{
  "data": {
    "similar": [
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/microsoft-execution-containers.json",
        "name": "Microsoft Execution Containers",
        "score": 76.3,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "microsoft-execution-containers"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/modal-sandboxes.json",
        "name": "Modal Sandboxes",
        "score": 75.5,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "modal-sandboxes"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/vercel-sandbox.json",
        "name": "Vercel Sandbox",
        "score": 69.6,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "vercel-sandbox"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/e2b.json",
        "name": "E2B",
        "score": 68.3,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "e2b"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.json",
        "name": "Cloudflare Sandbox SDK",
        "score": 67.5,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "cloudflare-sandbox-sdk"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/runloop.json",
        "name": "Runloop Devboxes",
        "score": 64.8,
        "shared": [
          "sandbox.code",
          "sandbox.fs",
          "sandbox.persist"
        ],
        "slug": "runloop"
      }
    ],
    "tool": {
      "slug": "together-code-sandbox",
      "name": "Together Code Sandbox",
      "vendor": "Together AI",
      "vendorUrl": "https://www.together.ai",
      "kind": "http-api",
      "category": "code-sandboxes",
      "summary": "Together AI's hosted virtual machine sandboxes for running commands and code, built from Docker-image snapshots and driven from the `together-sandbox` Python SDK, TypeScript SDK or CLI. Access is by allowlist, on request to Together.",
      "url": "https://www.anchorterminal.com/tools/together-code-sandbox",
      "markdownUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json",
      "repo": "https://github.com/togethercomputer/together-sandbox",
      "license": "Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://api.bartender.codesandbox.io",
      "packages": [
        {
          "registry": "pypi",
          "name": "together-sandbox"
        },
        {
          "registry": "npm",
          "name": "together-sandbox"
        }
      ],
      "auth": "api-key",
      "authNotes": "Access is by allowlist. The docs say the `together-sandbox` SDK and CLI must be enabled for an organisation and to contact Together to request it. Once enabled, a project-scoped Together API key is sent as a Bearer token, read from `TOGETHER_API_KEY`. Keys are revocable, can carry an expiry date and have no finer scopes. Each running sandbox also has its own agent token for the in-VM API, which the SDKs handle.",
      "pricing": "usage",
      "pricingNotes": "The pricing page lists Code Sandbox compute at $0.0446 per vCPU-hour and $0.0149 per GiB of RAM per hour, and does not say whether that rate covers the new SDK as well as the legacy one. No free tier or sandbox lets an agent start without a contract. Together has no free trial, platform access needs a $15 first credit purchase, and the organisation must then be enabled on request (https://www.together.ai/pricing, https://docs.together.ai/docs/billing-credits).",
      "priceSummary": "$0.0446 / vCPU-hr",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs page, the repository or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 3,
        "npmWeekly": 1298,
        "pypiWeekly": 3387,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.together.ai/docs/together-code-sandbox",
      "llmsTxt": "https://docs.together.ai/llms.txt",
      "openapi": "https://togethercomputer.github.io/together-sandbox/api-openapi.json",
      "capabilities": [
        "sandbox.code",
        "sandbox.fs",
        "sandbox.persist"
      ],
      "tags": [
        "hosted",
        "usage",
        "allowlist",
        "sales-led",
        "openapi",
        "llms-txt",
        "python",
        "typescript",
        "cli",
        "security-txt"
      ],
      "lastRelease": "2026-10-07",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 53.6,
        "grade": "D",
        "agentReady": false,
        "rank": 628,
        "ranked": true,
        "rankOf": 842,
        "categoryRank": 12,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 20,
          "reliability": 25,
          "schema": 86,
          "security": 47,
          "transparency": 60
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 25,
            "points": 5,
            "reason": "Read with the hosted lines. status.together.ai lists the website, the playground and inference models, and status.codesandbox.io lists the CodeSandbox API, website, editor, CI and two clusters. Neither names the sandbox management API at `api.bartender.codesandbox.io`, so half credit (10). No incident history for this service is readable on either page (5). No rate or concurrency limits found, and the migration guide says the concurrency count and limit are not exposed (0). Both SDKs retry 408, 429, 500, 502, 503 and 504 three times with exponential backoff from 0.5 seconds plus jitter, and the docs warn that `snapshots.create` is not idempotent. No `Retry-After` or idempotency keys found (10). No SLA found, and the terms make no uptime guarantee outside an order form (0). The SDK was announced on 1 October 2026 for organisations on an allowlist, which is not general availability (0)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 86,
            "points": 13.98,
            "reason": "Two public OpenAPI documents in the repository and on GitHub Pages, the management API (3.1.0, 17 operations) and the in-VM API (3.0.3, 25 operations) (25). docs.together.ai has llms.txt and a Markdown twin of the page, and each package ships an `LLMS.md` with the references (10). The concept docs say when to snapshot memory rather than disk only and what ephemeral means, while 36 of 114 typed nodes in the management document carry a description (14). Enums for status, bounds on `cpu`, `memory_bytes`, `ttl` and `limit`, with `experimental` left loose (12). Examples in Python, TypeScript and the CLI, and an error object with `code`, `message` and `errors`. No list of error codes found, and 429 is not in the document (10). `/v1` paths, semver packages and a generated `CHANGELOG.md` (15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 70,
            "points": 11.38,
            "reason": "List calls take `limit` from 1 to 100, batch reads take IDs and exec output can be read from a `lastSequence`. No field selection (15). Cursor pagination on sandboxes and snapshots, with filters for status, source snapshot, tags and retired snapshots (20). Errors return `code`, `message` and per-parameter entries, the SDKs raise one `HttpError` with the status, and `status_reason` names causes such as `out_of_capacity` and `oom_killed`. No catalogue of codes found (14). Built-in retries, but no idempotency keys, sandbox IDs can't be chosen and `snapshots.create` can register duplicates (8). Python and TypeScript SDKs and a CLI, with defaults of 1 vCPU and 2 GiB. A snapshot must be built first because no default image exists (13)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 47,
            "points": 8.23,
            "reason": "Project-scoped API keys, revocable, with optional expiry and no finer scopes. The docs say a key has full access to its project and can spend the credit balance (25). The in-VM document lists a `token` query parameter on the WebSocket exec path. We took 5 off, not the checklist's 10, because it is a per-sandbox agent token on one path and not the account key (-5). Each sandbox is a virtual machine. Every port is open to everyone unless an experimental inbound policy is set, no outbound rules exist, and project roles are admin and editor with no read-only role (8). The sandbox returns the output of code the agent ran, with no guidance on untrusted output found (8). Sandboxes can be listed with tags and `status_reason`. No audit log found (3). A signed security.txt valid to 30 September 2028 points to a private HackerOne programme. The trust centre is script-drawn and was unread (8)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 found (0). The pricing page lists Code Sandbox at $0.0446 per vCPU-hour and $0.0149 per GiB of RAM per hour without a login. It does not say whether the rate covers the new SDK as well as the legacy one (20). The billing docs say Together has no free trial and that platform access needs a $15 credit purchase (0). Access needs a browser signup, a payment and a request to Together to enable the organisation (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 83,
            "points": 7.26,
            "reason": "`together-sandbox` 4.1.1 on npm and PyPI on 7 October 2026 (30). Twelve tagged releases since 10 July 2026 (20). The repository has 3 stars and 6 open items, all pull requests from the team. The 30 most recent items are pull requests merged within days, so replies to outside reports can't be judged (12). Current official Python and TypeScript SDKs and a CLI, versioned together (15). Pull requests run the TypeScript unit tests, end-to-end tests run on pushes to main, and packages publish by OIDC trusted publishing. The Python tests are not in the pull request workflow, and we did not read the run results (6)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 60,
            "points": 5.25,
            "note": "editorial 43, provenance 77",
            "reason": "A closed service under Together's terms of service (19 May 2026), with the SDKs, CLI and OpenAPI documents under MIT (20). The privacy policy (17 December 2025) says data is not used for training without opt-in. Its table of data types covers inference, fine-tuning and GPU clusters with no sandbox row, and no retention period for sandbox filesystems or snapshots was found beyond an optional snapshot `ttl` (12). The legacy `@codesandbox/sdk` is marked deprecated with no end date, the deprecations page covers models only, and breaking SDK changes are marked in the changelog (8). No sub-processor list or data locations for sandboxes found. A docs example names a cluster `na-us-ce-01`, and the trust centre was unread (3)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "List calls take `limit` from 1 to 100, batch reads take IDs and exec output can be read from a `lastSequence`. No field selection (15). Cursor pagination on sandboxes and snapshots, with filters for status, source snapshot, tags and retired snapshots (20). Errors return `code`, `message` and per-parameter entries, the SDKs raise one `HttpError` with the status, and `status_reason` names causes such as `out_of_capacity` and `oom_killed`. No catalogue of codes found (14). Built-in retries, but no idempotency keys, sandbox IDs can't be chosen and `snapshots.create` can register duplicates (8). Python and TypeScript SDKs and a CLI, with defaults of 1 vCPU and 2 GiB. A snapshot must be built first because no default image exists (13).",
            "maintenance": "`together-sandbox` 4.1.1 on npm and PyPI on 7 October 2026 (30). Twelve tagged releases since 10 July 2026 (20). The repository has 3 stars and 6 open items, all pull requests from the team. The 30 most recent items are pull requests merged within days, so replies to outside reports can't be judged (12). Current official Python and TypeScript SDKs and a CLI, versioned together (15). Pull requests run the TypeScript unit tests, end-to-end tests run on pushes to main, and packages publish by OIDC trusted publishing. The Python tests are not in the pull request workflow, and we did not read the run results (6).",
            "payments": "No x402, MPP or L402 found (0). The pricing page lists Code Sandbox at $0.0446 per vCPU-hour and $0.0149 per GiB of RAM per hour without a login. It does not say whether the rate covers the new SDK as well as the legacy one (20). The billing docs say Together has no free trial and that platform access needs a $15 credit purchase (0). Access needs a browser signup, a payment and a request to Together to enable the organisation (0).",
            "reliability": "Read with the hosted lines. status.together.ai lists the website, the playground and inference models, and status.codesandbox.io lists the CodeSandbox API, website, editor, CI and two clusters. Neither names the sandbox management API at `api.bartender.codesandbox.io`, so half credit (10). No incident history for this service is readable on either page (5). No rate or concurrency limits found, and the migration guide says the concurrency count and limit are not exposed (0). Both SDKs retry 408, 429, 500, 502, 503 and 504 three times with exponential backoff from 0.5 seconds plus jitter, and the docs warn that `snapshots.create` is not idempotent. No `Retry-After` or idempotency keys found (10). No SLA found, and the terms make no uptime guarantee outside an order form (0). The SDK was announced on 1 October 2026 for organisations on an allowlist, which is not general availability (0).",
            "schema": "Two public OpenAPI documents in the repository and on GitHub Pages, the management API (3.1.0, 17 operations) and the in-VM API (3.0.3, 25 operations) (25). docs.together.ai has llms.txt and a Markdown twin of the page, and each package ships an `LLMS.md` with the references (10). The concept docs say when to snapshot memory rather than disk only and what ephemeral means, while 36 of 114 typed nodes in the management document carry a description (14). Enums for status, bounds on `cpu`, `memory_bytes`, `ttl` and `limit`, with `experimental` left loose (12). Examples in Python, TypeScript and the CLI, and an error object with `code`, `message` and `errors`. No list of error codes found, and 429 is not in the document (10). `/v1` paths, semver packages and a generated `CHANGELOG.md` (15).",
            "security": "Project-scoped API keys, revocable, with optional expiry and no finer scopes. The docs say a key has full access to its project and can spend the credit balance (25). The in-VM document lists a `token` query parameter on the WebSocket exec path. We took 5 off, not the checklist's 10, because it is a per-sandbox agent token on one path and not the account key (-5). Each sandbox is a virtual machine. Every port is open to everyone unless an experimental inbound policy is set, no outbound rules exist, and project roles are admin and editor with no read-only role (8). The sandbox returns the output of code the agent ran, with no guidance on untrusted output found (8). Sandboxes can be listed with tags and `status_reason`. No audit log found (3). A signed security.txt valid to 30 September 2028 points to a private HackerOne programme. The trust centre is script-drawn and was unread (8).",
            "transparency": "A closed service under Together's terms of service (19 May 2026), with the SDKs, CLI and OpenAPI documents under MIT (20). The privacy policy (17 December 2025) says data is not used for training without opt-in. Its table of data types covers inference, fine-tuning and GPU clusters with no sandbox row, and no retention period for sandbox filesystems or snapshots was found beyond an optional snapshot `ttl` (12). The legacy `@codesandbox/sdk` is marked deprecated with no end date, the deprecations page covers models only, and breaking SDK changes are marked in the changelog (8). No sub-processor list or data locations for sandboxes found. A docs example names a cluster `na-us-ce-01`, and the trust centre was unread (3)."
          },
          "sources": [
            {
              "what": "code sandbox docs page",
              "url": "https://docs.together.ai/docs/together-code-sandbox.md",
              "seen": "2026-10-08"
            },
            {
              "what": "legacy SDK page",
              "url": "https://docs.together.ai/docs/together-code-sandbox-legacy.md",
              "seen": "2026-10-08"
            },
            {
              "what": "docs changelog, 1 October 2026 entry",
              "url": "https://docs.together.ai/docs/changelog.md",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index",
              "url": "https://docs.together.ai/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK and CLI repository (cloned)",
              "url": "https://github.com/togethercomputer/together-sandbox",
              "seen": "2026-10-08"
            },
            {
              "what": "SDK changelog",
              "url": "https://github.com/togethercomputer/together-sandbox/blob/main/CHANGELOG.md",
              "seen": "2026-10-08"
            },
            {
              "what": "concepts, lifecycle and snapshots",
              "url": "https://github.com/togethercomputer/together-sandbox/blob/main/docs/sandboxes.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Python SDK reference, errors and retry",
              "url": "https://github.com/togethercomputer/together-sandbox/blob/main/docs/python-sdk.md",
              "seen": "2026-10-08"
            },
            {
              "what": "experimental network policy",
              "url": "https://github.com/togethercomputer/together-sandbox/blob/main/docs/experimental.md",
              "seen": "2026-10-08"
            },
            {
              "what": "migration guide from the CodeSandbox SDK",
              "url": "https://github.com/togethercomputer/together-sandbox/blob/main/docs/migrating-from-codesandbox.md",
              "seen": "2026-10-08"
            },
            {
              "what": "management API OpenAPI document",
              "url": "https://togethercomputer.github.io/together-sandbox/api-openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "npm latest",
              "url": "https://registry.npmjs.org/together-sandbox/latest",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI package",
              "url": "https://pypi.org/pypi/together-sandbox/json",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://www.together.ai/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "product page",
              "url": "https://www.together.ai/sandbox",
              "seen": "2026-10-08"
            },
            {
              "what": "billing and credits",
              "url": "https://docs.together.ai/docs/billing-credits.md",
              "seen": "2026-10-08"
            },
            {
              "what": "API keys",
              "url": "https://docs.together.ai/docs/api-keys-authentication.md",
              "seen": "2026-10-08"
            },
            {
              "what": "roles and permissions",
              "url": "https://docs.together.ai/docs/roles-permissions.md",
              "seen": "2026-10-08"
            },
            {
              "what": "terms of service",
              "url": "https://www.together.ai/terms-of-service",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://www.together.ai/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt",
              "url": "https://www.together.ai/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "Together status page",
              "url": "https://status.together.ai",
              "seen": "2026-10-08"
            },
            {
              "what": "CodeSandbox status page",
              "url": "https://status.codesandbox.io",
              "seen": "2026-10-08"
            },
            {
              "what": "management API host, one unauthenticated request (401)",
              "url": "https://api.bartender.codesandbox.io/v1/sandboxes",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "How long an access request takes and what Together asks of an organisation before enabling the SDK. The docs only say to contact Together.",
            "Whether the $0.0446 per vCPU-hour and $0.0149 per GiB-hour on the pricing page apply to the new SDK. The page lists them under Code Sandbox without naming either SDK, and a pull request adding billing usage to the SDKs was open on 8 October 2026.",
            "The isolation technology. The repository docs call a sandbox a virtual machine and the legacy page says microVM, and neither names the hypervisor for the new service.",
            "Rate limits, concurrency limits and maximum sandbox lifetime. None found.",
            "unchecked: trust.together.ai is script-drawn and showed our reader only its title, so certifications such as SOC 2 are unconfirmed.",
            "unchecked: GitHub Actions run results for the repository. We read the workflow files in the clone, not the runs.",
            "unchecked: a DPA or sub-processor list. The two paths we tried on www.together.ai returned 404 and no link was found on the terms or privacy pages.",
            "The lead described microVMs with forking. The new SDK has no live fork (the parent must terminate with a snapshot first), and the product page at together.ai/sandbox still shows the legacy `@codesandbox/sdk` and its 2 to 64 vCPU sizes, against 0.1 to 16 in the new SDK."
          ]
        },
        "negative": 0,
        "verdict": "Two public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.",
        "bestFor": "Teams already buying from Together, and former CodeSandbox SDK users, who want Docker-defined sandboxes with disk and memory snapshots from Python or TypeScript.",
        "strengths": [
          "Public OpenAPI documents for the management API (17 operations) and the in-VM API (25), in the repository and on GitHub Pages",
          "Terminating with `memory: true` saves disk and memory, and a new sandbox created from that snapshot resumes its running processes",
          "List calls are cursor-paginated (1 to 100 a page) with filters for status, source snapshot and tags",
          "Both SDKs retry 408, 429 and 5xx three times with exponential backoff, and the docs warn that `snapshots.create` is not idempotent",
          "Releases on 30 September, 1 October and 7 October 2026, with a generated changelog that marks breaking changes"
        ],
        "weaknesses": [
          "The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access",
          "No rate limits, concurrency limits or SLA found, and neither status.together.ai nor status.codesandbox.io names the service",
          "Every sandbox port is public unless an experimental inbound policy is set, and no outbound controls exist yet",
          "Three major versions between 2 June and 28 July 2026, and memory snapshots were removed in 4.0.0 and restored in 4.0.4",
          "The management API answers at `api.bartender.codesandbox.io`, off Together's domain, and the privacy policy's data table has no sandbox row"
        ],
        "agentNotes": [
          "Confirm the organisation is on Together's allowlist before installing. A valid `TOGETHER_API_KEY` alone is not enough",
          "Build a snapshot first with `snapshots.create`. No default image exists, and every sandbox needs `snapshot_id` or `snapshot_alias`",
          "Set `ttl` at creation or call `terminate()`. Nothing stops a sandbox otherwise, and closing the Python client leaves it running",
          "Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at `sandbox:\u003cid\u003e`",
          "Exclude `snapshots.create` from retries with `should_retry`, and set `experimental.network_policy` before serving anything private on a port"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 53.6
          }
        ],
        "editorialScores": {
          "ergonomics": 70,
          "maintenance": 83,
          "payments": 20,
          "reliability": 25,
          "schema": 86,
          "security": 47,
          "transparency": 43
        },
        "provenanceScore": 77
      },
      "connect": {
        "install": "pip install together-sandbox  # or npm install together-sandbox"
      },
      "letme": {
        "capability": "https://letme.dev/sandbox.code",
        "tool": "https://letme.dev/together-code-sandbox"
      },
      "sameCompany": [
        "together-fine-tuning"
      ],
      "notable": [
        "The SDK and CLI must be enabled per organisation, and the docs changelog of 1 October 2026 describes availability as an allowlist (https://docs.together.ai/docs/together-code-sandbox, https://docs.together.ai/docs/changelog)",
        "It replaces the CodeSandbox SDK. The legacy `@codesandbox/sdk` page is marked deprecated, and a migration guide lists what has no equivalent, including live fork, idle hibernation, wake on request, live resize and private previews (https://github.com/togethercomputer/together-sandbox/blob/main/docs/migrating-from-codesandbox.md)",
        "A sandbox can't be paused in place. Terminating with a snapshot saves disk, or disk and memory, and a new sandbox created from `sandbox:\u003cid\u003e` continues from it (https://github.com/togethercomputer/together-sandbox/blob/main/docs/sandboxes.md)",
        "Without a network policy every sandbox port is open to everyone. The inbound allowlist is experimental and outbound rules are not available yet (https://github.com/togethercomputer/together-sandbox/blob/main/docs/experimental.md)",
        "The management API's default host is `api.bartender.codesandbox.io`, changed from `api.bartender.codesandbox.stream` in 2.0.0, and it answered 401 `not_authenticated` to one unauthenticated request (https://github.com/togethercomputer/together-sandbox/blob/main/CHANGELOG.md)",
        "The product page at together.ai/sandbox still shows the legacy SDK and 2 to 64 vCPU sizes, while the new SDK takes 0.1 to 16 cores and 1 to 8 GB of memory per core (https://www.together.ai/sandbox)"
      ],
      "area": "agent-runtime",
      "details": [
        {
          "label": "Access",
          "value": "Allowlist. Together enables the SDK and CLI per organisation on request"
        },
        {
          "label": "Clients",
          "value": "`together-sandbox` 4.1.1 on PyPI (async, Python 3.10 or later) and npm (Node.js 18 or later), and a `together-sandbox` CLI installed as a self-contained binary, all MIT"
        },
        {
          "label": "APIs",
          "value": "Management API (OpenAPI 3.1.0, 17 operations, `/v1` at api.bartender.codesandbox.io) for sandboxes, snapshots and aliases. In-VM API (OpenAPI 3.0.3, 25 operations) for files, directories, execs and ports"
        },
        {
          "label": "Sizes",
          "value": "Default 1 vCPU and 2 GiB. `cpu` from 0.1 to 16 cores and 1 to 8 GB of memory per core, fixed at creation"
        },
        {
          "label": "Lifetime",
          "value": "Runs until terminated unless `ttl` (seconds from creation) is set. No idle detection, and a terminated sandbox can't restart"
        },
        {
          "label": "Persistence",
          "value": "Ephemeral by default. A termination policy or `terminate(snapshot=...)` saves disk, or disk and memory, as a snapshot aliased `sandbox:\u003cid\u003e`"
        },
        {
          "label": "Images",
          "value": "Snapshots built by Together's remote image builder from a public Docker image or a Dockerfile context. No default image"
        },
        {
          "label": "Network",
          "value": "All ports public by default. Experimental inbound allowlist by port, IP or CIDR with an optional `X-Sandbox-Token` requirement. No outbound rules"
        },
        {
          "label": "Retries",
          "value": "SDKs retry 408, 429, 500, 502, 503 and 504 three times with exponential backoff from 0.5 seconds. `snapshots.create` is not idempotent"
        },
        {
          "label": "Rate limits",
          "value": "None found. The migration guide says the concurrency count and limit are not exposed"
        },
        {
          "label": "Status",
          "value": "No sandbox component on status.together.ai or status.codesandbox.io"
        }
      ],
      "unitPrices": [
        {
          "item": "vCPU",
          "unit": "vcpu-hour",
          "usd": 0.0446,
          "note": "RAM extra at $0.0149 per GiB-hour. Listed under Code Sandbox on the pricing page, which doesn't name the SDK"
        },
        {
          "item": "Default sandbox (1 vCPU, 2 GiB)",
          "unit": "session-hour",
          "usd": 0.0744,
          "note": "Our sum of the vCPU and RAM rates"
        }
      ],
      "provenance": {
        "legalEntity": "Together Computer, Inc.",
        "domain": "together.ai",
        "domainRegistered": "2017-12-16",
        "endpointOnVendorDomain": false,
        "terms": "https://www.together.ai/terms-of-service",
        "privacy": "https://www.together.ai/privacy",
        "statusPage": "https://status.together.ai",
        "changelog": "https://github.com/togethercomputer/together-sandbox/blob/main/CHANGELOG.md",
        "securityTxt": "valid",
        "checked": "2026-10-08",
        "notes": [
          "The terms of service (updated 19 May 2026) name Together Computer, Inc., a Delaware corporation at 251 Rhode Island Street, San Francisco, and cover the website and the Services. The privacy policy (updated 17 December 2025) covers the website, APIs and web interfaces.",
          "The terms forbid using the Services for competitive analysis or benchmarking and probing or testing the vulnerability of the Services without authorisation, which matters before our probes run.",
          "The management API answers at api.bartender.codesandbox.io and sandbox URLs sit under csb.app. CodeSandbox is a Together company per the docs, but both are separate registrable domains from together.ai.",
          "status.together.ai has no sandbox component. status.codesandbox.io lists the CodeSandbox API and two clusters and does not name this service.",
          "security.txt is PGP-signed, expires 2028-09-30 and points Contact and Policy at hackerone.com/together_ai. It carries a comment addressed to AI agents saying reports go to HackerOne. Recorded as a fact, and we did not act on it.",
          "RDAP for together.ai gives a registration date of 2017-12-16.",
          "trust.together.ai is script-drawn and showed our reader only its title. No DPA or sub-processor page was found."
        ],
        "score": 77,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Together Computer, Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "together.ai, registered 2017-12-16 (8 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "api.bartender.codesandbox.io is not on together.ai",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Terms of service",
            "value": "read, states 5 of the 7 things a reader expects, and has 1 clause that costs points",
            "points": 6.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 7 of the 8 things a reader expects",
            "points": 9.3,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "status.together.ai",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "valid",
            "points": 10,
            "max": 10,
            "state": "ok"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://www.together.ai/terms-of-service",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 3964,
            "points": 6.3,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "This Agreement will be governed by the laws of the State of California, exclusive of its rules governing choice of law and conflict of laws.",
                "says": "The law of the State of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…even if informed of their possibility in advance, or (b) excluding customer's payment obligations, any aggregate liability in excess of the amounts paid by customer during the twelve (12) months preceding the claim (the \"ordinary cap\").",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "The Company may suspend your access to the Services immediately upon notice if you fail to pay any amounts hereunder at least five (5) days past the applicable due date."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "You will not use the Services to transmit or provide to the Company any financial or medical information of any nature or any sensitive personal data (e.g., social security numbers, driver’s license numbers, birth dates, personal bank account numbers, passport or visa numbers, and/or credit card numbers)."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "No guarantees are made with respect to the Services’ quality, stability, uptime, or reliability, unless otherwise agreed between the parties in an order form."
              }
            ],
            "toKnow": [
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "(c) use or access the Services to develop a product or service that is competitive with the Company’s products or services or engage in competitive analysis or benchmarking;",
                "costsPoints": true
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The parties owe each other no confidentiality unless they agree it in writing.",
                "quote": "The parties will have no confidentiality obligations to each other unless otherwise agreed in writing."
              },
              {
                "date": "2026-10-08",
                "text": "The customer may not cancel or end the agreement without Together's express written consent.",
                "quote": "You may not cancel or terminate this Agreement without our express written consent."
              },
              {
                "date": "2026-10-08",
                "text": "Customers may not send financial or medical information or sensitive personal data to Together through the services.",
                "quote": "You will not use the Services to transmit or provide to the Company any financial or medical information of any nature or any sensitive personal data"
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://www.together.ai/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "words": 3751,
            "points": 9.3,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": false
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "Data that we collect, including your Personal Data, will not be used to train the Company’s models without your explicit opt-in and consent."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "The Company will retain your Personal Data only for as long as is necessary for the purposes set out in this Policy.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We may share your Personal Data with Service Providers, Third-Party Vendors, Consultants, and other Business Partners in order to provide Services on our behalf, monitor and analyze the use of our Services, contact you, and for the reasons stated in our Terms of Service."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "The Company does not sell your Personal Data as defined under CCPA.",
                "says": "Says it does not sell personal data"
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "If, in the future, we do sell your Personal Data, we will notify you, and you may have the right to opt out of such sale."
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "In order to exercise any other privacy rights not specifically enumerated here, you may contact privacy@together.ai.",
                "says": "privacy@together.ai"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "When we share Personal Data of individuals in the EEA, Switzerland, or UK with third parties, we make use of a variety of legal mechanisms to safeguard the transfer, including the European Commission-approved standard contractual clauses as well as additional safeguards where appropriate.",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Data collected from a customer is not used to train Together's models unless the customer opts in.",
                "quote": "We do not use any data collected from you to train our models without your explicit opt-in and consent."
              },
              {
                "date": "2026-10-08",
                "text": "With Zero Data Retention on, Together cannot later retrieve, correct, export or delete the data, because it is removed once processing ends.",
                "quote": "This means we cannot later access, retrieve, correct, export, or delete your Personal Data on your behalf as it is removed from our systems as soon as processing concludes."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/together-code-sandbox.json",
      "live": {
        "slug": "together-code-sandbox",
        "probe": {
          "target": "https://api.bartender.codesandbox.io",
          "method": "get",
          "lastAt": "2026-10-09T09:27:07.784006733Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 143,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 146,
          "p95ms24h": 181,
          "samples24h": 20,
          "samples30d": 20,
          "days": [
            {
              "date": "2026-10-09",
              "probes": 20,
              "ok": 20
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.together.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-09T07:58:36.139351511Z"
        },
        "updatedAt": "2026-10-09T09:27:07.784006733Z"
      }
    },
    "verify": {
      "accepts": "a page on together.ai or one of its subdomains, or the README of github.com/togethercomputer/together-sandbox",
      "badgeUrl": "https://www.anchorterminal.com/badges/together-code-sandbox.svg",
      "body": {
        "slug": "together-code-sandbox",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/together-code-sandbox",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/together-code-sandbox\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/together-code-sandbox.svg\" alt=\"Together Code Sandbox on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Together Code Sandbox on Anchor Terminal](https://www.anchorterminal.com/badges/together-code-sandbox.svg)](https://www.anchorterminal.com/tools/together-code-sandbox)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/together-code-sandbox\"\u003eTogether Code Sandbox on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/together-code-sandbox",
    "json": "https://www.anchorterminal.com/tools/together-code-sandbox.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/together-code-sandbox.md",
    "slim": "https://www.anchorterminal.com/tools/together-code-sandbox.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 53.6/100 · rank #628 of 842 · #12 in Code execution sandboxes · not agent-ready · confidence medium**\n\n\nMore from Together AI, listed separately because each is its own product: [Together AI Fine-tuning](https://www.anchorterminal.com/tools/together-fine-tuning.md) (Fine-tuning).\n\n## Assessment\n\nTwo public OpenAPI documents, MIT clients for Python and TypeScript, cursor pagination and built-in retries make the surface easy for an agent to drive. Access is the limit. Together enables the SDK per organisation on request, publishes no rate limits or SLA, and neither status page names the sandbox service.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Together AI (https://www.together.ai) |\n| Kind | HTTP API |\n| Category | Code execution sandboxes (https://www.anchorterminal.com/categories/code-sandboxes) |\n| Transport | HTTP |\n| Endpoint | `https://api.bartender.codesandbox.io` |\n| Auth | API key · Access is by allowlist. The docs say the `together-sandbox` SDK and CLI must be enabled for an organisation and to contact Together to request it. Once enabled, a project-scoped Together API key is sent as a Bearer token, read from `TOGETHER_API_KEY`. Keys are revocable, can carry an expiry date and have no finer scopes. Each running sandbox also has its own agent token for the in-VM API, which the SDKs handle. |\n| Pricing | Pay per use ($0.0446 / vCPU-hr) · The pricing page lists Code Sandbox compute at $0.0446 per vCPU-hour and $0.0149 per GiB of RAM per hour, and does not say whether that rate covers the new SDK as well as the legacy one. No free tier or sandbox lets an agent start without a contract. Together has no free trial, platform access needs a $15 first credit purchase, and the organisation must then be enabled on request (https://www.together.ai/pricing, https://docs.together.ai/docs/billing-credits). |\n| x402 | No · No x402, MPP or L402 in the docs page, the repository or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary service under Together's terms of service. The SDKs, CLI and OpenAPI documents on GitHub are MIT |\n| Packages | pypi: `together-sandbox`; npm: `together-sandbox` |\n| Source | https://github.com/togethercomputer/together-sandbox |\n| Docs | https://docs.together.ai/docs/together-code-sandbox |\n| llms.txt | https://docs.together.ai/llms.txt |\n| Last release | 2026-10-07 |\n| GitHub stars | 3 (as of 2026-10-08) |\n| npm downloads / week | 1,298 |\n| PyPI downloads / week | 3,387 |\n| Access | Allowlist. Together enables the SDK and CLI per organisation on request |\n| Clients | `together-sandbox` 4.1.1 on PyPI (async, Python 3.10 or later) and npm (Node.js 18 or later), and a `together-sandbox` CLI installed as a self-contained binary, all MIT |\n| APIs | Management API (OpenAPI 3.1.0, 17 operations, `/v1` at api.bartender.codesandbox.io) for sandboxes, snapshots and aliases. In-VM API (OpenAPI 3.0.3, 25 operations) for files, directories, execs and ports |\n| Sizes | Default 1 vCPU and 2 GiB. `cpu` from 0.1 to 16 cores and 1 to 8 GB of memory per core, fixed at creation |\n| Lifetime | Runs until terminated unless `ttl` (seconds from creation) is set. No idle detection, and a terminated sandbox can't restart |\n| Persistence | Ephemeral by default. A termination policy or `terminate(snapshot=...)` saves disk, or disk and memory, as a snapshot aliased `sandbox:\u003cid\u003e` |\n| Images | Snapshots built by Together's remote image builder from a public Docker image or a Dockerfile context. No default image |\n| Network | All ports public by default. Experimental inbound allowlist by port, IP or CIDR with an optional `X-Sandbox-Token` requirement. No outbound rules |\n| Retries | SDKs retry 408, 429, 500, 502, 503 and 504 three times with exponential backoff from 0.5 seconds. `snapshots.create` is not idempotent |\n| Rate limits | None found. The migration guide says the concurrency count and limit are not exposed |\n| Status | No sandbox component on status.together.ai or status.codesandbox.io |\n| Capabilities | sandbox.code, sandbox.fs, sandbox.persist |\n| Tags | hosted, usage, allowlist, sales-led, openapi, llms-txt, python, typescript, cli, security-txt |\n| JSON | https://www.anchorterminal.com/api/v1/tools/together-code-sandbox.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 25 | 5.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 86 | 14.0 |\n| Agent ergonomics | 13% | 16.2 | 70 | 11.4 |\n| Security \u0026 auth | 14% | 17.5 | 47 | 8.2 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 83 | 7.3 |\n| Transparency \u0026 trust (editorial 43, provenance 77) | 7% | 8.8 | 60 | 5.2 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **53.6 → D** |\n\n### Why each score\n\n- Reliability 25: Read with the hosted lines. status.together.ai lists the website, the playground and inference models, and status.codesandbox.io lists the CodeSandbox API, website, editor, CI and two clusters. Neither names the sandbox management API at `api.bartender.codesandbox.io`, so half credit (10). No incident history for this service is readable on either page (5). No rate or concurrency limits found, and the migration guide says the concurrency count and limit are not exposed (0). Both SDKs retry 408, 429, 500, 502, 503 and 504 three times with exponential backoff from 0.5 seconds plus jitter, and the docs warn that `snapshots.create` is not idempotent. No `Retry-After` or idempotency keys found (10). No SLA found, and the terms make no uptime guarantee outside an order form (0). The SDK was announced on 1 October 2026 for organisations on an allowlist, which is not general availability (0).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 86: Two public OpenAPI documents in the repository and on GitHub Pages, the management API (3.1.0, 17 operations) and the in-VM API (3.0.3, 25 operations) (25). docs.together.ai has llms.txt and a Markdown twin of the page, and each package ships an `LLMS.md` with the references (10). The concept docs say when to snapshot memory rather than disk only and what ephemeral means, while 36 of 114 typed nodes in the management document carry a description (14). Enums for status, bounds on `cpu`, `memory_bytes`, `ttl` and `limit`, with `experimental` left loose (12). Examples in Python, TypeScript and the CLI, and an error object with `code`, `message` and `errors`. No list of error codes found, and 429 is not in the document (10). `/v1` paths, semver packages and a generated `CHANGELOG.md` (15).\n- Agent ergonomics 70: List calls take `limit` from 1 to 100, batch reads take IDs and exec output can be read from a `lastSequence`. No field selection (15). Cursor pagination on sandboxes and snapshots, with filters for status, source snapshot, tags and retired snapshots (20). Errors return `code`, `message` and per-parameter entries, the SDKs raise one `HttpError` with the status, and `status_reason` names causes such as `out_of_capacity` and `oom_killed`. No catalogue of codes found (14). Built-in retries, but no idempotency keys, sandbox IDs can't be chosen and `snapshots.create` can register duplicates (8). Python and TypeScript SDKs and a CLI, with defaults of 1 vCPU and 2 GiB. A snapshot must be built first because no default image exists (13).\n- Security \u0026 auth 47: Project-scoped API keys, revocable, with optional expiry and no finer scopes. The docs say a key has full access to its project and can spend the credit balance (25). The in-VM document lists a `token` query parameter on the WebSocket exec path. We took 5 off, not the checklist's 10, because it is a per-sandbox agent token on one path and not the account key (-5). Each sandbox is a virtual machine. Every port is open to everyone unless an experimental inbound policy is set, no outbound rules exist, and project roles are admin and editor with no read-only role (8). The sandbox returns the output of code the agent ran, with no guidance on untrusted output found (8). Sandboxes can be listed with tags and `status_reason`. No audit log found (3). A signed security.txt valid to 30 September 2028 points to a private HackerOne programme. The trust centre is script-drawn and was unread (8).\n- Payments \u0026 pricing 20: No x402, MPP or L402 found (0). The pricing page lists Code Sandbox at $0.0446 per vCPU-hour and $0.0149 per GiB of RAM per hour without a login. It does not say whether the rate covers the new SDK as well as the legacy one (20). The billing docs say Together has no free trial and that platform access needs a $15 credit purchase (0). Access needs a browser signup, a payment and a request to Together to enable the organisation (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 83: `together-sandbox` 4.1.1 on npm and PyPI on 7 October 2026 (30). Twelve tagged releases since 10 July 2026 (20). The repository has 3 stars and 6 open items, all pull requests from the team. The 30 most recent items are pull requests merged within days, so replies to outside reports can't be judged (12). Current official Python and TypeScript SDKs and a CLI, versioned together (15). Pull requests run the TypeScript unit tests, end-to-end tests run on pushes to main, and packages publish by OIDC trusted publishing. The Python tests are not in the pull request workflow, and we did not read the run results (6).\n- Transparency \u0026 trust 60: A closed service under Together's terms of service (19 May 2026), with the SDKs, CLI and OpenAPI documents under MIT (20). The privacy policy (17 December 2025) says data is not used for training without opt-in. Its table of data types covers inference, fine-tuning and GPU clusters with no sandbox row, and no retention period for sandbox filesystems or snapshots was found beyond an optional snapshot `ttl` (12). The legacy `@codesandbox/sdk` is marked deprecated with no end date, the deprecations page covers models only, and breaking SDK changes are marked in the changelog (8). No sub-processor list or data locations for sandboxes found. A docs example names a cluster `na-us-ce-01`, and the trust centre was unread (3).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (19 items): https://www.anchorterminal.com/fixes/together-code-sandbox.md (JSON https://www.anchorterminal.com/fixes/together-code-sandbox.json)\n\n### What we couldn't check\n\n- How long an access request takes and what Together asks of an organisation before enabling the SDK. The docs only say to contact Together.\n- Whether the $0.0446 per vCPU-hour and $0.0149 per GiB-hour on the pricing page apply to the new SDK. The page lists them under Code Sandbox without naming either SDK, and a pull request adding billing usage to the SDKs was open on 8 October 2026.\n- The isolation technology. The repository docs call a sandbox a virtual machine and the legacy page says microVM, and neither names the hypervisor for the new service.\n- Rate limits, concurrency limits and maximum sandbox lifetime. None found.\n- unchecked: trust.together.ai is script-drawn and showed our reader only its title, so certifications such as SOC 2 are unconfirmed.\n- unchecked: GitHub Actions run results for the repository. We read the workflow files in the clone, not the runs.\n- unchecked: a DPA or sub-processor list. The two paths we tried on www.together.ai returned 404 and no link was found on the terms or privacy pages.\n- The lead described microVMs with forking. The new SDK has no live fork (the parent must terminate with a snapshot first), and the product page at together.ai/sandbox still shows the legacy `@codesandbox/sdk` and its 2 to 64 vCPU sizes, against 0.1 to 16 in the new SDK.\n\n### Sources\n\n- code sandbox docs page: \u003chttps://docs.together.ai/docs/together-code-sandbox.md\u003e (seen 2026-10-08)\n- legacy SDK page: \u003chttps://docs.together.ai/docs/together-code-sandbox-legacy.md\u003e (seen 2026-10-08)\n- docs changelog, 1 October 2026 entry: \u003chttps://docs.together.ai/docs/changelog.md\u003e (seen 2026-10-08)\n- docs index: \u003chttps://docs.together.ai/llms.txt\u003e (seen 2026-10-08)\n- SDK and CLI repository (cloned): \u003chttps://github.com/togethercomputer/together-sandbox\u003e (seen 2026-10-08)\n- SDK changelog: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/CHANGELOG.md\u003e (seen 2026-10-08)\n- concepts, lifecycle and snapshots: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/docs/sandboxes.md\u003e (seen 2026-10-08)\n- Python SDK reference, errors and retry: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/docs/python-sdk.md\u003e (seen 2026-10-08)\n- experimental network policy: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/docs/experimental.md\u003e (seen 2026-10-08)\n- migration guide from the CodeSandbox SDK: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/docs/migrating-from-codesandbox.md\u003e (seen 2026-10-08)\n- management API OpenAPI document: \u003chttps://togethercomputer.github.io/together-sandbox/api-openapi.json\u003e (seen 2026-10-08)\n- npm latest: \u003chttps://registry.npmjs.org/together-sandbox/latest\u003e (seen 2026-10-08)\n- PyPI package: \u003chttps://pypi.org/pypi/together-sandbox/json\u003e (seen 2026-10-08)\n- pricing: \u003chttps://www.together.ai/pricing\u003e (seen 2026-10-08)\n- product page: \u003chttps://www.together.ai/sandbox\u003e (seen 2026-10-08)\n- billing and credits: \u003chttps://docs.together.ai/docs/billing-credits.md\u003e (seen 2026-10-08)\n- API keys: \u003chttps://docs.together.ai/docs/api-keys-authentication.md\u003e (seen 2026-10-08)\n- roles and permissions: \u003chttps://docs.together.ai/docs/roles-permissions.md\u003e (seen 2026-10-08)\n- terms of service: \u003chttps://www.together.ai/terms-of-service\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://www.together.ai/privacy\u003e (seen 2026-10-08)\n- security.txt: \u003chttps://www.together.ai/.well-known/security.txt\u003e (seen 2026-10-08)\n- Together status page: \u003chttps://status.together.ai\u003e (seen 2026-10-08)\n- CodeSandbox status page: \u003chttps://status.codesandbox.io\u003e (seen 2026-10-08)\n- management API host, one unauthenticated request (401): \u003chttps://api.bartender.codesandbox.io/v1/sandboxes\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 77/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Together Computer, Inc. | 20/20 |\n| Domain age | together.ai, registered 2017-12-16 (8 years) | 11/15 |\n| Endpoint on the vendor's domain | api.bartender.codesandbox.io is not on together.ai | 0/15 |\n| Terms of service | read, states 5 of the 7 things a reader expects, and has 1 clause that costs points | 6.3/10 |\n| Privacy policy | read, states 7 of the 8 things a reader expects | 9.3/10 |\n| Status page | status.together.ai | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | valid | 10/10 |\n\nThe terms of service (updated 19 May 2026) name Together Computer, Inc., a Delaware corporation at 251 Rhode Island Street, San Francisco, and cover the website and the Services. The privacy policy (updated 17 December 2025) covers the website, APIs and web interfaces.\n\nThe terms forbid using the Services for competitive analysis or benchmarking and probing or testing the vulnerability of the Services without authorisation, which matters before our probes run.\n\nThe management API answers at api.bartender.codesandbox.io and sandbox URLs sit under csb.app. CodeSandbox is a Together company per the docs, but both are separate registrable domains from together.ai.\n\nstatus.together.ai has no sandbox component. status.codesandbox.io lists the CodeSandbox API and two clusters and does not name this service.\n\nsecurity.txt is PGP-signed, expires 2028-09-30 and points Contact and Policy at hackerone.com/together_ai. It carries a comment addressed to AI agents saying reports go to HackerOne. Recorded as a fact, and we did not act on it.\n\nRDAP for together.ai gives a registration date of 2017-12-16.\n\ntrust.together.ai is script-drawn and showed our reader only its title. No DPA or sub-processor page was found.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://www.together.ai/terms-of-service), read 2026-10-08, gives no date, states 5 of the 7 things a reader expects.\n\n- To know. Restricts benchmarking or competitive use (costs points). \"(c) use or access the Services to develop a product or service that is competitive with the Company’s products or services or engage in competitive analysis or benchmarking;\"\n- Not found in the text. Gives the date it was last updated.\n- Names the governing law or courts. The law of the State of California.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Not found in the text. Says how changes to the terms are announced.\n- Also in the text (2026-10-08). The parties owe each other no confidentiality unless they agree it in writing. \"The parties will have no confidentiality obligations to each other unless otherwise agreed in writing.\"\n- Also in the text (2026-10-08). The customer may not cancel or end the agreement without Together's express written consent. \"You may not cancel or terminate this Agreement without our express written consent.\"\n- Also in the text (2026-10-08). Customers may not send financial or medical information or sensitive personal data to Together through the services. \"You will not use the Services to transmit or provide to the Company any financial or medical information of any nature or any sensitive personal data\"\n\n**Privacy policy** (https://www.together.ai/privacy), read 2026-10-08, gives no date, states 7 of the 8 things a reader expects.\n\n- Not found in the text. Gives the date it was last updated.\n- Says how long data is kept. For as long as needed, with no period named.\n- Says whether personal data is sold or shared for advertising. Says it does not sell personal data.\n- Gives a privacy contact. privacy@together.ai.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Data collected from a customer is not used to train Together's models unless the customer opts in. \"We do not use any data collected from you to train our models without your explicit opt-in and consent.\"\n- Also in the text (2026-10-08). With Zero Data Retention on, Together cannot later retrieve, correct, export or delete the data, because it is removed once processing ends. \"This means we cannot later access, retrieve, correct, export, or delete your Personal Data on your behalf as it is removed from our systems as soon as processing concludes.\"\n\n## Live (updated 2026-10-09 09:27 UTC)\n\n- Right now: up, HTTP 404, 143 ms, checked 2026-10-09 09:27 UTC (get on `https://api.bartender.codesandbox.io`)\n- Uptime 24h 100.0% (20 probes) · 30 days 100.0% (20 probes) · p50 146 ms · p95 181 ms\n- Vendor status page: unknown, no machine-readable status found\n- Always current: https://www.anchorterminal.com/api/v1/live/together-code-sandbox.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| vCPU | $0.0446 | per vCPU-hour | RAM extra at $0.0149 per GiB-hour. Listed under Code Sandbox on the pricing page, which doesn't name the SDK |\n| Default sandbox (1 vCPU, 2 GiB) | $0.0744 | per session-hour | Our sum of the vCPU and RAM rates |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI documents for the management API (17 operations) and the in-VM API (25), in the repository and on GitHub Pages\n- Terminating with `memory: true` saves disk and memory, and a new sandbox created from that snapshot resumes its running processes\n- List calls are cursor-paginated (1 to 100 a page) with filters for status, source snapshot and tags\n- Both SDKs retry 408, 429 and 5xx three times with exponential backoff, and the docs warn that `snapshots.create` is not idempotent\n- Releases on 30 September, 1 October and 7 October 2026, with a generated changelog that marks breaking changes\n\n## Weaknesses\n\n- The SDK and CLI work only for organisations Together has enabled, and the docs say to contact Together for access\n- No rate limits, concurrency limits or SLA found, and neither status.together.ai nor status.codesandbox.io names the service\n- Every sandbox port is public unless an experimental inbound policy is set, and no outbound controls exist yet\n- Three major versions between 2 June and 28 July 2026, and memory snapshots were removed in 4.0.0 and restored in 4.0.4\n- The management API answers at `api.bartender.codesandbox.io`, off Together's domain, and the privacy policy's data table has no sandbox row\n\n## Before you call it (notes for agents)\n\n1. Confirm the organisation is on Together's allowlist before installing. A valid `TOGETHER_API_KEY` alone is not enough\n2. Build a snapshot first with `snapshots.create`. No default image exists, and every sandbox needs `snapshot_id` or `snapshot_alias`\n3. Set `ttl` at creation or call `terminate()`. Nothing stops a sandbox otherwise, and closing the Python client leaves it running\n4. Store the snapshot alias, not the sandbox ID. A terminated sandbox can't restart, and its state lives at `sandbox:\u003cid\u003e`\n5. Exclude `snapshots.create` from retries with `should_retry`, and set `experimental.network_policy` before serving anything private on a port\n\n## Connect\n\nInstall:\n\n```bash\npip install together-sandbox  # or npm install together-sandbox\n```\n\nThrough letme (picks today, calling later): https://letme.dev/together-code-sandbox. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Microsoft Execution Containers | BB | 76.3 | 35 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/microsoft-execution-containers.md |\n| Modal Sandboxes | BB | 75.5 | 45 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/modal-sandboxes.md |\n| Vercel Sandbox | B | 69.6 | 168 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/vercel-sandbox.md |\n| E2B | B | 68.3 | 207 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/e2b.md |\n| Cloudflare Sandbox SDK | B | 67.5 | 231 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.md |\n| Runloop Devboxes | B | 64.8 | 305 | sandbox.code, sandbox.fs, sandbox.persist | no | https://www.anchorterminal.com/tools/runloop.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- The SDK and CLI must be enabled per organisation, and the docs changelog of 1 October 2026 describes availability as an allowlist (source: \u003chttps://docs.together.ai/docs/together-code-sandbox, https://docs.together.ai/docs/changelog\u003e)\n- It replaces the CodeSandbox SDK. The legacy `@codesandbox/sdk` page is marked deprecated, and a migration guide lists what has no equivalent, including live fork, idle hibernation, wake on request, live resize and private previews (source: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/docs/migrating-from-codesandbox.md\u003e)\n- A sandbox can't be paused in place. Terminating with a snapshot saves disk, or disk and memory, and a new sandbox created from `sandbox:\u003cid\u003e` continues from it (source: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/docs/sandboxes.md\u003e)\n- Without a network policy every sandbox port is open to everyone. The inbound allowlist is experimental and outbound rules are not available yet (source: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/docs/experimental.md\u003e)\n- The management API's default host is `api.bartender.codesandbox.io`, changed from `api.bartender.codesandbox.stream` in 2.0.0, and it answered 401 `not_authenticated` to one unauthenticated request (source: \u003chttps://github.com/togethercomputer/together-sandbox/blob/main/CHANGELOG.md\u003e)\n- The product page at together.ai/sandbox still shows the legacy SDK and 2 to 64 vCPU sizes, while the new SDK takes 0.1 to 16 cores and 1 to 8 GB of memory per core (source: \u003chttps://www.together.ai/sandbox\u003e)\n\n## Compare\n\n- [Amazon Bedrock AgentCore Code Interpreter vs Together Code Sandbox](https://www.anchorterminal.com/compare/agentcore-code-interpreter-vs-together-code-sandbox.md): BB 73.1 vs D 53.6\n- [Blaxel Sandboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/blaxel-sandboxes-vs-together-code-sandbox.md): C 60.7 vs D 53.6\n- [Cloudflare Sandbox SDK vs Together Code Sandbox](https://www.anchorterminal.com/compare/cloudflare-sandbox-sdk-vs-together-code-sandbox.md): B 67.5 vs D 53.6\n- [Daytona vs Together Code Sandbox](https://www.anchorterminal.com/compare/daytona-vs-together-code-sandbox.md): B 64.3 vs D 53.6\n- [Deno Sandbox vs Together Code Sandbox](https://www.anchorterminal.com/compare/deno-sandbox-vs-together-code-sandbox.md): D 50.3 vs D 53.6\n- [E2B vs Together Code Sandbox](https://www.anchorterminal.com/compare/e2b-vs-together-code-sandbox.md): B 68.3 vs D 53.6\n- [Freestyle vs Together Code Sandbox](https://www.anchorterminal.com/compare/freestyle-vs-together-code-sandbox.md): C 58.5 vs D 53.6\n- [Microsoft Execution Containers vs Together Code Sandbox](https://www.anchorterminal.com/compare/microsoft-execution-containers-vs-together-code-sandbox.md): BB 76.3 vs D 53.6\n- [Modal Sandboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/modal-sandboxes-vs-together-code-sandbox.md): BB 75.5 vs D 53.6\n- [Morph Cloud vs Together Code Sandbox](https://www.anchorterminal.com/compare/morph-cloud-vs-together-code-sandbox.md): D 50.8 vs D 53.6\n- [Runloop Devboxes vs Together Code Sandbox](https://www.anchorterminal.com/compare/runloop-vs-together-code-sandbox.md): B 64.8 vs D 53.6\n- [Sprites vs Together Code Sandbox](https://www.anchorterminal.com/compare/sprites-vs-together-code-sandbox.md): C 58.3 vs D 53.6\n- [Together Code Sandbox vs Vercel Sandbox](https://www.anchorterminal.com/compare/together-code-sandbox-vs-vercel-sandbox.md): D 53.6 vs B 69.6\n- [Agent 37 Cloud vs Together Code Sandbox](https://www.anchorterminal.com/compare/agent37-vs-together-code-sandbox.md): D 46.1 vs D 53.6\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on together.ai or one of its subdomains, or the README of github.com/togethercomputer/together-sandbox. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"together-code-sandbox\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/together-code-sandbox\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/together-code-sandbox.svg\" alt=\"Together Code Sandbox on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Together Code Sandbox on Anchor Terminal](https://www.anchorterminal.com/badges/together-code-sandbox.svg)](https://www.anchorterminal.com/tools/together-code-sandbox)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/together-code-sandbox\"\u003eTogether Code Sandbox on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Together Code Sandbox is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/together-code-sandbox-dark.png\n- Light: https://www.anchorterminal.com/assets/share/together-code-sandbox-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Code execution sandboxes",
        "url": "https://www.anchorterminal.com/categories/code-sandboxes"
      },
      {
        "name": "Together Code Sandbox",
        "url": ""
      }
    ],
    "description": "Together AI's hosted virtual machine sandboxes for running commands and code, built from Docker-image snapshots and driven from the together-sandbox Python SDK, TypeScript SDK or CLI. Access is by allowlist, on request to Together.",
    "facts": [
      "rank #628 of 842",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Together Code Sandbox",
    "image": "https://www.anchorterminal.com/assets/og/tools-together-code-sandbox.png",
    "path": "/tools/together-code-sandbox",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Together Code Sandbox review for AI agents, grade D (53.6/100)",
    "toc": null,
    "updated": "2026-10-09",
    "url": "https://www.anchorterminal.com/tools/together-code-sandbox"
  },
  "tokens": {
    "markdown": 7650,
    "slim": 1580
  },
  "version": 1
}
