Execution Sandbox
15 tools
Daytona
Agent sandboxes with independent kernel per sandbox and sub-90ms snapshot resume.
Firecracker
AWS's open-source microVM monitor powering Lambda and Fargate.
gVisor
Google's user-space application kernel for workload isolation, delivered as the runsc OCI runtime.
NVIDIA OpenShell
Policy-governed agent runtime that blocks all outbound network traffic by default.
E2B
Open-source Firecracker microVM sandboxes for AI agent code execution.
CubeSandbox
Tencent Cloud's open-source microVM agent sandbox, E2B-SDK compatible.
Kata Containers
OCI-compatible VM isolation that can drive QEMU, Cloud Hypervisor or Firecracker.
microsandbox
Self-hosted, local-first microVM sandboxes with OCI image compatibility.
Cloud Hypervisor
KVM-based Rust VMM built on rust-vmm, dual-licensed Apache-2.0 / MIT.
Agent Substrate
High-density runtime that multiplexes many stateful agents onto few Kubernetes workers.
Fly.io Machines
Firecracker microVMs with suspend/resume across 18+ regions.
Vercel Sandbox
Ephemeral Firecracker microVMs on Vercel, one per sandbox.
Deno Sandbox
Deno's managed microVM sandboxes with credential and egress controls.
K8E
A k3s-derived Kubernetes distribution, repositioned in 2026 as an agent sandbox matrix.
Modal Sandboxes
Managed container-based sandboxes on Modal, isolated with gVisor.