Category
Code Execution Sandboxes
Isolated environments where agents can run code, install packages, and keep state without touching your machine.
How to read this category
Agents that write code need somewhere to run it that is not your laptop. E2B gives each session an isolated Linux sandbox in the cloud, driven from Python or JavaScript SDKs, with templates, pause and resume, and a separate code interpreter layer for stateful data work.
This archive opens with one verified profile because the sandbox market is young and several well-known names could not be verified to the directory standard in this pass. A short, checked list beats a long, padded one; more profiles land as their records clear review.
The verified profiles
Side by side on sourced facts
| Tool | Pricing model | License | Deployment | MCP support | Checked |
|---|---|---|---|---|---|
| E2B | Usage based | Apache-2.0 | Managed cloud, Self-hosted runtime, BYOC on Enterprise | MCP gateway in sandboxes | 2026-10-07 |
Every cell traces to the tool profile, which traces to the official repository, package page, and documentation checked on the date shown. Pricing cells name the model, not a price: vendor prices change, so check the profile for the sourced pricing summary and the official pricing link.
What actually decides the choice
- Isolation and boot model come first: snapshot-based sandboxes start fast and reset clean, which suits generated code you do not trust yet.
- Check the pause and resume story before long-running agent work; always-on sandboxes bill like servers.
- Self-hosting options and license terms differ sharply across this space. Read them before you build on one.
How this archive is ordered, and why it is short
Profiles appear in the order they passed the AgentsUse review gate, not in a tested quality ranking. AgentsUse has not run head-to-head benchmarks for this category, so this page does not claim a winner. The comparison table is the ranking tool: sort by the dimension your job cannot compromise on, then read the full profiles for limitations.
This archive currently lists 1 verified profiles. AgentsUse normally asks for eight published profiles before opening a category archive. This one opens early, on the record, because every listed profile passed the full tool gate and readers comparing real choices need the side-by-side surface now, not a longer unvetted list later. The archive grows as more tools pass review. See how verification works.
Read before you give these tools real work
Guide
Agent Tool Permissions Done Right
Every tool you grant an AI agent is risk you accept. How to think in blast radius, tier permissions, gate irreversible actions, and audit what agents actually did.
2026-09-29
Guide
Agent Security Risks You Must Handle
Agents read untrusted content, run code, and call APIs - a new attack surface. The risks that actually materialize, explained plainly, with working mitigations.
2026-09-29
Guide
A Checklist Before Letting an AI Agent Touch Real Work
Twelve checks to run through before an AI agent handles anything that matters - customers, money, or your reputation.
2026-09-26
Back to the tools directory, the category index, or the guides.