Runtimes & sandboxes
sandboxes and code execution environments for agents
daytonaio/daytona daytonaio/daytona is the category leader by adoption; before choosing, decide whether you need kernel-level, stateful isolated sandboxes (fast snapshots) or a lighter local/permissioned runtime because projects mainly differ by isolation model, privacy and deployment model.
Which one matches your setup?
Answer any of the questions — the shortlist updates as you go. Recommendations come from the capability passports below, nothing else.
Comparison matrix
Axes are extracted from each project's docs by our review pipeline; the maturity score is computed from stars, growth and commit activity — not an opinion. Click a column to sort.
| Runs in | Models | Context | Cost to run | |||||
|---|---|---|---|---|---|---|---|---|
⭐ 35.2k +2142/7d | CLI | Fixed provider | No repo context | None mentioned | ●●●●● | Runs fully local | ●●●●● | Free, local install |
⭐ 30.7k +67/7d | CLI | AnthropicOpenAIBYOKOllama / local | Related files access | Basic gating | ●●●●● | Self-hostable | ●●●●● | Your API key (Anthropic/OpenAI) or local models |
⭐ 13.7k +97/7d | CLIWeb appCI | BYOK | Command-only | None | ●●●●● | Self-hostable | ●●●●● | E2B cloud (API key); self-hostable |
⭐ 3.6k +27/7d | CLIWeb appCoding-agent plugin | OpenAIAnthropicFixed provider | Whole workspace | Basic filters/config | ●●●●● | Self-hostable | ●●●●● | Free, self-hosted; external API costs apply |
⭐ 2.8k +40/7d | CLI | Fixed provider | Diff only | None | ●●●●● | Fully local | ●●●●● | Free, self-hosted |
⭐ 71.8k | CLIWeb appCIIDE | Fixed provider | Whole-repo access | Governance controls | ●●●●● | Hosted cloud (API key) | ●●●●● | Hosted service — account + API key |
⭐ 1.0k +6/7d | CLI | AnthropicOpenAI | Whole-repo VM | None documented | ●●●●● | Local VM; cloud models | ●●●●● | Free, local; third-party model API costs may apply |
⭐ 992 | CLIWeb app | Fixed provider | Diff only | None mentioned | ●●●●● | Fully local | ●●●●● | Self-hosted; uses your machine's resources |
⭐ 949 +9/7d | CLICICoding-agent plugin | OpenAIAnthropicGemini | No repo analysis | Config-based filters | ●●●●● | Fully local | ●●●●● | Free, local tool |
⭐ 928 +10/7d | Web appCLI | AnthropicFixed provider | Whole-repo analysis | Checkpoint & review | ●●●●● | Self-hostable | ●●●●● | Free self-hosted; agent models use your API key |
⭐ 662 +32/7d | Web appCLI | BYOK | Whole-repo analysis | Minimal controls | ●●●●● | Self-hosted (provider keys) | ●●●●● | Your API key; provider billing applies |
⭐ 3.8k | CLI | OpenAI | Files + related | No noise controls | ●●●●● | Your API key | ●●●●● | Your API key, per-request |
Capability profiles
Six axes, 0–5 each. The shape tells you the strategy: a wide hexagon is a generalist, a spike is a specialist. Showing the 8 most established — the rest are in the full catalog.
A terminal-first agent multiplexer that runs as a single Rust binary with detachable sessions, tmux-style interaction, and a plugin marketplace.
Provides compact, auditable agent runtime with true OS-level container isolation so agents run in separate containers with explicit mounts instead of one large shared process.
Provides secure, isolated cloud sandboxes for running AI-generated code with SDKs for JavaScript and Python, allowing real-world tool access in a managed environment.
Mounts dozens of services (S3, Slack, Gmail, databases, etc.) side-by-side as a single POSIX-like virtual filesystem so agents can use bash-native pipelines across backends.
Provides near-fork(2) microVM spawn and live BRANCHing via snapshot copy-on-write, enabling KVM-isolated agent fan-out with millisecond-scale latency.
Provides fast, stateful, OCI-compatible isolated sandboxes with dedicated kernels and persistent snapshots for running AI-generated code.
Runs coding agents inside a disposable full Linux VM (separate kernel), letting agents install packages and run services without exposing the host.
Provides permanent, idempotent, self-hosted agent sandboxes with fast freeze/wake and E2B compatibility, instead of disposable cloud sandboxes.
All repositories (16)
Daytona is a Secure and Elastic Infrastructure for Running AI-Generated Code
A lightweight alternative to OpenClaw that runs in containers for security. Connects to WhatsApp, Telegram, Sl…
Open-source, secure environment with real-world tools for enterprise-grade agents.
👾 Open source implementation of the ChatGPT Code Interpreter
Fork() for AI agent microVMs. Spawn 100 children in ~100ms from a warm parent; BRANCH a live VM in ~150ms. KVM…
The SQLite of agent sandboxes — self-hosted, E2B-compatible. One machine, sandboxes that live forever, idle co…
Lightweight, container-free sandbox for running commands with network and filesystem restrictions
Open-source, self-hosted AI app builder — an agent builds real apps in isolated sandboxes on your own server,…
HarnessRouter Community Edition: the self-hosted, Apache-2.0 edition of the unified interface for agent harnes…
免 ROOT 免 Termux,在手机上跑 DeepSeek Harness。完整 Ubuntu 环境 + proroot 零 ptrace 开销 · AI 输出实时上屏 · ADB 直连 · 数据不丢
The open-source Agent Gallery and Gateway for Codex, Claude Agent SDK, and OpenCode. Developers publish an Age…
Run, deploy and monitor CLI agents in secure cloud sandboxes.
Kubernetes-native sandbox platform to run AI agents, coding assistants and harnesses.
Hosted alternatives
If running your own reviewer is more ops than you want, these managed services cover the same job.
Hosted, secure sandboxes for running agent-generated code: spin up a cloud runtime per session through the API instead of building and isolating one yourself.
Try E2B →Serverless cloud compute that agents can call to execute code and long tasks in isolation, so the runtime scales for you rather than living on your own infrastructure.
Try Modal →The managed side of daytona: elastic, secure infrastructure for running AI-generated code, provisioned on demand instead of self-hosted.
Try Daytona →