Sandboxes for AI agents

This is a directory of agent sandbox products.

It updates on its own as new products get launched and existing products and pricing evolve.

The agent that runs the site, as well as the site itself, live on a sailbox.

Product Pricing The headline compute price as the provider states it. Sorting ranks prices stated per vCPU over time, converted to hourly. Other pricing models sort after, unranked. Free while idle Whether a stopped, paused, or sleeping sandbox costs nothing. Elastic Resources flex with what the sandbox actually uses, and the bill follows: yes when the provider bills on active or observed use, no when capacity is reserved or allocated and billed while it runs. Memory snapshots Whether RAM state survives a pause and resume, not just disk. Wake on request Whether a stopped sandbox wakes automatically on inbound traffic. Start / resume Typical time from create or resume to running. Sorting ranks stated times, converted to seconds; claims with no figure sort after, unranked. Max runtime The longest a sandbox may run. Isolation The isolation technology between sandboxes. GPUs Whether GPU instances are available for sandboxes. Docker Whether Docker containers can run inside the sandbox.
Sailboxes $0.015/vCPU-hr $0.015 per used vCPU-hour; $0.008 per used RAM GiB-hour; $0.0007 per used NVMe disk GiB-hour; $0.005-$0.012 per creation <3s No fixed limit Kernel-isolated Linux VM (full VM, not microVM)
Northflank Sandboxes $0.01667/vCPU-hr $0.01667/vCPU-hour Under 1 second (microVMs boot in <1s; P99 allocate ~566ms, P99 readiness ~733ms per ComputeSDK 2026 benchmark) No fixed limit MicroVM via Firecracker, gVisor, Kata Containers, and Cloud Hypervisor
Novita AI Sandbox $0.03528/vCPU-hr $0.0000098 per vCPU-second ($0.0353/vCPU-hr); $0.0000032 per GiB-second ($0.0115/GiB-hr) Under 200 ms on average for create; ~1 s to resume from paused 1 h (free tier); 3 h (paid tier); 4 h default, adjustable (enterprise tier) Firecracker microVM
Deno Sandbox $0.05/vCPU-hr $0.05 per CPU-hour (40h/month included with Pro plan, then $0.05/h; Free plan 15h included) under 1 second 30 min (per docs limits; extendable on demand via extendTimeout) Linux microVM (official docs say 'individual Linux microVMs'; Firecracker is named by third-party blogs and HN commentary but not in the official Deno documentation)
exe.dev $0.05/vCPU-hr $0.05 per CPU core-hour (usage pricing); $20/month Personal plan (2 vCPU / 8 GB RAM), $25/user/month Team plan Sub-second start; resume timing not specified KVM via Cloud Hypervisor (also uses crosvm; per a third-party article, Kata Containers)
Daytona $0.0504/vCPU-hr $0.0504 per vCPU-hour ~27 ms spin-up; under 90 ms end-to-end No fixed limit Linux namespaces and isolated containers for container sandboxes; full virtual machines with their own kernel for Linux and Windows VM sandboxes; isolated containers with exclusive GPU allocation for GPU sandboxes
E2B $0.0504/vCPU-hr $0.000014/vCPU-second (≈$0.0504/vCPU-hour); RAM $0.0000045/GiB/second (≈$0.0162/GiB-hour) less than 200 ms (same region) 24 h on Pro plan; 1 h on Hobby (free) plan Firecracker microVM
LangSmith Sandboxes $0.0576/vCPU-hr $0.0576 per vCPU-hour for compute, plus memory and storage <0.98 s p50 with prewarming No documented hard limit. idle_ttl_seconds (default 600s) auto-stops after inactivity; delete_after_stop_seconds deletes after stop. Setting idle_ttl_seconds=0 disables the idle stop. Hardware-virtualized microVM (kernel-isolated)
Fly.io Sprites $0.07/vCPU-hr $0.07 per CPU-hour and $0.04375 per GB-hour of memory ~100-500 ms warm resume; ~1-2 s cold start No fixed limit Firecracker microVM
Cloudflare Sandboxes $0.072/vCPU-hr $0.000020 per vCPU-second (~$0.072 per vCPU-hour) plus $0.0000025 per GiB-second of memory ~1-3 seconds No fixed limit; runtime is not guaranteed and may end on host restart Per-instance isolation on Cloudflare Containers platform (Firecracker microVMs; gVisor and QEMU also supported)
Azure Container Apps $0.0864/vCPU-hr $0.000024/vCPU-second and $0.000003/GiB-second while active (~$0.0864/vCPU-hour, ~$0.0108/GiB-hour). Sub-second No documented fixed limit; sandboxes auto-suspend after configurable idle timeout (1–60 min, default 5 min) and auto-delete after configurable days. Hardware-isolated microVM
AWS AgentCore Code Interpreter $0.0895/vCPU-hr $0.0895/vCPU-hour + $0.00945/GB-hour 300-800 ms 8 hours (configurable; 15 min default timeout, up to 8h max) Firecracker microVM (per-session, running on AWS Lambda MicroVMs)
AWS Lambda MicroVMs $0.0997/vCPU-hr $0.0000276944 per vCPU-second + $0.0000036667 per GB-second (ARM/Graviton, US East); snapshot read $0.00155/GB, write $0.0038/GB, storage $0.08/GB-month near-instant 8 h (28,800 s state-retention window) Firecracker microVM
Runloop $0.108/vCPU-hr $0.108 per CPU-hour (plus $0.0252 per GB-hour of memory) A few seconds to first command; suspend/resume typically takes seconds, depending on modified data Default 1 h, configurable Linux microVM with hardware isolation (two-layer VM + container)
Vercel Sandbox $0.128/vCPU-hr $0.128 per vCPU-hour (active CPU) Sub-second (millisecond-level startup with Firecracker microVMs) 24 h (Pro/Enterprise); 45 min (Hobby) Firecracker microVM
Modal Sandboxes $0.1419/vCPU-hr $0.00003942 per CPU core/sec, $0.00000667 per GiB memory/sec ~1 second for container boot; total Sandbox startup varies by image and initialization 24 h gVisor container runtime (default); full Linux VM with VM Sandboxes (Beta)
Ellipsis $0.142/vCPU-hr $0.142 / vCPU-hour (Ellipsis Cloud tier) ~8 s (warm snapshot boot); first session image build ~3m40s 24 h Linux container
Blaxel $0.0000115 per GB-RAM-second (active CPU) $0.0000115 per GB-RAM-second (active CPU) ~25 ms (resume from standby) Tier-dependent: up to 7 days (tier 0), up to 30 days (tier 1); unlimited in tier 2 and above microVM with hardware-level (kernel-level) isolation
CodeSandbox SDK $0.01486 per VM credit $0.01486 per VM credit 500 ms (P95) 24 h on Pro tier; no documented hard cap for Scale/Enterprise Firecracker microVM
Box by ASCII $0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe) $0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe) A few seconds for resume; create time not explicitly stated in extracted docs Default TTL overrideable up to 30 days; can disable auto-stop with ttl=null Hetzner Cloud VPS (current CX33); hypervisor not stated in docs
Morph Cloud $0.05 per MCU (Morph Compute Unit) $0.05 per MCU (Morph Compute Unit) ~250 ms (snapshot/restore via Infinibranch; cold-boot time for fresh images not documented) No fixed limit documented; TTLs control stop/pause on expiry Full VMs (hypervisor technology not explicitly named in public docs)
OpenComputer $0.07 per GB-hour of memory for a microVM $0.07 per GB-hour of memory for a microVM Sandboxes 'start in milliseconds' (docs overview); resume from hibernation 'in seconds' (home page, README). No specific P50/P95 latency published. No fixed limit (default 300s idle timeout auto-hibernates the VM) KVM (QEMU/KVM) — hardware-level virtualization; each sandbox is a full Linux VM with its own kernel
Scrapybara $29/month (Basic) or $99/month (Pro) $29/month (Basic) or $99/month (Pro) Under 1 second for Ubuntu and Browser instances; Windows instances are described as 'slow' without a specific figure Configurable via timeout_hours parameter; default 1 hour, no documented upper limit Full Linux (Ubuntu 22.04) and Windows 11 virtual machines; open-source computer service is packaged as a Docker image with xdotool/noVNC
Railway Sandboxes $50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB $50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB Per-sandbox VM on Railway's VM primitive (specific hypervisor technology not publicly disclosed)
Runwork Agent Sandbox $79/month (Startup tier: 3 seats, $30/month usage credits) $79/month (Startup tier: 3 seats, $30/month usage credits) Cold starts 'measured in milliseconds, not seconds' (no specific figure published) Bounded by per-task budgets, turn limits, and timeouts set in agent definitions; no global limit stated Isolated computing environment ("their own computer"), underlying isolation technology not specified publicly
Fly Machines From ~$0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering From ~$0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering Well under 1 s to start an existing or stopped Machine; a few hundred ms from suspend; ~2+ s for a cold start No fixed limit Firecracker microVM
Computer Agents Lite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour) Lite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour) Sub-second for warm container startup Isolated Linux container per agent (technology not specified)
GKE Agent Sandbox No Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing) No Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing) ~200 ms typical (90% of allocations under 200 ms; up to 300 sandboxes/sec/cluster; pre-warmed pods enable sub-second creation) Configurable TTL (no fixed maximum documented) gVisor (also supports Kata Containers and other OCI-compatible runtimes; runtimeClassName: gvisor)
Agent-Sandbox No published headline rate (open-source/self-hosted software) No published headline rate (open-source/self-hosted software)
Tencent Cloud CubeSandbox No published headline rate (open-source/self-hosted software) No published headline rate (open-source/self-hosted software) <60 ms average (bare metal; ~60 ms single concurrency, avg 67 ms under 50 concurrent creations) KVM MicroVM via RustVMM (each sandbox runs its own Linux kernel; hardware-isolated from the host and from other sandboxes)
Beam Per-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates) Per-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates) 1–3 s cold boot; container start under 1 s gVisor + runc
OpenSandbox

✓ yes · ✕ no · – no cited public fact. Hover or focus a dotted heading for what it measures.