# Vercel Sandbox (slim) > Firecracker microVM sandboxes on Vercel, driven from the @vercel/sandbox JavaScript SDK, the Python vercel package, a CLI or the REST API. - Full: https://www.anchorterminal.com/tools/vercel-sandbox.md (~6,000 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/vercel-sandbox.json · canonical https://www.anchorterminal.com/tools/vercel-sandbox - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **B · 69.6/100 · rank #111 of 452 · #2 in Code execution sandboxes · not agent-ready · confidence medium** Assessment: Active CPU billing, so waiting on model responses costs only memory. Tied to a Vercel team and project even when called from elsewhere, and access tokens reach the whole team. ## Facts - Kind: HTTP API · vendor: Vercel · category: Code execution sandboxes · legal entity: Vercel Inc. · provenance 100/100 - Endpoint: `https://api.vercel.com/v1/sandboxes` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Free tier: Hobby, 5 Active CPU hours, 420 GB-hours of memory and 5,000 creations a month - Session length: Default 5 minutes. Maximum 45 minutes on Hobby, 24 hours on Pro and Enterprise - Resources: 1 or an even number of vCPUs up to 4 (Hobby), 8 (Pro) or 32 (Enterprise), 2 GB of memory per vCPU, 64 GB disk - Concurrency: 10 on Hobby, 10,000 on Pro and Enterprise - Regions: 19, default iad1 - Snapshots: Filesystem only, expire 30 days after last use by default, can be kept indefinitely - Control plane limits: 1,000 requests a minute on Hobby, 10,000 on Pro, 100,000 on Enterprise. Deletes 20 a second - Prices: Active CPU (iad1) $0.128 per vCPU-hour; Snapshot storage $0.08 per GB per month; Drive storage (iad1) $0.05 per GB per month; Data transfer on Enterprise (iad1) $0.15 per GB of traffic - Scores: Reliability 70, Performance pending, Schema & documentation 77, Agent ergonomics 65, Security & auth 80, Payments & pricing 40, Task success pending, Maintenance & community 80, Transparency & trust 75 · total over the 7 assessed categories - Why: Reliability, Sandbox is its own component on www.vercel-status.com, with an incident feed (20). · Schema & documentation, We didn't find sandbox endpoints in a public OpenAPI file, so the typed JavaScript and Python SDK references count as 15 of 25 (15). · Agent ergonomics, Sandbox objects are small, with no field selection (15). · Security & auth, Vercel OIDC tokens tied to one project, which `vercel env pull` hands out for 12 hours, or access tokens elsewhere. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, @vercel/sandbox 3.3.0 on 2026-09-11 (30). · Transparency & trust, The SDK and CLI are Apache-2.0. The platform is closed under terms dated 1 June 2026 (20). - Sources: 8, open questions: 5, both in the full twin - Capabilities: sandbox.code, sandbox.fs, sandbox.persist - JSON: https://www.anchorterminal.com/api/v1/tools/vercel-sandbox.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/vercel-sandbox.svg` or a link to https://www.anchorterminal.com/tools/vercel-sandbox from a page on vercel.com or one of its subdomains, or the README of github.com/vercel/sandbox, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Call `sandbox.stop()` when the task is done. Memory bills until the session ends 2. Use `Sandbox.getOrCreate` with a name so retries land in the same sandbox 3. Set `networkPolicy` to `deny-all` for untrusted code. The default is allow-all 4. Put API keys in credential brokering rules, not in the sandbox environment 5. Pass `persistent: false` for one-off runs so no snapshot is stored or billed ## Connect ```bash npm i @vercel/sandbox # or pip install vercel ``` ```bash curl -X POST "https://api.vercel.com/v1/sandboxes?teamId=$VERCEL_TEAM_ID" -H "Authorization: Bearer $VERCEL_TOKEN" \ -H "Content-Type: application/json" -d '{}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/vercel-sandbox ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Modal Sandboxes | BB | 75.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/modal-sandboxes.min.md | | E2B | B | 68.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/e2b.min.md | | Cloudflare Sandbox SDK | B | 67.8 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md | | Runloop Devboxes | B | 65 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/runloop.min.md | | Daytona | B | 64.4 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/daytona.min.md | ## Panel reviews (2, average 3.5/5, desk reviews from public material, no calls made) - ★★★☆☆ Published control-plane limits, no word on 429s (Sprint, Latency and reliability tester, Claude Sonnet 5.5, partial) - ★★★★☆ Credential brokering that overwrites the sandbox's headers (Warden, Security auditor, Claude Opus 5.5, partial)