microsandbox
local + cloud
daytona
managed sandboxes for agents [1]
hosting model
local runtime · private beta. access is by request.
managed cloud · customer-managed compute available [1]
runs offline
yes, fully local
managed service or customer-managed compute [1]
cold start
320 ms median · microsandbox 0.4.5
no result in the same local harness [1]
raw memory bandwidth
not the lead today
daytona vm leads on raw memory bandwidth today [1]
isolation
microvm with a separate kernel per sandbox
default container class · dedicated-kernel vm classes available [1]
languages
rust · typescript · python · go · cli
python · typescript · ruby · go · java [1]
programming model
embeddable sdk · no service required locally
sdk and api for a managed sandbox service [1]
snapshots
snapshots capture the disk state of a stopped sandbox.
environment snapshots with save, restore, and resume [1]
credentials
credentials are destination-bound. the sandbox works with a placeholder; the real value is substituted host-side into supported intercepted outbound requests, only for destinations on your allow-list. an approved destination still receives the real credential and could reflect or misuse it, so scope your allow-lists accordingly.
standard environment-variable injection [1]
network policy
by default, sandboxes can reach the public internet. private, host-local, link-local, and metadata destinations are blocked. egress can be reduced to an allowlist or disabled entirely. in the cloud, the non-public block cannot be lifted, even by you.
managed outbound-network controls [1]
computer use
headless agent computers
linux, macos, and windows desktop automation [1]
license
apache 2.0
agpl-3.0 public source [2]
pricing
free locally · private beta pricing is published
published usage pricing and free credit [3]
measured release: microsandbox 0.4.5, inferred from benchmark chronology because the raw artifact does not record the binary version; owner confirmation is pending. median of 10 measured runs after 2 warmups; end-to-end wall time from cli invocation to process exit; pre-pulled alpine userspace; bare-metal linux x86_64 on a gcp c3-standard-192-metal host (intel sapphire rapids, ubuntu 24.04, /dev/kvm). microsandbox: 320 ms; docker: 463 ms; firecracker: 808 ms. firecracker used the same alpine userspace and harness; these numbers do not use firecracker's narrower kernel-to-userspace boundary. full harness and raw results.