Rank #1 of 8 in Agent Sandboxes & Code Execution
Access
Showcase


Try itExperimental
See what an agent can do with E2B before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$e2b --helprecorded session — replayed, not liveVerified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Capabilities hardware — stories about capabilities hardware in this arenaCapabilities hardwareevidence →
Stories about capabilities hardware in this arena
Code execution — stories about code execution in this arenaCode executionevidence →
Stories about code execution in this arena
Dev experience — day-to-day developer experience — setup friction, docs, debugging, iteration speedDev experienceevidence →
Day-to-day developer experience — setup friction, docs, debugging, iteration speed
Isolation security — stories about isolation security in this arenaIsolation securityevidence →
Stories about isolation security in this arena
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Performance scale — stories about performance scale in this arenaPerformance scaleevidence →
Stories about performance scale in this arena
Pricing limits — free-tier ceilings, usage caps, and rate limits before you have to payPricing limitsevidence →
Free-tier ceilings, usage caps, and rate limits before you have to pay
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Provisioning lifecycle — creating, updating, and tearing down resources across their lifecycleProvisioning lifecycleevidence →
Creating, updating, and tearing down resources across their lifecycle
Snapshot persistence — stories about snapshot persistence in this arenaSnapshot persistenceevidence →
Stories about snapshot persistence in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 2 free · 0 paid · 0 enterprise · 28 not stated in evidence
Follow the green: where the map greys out is where E2B stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
✓8/10
unlocks → Scoped API keys · MCP server · Machine-readable spec · Versioning policy
Subscribe to events via webhooks
✓6/10
Build against official SDKs
✓8/10
Issue scoped/least-privilege API credentials for an agent
—0/10
Connect an agent via an official MCP server
—0/10
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
✓8/10
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
✓9/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
~5/10
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
n/an/a
Set up automations that run autonomously in the background
~5/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Capabilities hardware — stories about capabilities hardware in this arenaCapabilities hardware
Stories about capabilities hardware in this arena
Code execution — stories about code execution in this arenaCode execution
Stories about code execution in this arena
Dev experience — day-to-day developer experience — setup friction, docs, debugging, iteration speedDev experience
Day-to-day developer experience — setup friction, docs, debugging, iteration speed
Isolation security — stories about isolation security in this arenaIsolation security
Stories about isolation security in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Performance scale — stories about performance scale in this arenaPerformance scale
Stories about performance scale in this arena
Pricing limits — free-tier ceilings, usage caps, and rate limits before you have to payPricing limits
Free-tier ceilings, usage caps, and rate limits before you have to pay
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Provisioning lifecycle — creating, updating, and tearing down resources across their lifecycleProvisioning lifecycle
Creating, updating, and tearing down resources across their lifecycle
Snapshot persistence — stories about snapshot persistence in this arenaSnapshot persistence
Stories about snapshot persistence in this arena
Sorted by importance (agentic first) (high → low) · 51/51 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | full | 8/10 | Tprobed | |
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 9/10 | Tprobed | |
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 8/10 | Tprobed | |
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | full | 6/10 | Cclaimed | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 5/10 | Cclaimed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | full | 8/10 | Cclaimed | |
Execute untrusted, AI-generated code without risking my own infrastructure C Untrusted code | developer | Code execution — stories about code execution in this arenaCode execution | 3 | full | 9/10 | Cclaimed | |
My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a human C Agent lifecycle | ai-native user | Dev experience — day-to-day developer experience — setup friction, docs, debugging, iteration speedDev experience | 3 | full | 9/10 | Cclaimed | |
Spin up an isolated sandbox with one API/SDK call and get a live environment in seconds C Lifecycle | developer | Provisioning lifecycle — creating, updating, and tearing down resources across their lifecycleProvisioning lifecycle | 3 | full | 9/10 | Cclaimed | |
Rely on a documented hard isolation boundary (microVM or equivalent) between sandboxes and my systems C Isolation | platform-engineer | Isolation security — stories about isolation security in this arenaIsolation security | 3 | full | 8/10 | Cclaimed | |
Restrict or allow the sandbox's network egress with explicit policy C Network policy | platform-engineer | Isolation security — stories about isolation security in this arenaIsolation security | 3 | full | 8/10 | Cclaimed | |
Snapshot a sandbox and later restore or fork new sandboxes from that snapshot C Snapshots | developer | Snapshot persistence — stories about snapshot persistence in this arenaSnapshot persistence | 3 | full | 8/10 | Cclaimed | |
Run large concurrent fleets of sandboxes with documented concurrency limits C Scale | platform-engineer | Performance scale — stories about performance scale in this arenaPerformance scale | 3 | partial | 6/10 | Cclaimed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partialfree | 6/10 | Cclaimed | |
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | partial | 4/10 | Cclaimed | |
Pay per second only for the compute a sandbox actually uses G Pricing | platform-engineer | Pricing limits — free-tier ceilings, usage caps, and rate limits before you have to payPricing limits | 3 | partial | 4/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 3/10 | Cclaimed | |
Start sandboxes with documented sub-second-to-few-second cold starts C Latency | developer | Performance scale — stories about performance scale in this arenaPerformance scale | 3 | none | 0/10 | ||
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | none | untested | none yet | |
Define custom sandbox templates or bring my own container image C Runtimes | developer | Code execution — stories about code execution in this arenaCode execution | 2 | full | 9/10 | Cclaimed | |
Run arbitrary shell commands and install packages inside the sandbox C Untrusted code | developer | Code execution — stories about code execution in this arenaCode execution | 2 | full | 9/10 | Cclaimed | |
Execute code in multiple language runtimes (Python, JavaScript, and more) and get rich results back C Runtimes | developer | Code execution — stories about code execution in this arenaCode execution | 2 | full | 8/10 | Cclaimed | |
Pause a running sandbox and resume it later with filesystem and memory state intact C Snapshots | developer | Snapshot persistence — stories about snapshot persistence in this arenaSnapshot persistence | 2 | full | 8/10 | Cclaimed | |
Read, write, upload, and download files in the sandbox filesystem via the SDK C Files | developer | Code execution — stories about code execution in this arenaCode execution | 2 | full | 8/10 | Cclaimed | |
Run coding agents like Claude Code or Codex inside the sandbox following the vendor's own recipe C Agent workloads | ai-native user | Capabilities hardware — stories about capabilities hardware in this arenaCapabilities hardware | 2 | full | 8/10 | Cclaimed | |
Set timeouts so sandboxes shut down automatically and stop billing when idle or done G Lifecycle | developer | Provisioning lifecycle — creating, updating, and tearing down resources across their lifecycleProvisioning lifecycle | 2 | full | 8/10 | Cclaimed | |
Give an agent a sandbox where host secrets and credentials are unreachable by the code it runs C Isolation | ai-native user | Isolation security — stories about isolation security in this arenaIsolation security | 2 | full | 7/10 | Cclaimed | |
Keep a sandbox session running for hours or days for long agent tasks C Scale | developer | Performance scale — stories about performance scale in this arenaPerformance scale | 2 | partial | 7/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | fullfree | 7/10 | Cclaimed | |
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 6/10 | Cclaimed | |
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | partial | 6/10 | Tprobed | |
Run a headless browser or full desktop environment inside the sandbox C Workloads | developer | Capabilities hardware — stories about capabilities hardware in this arenaCapabilities hardware | 2 | partial | 6/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 5/10 | Cclaimed | |
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | partial | 4/10 | Cclaimed | |
Attach GPUs to sandboxed workloads C Workloads | developer | Capabilities hardware — stories about capabilities hardware in this arenaCapabilities hardware | 2 | none | 0/10 | ||
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | 0/10 | ||
Expose a port from the sandbox on a public preview URL to reach services running inside C Preview access | developer | Provisioning lifecycle — creating, updating, and tearing down resources across their lifecycleProvisioning lifecycle | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | none | untested | none yet | |
Start building with a free tier or included credits without talking to sales G Pricing | developer | Pricing limits — free-tier ceilings, usage caps, and rate limits before you have to payPricing limits | 1 | full | 8/10 | Cclaimed | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 24 stories with headroom
What would move E2B’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productConnect an agent via an official MCP server
nonemoves agent-readyimpact 45
E2B is a sandbox/code-execution infrastructure product (not itself an agent), so an official MCP server exposing its sandbox tools to agents is a fair, applicable axis.
Performance scale — stories about performance scale in this arenaStart sandboxes with documented sub-second-to-few-second cold starts
nonemoves PA Scoreimpact 30
Missing: any explicit startup latency figures, benchmark data, or documentation stating cold-start speed in seconds.
Privacy posture — data-handling and privacy storiesPrevent my data from being used to train AI models
nonemoves PA Scoreimpact 30
The evidence pack contains no mention of E2B's data-training policies, opt-out controls, or data-use terms for AI model training; all evidence concerns sandbox execution, CLI, persistence, and networking features.
Agenticness — how well agents can access and operate the productIssue scoped/least-privilege API credentials for an agent
nonemoves agent-readyimpact 30
Evidence shows E2B supports multiple API keys per team/project (e2b-docs-30, e2b-docs-31, e2b-docs-34, e2b-docs-35) but no documentation of scoped or least-privilege permissions (e.g., read-only, sandbox-restricted, rate-limited keys) that would let an AI-native user issue a restricted credential to an agent.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Evidence shows extensive static documentation with code snippets (e2b-docs-1, e2b-docs-2, etc.) but no evidence of an interactive, runnable API reference — the probe explicitly found no OpenAPI/Swagger spec (e2b-probe-3), and no playground or 'try it' console is mentioned anywhere in the pack.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
E2B exposes SDKs and a CLI, but active probing found no OpenAPI/swagger spec at any standard location (all candidate paths returned 404), and no documentation page references a machine-readable API spec.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
The evidence pack covers SDK usage, CLI commands, sandbox lifecycle, and self-hosting, but contains no mention of API versioning scheme, changelog, or a documented deprecation policy; the openapi probe even returned 404s.
Automation depth — how much of the product can run unattendedDefine rules that trigger actions automatically on events
partialq3/10moves PA Scoreimpact 21
Missing: built-in conditional rule definitions, in-product automatic action execution, and any hands-on evidence of the webhook mechanism working end-to-end.
Showing the top 8 of 24 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map16 surfaces · 36 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
CLI docs16 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Drive the product through a documented public API
- Build against official SDKs
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Perform bulk operations across many items at once
- Define custom sandbox templates or bring my own container image
- Run arbitrary shell commands and install packages inside the sandbox
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Control data retention and deletion
- Set timeouts so sandboxes shut down automatically and stop billing when idle or done
- Spin up an isolated sandbox with one API/SDK call and get a live environment in seconds
- Pause a running sandbox and resume it later with filesystem and memory state intact
- Snapshot a sandbox and later restore or fork new sandboxes from that snapshot
Sandbox docs15 stories
- Run the product headlessly / in CI for automation
- Subscribe to events via webhooks
- Set up automations that run autonomously in the background
- Test against a sandbox environment without touching production data
- Define rules that trigger actions automatically on events
- Execute untrusted, AI-generated code without risking my own infrastructure
- My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a human
- Do everything through the API that I can do in the UI
- Run large concurrent fleets of sandboxes with documented concurrency limits
- Keep a sandbox session running for hours or days for long agent tasks
- Pay per second only for the compute a sandbox actually uses
- Control data retention and deletion
- Set timeouts so sandboxes shut down automatically and stop billing when idle or done
- Pause a running sandbox and resume it later with filesystem and memory state intact
- Snapshot a sandbox and later restore or fork new sandboxes from that snapshot
GitHub README12 stories
- Test against a sandbox environment without touching production data
- Run a headless browser or full desktop environment inside the sandbox
- Execute untrusted, AI-generated code without risking my own infrastructure
- Rely on a documented hard isolation boundary (microVM or equivalent) between sandboxes and my systems
- Give an agent a sandbox where host secrets and credentials are unreachable by the code it runs
- Do everything through the API that I can do in the UI
- Export all of my data in open formats and leave
- Read the product's source under an open license
- Self-host the core product
- Run large concurrent fleets of sandboxes with documented concurrency limits
- Choose where my data is stored (region/residency)
- Spin up an isolated sandbox with one API/SDK call and get a live environment in seconds
Quickstart docs11 stories
- Point an agent at llms.txt or agent-oriented docs
- Drive the product through a documented public API
- Build against official SDKs
- Operate the product with natural-language commands
- Test against a sandbox environment without touching production data
- Read, write, upload, and download files in the sandbox filesystem via the SDK
- Execute code in multiple language runtimes (Python, JavaScript, and more) and get rich results back
- My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a human
- Do everything through the API that I can do in the UI
- Start building with a free tier or included credits without talking to sales
- Spin up an isolated sandbox with one API/SDK call and get a live environment in seconds
Agents docs10 stories
- Build against official SDKs
- Operate the product with natural-language commands
- Test against a sandbox environment without touching production data
- Run coding agents like Claude Code or Codex inside the sandbox following the vendor's own recipe
- Execute untrusted, AI-generated code without risking my own infrastructure
- My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a human
- Rely on a documented hard isolation boundary (microVM or equivalent) between sandboxes and my systems
- Give an agent a sandbox where host secrets and credentials are unreachable by the code it runs
- Restrict or allow the sandbox's network egress with explicit policy
- Pause a running sandbox and resume it later with filesystem and memory state intact
Filesystem docs7 stories
- Drive the product through a documented public API
- Build against official SDKs
- Perform bulk operations across many items at once
- Read, write, upload, and download files in the sandbox filesystem via the SDK
- Execute code in multiple language runtimes (Python, JavaScript, and more) and get rich results back
- My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a human
- Export all of my data in open formats and leave
Use cases docs6 stories
- Drive the product through a documented public API
- Set up automations that run autonomously in the background
- Operate the product with natural-language commands
- Run coding agents like Claude Code or Codex inside the sandbox following the vendor's own recipe
- Execute untrusted, AI-generated code without risking my own infrastructure
- My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a human
Client docs5 stories
Commands docs5 stories
- Drive the product through a documented public API
- Build against official SDKs
- Execute code in multiple language runtimes (Python, JavaScript, and more) and get rich results back
- Run arbitrary shell commands and install packages inside the sandbox
- My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a human
Network docs5 stories
- Test against a sandbox environment without touching production data
- Execute untrusted, AI-generated code without risking my own infrastructure
- Rely on a documented hard isolation boundary (microVM or equivalent) between sandboxes and my systems
- Give an agent a sandbox where host secrets and credentials are unreachable by the code it runs
- Restrict or allow the sandbox's network egress with explicit policy
Pricing docs5 stories
- Perform bulk operations across many items at once
- Run large concurrent fleets of sandboxes with documented concurrency limits
- Keep a sandbox session running for hours or days for long agent tasks
- Start building with a free tier or included credits without talking to sales
- Pay per second only for the compute a sandbox actually uses
Template docs5 stories
- Test against a sandbox environment without touching production data
- Define custom sandbox templates or bring my own container image
- Run arbitrary shell commands and install packages inside the sandbox
- Do everything through the API that I can do in the UI
- Spin up an isolated sandbox with one API/SDK call and get a live environment in seconds
OpenAPI spec2 stories
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$e2b --helpreproduced$ e2b --help Usage: e2b [options] [command] Create sandbox templates from Dockerfiles by running e2b template create then use our SDKs to create sandboxes from these templates. Visit E2B docs (https://e2b.dev/docs) to learn how to create sandbox templates and start sandboxes. Options: -V, --version display E2B CLI version -h, --help display help for command Commands: auth authentication commands template|tpl manage sandbox templates sandbox|sbx work with sandboxes help [command] display help for command
$e2b --versionreproduced$ e2b --version 2.18.0
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
1 of 17 testable claims verified · 1 contradicted → integrity 0/100
20 distinct capability claims found in E2B’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
1
Verified
15
Unverified
1
Contradicted
20
Undersold
Verified (1)
“Official CLI to manage and interact with sandboxes and templates”
Unverified (18)
“Create a persistent sandbox and execute code in it via SDK call”
Spin up an isolated sandbox with one API/SDK call and get a live environment in secondsfullproof ↗
“Create a persistent sandbox and execute code in it via SDK call”
Execute code in multiple language runtimes (Python, JavaScript, and more) and get rich results backfullproof ↗
“List files in the sandbox filesystem”
Read, write, upload, and download files in the sandbox filesystem via the SDKfullproof ↗
“Pause a sandbox and resume later with filesystem and memory state intact”
Pause a running sandbox and resume it later with filesystem and memory state intactfullproof ↗
“Reset/extend a running sandbox's timeout dynamically via setTimeout/set_timeout”
Set timeouts so sandboxes shut down automatically and stop billing when idle or donefullproof ↗
“Manually shut down a sandbox early via a kill method”
Set timeouts so sandboxes shut down automatically and stop billing when idle or donefullproof ↗
“Write files into the sandbox filesystem, including multiple files at once”
Read, write, upload, and download files in the sandbox filesystem via the SDKfullproof ↗
“Read files from the sandbox filesystem”
Read, write, upload, and download files in the sandbox filesystem via the SDKfullproof ↗
“Run arbitrary terminal commands inside the sandbox”
Run arbitrary shell commands and install packages inside the sandboxfullproof ↗
“Control sandbox outbound internet access with on/off switch or allow/deny lists”
Restrict or allow the sandbox's network egress with explicit policyfullproof ↗
“Desktop SDK provides mouse, keyboard, screenshot, and full desktop streaming APIs”
Run a headless browser or full desktop environment inside the sandboxpartialproof ↗
“Self-host the E2B infrastructure using provided Terraform-based deployment guide”
“Sandbox sessions can run for up to 24 hours”
Keep a sandbox session running for hours or days for long agent taskspartialproof ↗
“Run up to 100 concurrently active sandboxes”
Run large concurrent fleets of sandboxes with documented concurrency limitspartialproof ↗
“Define custom sandbox templates specifying base image, env vars, files, setup commands, and start command”
Define custom sandbox templates or bring my own container imagefullproof ↗
“Open-source infrastructure for running AI-generated code in secure isolated cloud sandboxes”
Execute untrusted, AI-generated code without risking my own infrastructurefullproof ↗
“Open-source infrastructure for running AI-generated code in secure isolated cloud sandboxes”
Rely on a documented hard isolation boundary (microVM or equivalent) between sandboxes and my systemsfullproof ↗
“Open-source infrastructure for running AI-generated code in secure isolated cloud sandboxes”
Contradicted (1)
“Fully pre-configured sandboxes with running processes ready instantly, zero wait time”
Start sandboxes with documented sub-second-to-few-second cold startsnoneproof ↗
Undersold (20)
Point an agent at llms.txt or agent-oriented docsfullproof ↗
Run the product headlessly / in CI for automationfullproof ↗
Drive the product through a documented public APIfullproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Operate the product with natural-language commandspartialproof ↗
Test against a sandbox environment without touching production datafullproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Run coding agents like Claude Code or Codex inside the sandbox following the vendor's own recipefullproof ↗
My agent can provision its own sandbox, execute code, read the results, and tear it down — end to end without a humanfullproof ↗
Give an agent a sandbox where host secrets and credentials are unreachable by the code it runsfullproof ↗
Do everything through the API that I can do in the UIpartialproof ↗
Export all of my data in open formats and leavepartialproof ↗
Start building with a free tier or included credits without talking to salesfullproof ↗
Pay per second only for the compute a sandbox actually usespartialproof ↗
Choose where my data is stored (region/residency)partialproof ↗
Snapshot a sandbox and later restore or fork new sandboxes from that snapshotfullproof ↗
Claims outside our story set (3)
Real capability claims found in E2B’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Paused sandboxes are retained indefinitely with no automatic deletion”
source ↗“View sandbox metrics for CPU, memory, and disk usage”
source ↗“Customize sandbox CPU and RAM resources”
source ↗
Business model
Open-core (Apache-2.0, self-hostable); the hosted cloud has a free hobby tier with credits, then a Pro monthly base plus per-second vCPU/RAM usage, and custom enterprise plans.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
Agent surface uptime llms.txt 100% (30d, checked every 6h since Sep 8 '26)
