# Sandbox.watch: Agent Sandbox Comparison

> Source: <https://sandbox.watch/>
> Published: 2026-08-29 21:39:50+00:00

[Sailboxes](/p/sailboxes) |
$0.015/vCPU-hr
$0.015 per used vCPU-hour; $0.008 per used RAM GiB-hour; $0.0007 per used NVMe disk GiB-hour; $0.005-$0.012 per creation
|
✓ |
✓ |
✓ |
✓ |
<3s |
No fixed limit |
Kernel-isolated Linux VM (full VM, not microVM) |
✕ |
✓ |
[Northflank Sandboxes](/p/northflank) |
$0.01667/vCPU-hr
$0.01667/vCPU-hour
|
✕ |
✓ |
✕ |
✕ |
Under 1 second (microVMs boot in <1s; P99 allocate ~566ms, P99 readiness ~733ms per ComputeSDK 2026 benchmark) |
No fixed limit |
MicroVM via Firecracker, gVisor, Kata Containers, and Cloud Hypervisor |
✓ |
✓ |
[Novita AI Sandbox](/p/novita) |
$0.03528/vCPU-hr
$0.0000098 per vCPU-second ($0.0353/vCPU-hr); $0.0000032 per GiB-second ($0.0115/GiB-hr)
|
✕ |
✕ |
✓ |
✓ |
Under 200 ms on average for create; ~1 s to resume from paused |
1 h (free tier); 3 h (paid tier); 4 h default, adjustable (enterprise tier) |
Firecracker microVM |
✕ |
– |
[exe.dev](/p/exe-dev) |
$0.05/vCPU-hr
$0.05 per CPU core-hour (usage pricing); $20/month Personal plan (2 vCPU / 8 GB RAM), $25/user/month Team plan
|
✕ |
✓ |
✕ |
✕ |
Sub-second start; resume timing not specified |
– |
KVM via Cloud Hypervisor (also uses crosvm; per a third-party article, Kata Containers) |
✕ |
✓ |
[Daytona](/p/daytona) |
$0.0504/vCPU-hr
$0.0504 per vCPU-hour
|
✓ |
✕ |
✓ |
– |
~27 ms spin-up; under 90 ms end-to-end |
No fixed limit |
Linux namespaces and isolated containers for container sandboxes; full virtual machines with their own kernel for Linux and Windows VM sandboxes; isolated containers with exclusive GPU allocation for GPU sandboxes |
✓ |
✓ |
[E2B](/p/e2b) |
$0.0504/vCPU-hr
$0.000014/vCPU-second (≈$0.0504/vCPU-hour); RAM $0.0000045/GiB/second (≈$0.0162/GiB-hour)
|
✓ |
✕ |
✓ |
✓ |
less than 200 ms (same region); ~1 s to resume from a full snapshot |
24 h on Pro plan; 1 h on Hobby (free) plan |
Firecracker microVM |
✕ |
✓ |
[LangSmith Sandboxes](/p/langsmith-sandboxes) |
$0.0576/vCPU-hr
$0.0576 per vCPU-hour for compute, plus memory and storage
|
✕ |
– |
✓ |
✓ |
<0.98 s p50 with prewarming |
A configurable hard TTL can cap total runtime; no maximum value is publicly stated |
Hardware-virtualized microVM (kernel-isolated) |
✕ |
✓ |
[Fly.io Sprites](/p/fly-io-sprites) |
$0.07/vCPU-hr
$0.07 per CPU-hour and $0.04375 per GB-hour of memory
|
✓ |
✕ |
✕ |
✓ |
~100-500 ms warm resume; ~1-2 s cold start |
No fixed limit |
Firecracker microVM |
✕ |
✓ |
[Cloudflare Sandboxes](/p/cloudflare) |
$0.072/vCPU-hr
$0.000020 per vCPU-second (~$0.072 per vCPU-hour) plus $0.0000025 per GiB-second of memory
|
✓ |
✓ |
✕ |
✓ |
~1-3 seconds |
No fixed limit; runtime is not guaranteed and may end on host restart |
Per-instance isolation on Cloudflare Containers platform (Firecracker microVMs; gVisor and QEMU also supported) |
✕ |
✓ |
[Azure Container Apps](/p/microsoft-azure) |
$0.0864/vCPU-hr
$0.000024/vCPU-second and $0.000003/GiB-second while active (~$0.0864/vCPU-hour, ~$0.0108/GiB-hour).
|
✓ |
✓ |
✓ |
✓ |
Sub-second |
No documented fixed limit; sandboxes auto-suspend after configurable idle timeout (1–60 min, default 5 min) and auto-delete after configurable days. |
Hardware-isolated microVM |
✕ |
– |
[AWS AgentCore Code Interpreter](/p/aws-agentcore-code-interpreter) |
$0.0895/vCPU-hr
$0.0895/vCPU-hour + $0.00945/GB-hour
|
✕ |
✓ |
✓ |
✓ |
300-800 ms |
8 hours (configurable; 15 min default timeout, up to 8h max) |
Firecracker microVM (per-session, running on AWS Lambda MicroVMs) |
✕ |
✕ |
[AWS Lambda MicroVMs](/p/aws-lambda-microvms) |
$0.0997/vCPU-hr
$0.0000276944 per vCPU-second + $0.0000036667 per GB-second (ARM/Graviton, US East); snapshot read $0.00155/GB, write $0.0038/GB, storage $0.08/GB-month
|
✓ |
– |
✓ |
✓ |
near-instant |
8 h (28,800 s state-retention window) |
Firecracker microVM |
✕ |
✓ |
[Deno Sandbox](/p/deno-sandbox) |
$0.1/vCPU-hr
$0.10/CPU-hour; $0.025/GiB-hour of memory; $0.20/GiB-month of volume storage
|
✓ |
✓ |
✕ |
✕ |
under 1 second |
30 min (per docs limits; extendable on demand via extendTimeout) |
Linux microVM (official docs say 'individual Linux microVMs'; Firecracker is named by third-party blogs and HN commentary but not in the official Deno documentation) |
✕ |
✕ |
[Runloop](/p/runloop) |
$0.108/vCPU-hr
$0.108 per CPU-hour (plus $0.0252 per GB-hour of memory)
|
✓ |
✕ |
✕ |
✓ |
A few seconds to first command; suspend/resume typically takes seconds, depending on modified data |
Default 1 h, configurable |
Linux microVM with hardware isolation (two-layer VM + container) |
✓ |
✓ |
[Vercel Sandbox](/p/vercel) |
$0.128/vCPU-hr
$0.128 per vCPU-hour (active CPU)
|
✓ |
✓ |
✕ |
✕ |
Sub-second (millisecond-level startup with Firecracker microVMs) |
24 h (Pro/Enterprise); 45 min (Hobby) |
Firecracker microVM |
✕ |
✓ |
[Modal Sandboxes](/p/modal) |
$0.1419/vCPU-hr
$0.00003942 per CPU core/sec, $0.00000667 per GiB memory/sec
|
✕ |
– |
✓ |
✕ |
~1 second for container boot; total Sandbox startup varies by image and initialization |
24 h |
gVisor container runtime (default); full Linux VM with VM Sandboxes (Beta) |
✓ |
✓ |
[Ellipsis](/p/ellipsis) |
$0.142/vCPU-hr
$0.142 / vCPU-hour (Ellipsis Cloud tier)
|
✓ |
✕ |
✕ |
– |
~8 s (warm snapshot boot); first session image build ~3m40s |
24 h |
Linux container |
– |
– |
[Blaxel](/p/blaxel) |
$0.0000115 per GB-RAM-second (active CPU)
$0.0000115 per GB-RAM-second (active CPU)
|
✓ |
✓ |
✓ |
✓ |
~25 ms (resume from standby) |
Tier-dependent: up to 7 days (tier 0), up to 30 days (tier 1); unlimited in tier 2 and above |
microVM with hardware-level (kernel-level) isolation |
✕ |
✓ |
[CodeSandbox SDK](/p/codesandbox) |
$0.01486 per VM credit
$0.01486 per VM credit
|
– |
– |
✓ |
✓ |
500 ms (P95) |
24 h on Pro tier; no documented hard cap for Scale/Enterprise |
Firecracker microVM |
✕ |
✓ |
[Box by ASCII](/p/box-by-ascii) |
$0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe)
$0.036 per hour per box (4 shared vCPU / 8 GB RAM / 75 GB NVMe)
|
✓ |
✕ |
✕ |
– |
A few seconds for resume; create time not explicitly stated in extracted docs |
Default TTL overrideable up to 30 days; can disable auto-stop with ttl=null |
Hetzner Cloud VPS (current CX33); hypervisor not stated in docs |
✕ |
✓ |
[Morph Cloud](/p/morph) |
$0.05 per MCU (Morph Compute Unit)
$0.05 per MCU (Morph Compute Unit)
|
✓ |
– |
✓ |
✓ |
~250 ms (snapshot/restore via Infinibranch; cold-boot time for fresh images not documented) |
No fixed limit documented; TTLs control stop/pause on expiry |
Full VMs (hypervisor technology not explicitly named in public docs) |
– |
✓ |
[OpenComputer](/p/opencomputer) |
$0.24 per hour for the default 4GB/1vCPU sandbox
$0.24 per hour for the default 4GB/1vCPU sandbox
|
✓ |
✕ |
✓ |
✓ |
Sandboxes 'start in milliseconds' (docs overview); resume from hibernation 'in seconds' (home page, README). No specific P50/P95 latency published. |
No fixed limit (default 300s idle timeout auto-hibernates the VM) |
KVM (QEMU/KVM) — hardware-level virtualization; each sandbox is a full Linux VM with its own kernel |
✕ |
– |
[Scrapybara](/p/scrapybara) |
$29/month (Basic) or $99/month (Pro)
$29/month (Basic) or $99/month (Pro)
|
– |
– |
– |
– |
Under 1 second for Ubuntu and Browser instances; Windows instances are described as 'slow' without a specific figure |
24 h (configurable; 1 h default) |
Full Linux (Ubuntu 22.04) and Windows 11 virtual machines; open-source computer service is packaged as a Docker image with xdotool/noVNC |
– |
– |
[Railway Sandboxes](/p/railway) |
$50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB
$50/vCPU-month and $50/GB-memory-month (~$0.0000000193 per vCPU-second or GB-second); egress $0.05/GB
|
✕ |
✓ |
✕ |
✕ |
– |
– |
Per-sandbox VM on Railway's VM primitive (specific hypervisor technology not publicly disclosed) |
✕ |
✓ |
[Runwork Agent Sandbox](/p/runwork) |
$79/month (Startup tier: 3 seats, $30/month usage credits)
$79/month (Startup tier: 3 seats, $30/month usage credits)
|
✓ |
– |
– |
– |
Cold starts 'measured in milliseconds, not seconds' (no specific figure published) |
Bounded by per-task budgets, turn limits, and timeouts set in agent definitions; no global limit stated |
Isolated computing environment ("their own computer"), underlying isolation technology not specified publicly |
– |
– |
[Fly Machines](/p/fly) |
From ~$0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering
From ~$0.0027/hr (shared-cpu-1x, 256 MB) with per-second metering
|
✕ |
✕ |
✓ |
✓ |
Well under 1 s to start an existing or stopped Machine; a few hundred ms from suspend; ~2+ s for a cold start |
No fixed limit |
Firecracker microVM |
✕ |
✓ |
[Computer Agents](/p/computer-agents) |
Lite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour)
Lite: $0.0026/min ($0.16/hour) | Standard: $0.0052/min ($0.31/hour) | Power: $0.0097/min ($0.58/hour) | Desktop: $0.013/min ($0.78/hour)
|
✓ |
✓ |
– |
– |
Sub-second for warm container startup |
– |
Isolated Linux container per agent (technology not specified) |
– |
– |
[GKE Agent Sandbox](/p/gke-agent-sandbox) |
No Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing)
No Agent Sandbox surcharge; standard GKE vCPU/memory/storage rates apply (see GKE pricing)
|
✕ |
– |
✓ |
✕ |
~200 ms typical (90% of allocations under 200 ms; up to 300 sandboxes/sec/cluster; pre-warmed pods enable sub-second creation) |
Configurable TTL (no fixed maximum documented) |
gVisor (also supports Kata Containers and other OCI-compatible runtimes; runtimeClassName: gvisor) |
✓ |
✓ |
[Agent-Sandbox](/p/agent-sandbox) |
No published headline rate (open-source/self-hosted software)
No published headline rate (open-source/self-hosted software)
|
– |
– |
– |
– |
– |
– |
– |
– |
– |
[Tencent Cloud CubeSandbox](/p/tencent-cubesandbox) |
No published headline rate (open-source/self-hosted software)
No published headline rate (open-source/self-hosted software)
|
✓ |
– |
✓ |
✓ |
~60 ms (single concurrency; under 50 concurrent: avg 67 ms, P95 90 ms, P99 137 ms) |
– |
KVM MicroVM via RustVMM (each sandbox runs its own Linux kernel; hardware-isolated from the host and from other sandboxes) |
– |
✕ |
[Beam](/p/beam) |
Per-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates)
Per-second/per-millisecond billing for CPU, RAM, and GPU (see pricing page for per-unit rates)
|
✓ |
✕ |
✓ |
– |
1–3 s cold boot; container start under 1 s |
– |
gVisor + runc |
✓ |
✓ |
[Agentic Studio](/p/agentic-studio) |
– |
– |
– |
– |
– |
– |
– |
Process- and network-level isolation |
– |
– |
[OpenSandbox](/p/open-sandbox) |
– |
– |
– |
– |
– |
– |
– |
– |
– |
– |
