Vercel Sandbox

https://vercel.com/docs/sandbox

Vercel Sandbox is an on-demand, isolated Linux microVM (based on Firecracker) that safely runs arbitrary or untrusted code via an SDK or CLI. It is used by AI coding agents, AI code interpreters, and developer tools that need ephemeral, sandboxed execution environments for tasks such as running AI-generated scripts, executing user-submitted code, or previewing apps. Sandboxes are persistent by default, support snapshots and port exposure for live URLs, and can run in all 20 Vercel compute regions.

Pricing model Usage-based billing for active CPU and provisioned memory; creations, data transfer, snapshots, and drives billed separately
Pricing The headline compute price as the provider states it. Sorting ranks prices stated per vCPU over time, converted to hourly. Other pricing models sort after, unranked. $0.128 per vCPU-hour (active CPU)
Free while idle Whether a stopped, paused, or sleeping sandbox costs nothing. ✓
Elastic Resources flex with what the sandbox actually uses, and the bill follows: yes when the provider bills on active or observed use, no when capacity is reserved or allocated and billed while it runs. ✓
Memory snapshots Whether RAM state survives a pause and resume, not just disk. ✕
Wake on request Whether a stopped sandbox wakes automatically on inbound traffic. ✕
Start / resume Typical time from create or resume to running. Sorting ranks stated times, converted to seconds; claims with no figure sort after, unranked. Milliseconds for normal startup; snapshot restores p75 under 1 s and p95 about 5 s
Max runtime The longest a sandbox may run. 24 h (Pro/Enterprise); 45 min (Hobby)
Isolation The isolation technology between sandboxes. Firecracker microVM
GPUs Whether GPU instances are available for sandboxes. ✕
Docker Whether Docker containers can run inside the sandbox. ✓
SDKs JavaScript, TypeScript, Python

✓ yes · ✕ no · – no cited public fact.

Persistence is the default: the SDK snapshots the filesystem when a session stops and restores it on resume. Vercel does not document RAM state surviving a stop. Snapshots expire 30 days after their last use by default, and you can shorten, extend, or remove that expiration, so a snapshot can be kept indefinitely. Snapshot storage is billed separately from compute. Starting with SDK v3, sandboxes that specify neither a runtime nor an image use the Ubuntu-based `vercel/sandbox/universal:latest` managed image.

Sources

Last verified 2026-09-30. Corrections land through the update log.