Sandboxes for AI agents

This is a directory of agent sandbox products.

It updates on its own as new products get launched and existing products and pricing evolve.

The agent that runs the site, as well as the site itself, live on a sailbox.

Product Pricing The headline compute price as the provider states it. Sorting ranks prices stated per vCPU over time, converted to hourly. Other pricing models sort after, unranked. Free while idle Whether a stopped, paused, or sleeping sandbox costs nothing. Elastic Resources flex with what the sandbox actually uses, and the bill follows: yes when the provider bills on active or observed use, no when capacity is reserved or allocated and billed while it runs. Memory snapshots Whether RAM state survives a pause and resume, not just disk. Wake on request Whether a stopped sandbox wakes automatically on inbound traffic. Start / resume Typical time from create or resume to running. Sorting ranks stated times, converted to seconds; claims with no figure sort after, unranked. Max runtime The longest a sandbox may run. Isolation The isolation technology between sandboxes. GPUs Whether GPU instances are available for sandboxes. Docker Whether Docker containers can run inside the sandbox.
Agent37 Cloud $0.0011/vCPU-hr Cloud API: $0.0011 per vCPU-hour ✕ ✕ ✓ ✓ A few seconds to restore from sleep; create-to-ready time is not stated. No fixed limit; an instance lives until you delete it gVisor – ✕
Sailboxes $0.015/vCPU-hr $0.015 per used vCPU-hour; $0.008 per used RAM GiB-hour; $0.0007 per used NVMe disk GiB-hour; $0.000411 per volume-storage GiB-hour; $0.005-$0.012 per creation on Free ✓ ✓ ✓ ✓ <2s start/resume; waking from sleep takes a few seconds Unlimited by default; optional max lifetime up to 4,294,967,295 s Kernel-isolated Linux VM (full VM, not microVM) ✕ ✓
Northflank Sandboxes $0.01667/vCPU-hr $0.01667/vCPU-hour ✕ ✓ ✕ ✕ Under 1 second (microVMs boot in <1s; P99 allocate ~566ms, P99 readiness ~733ms per ComputeSDK 2026 benchmark) No fixed limit CPU workloads: microVMs; GPU workloads: gVisor (Northflank cloud) ✓ ✓
Novita AI Sandbox $0.03528/vCPU-hr $0.0000098 per vCPU-second ($0.0353/vCPU-hr); $0.0000032 per GiB-second ($0.0115/GiB-hr) ✕ ✕ ✓ ✓ Under 200 ms on average for create; ~1 s to resume from paused 1 h (free tier); 3 h (paid tier); 4 h default, adjustable (enterprise tier) Firecracker microVM ✕ –
Fly.io Sprites $0.0385/vCPU-hr $0.0385 per CPU-hour; $0.021875 per GB-hour of memory ✓ ✕ ✓ ✓ ~100-500 ms warm resume; ~1-2 s cold start No fixed limit Firecracker microVM ✕ ✓
DigitalOcean Agent Droplets $0.044/vCPU-hr $0.044 per vCPU-hour at the published list rate, before plan discounts ✕ ✕ – – About 1 second to start; about 200 ms to resume 744 h of active compute per session per month Firecracker microVM – –
DigitalOcean Managed Agents $0.044/vCPU-hr $0.044 per vCPU-hour for CPU actual use ✕ ✓ ✓ ✓ Create: under a couple of seconds generally; resume: about 200 ms; LangGraph cold start: about 20 s – Dedicated Firecracker microVM per session – –
Google Cloud Agent Sandbox $0.0445/vCPU-hr GKE Autopilot general-purpose, regular price: $0.0445 per vCPU-hour ✕ ✕ ✓ ✓ ~200 ms for 90% of warm-pool allocations; under 1 second with pre-warmed Pods No fixed limit; runs until deleted unless a shutdown time is set Runtime-configurable kernel-level isolation, typically gVisor; Kata Containers is also supported ✓ ✓
Daytona $0.0504/vCPU-hr $0.0504 per vCPU-hour ✓ ✕ ✓ – ~27 ms spin-up; under 90 ms end-to-end No fixed limit Linux namespaces and isolated containers for container sandboxes; full virtual machines with their own kernel for Linux and Windows VM sandboxes; isolated containers with exclusive GPU allocation for GPU sandboxes ✓ ✓
E2B $0.0504/vCPU-hr $0.000014/vCPU-second (≈$0.0504/vCPU-hour); RAM $0.0000045/GiB/second (≈$0.0162/GiB-hour) ✓ ✕ ✓ ✓ ~1 s to resume a paused sandbox; create time not stated 24 h on Pro plan; 1 h on Hobby (free) plan Firecracker microVM ✕ ✓
LangSmith Sandboxes $0.0576/vCPU-hr $0.0576 per vCPU-hour; $0.01845 per GiB-hour of memory; $0.000123 per GiB-hour of storage (LSU rates, 1 LSU = $1) ✕ – ✓ ✓ p50 under 0.98 s with prewarming; cold-resume duration not publicly stated A configurable hard TTL can cap total runtime; no maximum value is publicly stated Hardware-virtualized microVM (kernel-isolated) ✕ ✓
Islo $0.07/vCPU-hr $0.07 per CPU-hour ✓ ✕ – ✓ – No fixed limit documented; an optional active-runtime limit can be set MicroVM with its own kernel – –
Cloudflare Sandboxes $0.072/vCPU-hr $0.000020 per vCPU-second (~$0.072 per vCPU-hour) plus $0.0000025 per GiB-second of memory ✓ ✓ ✕ ✓ ~1-3 seconds No fixed limit; runtime is not guaranteed and may end on host restart Dedicated VM per container instance ✕ ✓
Azure Container Apps $0.0864/vCPU-hr $0.000024/vCPU-second and $0.000003/GiB-second while active (~$0.0864/vCPU-hour, ~$0.0108/GiB-hour). ✓ ✓ ✓ – Sub-second No documented fixed limit; sandboxes auto-suspend after configurable idle timeout (1–60 min, default 5 min) and auto-delete after configurable days. Isolated, lightweight virtual machine ✕ –
AWS AgentCore Code Interpreter $0.0895/vCPU-hr $0.0895/vCPU-hour + $0.00945/GB-hour ✕ ✓ ✓ – 300-800 ms 8 hours (configurable; 15 min default timeout, up to 8h max) Firecracker microVM (per-session, running on AWS Lambda MicroVMs) ✕ ✕
AWS Lambda MicroVMs $0.0997/vCPU-hr $0.0000276944 per vCPU-second + $0.0000036667 per GB-second (ARM/Graviton, US East); snapshot read $0.00155/GB, write $0.0038/GB, storage $0.08/GB-month ✓ – ✓ ✓ Near-instant; no numeric typical duration published Up to 8 hours Firecracker microVM ✕ ✓
Deno Sandbox $0.1/vCPU-hr $0.10/CPU-hour; $0.025/GiB-hour of memory; $0.20/GiB-month of volume storage ✓ ✓ – – under 200 ms (product page demo shows 93 ms) 30 min (per docs limits; extendable on demand via extendTimeout) Firecracker microVM – –
Runloop $0.108/vCPU-hr $0.108 per CPU-hour (plus $0.0252 per GB-hour of memory) ✓ ✕ ✕ ✓ A few seconds to first command; suspend/resume typically takes seconds, depending on modified data Default 1 h, configurable Linux microVM with hardware isolation (two-layer VM + container) ✓ ✓
AWS AgentCore Runtime $0.1276/vCPU-hr $0.1276 per vCPU-hour for Runtime V2 consumption pricing ✕ ✓ ✕ ✓ P75 1.9–2.0 seconds for 200 MB–2 GB container images on Runtime V2 Up to 8 hours per microVM lifecycle; up to 14 days on Instances. Dedicated microVM per user session for serverless compute, with hardware-enforced session isolation; Instances use managed EC2 compute. ✓ ✓
Vercel Sandbox $0.128/vCPU-hr $0.128 per vCPU-hour (active CPU) ✓ ✓ ✕ ✕ Milliseconds for normal startup; snapshot restores p75 under 1 s and p95 about 5 s 24 h (Pro/Enterprise); 45 min (Hobby) Firecracker microVM ✕ ✓
Modal Sandboxes $0.1419/vCPU-hr $0.00003942 per CPU core/sec, $0.00000667 per GiB memory/sec ✕ – ✓ ✕ ~1 s container boot; warm-up can range from seconds to minutes 24 h gVisor container runtime (default); full Linux VM with VM Sandboxes (Beta) ✓ ✓
Ellipsis $0.142/vCPU-hr $0.142 / vCPU-hour (Ellipsis Cloud tier) ✓ ✕ ✕ – ~8 s (warm snapshot boot); first session image build ~3m40s 24 h Isolated Linux VM/machine; exact underlying technology is not publicly specified – –
Blaxel $0.0000115 / GB RAM-second for active sandbox compute; $0.20 / GB-month for standby snapshot storage $0.0000115 / GB RAM-second for active sandbox compute; $0.20 / GB-month for standby snapshot storage ✓ ✓ ✓ ✓ ~25 ms (resume from standby) Tier-dependent: up to 7 days (tier 0), up to 30 days (tier 1); unlimited in tier 2 and above microVM with hardware-level (kernel-level) isolation ✕ ✓
OpenComputer $0.00315/min for the default 2 GB / 1 vCPU agent-session machine, billed to the second. $0.00315/min for the default 2 GB / 1 vCPU agent-session machine, billed to the second. ✓ ✕ ✓ ✓ ~300 ms from a golden snapshot; under 1 s at p95 for boot; 1-2 s average wake from hibernation No fixed limit (default 300s idle timeout auto-hibernates the VM) KVM (QEMU/KVM) — hardware-level virtualization; each sandbox is a full Linux VM with its own kernel ✕ –
CodeSandbox SDK $0.01486 per VM credit $0.01486 per VM credit – – ✓ ✓ 1-3 s to create from a template; 0.5-2 s to resume from a memory/disk snapshot, 5-20 s from a disk snapshot, 20-60 s from archive Unlimited Firecracker microVM ✕ ✓
boat by ASCII $0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe) $0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe) ✓ ✕ ✕ – A few seconds for resume; create time not explicitly stated in extracted docs Default TTL overrideable up to 30 days; can disable auto-stop with ttl=null Linux (Ubuntu) VM, normally on AMD Ryzen 9 9950X bare-metal hosts, with Hetzner cloud VM fallback when capacity is exhausted; hypervisor not stated ✕ ✓
Morph Cloud $0.05 per MCU-hour $0.05 per MCU-hour ✓ – ✓ ✓ <250 ms No fixed limit documented; TTLs control stop/pause on expiry Full VMs (hypervisor technology not explicitly named in public docs) – ✓
Scrapybara $29/month (Basic) or $99/month (Pro) $29/month (Basic) or $99/month (Pro) – – – – Under 1 second for Ubuntu and Browser instances; Windows instances are described as 'slow' without a specific figure 24 h (configurable; 1 h default) Full Linux (Ubuntu 22.04) and Windows 11 virtual machines; open-source computer service is packaged as a Docker image with xdotool/noVNC – –
Railway Sandboxes $50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB $50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB ✕ ✓ ✕ ✕ – No fixed wall-clock maximum stated; Hobby/Pro can disable idle destruction for an infinite TTL, while Trial/Free top out at a 5-minute idle timeout Per-sandbox VM on Railway's VM primitive (specific hypervisor technology not publicly disclosed) ✕ ✓
Runwork Agent Sandbox $79/month (Startup tier: 3 seats, $30/month usage credits) $79/month (Startup tier: 3 seats, $30/month usage credits) ✓ – – – Cold starts 'measured in milliseconds, not seconds' (no specific figure published) Bounded by per-task budgets, turn limits, and timeouts set in agent definitions; no global limit stated Isolated computing environment ("their own computer"), underlying isolation technology not specified publicly – –
OpenAI Hosted Sandboxes 1 GB: $0.03; 4 GB: $0.12; 16 GB: $0.48; 64 GB: $1.92 per 20-minute session per container 1 GB: $0.03; 4 GB: $0.12; 16 GB: $0.48; 64 GB: $1.92 per 20-minute session per container – ✕ – – – – – – –
Fly Machines From $0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering From $0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering ✕ ✕ ✓ ✓ Well under 1 s to start a stopped Machine; a few hundred ms from suspend; ~2+ s cold start for common apps; low double-digit seconds to create a new Machine No fixed limit Firecracker microVM ✕ ✕
exe.dev From $15/month pooled subscription; standalone sandboxes are $0.105 per 2 vCPUs per hour From $15/month pooled subscription; standalone sandboxes are $0.105 per 2 vCPUs per hour ✓ ✕ ✕ ✕ ~2 s to create a new VM – KVM via Cloud Hypervisor (also uses crosvm; per a third-party article, Kata Containers) ✕ ✓
Computer Agents Lite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour) Lite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour) ✓ ✓ – – Sub-second for warm container startup – Isolated Linux container per agent (technology not specified) – –
Docker Cloud Sandboxes Micro (1 vCPU, 2 GiB): $0.07 per hour Micro (1 vCPU, 2 GiB): $0.07 per hour ✓ ✕ ✓ – – 24 h per session Docker-built microVM with its own kernel – ✓
GKE Agent Sandbox No Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing) No Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing) ✕ – ✓ ✕ ~200 ms typical (90% of allocations under 200 ms; up to 300 sandboxes/sec/cluster; pre-warmed pods enable sub-second creation) No fixed limit; standard sandboxes run until manually deleted unless a shutdown time is configured gVisor through GKE Sandbox (`runtimeClassName: gvisor`); Agent Sandbox is runtime-agnostic and can also use Kata Containers ✓ ✓
NVIDIA OpenShell No OpenShell compute rate published; compute is user-provided No OpenShell compute rate published; compute is user-provided – – ✕ ✕ – – Configurable Docker or Podman containers, Kubernetes pods, or VMs, with Landlock, seccomp, and network-namespace controls on the agent process ✓ ✕
Agent Substrate No public Agent Substrate compute rate stated No public Agent Substrate compute rate stated ✓ ✓ ✓ ✓ Sub-500 ms for resume; separate cold-start time is not stated – gVisor or Cloud Hypervisor microVMs ✕ –
Brig No public compute rate stated No public compute rate stated – – – – – – macOS: hull microVM runtime, usually using hvi with Hypervisor.framework; vz/Virtualization.framework is another backend. Linux: nerdctl/containerd with the urunc shim, which boots a microVM. ✕ ✕
Proliferate No published compute rate (open-source, self-hosted software) No published compute rate (open-source, self-hosted software) – – – – – – – – ✓
Auctus Core No published headline rate (custom private-offer pricing on AWS Marketplace) No published headline rate (custom private-offer pricing on AWS Marketplace) – – – – – – – – –
Agent-Sandbox No published headline rate (open-source/self-hosted software) No published headline rate (open-source/self-hosted software) – – – – – – – – –
NVIDIA NemoClaw No published headline rate (open-source/self-hosted software) No published headline rate (open-source/self-hosted software) – – – – – – – – –
Tencent Cloud CubeSandbox No published headline rate (open-source/self-hosted software) No published headline rate (open-source/self-hosted software) ✓ – ✓ ✓ ~60 ms create (single-concurrency bare-metal benchmark); ~67 ms average under 50 concurrent creations; auto-resume typically sub-second to a few seconds – KVM MicroVM via RustVMM (each sandbox runs its own Linux kernel; hardware-isolated from the host and from other sandboxes) ✕ ✕
Beam Per-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates) Per-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates) ✓ ✕ ✓ – 1–3 s cold boot No fixed limit (TTL = -1) gVisor + runc ✓ ✓
Sai Starter $50/month (early-access discount, down from $200/month) Starter $50/month (early-access discount, down from $200/month) – – – – – – – – –
Agentic Studio – – – – – – – Process- and network-level isolation – –
Managed Agents API on Agent Platform – – – – – – – Isolated sandbox container – –
OpenSandbox – – – – – – – – – –
StateSet Sandboxes – – – – – – – Container, gVisor, Kata, Firecracker, or WASM (selectable per workload) – –

✓ yes · ✕ no · – no cited public fact. Hover or focus a dotted heading for what it measures.