Skip to content
A

Execution Sandbox

15 tools

Daytona

Agent sandboxes with independent kernel per sandbox and sub-90ms snapshot resume.

Open source★ 71,667Archived

Firecracker

AWS's open-source microVM monitor powering Lambda and Fargate.

Open source★ 37,138

gVisor

Google's user-space application kernel for workload isolation, delivered as the runsc OCI runtime.

Open source★ 19,501Caveat

NVIDIA OpenShell

Policy-governed agent runtime that blocks all outbound network traffic by default.

Open source★ 14,749Caveat

E2B

Open-source Firecracker microVM sandboxes for AI agent code execution.

Open source★ 14,150Caveat

CubeSandbox

Tencent Cloud's open-source microVM agent sandbox, E2B-SDK compatible.

Open source★ 12,798Caveat

Kata Containers

OCI-compatible VM isolation that can drive QEMU, Cloud Hypervisor or Firecracker.

Open source★ 8,874

microsandbox

Self-hosted, local-first microVM sandboxes with OCI image compatibility.

Open source★ 8,555Caveat

Cloud Hypervisor

KVM-based Rust VMM built on rust-vmm, dual-licensed Apache-2.0 / MIT.

Open source★ 6,285

Agent Substrate

High-density runtime that multiplexes many stateful agents onto few Kubernetes workers.

Open source★ 4,248Caveat

Fly.io Machines

Firecracker microVMs with suspend/resume across 18+ regions.

Proprietary★ 1,717Caveat

Vercel Sandbox

Ephemeral Firecracker microVMs on Vercel, one per sandbox.

Proprietary★ 208Caveat

Deno Sandbox

Deno's managed microVM sandboxes with credential and egress controls.

ProprietaryCaveat

K8E

A k3s-derived Kubernetes distribution, repositioned in 2026 as an agent sandbox matrix.

Open sourceCaveat

Modal Sandboxes

Managed container-based sandboxes on Modal, isolated with gVisor.

ProprietaryCaveat