{"slug": "sandbox-watch-agent-sandbox-comparison", "title": "Sandbox.watch: Agent Sandbox Comparison", "summary": "Sandbox.watch published a comparison of 13 agent sandbox providers, listing per-vCPU-hour prices from $0.015 (Sailboxes) to $0.10 (Deno Sandbox), with details on isolation technology, startup times, and runtime limits. The comparison covers providers including Northflank, Novita AI, exe.dev, Daytona, E2B, LangSmith, Fly.io, Cloudflare, Azure Container Apps, AWS AgentCore, AWS Lambda, and Deno.", "body_md": "[Sailboxes](/p/sailboxes) |\n$0.015/vCPU-hr\n$0.015 per used vCPU-hour; $0.008 per used RAM GiB-hour; $0.0007 per used NVMe disk GiB-hour; $0.005-$0.012 per creation\n|\n✓ |\n✓ |\n✓ |\n✓ |\n<3s |\nNo fixed limit |\nKernel-isolated Linux VM (full VM, not microVM) |\n✕ |\n✓ |\n[Northflank Sandboxes](/p/northflank) |\n$0.01667/vCPU-hr\n$0.01667/vCPU-hour\n|\n✕ |\n✓ |\n✕ |\n✕ |\nUnder 1 second (microVMs boot in <1s; P99 allocate ~566ms, P99 readiness ~733ms per ComputeSDK 2026 benchmark) |\nNo fixed limit |\nMicroVM via Firecracker, gVisor, Kata Containers, and Cloud Hypervisor |\n✓ |\n✓ |\n[Novita AI Sandbox](/p/novita) |\n$0.03528/vCPU-hr\n$0.0000098 per vCPU-second ($0.0353/vCPU-hr); $0.0000032 per GiB-second ($0.0115/GiB-hr)\n|\n✕ |\n✕ |\n✓ |\n✓ |\nUnder 200 ms on average for create; ~1 s to resume from paused |\n1 h (free tier); 3 h (paid tier); 4 h default, adjustable (enterprise tier) |\nFirecracker microVM |\n✕ |\n– |\n[exe.dev](/p/exe-dev) |\n$0.05/vCPU-hr\n$0.05 per CPU core-hour (usage pricing); $20/month Personal plan (2 vCPU / 8 GB RAM), $25/user/month Team plan\n|\n✕ |\n✓ |\n✕ |\n✕ |\nSub-second start; resume timing not specified |\n– |\nKVM via Cloud Hypervisor (also uses crosvm; per a third-party article, Kata Containers) |\n✕ |\n✓ |\n[Daytona](/p/daytona) |\n$0.0504/vCPU-hr\n$0.0504 per vCPU-hour\n|\n✓ |\n✕ |\n✓ |\n– |\n~27 ms spin-up; under 90 ms end-to-end |\nNo fixed limit |\nLinux namespaces and isolated containers for container sandboxes; full virtual machines with their own kernel for Linux and Windows VM sandboxes; isolated containers with exclusive GPU allocation for GPU sandboxes |\n✓ |\n✓ |\n[E2B](/p/e2b) |\n$0.0504/vCPU-hr\n$0.000014/vCPU-second (≈$0.0504/vCPU-hour); RAM $0.0000045/GiB/second (≈$0.0162/GiB-hour)\n|\n✓ |\n✕ |\n✓ |\n✓ |\nless than 200 ms (same region); ~1 s to resume from a full snapshot |\n24 h on Pro plan; 1 h on Hobby (free) plan |\nFirecracker microVM |\n✕ |\n✓ |\n[LangSmith Sandboxes](/p/langsmith-sandboxes) |\n$0.0576/vCPU-hr\n$0.0576 per vCPU-hour for compute, plus memory and storage\n|\n✕ |\n– |\n✓ |\n✓ |\n<0.98 s p50 with prewarming |\nA configurable hard TTL can cap total runtime; no maximum value is publicly stated |\nHardware-virtualized microVM (kernel-isolated) |\n✕ |\n✓ |\n[Fly.io Sprites](/p/fly-io-sprites) |\n$0.07/vCPU-hr\n$0.07 per CPU-hour and $0.04375 per GB-hour of memory\n|\n✓ |\n✕ |\n✕ |\n✓ |\n~100-500 ms warm resume; ~1-2 s cold start |\nNo fixed limit |\nFirecracker microVM |\n✕ |\n✓ |\n[Cloudflare Sandboxes](/p/cloudflare) |\n$0.072/vCPU-hr\n$0.000020 per vCPU-second (~$0.072 per vCPU-hour) plus $0.0000025 per GiB-second of memory\n|\n✓ |\n✓ |\n✕ |\n✓ |\n~1-3 seconds |\nNo fixed limit; runtime is not guaranteed and may end on host restart |\nPer-instance isolation on Cloudflare Containers platform (Firecracker microVMs; gVisor and QEMU also supported) |\n✕ |\n✓ |\n[Azure Container Apps](/p/microsoft-azure) |\n$0.0864/vCPU-hr\n$0.000024/vCPU-second and $0.000003/GiB-second while active (~$0.0864/vCPU-hour, ~$0.0108/GiB-hour).\n|\n✓ |\n✓ |\n✓ |\n✓ |\nSub-second |\nNo documented fixed limit; sandboxes auto-suspend after configurable idle timeout (1–60 min, default 5 min) and auto-delete after configurable days. |\nHardware-isolated microVM |\n✕ |\n– |\n[AWS AgentCore Code Interpreter](/p/aws-agentcore-code-interpreter) |\n$0.0895/vCPU-hr\n$0.0895/vCPU-hour + $0.00945/GB-hour\n|\n✕ |\n✓ |\n✓ |\n✓ |\n300-800 ms |\n8 hours (configurable; 15 min default timeout, up to 8h max) |\nFirecracker microVM (per-session, running on AWS Lambda MicroVMs) |\n✕ |\n✕ |\n[AWS Lambda MicroVMs](/p/aws-lambda-microvms) |\n$0.0997/vCPU-hr\n$0.0000276944 per vCPU-second + $0.0000036667 per GB-second (ARM/Graviton, US East); snapshot read $0.00155/GB, write $0.0038/GB, storage $0.08/GB-month\n|\n✓ |\n– |\n✓ |\n✓ |\nnear-instant |\n8 h (28,800 s state-retention window) |\nFirecracker microVM |\n✕ |\n✓ |\n[Deno Sandbox](/p/deno-sandbox) |\n$0.1/vCPU-hr\n$0.10/CPU-hour; $0.025/GiB-hour of memory; $0.20/GiB-month of volume storage\n|\n✓ |\n✓ |\n✕ |\n✕ |\nunder 1 second |\n30 min (per docs limits; extendable on demand via extendTimeout) |\nLinux microVM (official docs say 'individual Linux microVMs'; Firecracker is named by third-party blogs and HN commentary but not in the official Deno documentation) |\n✕ |\n✕ |\n[Runloop](/p/runloop) |\n$0.108/vCPU-hr\n$0.108 per CPU-hour (plus $0.0252 per GB-hour of memory)\n|\n✓ |\n✕ |\n✕ |\n✓ |\nA few seconds to first command; suspend/resume typically takes seconds, depending on modified data |\nDefault 1 h, configurable |\nLinux microVM with hardware isolation (two-layer VM + container) |\n✓ |\n✓ |\n[Vercel Sandbox](/p/vercel) |\n$0.128/vCPU-hr\n$0.128 per vCPU-hour (active CPU)\n|\n✓ |\n✓ |\n✕ |\n✕ |\nSub-second (millisecond-level startup with Firecracker microVMs) |\n24 h (Pro/Enterprise); 45 min (Hobby) |\nFirecracker microVM |\n✕ |\n✓ |\n[Modal Sandboxes](/p/modal) |\n$0.1419/vCPU-hr\n$0.00003942 per CPU core/sec, $0.00000667 per GiB memory/sec\n|\n✕ |\n– |\n✓ |\n✕ |\n~1 second for container boot; total Sandbox startup varies by image and initialization |\n24 h |\ngVisor container runtime (default); full Linux VM with VM Sandboxes (Beta) |\n✓ |\n✓ |\n[Ellipsis](/p/ellipsis) |\n$0.142/vCPU-hr\n$0.142 / vCPU-hour (Ellipsis Cloud tier)\n|\n✓ |\n✕ |\n✕ |\n– |\n~8 s (warm snapshot boot); first session image build ~3m40s |\n24 h |\nLinux container |\n– |\n– |\n[Blaxel](/p/blaxel) |\n$0.0000115 per GB-RAM-second (active CPU)\n$0.0000115 per GB-RAM-second (active CPU)\n|\n✓ |\n✓ |\n✓ |\n✓ |\n~25 ms (resume from standby) |\nTier-dependent: up to 7 days (tier 0), up to 30 days (tier 1); unlimited in tier 2 and above |\nmicroVM with hardware-level (kernel-level) isolation |\n✕ |\n✓ |\n[CodeSandbox SDK](/p/codesandbox) |\n$0.01486 per VM credit\n$0.01486 per VM credit\n|\n– |\n– |\n✓ |\n✓ |\n500 ms (P95) |\n24 h on Pro tier; no documented hard cap for Scale/Enterprise |\nFirecracker microVM |\n✕ |\n✓ |\n[Box by ASCII](/p/box-by-ascii) |\n$0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe)\n$0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe)\n|\n✓ |\n✕ |\n✕ |\n– |\nA few seconds for resume; create time not explicitly stated in extracted docs |\nDefault TTL overrideable up to 30 days; can disable auto-stop with ttl=null |\nHetzner Cloud VPS (current CX33); hypervisor not stated in docs |\n✕ |\n✓ |\n[Morph Cloud](/p/morph) |\n$0.05 per MCU (Morph Compute Unit)\n$0.05 per MCU (Morph Compute Unit)\n|\n✓ |\n– |\n✓ |\n✓ |\n~250 ms (snapshot/restore via Infinibranch; cold-boot time for fresh images not documented) |\nNo fixed limit documented; TTLs control stop/pause on expiry |\nFull VMs (hypervisor technology not explicitly named in public docs) |\n– |\n✓ |\n[OpenComputer](/p/opencomputer) |\n$0.24 per hour for the default 4GB/1vCPU sandbox\n$0.24 per hour for the default 4GB/1vCPU sandbox\n|\n✓ |\n✕ |\n✓ |\n✓ |\nSandboxes 'start in milliseconds' (docs overview); resume from hibernation 'in seconds' (home page, README). No specific P50/P95 latency published. |\nNo fixed limit (default 300s idle timeout auto-hibernates the VM) |\nKVM (QEMU/KVM) — hardware-level virtualization; each sandbox is a full Linux VM with its own kernel |\n✕ |\n– |\n[Scrapybara](/p/scrapybara) |\n$29/month (Basic) or $99/month (Pro)\n$29/month (Basic) or $99/month (Pro)\n|\n– |\n– |\n– |\n– |\nUnder 1 second for Ubuntu and Browser instances; Windows instances are described as 'slow' without a specific figure |\n24 h (configurable; 1 h default) |\nFull Linux (Ubuntu 22.04) and Windows 11 virtual machines; open-source computer service is packaged as a Docker image with xdotool/noVNC |\n– |\n– |\n[Railway Sandboxes](/p/railway) |\n$50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB\n$50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB\n|\n✕ |\n✓ |\n✕ |\n✕ |\n– |\n– |\nPer-sandbox VM on Railway's VM primitive (specific hypervisor technology not publicly disclosed) |\n✕ |\n✓ |\n[Runwork Agent Sandbox](/p/runwork) |\n$79/month (Startup tier: 3 seats, $30/month usage credits)\n$79/month (Startup tier: 3 seats, $30/month usage credits)\n|\n✓ |\n– |\n– |\n– |\nCold starts 'measured in milliseconds, not seconds' (no specific figure published) |\nBounded by per-task budgets, turn limits, and timeouts set in agent definitions; no global limit stated |\nIsolated computing environment (\"their own computer\"), underlying isolation technology not specified publicly |\n– |\n– |\n[Fly Machines](/p/fly) |\nFrom ~$0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering\nFrom ~$0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering\n|\n✕ |\n✕ |\n✓ |\n✓ |\nWell under 1 s to start an existing or stopped Machine; a few hundred ms from suspend; ~2+ s for a cold start |\nNo fixed limit |\nFirecracker microVM |\n✕ |\n✓ |\n[Computer Agents](/p/computer-agents) |\nLite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour)\nLite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour)\n|\n✓ |\n✓ |\n– |\n– |\nSub-second for warm container startup |\n– |\nIsolated Linux container per agent (technology not specified) |\n– |\n– |\n[GKE Agent Sandbox](/p/gke-agent-sandbox) |\nNo Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing)\nNo Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing)\n|\n✕ |\n– |\n✓ |\n✕ |\n~200 ms typical (90% of allocations under 200 ms; up to 300 sandboxes/sec/cluster; pre-warmed pods enable sub-second creation) |\nConfigurable TTL (no fixed maximum documented) |\ngVisor (also supports Kata Containers and other OCI-compatible runtimes; runtimeClassName: gvisor) |\n✓ |\n✓ |\n[Agent-Sandbox](/p/agent-sandbox) |\nNo published headline rate (open-source/self-hosted software)\nNo published headline rate (open-source/self-hosted software)\n|\n– |\n– |\n– |\n– |\n– |\n– |\n– |\n– |\n– |\n[Tencent Cloud CubeSandbox](/p/tencent-cubesandbox) |\nNo published headline rate (open-source/self-hosted software)\nNo published headline rate (open-source/self-hosted software)\n|\n✓ |\n– |\n✓ |\n✓ |\n~60 ms (single concurrency; under 50 concurrent: avg 67 ms, P95 90 ms, P99 137 ms) |\n– |\nKVM MicroVM via RustVMM (each sandbox runs its own Linux kernel; hardware-isolated from the host and from other sandboxes) |\n– |\n✕ |\n[Beam](/p/beam) |\nPer-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates)\nPer-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates)\n|\n✓ |\n✕ |\n✓ |\n– |\n1–3 s cold boot; container start under 1 s |\n– |\ngVisor + runc |\n✓ |\n✓ |\n[Agentic Studio](/p/agentic-studio) |\n– |\n– |\n– |\n– |\n– |\n– |\n– |\nProcess- and network-level isolation |\n– |\n– |\n[OpenSandbox](/p/open-sandbox) |\n– |\n– |\n– |\n– |\n– |\n– |\n– |\n– |\n– |\n– |", "url": "https://wpnews.pro/news/sandbox-watch-agent-sandbox-comparison", "canonical_source": "https://sandbox.watch/", "published_at": "2026-08-29 21:39:50+00:00", "updated_at": "2026-08-29 22:18:28.678745+00:00", "lang": "en", "topics": ["ai-infrastructure", "developer-tools"], "entities": ["Sandbox.watch", "Sailboxes", "Northflank", "Novita AI", "exe.dev", "Daytona", "E2B", "LangSmith"], "alternates": {"html": "https://wpnews.pro/news/sandbox-watch-agent-sandbox-comparison", "markdown": "https://wpnews.pro/news/sandbox-watch-agent-sandbox-comparison.md", "text": "https://wpnews.pro/news/sandbox-watch-agent-sandbox-comparison.txt", "jsonld": "https://wpnews.pro/news/sandbox-watch-agent-sandbox-comparison.jsonld"}}