no service behind it. The telemetry docs list what the optional Windows events contain (version, backend, bounded outcomes, policy fingerprints) and what they omit (commands, file paths, credentials, free-form error text), and the consent prompt links Microsoft's privacy statement. No retention period for those events is stated (24 of 30). The release notes name V1 as the compatibility boundary for 1.x under semver 2.0, breaking changes need a new versioned surface, and the schema docs mark retired contracts. No notice period with dates was found (12 of 20). Telemetry is disclosed in the README, off by default, opt-in for each run, subject to user consent and an administrative block, and absent on Linux and macOS (20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (18 items): https://www.anchorterminal.com/fixes/microsoft-execution-containers.md (JSON https://www.anchorterminal.com/fixes/microsoft-execution-containers.json) ### What we couldn't check - The scout was right on vendor, packages, licence and category. One correction. The repository now carries a stability label, because the v1.0.0 release notes of 7 October 2026 call it the first stable release. The June blog's early preview label predates that. - The repository README names the product Microsoft eXecution Container (MXC), and the blog and the npm description say Microsoft Execution Containers. The listing uses the blog's form. - Why npm shows 471,674 weekly downloads for a package that reached 1.0.0 on 6 October. The blog says GitHub Copilot CLI adopted MXC, which may account for it, but we did not confirm the dependency. - Whether MXC falls under a Microsoft bug bounty programme. SECURITY.md points to MSRC in general terms. - Whether the 20 or more enforcement gaps fixed through public issues between August and October 2026 affected any published npm version on a default backend. We took no deduction. - unchecked: the GitHub REST API refused our reader with a rate limit, so the repository's creation date, the full release asset list and reply times on issues were not read. Star count and release dates came from the web pages. - unchecked: how long Microsoft retains the optional Windows telemetry events. - unchecked: nothing was installed or run. Start time, isolation and enforcement claims are the vendor's documentation, not our measurement. ### Sources - repository README (backends, packages, telemetry summary, audit mode): (seen 2026-10-08) - v1.0.0 release notes: (seen 2026-10-08) - npm registry record (versions, dates, engines, maintainers): (seen 2026-10-08) - npm weekly downloads: (seen 2026-10-08) - Rust crate record: (seen 2026-10-08) - NuGet registration record: (seen 2026-10-08) - Node SDK README: (seen 2026-10-08) - Node SDK changelog: (seen 2026-10-08) - Node V1 operation signatures: (seen 2026-10-08) - Node V1 types, including the error codes: (seen 2026-10-08) - configuration schema, network defaults and contract versions: (seen 2026-10-08) - stable 1.0.0 JSON Schema: (seen 2026-10-08) - telemetry policy and consent: (seen 2026-10-08) - telemetry architecture, event contents and local audit records: (seen 2026-10-08) - Windows build requirements: (seen 2026-10-08) - Seatbelt backend guide (cooperative proxy): (seen 2026-10-08) - Build workflow runs on main: (seen 2026-10-08) - open issues: (seen 2026-10-08) - issue on the PATH-resolved whoami at import: (seen 2026-10-08) - issue on LXC container-to-host egress, closed 16 September 2026: (seen 2026-10-08) - security advisories: (seen 2026-10-08) - Microsoft security reporting policy: (seen 2026-10-08) - security.txt: (seen 2026-10-08) - announcement on the Windows Developer Blog, 2 June 2026: (seen 2026-10-08) - domain registration (RDAP): (seen 2026-10-08) ## Who's behind it (provenance 79/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Microsoft Corporation | 20/20 | | Domain age | microsoft.com, registered 1991-05-02 (35 years) | 15/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | nothing hosted, so the MIT licence stands in | 10/10 | | Privacy policy | published, but our reader couldn't read it | 7/10 | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | published but past its Expires date | 5/10 | The repository is under GitHub's microsoft organisation, `LICENSE.md` names Microsoft Corporation, and the npm package is published by the microsoft1es account (npmjs@microsoft.com). www.microsoft.com/.well-known/security.txt loads and points to the MSRC researcher portal, but its Expires field is 2026-09-23T16:00:00.000Z, which had passed on 8 October 2026. RDAP for microsoft.com gives a registration date of 1991-05-02. No terms page applies to the open-source SDK beyond the MIT licence. The privacy link is the Microsoft Privacy Statement that the telemetry consent prompt uses, per docs/development/architecture/telemetry-consent-design.md. No status page is listed because the software runs on the owner's machine, and there is no endpoint to place on a vendor domain. https://learn.microsoft.com/en-us/windows/ai/mxc/ returned 404 on 8 October 2026, so the repository is the only documentation found. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The MIT licence stands in and the check scores in full. **Privacy policy** (https://go.microsoft.com/fwlink/?linkid=521839), read 2026-10-08. Our reader couldn't read it (robots.txt asks readers like ours not to fetch it). ## Live (updated 2026-10-08 18:20 UTC) - github `microsoft/mxc` v1.0.0, released 2026-10-07 - npm `@microsoft/mxc-sdk` 1.0.0 - security.txt: expired, expires 2026-09-23T16:00:00.000Z - Watching privacy - Always current: https://www.anchorterminal.com/api/v1/live/microsoft-execution-containers.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - MIT licence, with SDKs for Node.js, .NET and Rust all at 1.0.0 and the native runtime bundled in the npm and NuGet packages - Egress, ingress and host loopback default to `deny`, and filesystem access is limited to listed read-only and read-write paths - A draft-07 JSON Schema for the stable 1.0.0 request, with descriptions on 135 of 150 properties - Errors carry one of 12 typed codes plus an optional remediation, and `validate*` calls dry-run a request without creating a container - Telemetry is opt-in, Windows-only and gated on user consent and an administrative policy that can only block it ## Weaknesses - 1.0.0 shipped on 6 October 2026, and the Node changelog still lists the V1 changes under Unreleased - Enforcement differs by backend. `isolation_session` cannot restrict networking, and proxy routing is cooperative on Seatbelt and WSLC - Persistent containers exist only for `isolation_session` and `wslc`, both on Windows - On Windows the Node SDK runs a PATH-resolved `whoami` at import, reported on 24 September 2026 and still open - The npm package is 37.7 MB compressed, needs Node.js 24 or later, and carries no `repository` field or provenance attestation ## Before you call it (notes for agents) 1. Import from `@microsoft/mxc-sdk/v1`. The package root exports nothing. 2. Call `getPlatformSupport()` first and stop if `isSupported` is false. `getAvailableBackends()` is advisory and launch-time validation still applies. 3. Set `network.egress.default` to `allow` only when the task needs it. Omitted network policy resolves to deny in every direction. 4. Never pass `--audit` to an executor for untrusted code. It turns off all sandbox security for the workload. 5. Read `ExecutionResult.warnings` after each run. Security warnings arrive there and are not written to stdout or stderr. ## Connect Install: ```bash npm install @microsoft/mxc-sdk ``` Through letme (picks today, calling later): https://letme.dev/microsoft-execution-containers (letme picks it for sandbox.code, the top-graded tool for the job, letme picks it for sandbox.fs, the top-graded tool for the job, letme picks it for sandbox.persist, the top-graded tool for the job). letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | Modal Sandboxes | BB | 75.5 | 41 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/modal-sandboxes.md | | Vercel Sandbox | B | 69.6 | 144 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/vercel-sandbox.md | | E2B | B | 68.3 | 174 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/e2b.md | | Cloudflare Sandbox SDK | B | 67.5 | 191 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md | | Runloop Devboxes | B | 64.8 | 245 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/runloop.md | | Daytona | B | 64.3 | 256 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/daytona.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - v1.0.0 was published to npm and crates.io on 6 October 2026 and to NuGet and GitHub releases on 7 October. The release notes call it the first stable release and commit the 1.x line to semver 2.0 (source: ) - Microsoft announced MXC on 2 June 2026 as an early preview. The same post says GitHub Copilot CLI adopted MXC process isolation and that NVIDIA's OpenShell on Windows is built on it (source: ) - Nine backends are named in the README. `processcontainer` is the Windows default, `bubblewrap` the Linux default and `seatbelt` the only macOS backend. `windows_sandbox`, and `microvm` and `hyperlight` on Windows, are marked experimental (source: ) - Network policy is deny by default. Egress, ingress and host loopback each resolve to `deny` when the request omits them (source: ) - Telemetry is off unless the run opts in, the Windows user has consented and administrative policy permits it. It is a no-op on Linux and macOS, and local open-source builds send nothing to Microsoft (source: ) - On Windows the Node SDK runs `whoami` through the shell when the module loads, resolved from PATH. The report has been open since 24 September 2026 and the call is still in the published 1.0.0 package (source: ) - npm recorded 471,674 downloads of @microsoft/mxc-sdk in the week of 28 September to 4 October 2026, against 20 total downloads of the Rust crate published on 6 October (source: , ) ## Compare - [Blaxel Sandboxes vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-microsoft-execution-containers.md): C 60.7 vs BB 76.3 - [Cloudflare Sandbox SDK vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-microsoft-execution-containers.md): B 67.5 vs BB 76.3 - [Daytona vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/daytona-vs-microsoft-execution-containers.md): B 64.3 vs BB 76.3 - [E2B vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/e2b-vs-microsoft-execution-containers.md): B 68.3 vs BB 76.3 - [Microsoft Execution Containers vs Modal Sandboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-modal-sandboxes.md): BB 76.3 vs BB 75.5 - [Microsoft Execution Containers vs Morph Cloud](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-morph-cloud.md): BB 76.3 vs D 50.8 - [Microsoft Execution Containers vs Runloop Devboxes](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-runloop.md): BB 76.3 vs B 64.8 - [Microsoft Execution Containers vs Vercel Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-vercel-sandbox.md): BB 76.3 vs B 69.6 - [Agent 37 Cloud vs Microsoft Execution Containers](https://www.anchorterminal.com/compare/agent37-vs-microsoft-execution-containers.md): D 46.1 vs BB 76.3 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on microsoft.com or one of its subdomains, a page under github.com/microsoft, or the README of github.com/microsoft/mxc. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "microsoft-execution-containers", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Microsoft Execution Containers on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Microsoft Execution Containers on Anchor Terminal](https://www.anchorterminal.com/badges/microsoft-execution-containers.svg)](https://www.anchorterminal.com/tools/microsoft-execution-containers) ``` Plain link: ```html Microsoft Execution Containers on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Microsoft Execution Containers is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/microsoft-execution-containers-dark.png - Light: https://www.anchorterminal.com/assets/share/microsoft-execution-containers-light.png