microsandbox
local + cloud
modal
managed cloud compute and sandboxes [1]
primary use case
per-session agent computers · untrusted code
managed functions, sandboxes, gpu compute, and batch jobs [1]
hosting model
local runtime · microsandbox cloud (private beta, access by request) [20]
managed cloud [1]
isolation options
hardware microvm · separate kernel
gvisor by default · beta full-vm sandboxes available [2]
runs offline
local, after provisioning runtime dependencies and images [23]
managed service [1]
languages
rust · typescript · python · go · ruby · cli
python · javascript · go sandbox clients [1]
programming model
embedded local runtime · same CLI and SDKs for hosted cloud [20]
managed app and sandbox api [1]
snapshots
local snapshots save disk state, or disk, memory, and running processes with --full. cloud currently supports disk snapshots from stopped persistent sandboxes and disk restore. [21]
filesystem and directory snapshots · alpha memory snapshots [4]
employee-device deployment
administrator settings deployed to employee devices with Jamf or Intune; supported CLI and SDK releases apply managed overrides [22]
local client calls modal's hosted sandbox service [1]
credentials
credentials are destination-bound. the sandbox works with a placeholder; the real value is substituted host-side into supported intercepted outbound requests, only for destinations on your allow-list. an approved destination still receives the real credential and could reflect or misuse it, so scope your allow-lists accordingly.
modal secrets are supplied to sandboxes as environment variables [1]
network policy
by default, sandboxes can reach the public internet. private, host-local, link-local, and metadata destinations are blocked. egress can be reduced to an allowlist or disabled entirely. in the cloud, the non-public block cannot be lifted, even by you.
managed sandbox networking and egress configuration [1]
gpu support
cpu today · gpu is not offered
documented gpu acceleration and gpu resource selection [1]
readiness and long jobs
application controls lifecycle through the sdk
readiness probes, idle timeouts, detach, and managed job lifecycle [1]
pricing
free locally · private beta pricing is published
published usage pricing and free credit [3]
license
apache 2.0
managed proprietary service [1]