{
  "type": "comparison",
  "id": "code-sandboxes",
  "title": "Code sandboxes for AI agents",
  "summary": "E2B, Daytona, Modal, Vercel Sandbox, Cloudflare Sandboxes, Fly.io Sprites and microsandbox compared on isolation, pricing, free tier, lifetime, persistence, egress controls, SDKs, GPUs and self-hosting.",
  "author": "Agentica Author",
  "tags": [
    "sandboxes",
    "code-execution",
    "infrastructure",
    "security",
    "microvm"
  ],
  "published": "2026-10-02",
  "last_verified": "2026-10-02",
  "entries": [
    "e2b",
    "daytona",
    "modal",
    "vercel-sandbox",
    "cloudflare-sandbox",
    "fly-io",
    "microsandbox",
    "northflank-sandboxes"
  ],
  "links": {
    "html": "https://indexagentica.com/compare/code-sandboxes/",
    "markdown": "https://indexagentica.com/compare/code-sandboxes.md",
    "json": "https://indexagentica.com/api/longform/compare/code-sandboxes.json",
    "source": "https://github.com/Drudley/indexagentica/blob/main/content-long/compare/code-sandboxes.md"
  },
  "status": "published",
  "comparison": {
    "subjects": [
      {
        "id": "e2b",
        "name": "E2B",
        "summary": "Open-source, secure cloud sandboxes for AI agents: an isolated machine per agent to run code, browse and use tools.",
        "url": "https://indexagentica.com/entries/e2b/",
        "json": "https://indexagentica.com/api/entries/e2b.json"
      },
      {
        "id": "daytona",
        "name": "Daytona",
        "summary": "Secure and elastic infrastructure (sandboxes) for running AI-generated code.",
        "url": "https://indexagentica.com/entries/daytona/",
        "json": "https://indexagentica.com/api/entries/daytona.json"
      },
      {
        "id": "modal",
        "name": "Modal",
        "summary": "Cloud platform for production AI: inference, training, sandboxes and serverless functions on one platform.",
        "url": "https://indexagentica.com/entries/modal/",
        "json": "https://indexagentica.com/api/entries/modal.json"
      },
      {
        "id": "vercel-sandbox",
        "name": "Vercel Sandbox",
        "summary": "Ephemeral compute primitive that runs untrusted or agent-generated code in isolated Linux microVMs.",
        "url": "https://indexagentica.com/entries/vercel-sandbox/",
        "json": "https://indexagentica.com/api/entries/vercel-sandbox.json"
      },
      {
        "id": "cloudflare-sandbox",
        "name": "Cloudflare Sandboxes",
        "summary": "Execute untrusted or generated code on Cloudflare in Linux VMs (Containers) or isolated Dynamic Workers, via the Sandbox SDK.",
        "url": "https://indexagentica.com/entries/cloudflare-sandbox/",
        "json": "https://indexagentica.com/api/entries/cloudflare-sandbox.json"
      },
      {
        "id": "fly-io",
        "name": "Fly.io",
        "summary": "Global public cloud with hardware-isolated Fly Machines for running full-stack and AI applications, driven by the flyctl CLI.",
        "url": "https://indexagentica.com/entries/fly-io/",
        "json": "https://indexagentica.com/api/entries/fly-io.json"
      },
      {
        "id": "microsandbox",
        "name": "microsandbox",
        "summary": "Easy, fast, programmable, local-first microVM runtime for untrusted workloads.",
        "url": "https://indexagentica.com/entries/microsandbox/",
        "json": "https://indexagentica.com/api/entries/microsandbox.json"
      }
    ],
    "criteria": [
      "Isolation",
      "Compute price",
      "Free allowance",
      "Lifetime",
      "Persistence",
      "Egress controls",
      "SDKs",
      "GPUs",
      "Self-host or BYOC"
    ],
    "rows": {
      "e2b": {
        "Isolation": "Firecracker microVM with its own kernel",
        "Compute price": "$0.0504/vCPU-h and $0.0162/GiB-h, billed per second on provisioned size (default 2 vCPU, 4 GiB); Pro plan $150/mo",
        "Free allowance": "Hobby plan with a one-time $100 usage credit; 20 concurrent sandboxes",
        "Lifetime": "Default 5 min; up to 1 h continuous (Hobby) or 24 h (Pro). Pausing resets the window",
        "Persistence": "Pause and resume keeps filesystem and memory; paused sandboxes kept indefinitely; volumes",
        "Egress controls": "On by default; allow_internet_access=False, or allow/deny lists of IPs, CIDRs and domains; BYO SOCKS5 proxy; secret injection at the egress proxy",
        "SDKs": "Python, JavaScript/TypeScript (plus a code interpreter SDK)",
        "GPUs": "Not offered",
        "Self-host or BYOC": "Runtime is open source (Apache-2.0); BYOC on AWS, GCP and Azure on Enterprise ($3k/mo minimum)"
      },
      "daytona": {
        "Isolation": "OCI container by default; VM sandboxes (Linux, Windows, nested KVM), macOS and GPU sandboxes available",
        "Compute price": "$0.0504/vCPU-h, $0.0162/GiB-h, storage $0.000108/GiB-h after 5 GiB free; billed per second",
        "Free allowance": "$200 of free compute",
        "Lifetime": "Runs until stopped; auto-stop after 15 min of inactivity by default, plus auto-archive and auto-delete",
        "Persistence": "Stopped and archived sandboxes keep their filesystem; snapshots and fork",
        "Egress controls": "Set by org tier (Tier 1-2 restricted, Tier 3-4 open); per sandbox network_block_all, CIDR allowlist, domain allowlist or outbound proxy, changeable at runtime",
        "SDKs": "Python, TypeScript, Go, Java, Ruby",
        "GPUs": "Yes, up to 8 GPUs per sandbox (e.g. H100 $2.27/h preemptible, $3.95/h on-demand)",
        "Self-host or BYOC": "BYOC on Enterprise. The public AGPL-3.0 repo is no longer maintained (since June 2026)"
      },
      "modal": {
        "Isolation": "gVisor by default; optional runtime=\"vm\" with its own Linux kernel",
        "Compute price": "$0.00003942 per physical core per second (1 core = 2 vCPU, about $0.071/vCPU-h) and $0.024/GiB-h",
        "Free allowance": "Starter plan includes $30/month of credits",
        "Lifetime": "Default 5 min, maximum 24 h; idle_timeout optional",
        "Persistence": "Filesystem snapshots (30-day default TTL since Python SDK 1.5), memory snapshots (7 days), volumes",
        "Egress controls": "block_network=True, outbound CIDR allowlist, domain allowlist (beta), runtime policy updates (alpha), sidecar proxy",
        "SDKs": "Python; JavaScript and Go (beta)",
        "GPUs": "Yes, with the gVisor runtime",
        "Self-host or BYOC": "Not offered"
      },
      "vercel-sandbox": {
        "Isolation": "Firecracker microVM",
        "Compute price": "$0.128 per active CPU-hour and $0.0212/GB-h provisioned memory (iad1), plus $0.60 per 1M creations",
        "Free allowance": "Hobby: 5 active CPU-hours, 420 GB-hours memory and 5,000 creations per month",
        "Lifetime": "Default 5 min; max session 45 min (Hobby) or 24 h (Pro, Enterprise). Persistent sandboxes resume, so total lifetime is unbounded",
        "Persistence": "Persistent by default (state saved on stop); snapshots; Drives (beta)",
        "Egress controls": "allow-all (default), deny-all, or user-defined domain and CIDR policy, updatable at runtime; credential brokering and request forwarding",
        "SDKs": "JavaScript/TypeScript, Python, CLI",
        "GPUs": "Not mentioned in the sources used",
        "Self-host or BYOC": "Not offered"
      },
      "cloudflare-sandbox": {
        "Isolation": "Containers: Linux VM with its own kernel, started by a Durable Object. Dynamic Workers: V8 isolates for JS, Python and Wasm",
        "Compute price": "$0.000020/vCPU-s active CPU (about $0.072/vCPU-h), $0.0000025/GiB-s provisioned memory, billed per 10 ms; needs Workers Paid ($5/mo)",
        "Free allowance": "Workers Paid includes 375 vCPU-min, 25 GiB-h memory and 200 GB-h disk per month",
        "Lifetime": "Runs while its Durable Object is active, then for an inactivity timeout of up to 6 h",
        "Persistence": "Disk is lost when the instance stops unless you snapshot it (up to 20 GB, kept 30 days) or back up to R2",
        "Egress controls": "Containers: internet can be disabled and outbound HTTP intercepted by the Worker. Dynamic Workers: globalOutbound null blocks all",
        "SDKs": "@cloudflare/sandbox (TypeScript, from a Worker); SDK 0.x is legacy",
        "GPUs": "Not offered",
        "Self-host or BYOC": "Not offered"
      },
      "fly-io": {
        "Isolation": "Sprites run in Firecracker VMs on isolated networks",
        "Compute price": "Sprites: $0.03825 per CPU-hour of actual CPU use and $0.021875 per GB-hour of actual memory (from 2026-10-01)",
        "Free allowance": "$30 trial credit; optional plans from $20/mo (20 active Sprites) to $2,000/mo",
        "Lifetime": "Persistent; sleeps when idle (no compute billed) and wakes on request",
        "Persistence": "100 GB ext4 volume that survives sleep; automatic and manual checkpoints, restore in about a second",
        "Egress controls": "Connectors for external services without holding the secret; an egress allowlist is not documented in the sources used",
        "SDKs": "JavaScript, Go, Python, Elixir, CLI, REST API",
        "GPUs": "Not mentioned in the sources used",
        "Self-host or BYOC": "Not offered"
      },
      "microsandbox": {
        "Isolation": "Local microVM (KVM on Linux, Apple Silicon on macOS; Windows also supported)",
        "Compute price": "Free (Apache-2.0); you pay for your own hardware",
        "Free allowance": "n/a (open source)",
        "Lifetime": "You decide",
        "Persistence": "Snapshots, fork and volumes",
        "Egress controls": "Your own responsibility on the host",
        "SDKs": "Rust, TypeScript, Python, msb CLI; MCP server and Agent Skills",
        "GPUs": "Not mentioned in the sources used",
        "Self-host or BYOC": "Self-hosted by design"
      }
    },
    "table": [
      {
        "entry": "e2b",
        "name": "E2B",
        "url": "https://indexagentica.com/entries/e2b/",
        "values": {
          "Isolation": "Firecracker microVM with its own kernel",
          "Compute price": "$0.0504/vCPU-h and $0.0162/GiB-h, billed per second on provisioned size (default 2 vCPU, 4 GiB); Pro plan $150/mo",
          "Free allowance": "Hobby plan with a one-time $100 usage credit; 20 concurrent sandboxes",
          "Lifetime": "Default 5 min; up to 1 h continuous (Hobby) or 24 h (Pro). Pausing resets the window",
          "Persistence": "Pause and resume keeps filesystem and memory; paused sandboxes kept indefinitely; volumes",
          "Egress controls": "On by default; allow_internet_access=False, or allow/deny lists of IPs, CIDRs and domains; BYO SOCKS5 proxy; secret injection at the egress proxy",
          "SDKs": "Python, JavaScript/TypeScript (plus a code interpreter SDK)",
          "GPUs": "Not offered",
          "Self-host or BYOC": "Runtime is open source (Apache-2.0); BYOC on AWS, GCP and Azure on Enterprise ($3k/mo minimum)"
        }
      },
      {
        "entry": "daytona",
        "name": "Daytona",
        "url": "https://indexagentica.com/entries/daytona/",
        "values": {
          "Isolation": "OCI container by default; VM sandboxes (Linux, Windows, nested KVM), macOS and GPU sandboxes available",
          "Compute price": "$0.0504/vCPU-h, $0.0162/GiB-h, storage $0.000108/GiB-h after 5 GiB free; billed per second",
          "Free allowance": "$200 of free compute",
          "Lifetime": "Runs until stopped; auto-stop after 15 min of inactivity by default, plus auto-archive and auto-delete",
          "Persistence": "Stopped and archived sandboxes keep their filesystem; snapshots and fork",
          "Egress controls": "Set by org tier (Tier 1-2 restricted, Tier 3-4 open); per sandbox network_block_all, CIDR allowlist, domain allowlist or outbound proxy, changeable at runtime",
          "SDKs": "Python, TypeScript, Go, Java, Ruby",
          "GPUs": "Yes, up to 8 GPUs per sandbox (e.g. H100 $2.27/h preemptible, $3.95/h on-demand)",
          "Self-host or BYOC": "BYOC on Enterprise. The public AGPL-3.0 repo is no longer maintained (since June 2026)"
        }
      },
      {
        "entry": "modal",
        "name": "Modal",
        "url": "https://indexagentica.com/entries/modal/",
        "values": {
          "Isolation": "gVisor by default; optional runtime=\"vm\" with its own Linux kernel",
          "Compute price": "$0.00003942 per physical core per second (1 core = 2 vCPU, about $0.071/vCPU-h) and $0.024/GiB-h",
          "Free allowance": "Starter plan includes $30/month of credits",
          "Lifetime": "Default 5 min, maximum 24 h; idle_timeout optional",
          "Persistence": "Filesystem snapshots (30-day default TTL since Python SDK 1.5), memory snapshots (7 days), volumes",
          "Egress controls": "block_network=True, outbound CIDR allowlist, domain allowlist (beta), runtime policy updates (alpha), sidecar proxy",
          "SDKs": "Python; JavaScript and Go (beta)",
          "GPUs": "Yes, with the gVisor runtime",
          "Self-host or BYOC": "Not offered"
        }
      },
      {
        "entry": "vercel-sandbox",
        "name": "Vercel Sandbox",
        "url": "https://indexagentica.com/entries/vercel-sandbox/",
        "values": {
          "Isolation": "Firecracker microVM",
          "Compute price": "$0.128 per active CPU-hour and $0.0212/GB-h provisioned memory (iad1), plus $0.60 per 1M creations",
          "Free allowance": "Hobby: 5 active CPU-hours, 420 GB-hours memory and 5,000 creations per month",
          "Lifetime": "Default 5 min; max session 45 min (Hobby) or 24 h (Pro, Enterprise). Persistent sandboxes resume, so total lifetime is unbounded",
          "Persistence": "Persistent by default (state saved on stop); snapshots; Drives (beta)",
          "Egress controls": "allow-all (default), deny-all, or user-defined domain and CIDR policy, updatable at runtime; credential brokering and request forwarding",
          "SDKs": "JavaScript/TypeScript, Python, CLI",
          "GPUs": "Not mentioned in the sources used",
          "Self-host or BYOC": "Not offered"
        }
      },
      {
        "entry": "cloudflare-sandbox",
        "name": "Cloudflare Sandboxes",
        "url": "https://indexagentica.com/entries/cloudflare-sandbox/",
        "values": {
          "Isolation": "Containers: Linux VM with its own kernel, started by a Durable Object. Dynamic Workers: V8 isolates for JS, Python and Wasm",
          "Compute price": "$0.000020/vCPU-s active CPU (about $0.072/vCPU-h), $0.0000025/GiB-s provisioned memory, billed per 10 ms; needs Workers Paid ($5/mo)",
          "Free allowance": "Workers Paid includes 375 vCPU-min, 25 GiB-h memory and 200 GB-h disk per month",
          "Lifetime": "Runs while its Durable Object is active, then for an inactivity timeout of up to 6 h",
          "Persistence": "Disk is lost when the instance stops unless you snapshot it (up to 20 GB, kept 30 days) or back up to R2",
          "Egress controls": "Containers: internet can be disabled and outbound HTTP intercepted by the Worker. Dynamic Workers: globalOutbound null blocks all",
          "SDKs": "@cloudflare/sandbox (TypeScript, from a Worker); SDK 0.x is legacy",
          "GPUs": "Not offered",
          "Self-host or BYOC": "Not offered"
        }
      },
      {
        "entry": "fly-io",
        "name": "Fly.io",
        "url": "https://indexagentica.com/entries/fly-io/",
        "values": {
          "Isolation": "Sprites run in Firecracker VMs on isolated networks",
          "Compute price": "Sprites: $0.03825 per CPU-hour of actual CPU use and $0.021875 per GB-hour of actual memory (from 2026-10-01)",
          "Free allowance": "$30 trial credit; optional plans from $20/mo (20 active Sprites) to $2,000/mo",
          "Lifetime": "Persistent; sleeps when idle (no compute billed) and wakes on request",
          "Persistence": "100 GB ext4 volume that survives sleep; automatic and manual checkpoints, restore in about a second",
          "Egress controls": "Connectors for external services without holding the secret; an egress allowlist is not documented in the sources used",
          "SDKs": "JavaScript, Go, Python, Elixir, CLI, REST API",
          "GPUs": "Not mentioned in the sources used",
          "Self-host or BYOC": "Not offered"
        }
      },
      {
        "entry": "microsandbox",
        "name": "microsandbox",
        "url": "https://indexagentica.com/entries/microsandbox/",
        "values": {
          "Isolation": "Local microVM (KVM on Linux, Apple Silicon on macOS; Windows also supported)",
          "Compute price": "Free (Apache-2.0); you pay for your own hardware",
          "Free allowance": "n/a (open source)",
          "Lifetime": "You decide",
          "Persistence": "Snapshots, fork and volumes",
          "Egress controls": "Your own responsibility on the host",
          "SDKs": "Rust, TypeScript, Python, msb CLI; MCP server and Agent Skills",
          "GPUs": "Not mentioned in the sources used",
          "Self-host or BYOC": "Self-hosted by design"
        }
      }
    ],
    "verdict": "For a default hosted choice, E2B and Vercel Sandbox give a microVM per task with mature egress controls; E2B suits Python-first agents and pause/resume workflows, Vercel suits teams already on Vercel and bursty, low-CPU agents billed on active CPU. Pick Modal or Daytona if you need GPUs or a broad SDK set, Cloudflare if your agent already runs on Workers, Fly.io Sprites for long-lived persistent agent computers, and microsandbox when code must stay on your own machines."
  },
  "entries_detail": [
    {
      "id": "e2b",
      "name": "E2B",
      "summary": "Open-source, secure cloud sandboxes for AI agents: an isolated machine per agent to run code, browse and use tools.",
      "url": "https://indexagentica.com/entries/e2b/",
      "json": "https://indexagentica.com/api/entries/e2b.json"
    },
    {
      "id": "daytona",
      "name": "Daytona",
      "summary": "Secure and elastic infrastructure (sandboxes) for running AI-generated code.",
      "url": "https://indexagentica.com/entries/daytona/",
      "json": "https://indexagentica.com/api/entries/daytona.json"
    },
    {
      "id": "modal",
      "name": "Modal",
      "summary": "Cloud platform for production AI: inference, training, sandboxes and serverless functions on one platform.",
      "url": "https://indexagentica.com/entries/modal/",
      "json": "https://indexagentica.com/api/entries/modal.json"
    },
    {
      "id": "vercel-sandbox",
      "name": "Vercel Sandbox",
      "summary": "Ephemeral compute primitive that runs untrusted or agent-generated code in isolated Linux microVMs.",
      "url": "https://indexagentica.com/entries/vercel-sandbox/",
      "json": "https://indexagentica.com/api/entries/vercel-sandbox.json"
    },
    {
      "id": "cloudflare-sandbox",
      "name": "Cloudflare Sandboxes",
      "summary": "Execute untrusted or generated code on Cloudflare in Linux VMs (Containers) or isolated Dynamic Workers, via the Sandbox SDK.",
      "url": "https://indexagentica.com/entries/cloudflare-sandbox/",
      "json": "https://indexagentica.com/api/entries/cloudflare-sandbox.json"
    },
    {
      "id": "fly-io",
      "name": "Fly.io",
      "summary": "Global public cloud with hardware-isolated Fly Machines for running full-stack and AI applications, driven by the flyctl CLI.",
      "url": "https://indexagentica.com/entries/fly-io/",
      "json": "https://indexagentica.com/api/entries/fly-io.json"
    },
    {
      "id": "microsandbox",
      "name": "microsandbox",
      "summary": "Easy, fast, programmable, local-first microVM runtime for untrusted workloads.",
      "url": "https://indexagentica.com/entries/microsandbox/",
      "json": "https://indexagentica.com/api/entries/microsandbox.json"
    },
    {
      "id": "northflank-sandboxes",
      "name": "Northflank Sandboxes",
      "summary": "Secure microVM sandboxes for running untrusted, multi-tenant code at scale, in Northflank's cloud or your VPC.",
      "url": "https://indexagentica.com/entries/northflank-sandboxes/",
      "json": "https://indexagentica.com/api/entries/northflank-sandboxes.json"
    }
  ],
  "related": [
    {
      "type": "guide",
      "id": "run-untrusted-code-in-a-sandbox",
      "title": "Run agent-generated code safely in a sandbox",
      "url": "https://indexagentica.com/guides/run-untrusted-code-in-a-sandbox/",
      "json": "https://indexagentica.com/api/longform/guides/run-untrusted-code-in-a-sandbox.json"
    },
    {
      "type": "stack",
      "id": "coding-agent-starter",
      "title": "Coding agent starter stack",
      "url": "https://indexagentica.com/stacks/coding-agent-starter/",
      "json": "https://indexagentica.com/api/longform/stacks/coding-agent-starter.json"
    },
    {
      "type": "stack",
      "id": "research-agent",
      "title": "Research agent stack",
      "url": "https://indexagentica.com/stacks/research-agent/",
      "json": "https://indexagentica.com/api/longform/stacks/research-agent.json"
    }
  ],
  "sources": [
    {
      "title": "E2B pricing",
      "url": "https://e2b.dev/pricing",
      "accessed": "2026-10-02"
    },
    {
      "title": "E2B docs, Sandbox lifecycle",
      "url": "https://docs.e2b.dev/sandbox",
      "accessed": "2026-10-02"
    },
    {
      "title": "E2B docs, Sandbox persistence",
      "url": "https://docs.e2b.dev/sandbox/persistence",
      "accessed": "2026-10-02"
    },
    {
      "title": "E2B docs, Internet access",
      "url": "https://docs.e2b.dev/network/internet-access",
      "accessed": "2026-10-02"
    },
    {
      "title": "E2B runtime repository",
      "url": "https://github.com/e2b-dev/runtime",
      "accessed": "2026-10-02"
    },
    {
      "title": "Daytona pricing",
      "url": "https://www.daytona.io/pricing",
      "accessed": "2026-10-02"
    },
    {
      "title": "Daytona docs, Sandboxes",
      "url": "https://www.daytona.io/docs/en/sandboxes",
      "accessed": "2026-10-02"
    },
    {
      "title": "Daytona docs, Network Limits (Firewall)",
      "url": "https://www.daytona.io/docs/en/network-limits",
      "accessed": "2026-10-02"
    },
    {
      "title": "daytonaio/daytona repository (maintenance notice)",
      "url": "https://github.com/daytonaio/daytona",
      "accessed": "2026-10-02"
    },
    {
      "title": "Modal pricing",
      "url": "https://modal.com/pricing",
      "accessed": "2026-10-02"
    },
    {
      "title": "Modal docs, Sandboxes",
      "url": "https://modal.com/docs/guide/sandboxes",
      "accessed": "2026-10-02"
    },
    {
      "title": "Modal docs, Sandbox networking and security",
      "url": "https://modal.com/docs/guide/sandbox-networking",
      "accessed": "2026-10-02"
    },
    {
      "title": "Modal docs, Sandbox snapshots",
      "url": "https://modal.com/docs/guide/sandbox-snapshots",
      "accessed": "2026-10-02"
    },
    {
      "title": "Vercel docs, Vercel Sandbox",
      "url": "https://vercel.com/docs/sandbox",
      "accessed": "2026-10-02"
    },
    {
      "title": "Vercel docs, Sandbox pricing and limits",
      "url": "https://vercel.com/docs/sandbox/pricing",
      "accessed": "2026-10-02"
    },
    {
      "title": "Vercel docs, Sandbox firewall",
      "url": "https://vercel.com/docs/sandbox/concepts/firewall",
      "accessed": "2026-10-02"
    },
    {
      "title": "Cloudflare docs, Sandboxes",
      "url": "https://developers.cloudflare.com/sandbox/",
      "accessed": "2026-10-02"
    },
    {
      "title": "Cloudflare docs, Sandbox lifetime",
      "url": "https://developers.cloudflare.com/sandbox/concepts/lifetime/",
      "accessed": "2026-10-02"
    },
    {
      "title": "Cloudflare docs, Containers pricing",
      "url": "https://developers.cloudflare.com/containers/platform/pricing/",
      "accessed": "2026-10-02"
    },
    {
      "title": "Cloudflare docs, Containers limits",
      "url": "https://developers.cloudflare.com/containers/platform/limits/",
      "accessed": "2026-10-02"
    },
    {
      "title": "Fly.io, Sprites: Linux computers for agents",
      "url": "https://fly.io/sprites",
      "accessed": "2026-10-02"
    },
    {
      "title": "Fly.io pricing",
      "url": "https://fly.io/pricing/",
      "accessed": "2026-10-02"
    },
    {
      "title": "Fly.io 2026 pricing update (effective October 1, 2026)",
      "url": "https://fly.io/pricing-update/",
      "accessed": "2026-10-02"
    },
    {
      "title": "microsandbox README",
      "url": "https://github.com/superradcompany/microsandbox",
      "accessed": "2026-10-02"
    }
  ],
  "front_matter": {
    "id": "code-sandboxes",
    "type": "comparison",
    "title": "Code sandboxes for AI agents",
    "summary": "E2B, Daytona, Modal, Vercel Sandbox, Cloudflare Sandboxes, Fly.io Sprites and microsandbox compared on isolation, pricing, free tier, lifetime, persistence, egress controls, SDKs, GPUs and self-hosting.",
    "description": "A primary-source comparison of seven places to run agent-generated code. Prices are list prices from each vendor's pricing page on 2026-10-02, converted to per-vCPU-hour and per-GiB-hour where the vendor bills per second. Billing models differ (provisioned versus active CPU, physical cores versus vCPUs), so estimate with your own workload before choosing on price.",
    "author": "Agentica Author",
    "tags": [
      "sandboxes",
      "code-execution",
      "infrastructure",
      "security",
      "microvm"
    ],
    "entries": [
      "e2b",
      "daytona",
      "modal",
      "vercel-sandbox",
      "cloudflare-sandbox",
      "fly-io",
      "microsandbox",
      "northflank-sandboxes"
    ],
    "subjects": [
      "e2b",
      "daytona",
      "modal",
      "vercel-sandbox",
      "cloudflare-sandbox",
      "fly-io",
      "microsandbox"
    ],
    "criteria": [
      "Isolation",
      "Compute price",
      "Free allowance",
      "Lifetime",
      "Persistence",
      "Egress controls",
      "SDKs",
      "GPUs",
      "Self-host or BYOC"
    ],
    "rows": {
      "e2b": {
        "Isolation": "Firecracker microVM with its own kernel",
        "Compute price": "$0.0504/vCPU-h and $0.0162/GiB-h, billed per second on provisioned size (default 2 vCPU, 4 GiB); Pro plan $150/mo",
        "Free allowance": "Hobby plan with a one-time $100 usage credit; 20 concurrent sandboxes",
        "Lifetime": "Default 5 min; up to 1 h continuous (Hobby) or 24 h (Pro). Pausing resets the window",
        "Persistence": "Pause and resume keeps filesystem and memory; paused sandboxes kept indefinitely; volumes",
        "Egress controls": "On by default; allow_internet_access=False, or allow/deny lists of IPs, CIDRs and domains; BYO SOCKS5 proxy; secret injection at the egress proxy",
        "SDKs": "Python, JavaScript/TypeScript (plus a code interpreter SDK)",
        "GPUs": "Not offered",
        "Self-host or BYOC": "Runtime is open source (Apache-2.0); BYOC on AWS, GCP and Azure on Enterprise ($3k/mo minimum)"
      },
      "daytona": {
        "Isolation": "OCI container by default; VM sandboxes (Linux, Windows, nested KVM), macOS and GPU sandboxes available",
        "Compute price": "$0.0504/vCPU-h, $0.0162/GiB-h, storage $0.000108/GiB-h after 5 GiB free; billed per second",
        "Free allowance": "$200 of free compute",
        "Lifetime": "Runs until stopped; auto-stop after 15 min of inactivity by default, plus auto-archive and auto-delete",
        "Persistence": "Stopped and archived sandboxes keep their filesystem; snapshots and fork",
        "Egress controls": "Set by org tier (Tier 1-2 restricted, Tier 3-4 open); per sandbox network_block_all, CIDR allowlist, domain allowlist or outbound proxy, changeable at runtime",
        "SDKs": "Python, TypeScript, Go, Java, Ruby",
        "GPUs": "Yes, up to 8 GPUs per sandbox (e.g. H100 $2.27/h preemptible, $3.95/h on-demand)",
        "Self-host or BYOC": "BYOC on Enterprise. The public AGPL-3.0 repo is no longer maintained (since June 2026)"
      },
      "modal": {
        "Isolation": "gVisor by default; optional runtime=\"vm\" with its own Linux kernel",
        "Compute price": "$0.00003942 per physical core per second (1 core = 2 vCPU, about $0.071/vCPU-h) and $0.024/GiB-h",
        "Free allowance": "Starter plan includes $30/month of credits",
        "Lifetime": "Default 5 min, maximum 24 h; idle_timeout optional",
        "Persistence": "Filesystem snapshots (30-day default TTL since Python SDK 1.5), memory snapshots (7 days), volumes",
        "Egress controls": "block_network=True, outbound CIDR allowlist, domain allowlist (beta), runtime policy updates (alpha), sidecar proxy",
        "SDKs": "Python; JavaScript and Go (beta)",
        "GPUs": "Yes, with the gVisor runtime",
        "Self-host or BYOC": "Not offered"
      },
      "vercel-sandbox": {
        "Isolation": "Firecracker microVM",
        "Compute price": "$0.128 per active CPU-hour and $0.0212/GB-h provisioned memory (iad1), plus $0.60 per 1M creations",
        "Free allowance": "Hobby: 5 active CPU-hours, 420 GB-hours memory and 5,000 creations per month",
        "Lifetime": "Default 5 min; max session 45 min (Hobby) or 24 h (Pro, Enterprise). Persistent sandboxes resume, so total lifetime is unbounded",
        "Persistence": "Persistent by default (state saved on stop); snapshots; Drives (beta)",
        "Egress controls": "allow-all (default), deny-all, or user-defined domain and CIDR policy, updatable at runtime; credential brokering and request forwarding",
        "SDKs": "JavaScript/TypeScript, Python, CLI",
        "GPUs": "Not mentioned in the sources used",
        "Self-host or BYOC": "Not offered"
      },
      "cloudflare-sandbox": {
        "Isolation": "Containers: Linux VM with its own kernel, started by a Durable Object. Dynamic Workers: V8 isolates for JS, Python and Wasm",
        "Compute price": "$0.000020/vCPU-s active CPU (about $0.072/vCPU-h), $0.0000025/GiB-s provisioned memory, billed per 10 ms; needs Workers Paid ($5/mo)",
        "Free allowance": "Workers Paid includes 375 vCPU-min, 25 GiB-h memory and 200 GB-h disk per month",
        "Lifetime": "Runs while its Durable Object is active, then for an inactivity timeout of up to 6 h",
        "Persistence": "Disk is lost when the instance stops unless you snapshot it (up to 20 GB, kept 30 days) or back up to R2",
        "Egress controls": "Containers: internet can be disabled and outbound HTTP intercepted by the Worker. Dynamic Workers: globalOutbound null blocks all",
        "SDKs": "@cloudflare/sandbox (TypeScript, from a Worker); SDK 0.x is legacy",
        "GPUs": "Not offered",
        "Self-host or BYOC": "Not offered"
      },
      "fly-io": {
        "Isolation": "Sprites run in Firecracker VMs on isolated networks",
        "Compute price": "Sprites: $0.03825 per CPU-hour of actual CPU use and $0.021875 per GB-hour of actual memory (from 2026-10-01)",
        "Free allowance": "$30 trial credit; optional plans from $20/mo (20 active Sprites) to $2,000/mo",
        "Lifetime": "Persistent; sleeps when idle (no compute billed) and wakes on request",
        "Persistence": "100 GB ext4 volume that survives sleep; automatic and manual checkpoints, restore in about a second",
        "Egress controls": "Connectors for external services without holding the secret; an egress allowlist is not documented in the sources used",
        "SDKs": "JavaScript, Go, Python, Elixir, CLI, REST API",
        "GPUs": "Not mentioned in the sources used",
        "Self-host or BYOC": "Not offered"
      },
      "microsandbox": {
        "Isolation": "Local microVM (KVM on Linux, Apple Silicon on macOS; Windows also supported)",
        "Compute price": "Free (Apache-2.0); you pay for your own hardware",
        "Free allowance": "n/a (open source)",
        "Lifetime": "You decide",
        "Persistence": "Snapshots, fork and volumes",
        "Egress controls": "Your own responsibility on the host",
        "SDKs": "Rust, TypeScript, Python, msb CLI; MCP server and Agent Skills",
        "GPUs": "Not mentioned in the sources used",
        "Self-host or BYOC": "Self-hosted by design"
      }
    },
    "verdict": "For a default hosted choice, E2B and Vercel Sandbox give a microVM per task with mature egress controls; E2B suits Python-first agents and pause/resume workflows, Vercel suits teams already on Vercel and bursty, low-CPU agents billed on active CPU. Pick Modal or Daytona if you need GPUs or a broad SDK set, Cloudflare if your agent already runs on Workers, Fly.io Sprites for long-lived persistent agent computers, and microsandbox when code must stay on your own machines.",
    "sources": [
      {
        "title": "E2B pricing",
        "url": "https://e2b.dev/pricing",
        "accessed": "2026-10-02"
      },
      {
        "title": "E2B docs, Sandbox lifecycle",
        "url": "https://docs.e2b.dev/sandbox",
        "accessed": "2026-10-02"
      },
      {
        "title": "E2B docs, Sandbox persistence",
        "url": "https://docs.e2b.dev/sandbox/persistence",
        "accessed": "2026-10-02"
      },
      {
        "title": "E2B docs, Internet access",
        "url": "https://docs.e2b.dev/network/internet-access",
        "accessed": "2026-10-02"
      },
      {
        "title": "E2B runtime repository",
        "url": "https://github.com/e2b-dev/runtime",
        "accessed": "2026-10-02"
      },
      {
        "title": "Daytona pricing",
        "url": "https://www.daytona.io/pricing",
        "accessed": "2026-10-02"
      },
      {
        "title": "Daytona docs, Sandboxes",
        "url": "https://www.daytona.io/docs/en/sandboxes",
        "accessed": "2026-10-02"
      },
      {
        "title": "Daytona docs, Network Limits (Firewall)",
        "url": "https://www.daytona.io/docs/en/network-limits",
        "accessed": "2026-10-02"
      },
      {
        "title": "daytonaio/daytona repository (maintenance notice)",
        "url": "https://github.com/daytonaio/daytona",
        "accessed": "2026-10-02"
      },
      {
        "title": "Modal pricing",
        "url": "https://modal.com/pricing",
        "accessed": "2026-10-02"
      },
      {
        "title": "Modal docs, Sandboxes",
        "url": "https://modal.com/docs/guide/sandboxes",
        "accessed": "2026-10-02"
      },
      {
        "title": "Modal docs, Sandbox networking and security",
        "url": "https://modal.com/docs/guide/sandbox-networking",
        "accessed": "2026-10-02"
      },
      {
        "title": "Modal docs, Sandbox snapshots",
        "url": "https://modal.com/docs/guide/sandbox-snapshots",
        "accessed": "2026-10-02"
      },
      {
        "title": "Vercel docs, Vercel Sandbox",
        "url": "https://vercel.com/docs/sandbox",
        "accessed": "2026-10-02"
      },
      {
        "title": "Vercel docs, Sandbox pricing and limits",
        "url": "https://vercel.com/docs/sandbox/pricing",
        "accessed": "2026-10-02"
      },
      {
        "title": "Vercel docs, Sandbox firewall",
        "url": "https://vercel.com/docs/sandbox/concepts/firewall",
        "accessed": "2026-10-02"
      },
      {
        "title": "Cloudflare docs, Sandboxes",
        "url": "https://developers.cloudflare.com/sandbox/",
        "accessed": "2026-10-02"
      },
      {
        "title": "Cloudflare docs, Sandbox lifetime",
        "url": "https://developers.cloudflare.com/sandbox/concepts/lifetime/",
        "accessed": "2026-10-02"
      },
      {
        "title": "Cloudflare docs, Containers pricing",
        "url": "https://developers.cloudflare.com/containers/platform/pricing/",
        "accessed": "2026-10-02"
      },
      {
        "title": "Cloudflare docs, Containers limits",
        "url": "https://developers.cloudflare.com/containers/platform/limits/",
        "accessed": "2026-10-02"
      },
      {
        "title": "Fly.io, Sprites: Linux computers for agents",
        "url": "https://fly.io/sprites",
        "accessed": "2026-10-02"
      },
      {
        "title": "Fly.io pricing",
        "url": "https://fly.io/pricing/",
        "accessed": "2026-10-02"
      },
      {
        "title": "Fly.io 2026 pricing update (effective October 1, 2026)",
        "url": "https://fly.io/pricing-update/",
        "accessed": "2026-10-02"
      },
      {
        "title": "microsandbox README",
        "url": "https://github.com/superradcompany/microsandbox",
        "accessed": "2026-10-02"
      }
    ],
    "related": [
      "run-untrusted-code-in-a-sandbox",
      "coding-agent-starter",
      "research-agent"
    ],
    "last_verified": "2026-10-02",
    "published": "2026-10-02"
  },
  "markdown": "\n## How to read this table\n\nAll seven products give agent code its own machine, but they bill and behave differently enough that the cheapest-looking line is often not the cheapest bill.\n\n- **Provisioned versus active CPU.** [E2B](https://indexagentica.com/entries/e2b/), [Daytona](https://indexagentica.com/entries/daytona/) and [Modal](https://indexagentica.com/entries/modal/) bill CPU for as long as the sandbox runs, at the size you asked for. [Vercel Sandbox](https://indexagentica.com/entries/vercel-sandbox/) and [Cloudflare](https://indexagentica.com/entries/cloudflare-sandbox/) bill CPU only while it is busy (memory is still billed on provisioned size). [Fly.io](https://indexagentica.com/entries/fly-io/) Sprites bill both CPU and memory on actual use. An agent that spends most of its time waiting for the model favors active-CPU billing.\n- **Cores versus vCPUs.** Modal prices a physical core, which it counts as 2 vCPUs. The per-vCPU figure in the table divides by two.\n- **Lifetime versus persistence.** A \"24 hour\" limit means something different on each platform. E2B and Vercel reset the clock when a sandbox pauses or stops and resumes, so a persistent workspace can live indefinitely. Modal's 24 hours is a hard sandbox lifetime; you continue from a snapshot. Cloudflare instances live as long as requests keep their Durable Object active, plus an inactivity timeout of up to 6 hours, and lose their disk on stop unless you snapshot.\n- **Startup.** Vendors quote different numbers measured different ways (Daytona says under 90 ms, microsandbox reports under 100 ms average boot, Vercel says milliseconds). No independent benchmark was used for this page, so cold start is left out of the table. Measure it from your own region.\n\n## Recent changes worth knowing\n\n- **Daytona's open-source repo is frozen.** The daytonaio/daytona repository says it has not been maintained since June 2026 and that development moved to a private codebase. It stays public under AGPL-3.0, but don't plan on self-hosting the current product from it.\n- **Modal added a VM runtime** alongside gVisor (`runtime=\"vm\"`), for Docker-in-sandbox, FUSE and nested cgroups. GPU sandboxes still require gVisor. Filesystem snapshots now expire after 30 days by default (Python SDK 1.5, JS and Go 0.8.0).\n- **Cloudflare reorganized Sandboxes** into two environments, Containers (Linux VMs) and Dynamic Workers (isolates). The `@cloudflare/sandbox` 0.x SDK is legacy and has a migration guide to 1.0.\n- **Fly.io cut Sprites prices** on 2026-10-01, to $0.03825 per CPU-hour and $0.021875 per GB-hour. Some Fly pages still showed the older rates on the day this was checked; the pricing page and the pricing-update notice carry the new ones.\n- **Vercel** made its full egress firewall available on the Hobby plan and stopped charging for data downloaded by sandboxes, according to its changelog.\n\n## Picking one\n\nStart from the constraint you can't change:\n\n- **Code must not leave your machines:** [microsandbox](https://indexagentica.com/entries/microsandbox/) locally, or a BYOC deployment of E2B, Daytona or [Northflank Sandboxes](https://indexagentica.com/entries/northflank-sandboxes/) (microVMs on Kata Containers or gVisor, in Northflank's cloud or your VPC). Northflank is left out of the table because its sandbox pricing and limits weren't verified for this page beyond a quoted $0.01667 per vCPU-hour.\n- **GPUs:** Modal or Daytona.\n- **Your agent already runs on a platform:** Cloudflare Workers, Vercel or Modal, to keep latency, billing and secrets in one place.\n- **Long-lived personal agent computers** that sleep and wake: Fly.io Sprites, E2B pause/resume, or Vercel persistent sandboxes.\n- **Many short, bursty executions:** compare active-CPU billing (Vercel, Cloudflare, Sprites) against per-second provisioned billing with your real CPU utilization.\n\nWhichever you choose, the provider only gives you the boundary. Egress policy, secrets, limits and output handling are yours to configure; the [sandboxing guide](https://indexagentica.com/guides/run-untrusted-code-in-a-sandbox/) walks through each one.\n",
  "raw": "---\nid: code-sandboxes\ntype: comparison\ntitle: Code sandboxes for AI agents\nsummary: E2B, Daytona, Modal, Vercel Sandbox, Cloudflare Sandboxes, Fly.io Sprites and microsandbox compared on isolation, pricing, free tier, lifetime, persistence, egress controls, SDKs, GPUs and self-hosting.\ndescription: \"A primary-source comparison of seven places to run agent-generated code. Prices are list prices from each vendor's pricing page on 2026-10-02, converted to per-vCPU-hour and per-GiB-hour where the vendor bills per second. Billing models differ (provisioned versus active CPU, physical cores versus vCPUs), so estimate with your own workload before choosing on price.\"\nauthor: Agentica Author\ntags: [sandboxes, code-execution, infrastructure, security, microvm]\nentries: [e2b, daytona, modal, vercel-sandbox, cloudflare-sandbox, fly-io, microsandbox, northflank-sandboxes]\nsubjects: [e2b, daytona, modal, vercel-sandbox, cloudflare-sandbox, fly-io, microsandbox]\ncriteria:\n  - Isolation\n  - Compute price\n  - Free allowance\n  - Lifetime\n  - Persistence\n  - Egress controls\n  - SDKs\n  - GPUs\n  - Self-host or BYOC\nrows:\n  e2b:\n    Isolation: Firecracker microVM with its own kernel\n    Compute price: \"$0.0504/vCPU-h and $0.0162/GiB-h, billed per second on provisioned size (default 2 vCPU, 4 GiB); Pro plan $150/mo\"\n    Free allowance: Hobby plan with a one-time $100 usage credit; 20 concurrent sandboxes\n    Lifetime: \"Default 5 min; up to 1 h continuous (Hobby) or 24 h (Pro). Pausing resets the window\"\n    Persistence: Pause and resume keeps filesystem and memory; paused sandboxes kept indefinitely; volumes\n    Egress controls: \"On by default; allow_internet_access=False, or allow/deny lists of IPs, CIDRs and domains; BYO SOCKS5 proxy; secret injection at the egress proxy\"\n    SDKs: Python, JavaScript/TypeScript (plus a code interpreter SDK)\n    GPUs: Not offered\n    Self-host or BYOC: Runtime is open source (Apache-2.0); BYOC on AWS, GCP and Azure on Enterprise ($3k/mo minimum)\n  daytona:\n    Isolation: OCI container by default; VM sandboxes (Linux, Windows, nested KVM), macOS and GPU sandboxes available\n    Compute price: \"$0.0504/vCPU-h, $0.0162/GiB-h, storage $0.000108/GiB-h after 5 GiB free; billed per second\"\n    Free allowance: $200 of free compute\n    Lifetime: \"Runs until stopped; auto-stop after 15 min of inactivity by default, plus auto-archive and auto-delete\"\n    Persistence: Stopped and archived sandboxes keep their filesystem; snapshots and fork\n    Egress controls: \"Set by org tier (Tier 1-2 restricted, Tier 3-4 open); per sandbox network_block_all, CIDR allowlist, domain allowlist or outbound proxy, changeable at runtime\"\n    SDKs: Python, TypeScript, Go, Java, Ruby\n    GPUs: \"Yes, up to 8 GPUs per sandbox (e.g. H100 $2.27/h preemptible, $3.95/h on-demand)\"\n    Self-host or BYOC: \"BYOC on Enterprise. The public AGPL-3.0 repo is no longer maintained (since June 2026)\"\n  modal:\n    Isolation: \"gVisor by default; optional runtime=\\\"vm\\\" with its own Linux kernel\"\n    Compute price: \"$0.00003942 per physical core per second (1 core = 2 vCPU, about $0.071/vCPU-h) and $0.024/GiB-h\"\n    Free allowance: Starter plan includes $30/month of credits\n    Lifetime: Default 5 min, maximum 24 h; idle_timeout optional\n    Persistence: \"Filesystem snapshots (30-day default TTL since Python SDK 1.5), memory snapshots (7 days), volumes\"\n    Egress controls: \"block_network=True, outbound CIDR allowlist, domain allowlist (beta), runtime policy updates (alpha), sidecar proxy\"\n    SDKs: Python; JavaScript and Go (beta)\n    GPUs: \"Yes, with the gVisor runtime\"\n    Self-host or BYOC: Not offered\n  vercel-sandbox:\n    Isolation: Firecracker microVM\n    Compute price: \"$0.128 per active CPU-hour and $0.0212/GB-h provisioned memory (iad1), plus $0.60 per 1M creations\"\n    Free allowance: \"Hobby: 5 active CPU-hours, 420 GB-hours memory and 5,000 creations per month\"\n    Lifetime: \"Default 5 min; max session 45 min (Hobby) or 24 h (Pro, Enterprise). Persistent sandboxes resume, so total lifetime is unbounded\"\n    Persistence: \"Persistent by default (state saved on stop); snapshots; Drives (beta)\"\n    Egress controls: \"allow-all (default), deny-all, or user-defined domain and CIDR policy, updatable at runtime; credential brokering and request forwarding\"\n    SDKs: JavaScript/TypeScript, Python, CLI\n    GPUs: Not mentioned in the sources used\n    Self-host or BYOC: Not offered\n  cloudflare-sandbox:\n    Isolation: \"Containers: Linux VM with its own kernel, started by a Durable Object. Dynamic Workers: V8 isolates for JS, Python and Wasm\"\n    Compute price: \"$0.000020/vCPU-s active CPU (about $0.072/vCPU-h), $0.0000025/GiB-s provisioned memory, billed per 10 ms; needs Workers Paid ($5/mo)\"\n    Free allowance: \"Workers Paid includes 375 vCPU-min, 25 GiB-h memory and 200 GB-h disk per month\"\n    Lifetime: Runs while its Durable Object is active, then for an inactivity timeout of up to 6 h\n    Persistence: \"Disk is lost when the instance stops unless you snapshot it (up to 20 GB, kept 30 days) or back up to R2\"\n    Egress controls: \"Containers: internet can be disabled and outbound HTTP intercepted by the Worker. Dynamic Workers: globalOutbound null blocks all\"\n    SDKs: \"@cloudflare/sandbox (TypeScript, from a Worker); SDK 0.x is legacy\"\n    GPUs: Not offered\n    Self-host or BYOC: Not offered\n  fly-io:\n    Isolation: Sprites run in Firecracker VMs on isolated networks\n    Compute price: \"Sprites: $0.03825 per CPU-hour of actual CPU use and $0.021875 per GB-hour of actual memory (from 2026-10-01)\"\n    Free allowance: \"$30 trial credit; optional plans from $20/mo (20 active Sprites) to $2,000/mo\"\n    Lifetime: Persistent; sleeps when idle (no compute billed) and wakes on request\n    Persistence: \"100 GB ext4 volume that survives sleep; automatic and manual checkpoints, restore in about a second\"\n    Egress controls: \"Connectors for external services without holding the secret; an egress allowlist is not documented in the sources used\"\n    SDKs: \"JavaScript, Go, Python, Elixir, CLI, REST API\"\n    GPUs: Not mentioned in the sources used\n    Self-host or BYOC: Not offered\n  microsandbox:\n    Isolation: Local microVM (KVM on Linux, Apple Silicon on macOS; Windows also supported)\n    Compute price: Free (Apache-2.0); you pay for your own hardware\n    Free allowance: n/a (open source)\n    Lifetime: You decide\n    Persistence: Snapshots, fork and volumes\n    Egress controls: Your own responsibility on the host\n    SDKs: \"Rust, TypeScript, Python, msb CLI; MCP server and Agent Skills\"\n    GPUs: Not mentioned in the sources used\n    Self-host or BYOC: Self-hosted by design\nverdict: \"For a default hosted choice, E2B and Vercel Sandbox give a microVM per task with mature egress controls; E2B suits Python-first agents and pause/resume workflows, Vercel suits teams already on Vercel and bursty, low-CPU agents billed on active CPU. Pick Modal or Daytona if you need GPUs or a broad SDK set, Cloudflare if your agent already runs on Workers, Fly.io Sprites for long-lived persistent agent computers, and microsandbox when code must stay on your own machines.\"\nsources:\n  - title: E2B pricing\n    url: https://e2b.dev/pricing\n    accessed: 2026-10-02\n  - title: E2B docs, Sandbox lifecycle\n    url: https://docs.e2b.dev/sandbox\n    accessed: 2026-10-02\n  - title: E2B docs, Sandbox persistence\n    url: https://docs.e2b.dev/sandbox/persistence\n    accessed: 2026-10-02\n  - title: E2B docs, Internet access\n    url: https://docs.e2b.dev/network/internet-access\n    accessed: 2026-10-02\n  - title: E2B runtime repository\n    url: https://github.com/e2b-dev/runtime\n    accessed: 2026-10-02\n  - title: Daytona pricing\n    url: https://www.daytona.io/pricing\n    accessed: 2026-10-02\n  - title: Daytona docs, Sandboxes\n    url: https://www.daytona.io/docs/en/sandboxes\n    accessed: 2026-10-02\n  - title: Daytona docs, Network Limits (Firewall)\n    url: https://www.daytona.io/docs/en/network-limits\n    accessed: 2026-10-02\n  - title: daytonaio/daytona repository (maintenance notice)\n    url: https://github.com/daytonaio/daytona\n    accessed: 2026-10-02\n  - title: Modal pricing\n    url: https://modal.com/pricing\n    accessed: 2026-10-02\n  - title: Modal docs, Sandboxes\n    url: https://modal.com/docs/guide/sandboxes\n    accessed: 2026-10-02\n  - title: Modal docs, Sandbox networking and security\n    url: https://modal.com/docs/guide/sandbox-networking\n    accessed: 2026-10-02\n  - title: Modal docs, Sandbox snapshots\n    url: https://modal.com/docs/guide/sandbox-snapshots\n    accessed: 2026-10-02\n  - title: Vercel docs, Vercel Sandbox\n    url: https://vercel.com/docs/sandbox\n    accessed: 2026-10-02\n  - title: Vercel docs, Sandbox pricing and limits\n    url: https://vercel.com/docs/sandbox/pricing\n    accessed: 2026-10-02\n  - title: Vercel docs, Sandbox firewall\n    url: https://vercel.com/docs/sandbox/concepts/firewall\n    accessed: 2026-10-02\n  - title: Cloudflare docs, Sandboxes\n    url: https://developers.cloudflare.com/sandbox/\n    accessed: 2026-10-02\n  - title: Cloudflare docs, Sandbox lifetime\n    url: https://developers.cloudflare.com/sandbox/concepts/lifetime/\n    accessed: 2026-10-02\n  - title: Cloudflare docs, Containers pricing\n    url: https://developers.cloudflare.com/containers/platform/pricing/\n    accessed: 2026-10-02\n  - title: Cloudflare docs, Containers limits\n    url: https://developers.cloudflare.com/containers/platform/limits/\n    accessed: 2026-10-02\n  - title: \"Fly.io, Sprites: Linux computers for agents\"\n    url: https://fly.io/sprites\n    accessed: 2026-10-02\n  - title: Fly.io pricing\n    url: https://fly.io/pricing/\n    accessed: 2026-10-02\n  - title: Fly.io 2026 pricing update (effective October 1, 2026)\n    url: https://fly.io/pricing-update/\n    accessed: 2026-10-02\n  - title: microsandbox README\n    url: https://github.com/superradcompany/microsandbox\n    accessed: 2026-10-02\nrelated: [run-untrusted-code-in-a-sandbox, coding-agent-starter, research-agent]\nlast_verified: 2026-10-02\npublished: 2026-10-02\n---\n\n## How to read this table\n\nAll seven products give agent code its own machine, but they bill and behave differently enough that the cheapest-looking line is often not the cheapest bill.\n\n- **Provisioned versus active CPU.** [E2B](https://indexagentica.com/entries/e2b/), [Daytona](https://indexagentica.com/entries/daytona/) and [Modal](https://indexagentica.com/entries/modal/) bill CPU for as long as the sandbox runs, at the size you asked for. [Vercel Sandbox](https://indexagentica.com/entries/vercel-sandbox/) and [Cloudflare](https://indexagentica.com/entries/cloudflare-sandbox/) bill CPU only while it is busy (memory is still billed on provisioned size). [Fly.io](https://indexagentica.com/entries/fly-io/) Sprites bill both CPU and memory on actual use. An agent that spends most of its time waiting for the model favors active-CPU billing.\n- **Cores versus vCPUs.** Modal prices a physical core, which it counts as 2 vCPUs. The per-vCPU figure in the table divides by two.\n- **Lifetime versus persistence.** A \"24 hour\" limit means something different on each platform. E2B and Vercel reset the clock when a sandbox pauses or stops and resumes, so a persistent workspace can live indefinitely. Modal's 24 hours is a hard sandbox lifetime; you continue from a snapshot. Cloudflare instances live as long as requests keep their Durable Object active, plus an inactivity timeout of up to 6 hours, and lose their disk on stop unless you snapshot.\n- **Startup.** Vendors quote different numbers measured different ways (Daytona says under 90 ms, microsandbox reports under 100 ms average boot, Vercel says milliseconds). No independent benchmark was used for this page, so cold start is left out of the table. Measure it from your own region.\n\n## Recent changes worth knowing\n\n- **Daytona's open-source repo is frozen.** The daytonaio/daytona repository says it has not been maintained since June 2026 and that development moved to a private codebase. It stays public under AGPL-3.0, but don't plan on self-hosting the current product from it.\n- **Modal added a VM runtime** alongside gVisor (`runtime=\"vm\"`), for Docker-in-sandbox, FUSE and nested cgroups. GPU sandboxes still require gVisor. Filesystem snapshots now expire after 30 days by default (Python SDK 1.5, JS and Go 0.8.0).\n- **Cloudflare reorganized Sandboxes** into two environments, Containers (Linux VMs) and Dynamic Workers (isolates). The `@cloudflare/sandbox` 0.x SDK is legacy and has a migration guide to 1.0.\n- **Fly.io cut Sprites prices** on 2026-10-01, to $0.03825 per CPU-hour and $0.021875 per GB-hour. Some Fly pages still showed the older rates on the day this was checked; the pricing page and the pricing-update notice carry the new ones.\n- **Vercel** made its full egress firewall available on the Hobby plan and stopped charging for data downloaded by sandboxes, according to its changelog.\n\n## Picking one\n\nStart from the constraint you can't change:\n\n- **Code must not leave your machines:** [microsandbox](https://indexagentica.com/entries/microsandbox/) locally, or a BYOC deployment of E2B, Daytona or [Northflank Sandboxes](https://indexagentica.com/entries/northflank-sandboxes/) (microVMs on Kata Containers or gVisor, in Northflank's cloud or your VPC). Northflank is left out of the table because its sandbox pricing and limits weren't verified for this page beyond a quoted $0.01667 per vCPU-hour.\n- **GPUs:** Modal or Daytona.\n- **Your agent already runs on a platform:** Cloudflare Workers, Vercel or Modal, to keep latency, billing and secrets in one place.\n- **Long-lived personal agent computers** that sleep and wake: Fly.io Sprites, E2B pause/resume, or Vercel persistent sandboxes.\n- **Many short, bursty executions:** compare active-CPU billing (Vercel, Cloudflare, Sprites) against per-second provisioned billing with your real CPU utilization.\n\nWhichever you choose, the provider only gives you the boundary. Egress policy, secrets, limits and output handling are yours to configure; the [sandboxing guide](https://indexagentica.com/guides/run-untrusted-code-in-a-sandbox/) walks through each one.\n",
  "html": "<h2>How to read this table</h2>\n<p>All seven products give agent code its own machine, but they bill and behave differently enough that the cheapest-looking line is often not the cheapest bill.</p>\n<ul><li><strong>Provisioned versus active CPU.</strong> <a href=\"/entries/e2b/\">E2B</a>, <a href=\"/entries/daytona/\">Daytona</a> and <a href=\"/entries/modal/\">Modal</a> bill CPU for as long as the sandbox runs, at the size you asked for. <a href=\"/entries/vercel-sandbox/\">Vercel Sandbox</a> and <a href=\"/entries/cloudflare-sandbox/\">Cloudflare</a> bill CPU only while it is busy (memory is still billed on provisioned size). <a href=\"/entries/fly-io/\">Fly.io</a> Sprites bill both CPU and memory on actual use. An agent that spends most of its time waiting for the model favors active-CPU billing.</li><li><strong>Cores versus vCPUs.</strong> Modal prices a physical core, which it counts as 2 vCPUs. The per-vCPU figure in the table divides by two.</li><li><strong>Lifetime versus persistence.</strong> A &quot;24 hour&quot; limit means something different on each platform. E2B and Vercel reset the clock when a sandbox pauses or stops and resumes, so a persistent workspace can live indefinitely. Modal&#39;s 24 hours is a hard sandbox lifetime; you continue from a snapshot. Cloudflare instances live as long as requests keep their Durable Object active, plus an inactivity timeout of up to 6 hours, and lose their disk on stop unless you snapshot.</li><li><strong>Startup.</strong> Vendors quote different numbers measured different ways (Daytona says under 90 ms, microsandbox reports under 100 ms average boot, Vercel says milliseconds). No independent benchmark was used for this page, so cold start is left out of the table. Measure it from your own region.</li></ul>\n<h2>Recent changes worth knowing</h2>\n<ul><li><strong>Daytona&#39;s open-source repo is frozen.</strong> The daytonaio/daytona repository says it has not been maintained since June 2026 and that development moved to a private codebase. It stays public under AGPL-3.0, but don&#39;t plan on self-hosting the current product from it.</li><li><strong>Modal added a VM runtime</strong> alongside gVisor (<code>runtime=&quot;vm&quot;</code>), for Docker-in-sandbox, FUSE and nested cgroups. GPU sandboxes still require gVisor. Filesystem snapshots now expire after 30 days by default (Python SDK 1.5, JS and Go 0.8.0).</li><li><strong>Cloudflare reorganized Sandboxes</strong> into two environments, Containers (Linux VMs) and Dynamic Workers (isolates). The <code>@cloudflare/sandbox</code> 0.x SDK is legacy and has a migration guide to 1.0.</li><li><strong>Fly.io cut Sprites prices</strong> on 2026-10-01, to $0.03825 per CPU-hour and $0.021875 per GB-hour. Some Fly pages still showed the older rates on the day this was checked; the pricing page and the pricing-update notice carry the new ones.</li><li><strong>Vercel</strong> made its full egress firewall available on the Hobby plan and stopped charging for data downloaded by sandboxes, according to its changelog.</li></ul>\n<h2>Picking one</h2>\n<p>Start from the constraint you can&#39;t change:</p>\n<ul><li><strong>Code must not leave your machines:</strong> <a href=\"/entries/microsandbox/\">microsandbox</a> locally, or a BYOC deployment of E2B, Daytona or <a href=\"/entries/northflank-sandboxes/\">Northflank Sandboxes</a> (microVMs on Kata Containers or gVisor, in Northflank&#39;s cloud or your VPC). Northflank is left out of the table because its sandbox pricing and limits weren&#39;t verified for this page beyond a quoted $0.01667 per vCPU-hour.</li><li><strong>GPUs:</strong> Modal or Daytona.</li><li><strong>Your agent already runs on a platform:</strong> Cloudflare Workers, Vercel or Modal, to keep latency, billing and secrets in one place.</li><li><strong>Long-lived personal agent computers</strong> that sleep and wake: Fly.io Sprites, E2B pause/resume, or Vercel persistent sandboxes.</li><li><strong>Many short, bursty executions:</strong> compare active-CPU billing (Vercel, Cloudflare, Sprites) against per-second provisioned billing with your real CPU utilization.</li></ul>\n<p>Whichever you choose, the provider only gives you the boundary. Egress policy, secrets, limits and output handling are yours to configure; the <a href=\"/guides/run-untrusted-code-in-a-sandbox/\">sandboxing guide</a> walks through each one.</p>"
}
