microsandbox
local + cloud
daytona
managed sandboxes for agents [1]
hosting model
local runtime · microsandbox cloud (private beta, access by request) [20]
hosted service · own compute with daytona control plane [7]
runs offline
local, after provisioning runtime dependencies and images [23]
hosted service or own compute linked to daytona [7]
isolation
microvm with a separate kernel per sandbox
container class · linux and windows VM classes with their own kernel [5]
languages
rust · typescript · python · go · ruby · cli
python · typescript · ruby · go · java [1]
programming model
embeddable sdk · no service required locally
sdk and api for a managed sandbox service [1]
snapshots
local snapshots save disk state, or disk, memory, and running processes with --full. cloud currently supports disk snapshots from stopped persistent sandboxes and disk restore. [21]
container snapshots save files · VM hot snapshots also save memory [6]
employee-device deployment
administrator settings deployed to employee devices with Jamf or Intune; supported CLI and SDK releases apply managed overrides [22]
own compute connects infrastructure to daytona's control plane [7]
credentials
credentials are destination-bound. the sandbox works with a placeholder; the real value is substituted host-side into supported intercepted outbound requests, only for destinations on your allow-list. an approved destination still receives the real credential and could reflect or misuse it, so scope your allow-lists accordingly.
proxy substitutes secret placeholders in HTTPS headers; configure a host allowlist to restrict destinations [8]
network policy
by default, sandboxes can reach the public internet. private, host-local, link-local, and metadata destinations are blocked. egress can be reduced to an allowlist or disabled entirely. in the cloud, the non-public block cannot be lifted, even by you.
block-all, CIDR or domain allowlists, and outbound proxy controls [5]
computer use
Linux GUI workloads via a documented local VNC setup [9]
computer-use APIs for desktop interaction [4]
license
apache 2.0
agpl-3.0 public source [2]
pricing
free locally · private beta pricing is published
published usage pricing and free credit [3]