Cloudflare Sandboxes
https://developers.cloudflare.com/sandboxes/
Cloudflare provides two sandbox environments, both accessible through a Worker: Containers run a provided image in a full Linux environment, and Dynamic Workers create a new Worker at runtime to run untrusted JavaScript, Python, or WebAssembly. Use cases include agent-written code, user-uploaded applications, data analysis, development previews, and build pipelines, along with any other work that should not share a process with the application.
| Pricing model | Per-second (10ms granularity), billed only while the instance is awake for active vCPU, memory, and disk |
|---|---|
| Pricing The headline compute price as the provider states it. Sorting ranks prices stated per vCPU over time, converted to hourly. Other pricing models sort after, unranked. | $0.000020 per vCPU-second (~$0.072 per vCPU-hour) plus $0.0000025 per GiB-second of memory |
| Free while idle Whether a stopped, paused, or sleeping sandbox costs nothing. | ✓ |
| Elastic Resources flex with what the sandbox actually uses, and the bill follows: yes when the provider bills on active or observed use, no when capacity is reserved or allocated and billed while it runs. | ✓ |
| Memory snapshots Whether RAM state survives a pause and resume, not just disk. | ✕ |
| Wake on request Whether a stopped sandbox wakes automatically on inbound traffic. | ✓ |
| Start / resume Typical time from create or resume to running. Sorting ranks stated times, converted to seconds; claims with no figure sort after, unranked. | ~1-3 seconds |
| Max runtime The longest a sandbox may run. | No fixed limit; runtime is not guaranteed and may end on host restart |
| Isolation The isolation technology between sandboxes. | Dedicated VM per container instance |
| GPUs Whether GPU instances are available for sandboxes. | ✕ |
| Docker Whether Docker containers can run inside the sandbox. | ✓ |
| SDKs | TypeScript |
✓ yes · ✕ no · – no cited public fact.
Container snapshots are in public beta and save the writable root filesystem only; they do not include mounted directories, memory, or running processes.
Sources
- https://developers.cloudflare.com/sandbox/guides/docker-in-docker/
- https://github.com/cloudflare/sandbox-sdk/blob/main/DOCKER_README.md
- https://github.com/cloudflare/sandbox-sdk
- https://github.com/cloudflare/sandbox-sdk/blob/main/packages/sandbox/README.md
- https://blog.cloudflare.com/sandbox-ga/
- https://developers.cloudflare.com/sandbox/
- https://www.ernestchiang.com/en/posts/2025/firecracker-powered-containers-arrive-on-cloudflare/
- https://developers.cloudflare.com/sandbox/api/backups/
- https://developers.cloudflare.com/containers/faq/
- https://developers.cloudflare.com/containers/platform-details/architecture/
- https://developers.cloudflare.com/sandbox/api/lifecycle/
- https://developers.cloudflare.com/sandbox/concepts/sandboxes/
- https://developers.cloudflare.com/sandbox/configuration/sandbox-options/
- https://developers.cloudflare.com/sandbox/platform/pricing/
- https://blog.cloudflare.com/container-platform-preview/
- https://nirvanalabs.io/blog/agent-sandboxes-comparison-2026
- https://developers.cloudflare.com/containers/concepts/architecture/
- https://developers.cloudflare.com/sandbox/files/save-and-restore-a-workspace/
- https://developers.cloudflare.com/sandbox/concepts/lifetime/
Last verified 2026-10-05. Corrections land through the update log.