17 tracked

AI Agent & Code-Execution Sandboxes

Ephemeral, secure runtimes (microVMs and containers) that spin up in milliseconds so agents and apps can execute generated code safely. Compared on cold start, isolation, pricing, GPU, persistence and SDK support.

Data last verified 2026-07-26

17 code sandboxes
25ms fastest start
$0.017 lowest vCPU-hr
5 with GPUs

Compare at a glance

SandboxIsolationCold start$/vCPU-hrGPUSessionMCP
Blaxel microVM 25ms $0.083 No Persistent (hibernation) Yes
Cloudflare Sandbox SDK V8 isolate + container 50ms $0.072 No 30min execution cap Yes
Daytona Docker container 90ms $0.05 Yes Persistent (lifecycle-managed) Yes
E2B Firecracker microVM 150ms $0.05 No Up to 24h n/a
Northflank Kata / gVisor microVM (selectable) 300ms $0.01667 Yes Unlimited n/a
Fly.io Machines microVM 300ms $0.07 Yes Persistent Yes
Vercel Sandbox Firecracker microVM 400ms $0.128 No 45min (Hobby) / 24h (Pro) n/a
Runloop microVM 400ms $0.108 No Configurable Yes
CodeSandbox SDK Firecracker microVM 500ms $0.05 No Configurable n/a
Modal gVisor 800ms $0.14 Yes Configurable n/a
Beam Container n/a n/a Yes Configurable n/a
Freestyle Hardware-virtualized VM n/a $0.04 No Persistent VMs (paid plans) n/a
Fly.io Sprites Firecracker microVM n/a $0.07 No Persistent (pauses when idle) n/a
Together Code Interpreter Managed isolated sandbox n/a n/a No 60-minute reusable sessions n/a
Deno Sandbox V8 isolate n/a $0.05 No n/a n/a
Blacksmith Sandboxes Full VM n/a n/a No n/a n/a
AWS Fargate Firecracker microVM n/a $0.04048 No Long-running tasks n/a

Figures are vendor-published approximations as of the verified date. Tap a name for sources.

All ai sandboxes

Blaxel

AI code-execution sandbox

Blaxel is an idle-cost-optimized sandbox that resumes from hibernation in ~25ms with memory and processes intact, and charges $0 for compute on standby.

25ms cold start Compare

Cloudflare Sandbox SDK

AI code-execution sandbox

Cloudflare Sandbox SDK runs code on Cloudflare Containers + Durable Objects, blending V8 isolates (~50ms) with containers, bundled into the Workers Paid plan.

50ms cold start Compare

Daytona

AI code-execution sandbox

Daytona is an open-source, container-isolated sandbox for AI agents with ~90ms creation, persistent stateful workspaces, mid-execution snapshots and optional H100 GPUs.

90ms cold start Compare

E2B

AI code-execution sandbox

E2B is a Firecracker-microVM sandbox that gives AI agents a secure, ~150ms-cold-start environment to run generated code, with pause/resume and filesystem snapshots.

150ms cold start Compare

Northflank

AI code-execution sandbox

Northflank runs sandboxes with selectable Kata/gVisor microVM isolation, unlimited session duration, any OCI image and BYOC deployment, at the lowest published vCPU rate in the category.

300ms cold start Compare

Fly.io Machines

AI code-execution sandbox

Fly.io Machines are fast-booting microVMs with a persistent ext4 filesystem, ~300ms checkpoints, zero idle cost and a native MCP endpoint.

300ms cold start Compare

Vercel Sandbox

AI code-execution sandbox

Vercel Sandbox is a Firecracker-based, JavaScript/TypeScript-native sandbox that is persistent by default, billed on active CPU plus a per-creation fee.

400ms cold start Compare

Runloop

AI code-execution sandbox

Runloop provides enterprise "devbox" infrastructure for coding agents: SOC 2, 10K+ parallel instances, git-style disk snapshots with branching, and built-in SWE-bench evaluation.

400ms cold start Compare

CodeSandbox SDK

AI code-execution sandbox

CodeSandbox SDK (now Together Code Sandbox) runs Firecracker microVMs with a git-versioned filesystem, ~500ms resume and sub-second forking, tuned for web-dev agents.

500ms cold start Compare

Modal

AI code-execution sandbox

Modal is a Python-first serverless compute platform whose Sandboxes offer gVisor isolation, sub-second cold start and, uniquely, GPUs (T4 through B200) inside the sandbox.

800ms cold start Compare

Beam

AI code-execution sandbox

Beam is a serverless sandbox and GPU platform with sub-second cold starts, per-second billing and no subscription floor, notable for offering GPUs inside the sandbox (H100 at $1.74/hr).

$30/mo free credits, no subscription floor Compare

Freestyle

AI code-execution sandbox

Freestyle gives AI agents hardware-virtualized Linux VMs with built-in Git, real persistent state and per-second billing at $0.04/vCPU-hr.

20 vCPU-hrs/day, 10 concurrent VMs (free forever) Compare

Fly.io Sprites

AI code-execution sandbox

Fly.io Sprites are stateful sandbox environments on Firecracker microVMs, with a persistent ext4 filesystem and roughly 300ms checkpoint/restore, that pause to zero cost when idle.

AI code-execution sandbox Compare

Together Code Interpreter

AI code-execution sandbox

Together Code Interpreter is a session-based API that runs LLM-generated Python in an isolated sandbox, billed at a flat $0.03 per 60-minute session.

AI code-execution sandbox Compare

Deno Sandbox

AI code-execution sandbox

Deno Sandbox is a V8-isolate sandbox, part of Deno Deploy, for running untrusted or LLM-generated JavaScript and TypeScript, billed on CPU time rather than wall-clock.

Included in Deno Deploy Pro (40 CPU-h, 1000 GB-h, 5 GiB volume) Compare

Blacksmith Sandboxes

AI code-execution sandbox

Blacksmith Sandboxes (beta) are full VMs for coding agents that mirror a CI environment: they run Docker, system packages and services, boot from managed environment snapshots, and target the fastest single-core CPU for build- and test-heavy agent work.

Beta access (waitlist) Compare

AWS Fargate

AI code-execution sandbox

AWS Fargate is serverless container compute for ECS and EKS that runs each task in a Firecracker microVM, a general-purpose primitive teams use to isolate untrusted or agent-generated code, priced at $0.04048 per vCPU-hour and $0.004445 per GB-hour (Linux/x86, US East).

No free tier Compare

FAQ

What is an AI agent sandbox?

An AI agent sandbox is an isolated compute environment (usually a microVM or container) where an AI agent can execute generated code securely, without risking the host. Key attributes are cold-start time, isolation strength, pricing, persistence and GPU support.

Which AI sandbox has the fastest cold start?

Among tracked providers, V8-isolate and hibernation-based options are fastest (Cloudflare isolates ~50ms, Blaxel resume ~25ms), while Firecracker microVMs like E2B land around 150ms. Full container/microVM cold starts range up to a few seconds.

Which AI sandboxes support GPUs?

Modal, Daytona, Northflank and Fly.io offer GPU access inside or alongside the sandbox; Modal is the standout for GPU-in-sandbox workloads.

The Sandbox Brief

What moved in the sandbox world, every Friday.

Pricing changes, new entrants, benchmark refreshes and one sharp take from Eve Harper. Read by engineers choosing where their agents and apps run. No fluff. Read the archive.

Free · unsubscribe anytime · no spam.