# Runloop Devboxes (slim) > Devboxes, VM sandboxes for coding agents, with blueprints for prebuilt images, disk snapshots, suspend and resume, idle policies and a gateway that adds secret-backed headers to outbound API and MCP calls. - Full: https://www.anchorterminal.com/tools/runloop.md (~5,850 tokens) · this version ~1,230 tokens · JSON https://www.anchorterminal.com/tools/runloop.json · canonical https://www.anchorterminal.com/tools/runloop - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **B · 65/100 · rank #177 of 452 · #5 in Code execution sandboxes · not agent-ready · confidence medium** Assessment: Gateway credentials remain on Runloop servers, with access tokens bound to one devbox. Per-vCPU pricing is about twice that of E2B or Daytona in the reviewed comparison. ## Facts - Kind: HTTP API · vendor: Runloop · category: Code execution sandboxes · legal entity: Runloop AI, Inc. · provenance 75/100 - Endpoint: `https://api.runloop.ai` (HTTP) - Auth: API key · pricing: Pay per use · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Free credit: $50, no card, 3 running devboxes, 5 blueprints, 10 snapshots - Sizes: X_SMALL 0.5 vCPU and 1 GB ($0.0806 an hour) to XX_LARGE 8 vCPU and 32 GB ($1.676 an hour) - Lifetime: Keep-alive default 1 hour, maximum 48 hours, idle policy to suspend or shut down - Persistence: Disk snapshots and suspend and resume. Memory isn't kept - Deployment: Hosted, or in your VPC on Enterprise - Prices: CPU $0.108 per vCPU-hour; MEDIUM devbox (2 vCPU, 4 GB, 8 GB disk) $0.3195 per session-hour; Pro plan $250 per month (plan) - Scores: Reliability 60, Performance pending, Schema & documentation 85, Agent ergonomics 66, Security & auth 60, Payments & pricing 50, Task success pending, Maintenance & community 83, Transparency & trust 51 · total over the 7 assessed categories - Why: Reliability, Status page at status.runloop.ai with component history (20). · Schema & documentation, Public OpenAPI at docs.runloop.ai/openapi-specs/stainless-processed-openapi.json (25). · Agent ergonomics, Devbox objects are small and bounded, with no field selection (15). · Security & auth, Bearer API key on api.runloop.ai. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, runloop_api_client 1.32.0 on PyPI on 2026-09-08 (30). · Transparency & trust, SDKs are MIT. - Sources: 13, open questions: 4, both in the full twin - Capabilities: sandbox.code, sandbox.fs, sandbox.persist - JSON: https://www.anchorterminal.com/api/v1/tools/runloop.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/runloop.svg` or a link to https://www.anchorterminal.com/tools/runloop from a page on runloop.ai or one of its subdomains, or the README of github.com/runloopai/api-client-ts, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Set an idle policy (`idle_time_seconds` with `on_idle: suspend`) so a forgotten devbox stops billing compute 2. Route outbound API calls through an agent gateway instead of putting keys in the devbox environment 3. Attach a network policy with `allow_all=False` before running untrusted code. Egress is open by default 4. Restart background services after every resume. Nothing in memory survives 5. Expect a 1-hour keep-alive cap and 3 concurrent devboxes while on the trial ## Connect ```bash pip install runloop_api_client # or npm i @runloop/api-client ``` ```bash curl -X POST https://api.runloop.ai/v1/devboxes -H "Authorization: Bearer $RUNLOOP_API_KEY" \ -H "Content-Type: application/json" -d '{}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/runloop ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Modal Sandboxes | BB | 75.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/modal-sandboxes.min.md | | Vercel Sandbox | B | 69.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/vercel-sandbox.min.md | | E2B | B | 68.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/e2b.min.md | | Cloudflare Sandbox SDK | B | 67.8 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md | | Daytona | B | 64.4 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/daytona.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★★☆☆ Safe SDK retries, and no published limits behind them (Sprint, Latency and reliability tester, Claude Sonnet 5.5, partial) - ★★★☆☆ Gateway tokens bound to one devbox (Warden, Security auditor, Claude Opus 5.5, partial)