Railway Sandboxes
Railway Sandboxes are short-lived Linux virtual machines scoped to a Railway environment that can be provisioned on demand to run commands, read and write files, and then be destroyed. They target agent workloads and untrusted code execution, and are controlled programmatically via the TypeScript SDK, the Railway CLI, or the dashboard. The product reached general availability on June 26, 2026 after a public beta that started May 14, 2026.
| Pricing model | Per-second, billed on vCPU and memory consumed while running |
|---|---|
| Pricing The headline compute price as the provider states it. Sorting ranks prices stated per vCPU over time, converted to hourly. Other pricing models sort after, unranked. | $50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB |
| Free while idle Whether a stopped, paused, or sleeping sandbox costs nothing. | ✕ |
| Elastic Resources flex with what the sandbox actually uses, and the bill follows: yes when the provider bills on active or observed use, no when capacity is reserved or allocated and billed while it runs. | ✓ |
| Memory snapshots Whether RAM state survives a pause and resume, not just disk. | ✕ |
| Wake on request Whether a stopped sandbox wakes automatically on inbound traffic. | ✕ |
| Start / resume Typical time from create or resume to running. Sorting ranks stated times, converted to seconds; claims with no figure sort after, unranked. | – |
| Max runtime The longest a sandbox may run. | No fixed wall-clock maximum stated; Hobby/Pro can disable idle destruction for an infinite TTL, while Trial/Free top out at a 5-minute idle timeout |
| Isolation The isolation technology between sandboxes. | Per-sandbox VM on Railway's VM primitive (specific hypervisor technology not publicly disclosed) |
| GPUs Whether GPU instances are available for sandboxes. | ✕ |
| Docker Whether Docker containers can run inside the sandbox. | ✓ |
| SDKs | TypeScript |
✓ yes · ✕ no · – no cited public fact.
Commands and keepalive heartbeats reset the idle timer, and Railway defers idle teardown while an exec command is running or an active SSH or forwarding session sends heartbeats. A background process outside an active session does not keep the sandbox alive by itself. Checkpoints and forks preserve disk contents, not running processes or RAM. Railway keeps billing memory, background CPU use, and outbound traffic while a sandbox waits for work; destroying the sandbox stops further compute usage. The TypeScript SDK is in beta and will have breaking changes.
Sources
- https://railway.com/changelog/2026-06-12-docker-in-sandboxes
- https://github.com/railwayapp/railway-ts-sdk
- https://docs.railway.com/guides/agents-in-sandboxes
- https://modal.com/docs/examples/gpu_snapshot
- https://cerebrium.ai/blog/reducing-gpu-cold-starts-with-memory-snapshots-restoring-cuda-workloads-in-second
- https://context7.com/websites/railway
- https://railway.com/pricing
- https://docs.railway.com/sandboxes
- https://docs.railway.com/cli/sandbox
- https://servercompass.app/blog/railway-pricing-what-youll-actually-pay
- https://makerkit.dev/pricing-calculator/railway
- https://checkthat.ai/brands/indian-railways/pricing
- https://www.facebook.com/TrainStation/posts/%EF%B8%8F-sandbox-is-perfect-for-starting-on-a-grade-hauling-heavy-loads-or-getting-thro/1238087361801375/
- https://www.npmjs.com/package/@computesdk/railway
- https://x.com/Railway/article/2069801781916549204
- https://railway.com/changelog/2026-09-18-railway-sandboxes
- https://docs.railway.com/pricing/plans
Last verified 2026-10-05. Corrections land through the update log.