{
 "snapshot_any": {
  "label": "snapshots",
  "why": null
 },
 "snapshot_mem": {
  "label": "memory snapshots",
  "why": null
 },
 "fork": {
  "label": "fork/clone",
  "why": null
 },
 "pause_resume": {
  "label": "pause/resume",
  "why": null
 },
 "persistent_disk": {
  "label": "persistent disk",
  "why": null
 },
 "volumes": {
  "label": "volumes",
  "why": null
 },
 "auto_stop_idle": {
  "label": "idle auto-stop",
  "why": null
 },
 "long_sessions": {
  "label": "≥24 h sessions",
  "why": null
 },
 "custom_image": {
  "label": "custom image (Docker or snapshot)",
  "why": null
 },
 "image_snapshot": {
  "label": "start from your own snapshot",
  "why": null
 },
 "image_oci": {
  "label": "your own Docker/OCI image",
  "why": null
 },
 "vm_isolation": {
  "label": "full VM (own kernel)",
  "why": "Its own Linux kernel instead of sharing the host’s with other customers (containers, gVisor and isolates share or emulate one):\n• The agent can use what a shared kernel keeps locked: kernel modules, eBPF, sysctls, mounting filesystems, its own firewall rules. It has real root, with no special container flags from the provider.\n• Docker, systemd and /dev/kvm work the normal way, not through privileged-container workarounds, so what the agent builds runs like it will in production.\n• A hardware-enforced wall: untrusted code your agents run has to break a hypervisor, not just the kernel it shares with everyone else on the host."
 },
 "docker_inside": {
  "label": "Docker inside",
  "why": null
 },
 "nested_virt": {
  "label": "nested virtualization",
  "why": null
 },
 "root": {
  "label": "root",
  "why": null
 },
 "systemd": {
  "label": "systemd",
  "why": null
 },
 "browser": {
  "label": "browser",
  "why": null
 },
 "desktop": {
  "label": "desktop GUI",
  "why": null
 },
 "computer_use": {
  "label": "computer-use API",
  "why": null
 },
 "code_interpreter": {
  "label": "code interpreter",
  "why": null
 },
 "browser_control": {
  "label": "browser automation API",
  "why": null
 },
 "desktop_control": {
  "label": "desktop control API",
  "why": null
 },
 "browser_and_desktop": {
  "label": "browser + desktop control",
  "why": null
 },
 "anti_bot": {
  "label": "anti-bot stealth",
  "why": null
 },
 "captcha_solving": {
  "label": "CAPTCHA solving",
  "why": null
 },
 "residential_ip": {
  "label": "residential IPs",
  "why": null
 },
 "agent_harnesses": {
  "label": "preinstalled agents",
  "why": null
 },
 "ssh": {
  "label": "SSH",
  "why": null
 },
 "public_ipv4": {
  "label": "public IPv4",
  "why": null
 },
 "inbound_https": {
  "label": "HTTPS preview URLs",
  "why": null
 },
 "custom_domain": {
  "label": "custom domains",
  "why": null
 },
 "raw_tcp_inbound": {
  "label": "raw TCP inbound",
  "why": null
 },
 "egress_allowlist": {
  "label": "egress allowlist",
  "why": "The provider limits where the machine can connect (allowed domains or IPs, or no internet at all):\n• Enforced outside the machine, so an agent with root can’t turn it off.\n• Stops untrusted code or a prompt-injected agent from sending your data anywhere else."
 },
 "open_internet": {
  "label": "open internet",
  "why": "Sandboxes can reach any site or API on a plan you can buy yourself:\n• Browser agents, scrapers and agents calling your own services need it.\n• Some providers only reach an allowlist (package registries, GitHub, AI APIs) on cheap tiers and open the network on a bigger tier or after a prepaid top-up; the estimator prices that tier.\n• No means open internet only through sales, or not at all."
 },
 "static_egress_ip": {
  "label": "static egress IP",
  "why": null
 },
 "private_network": {
  "label": "private networking",
  "why": null
 },
 "self_host": {
  "label": "self-hosting",
  "why": null
 },
 "byoc": {
  "label": "BYOC",
  "why": null
 },
 "open_source": {
  "label": "open source",
  "why": null
 },
 "soc2": {
  "label": "SOC 2",
  "why": null
 },
 "hipaa": {
  "label": "HIPAA",
  "why": null
 },
 "sso": {
  "label": "SSO",
  "why": null
 },
 "gpu": {
  "label": "GPU",
  "why": null
 },
 "arm64": {
  "label": "arm64",
  "why": null
 },
 "windows": {
  "label": "Windows",
  "why": null
 },
 "macos": {
  "label": "macOS",
  "why": null
 },
 "lang_python": {
  "label": "Python",
  "why": null
 },
 "lang_node": {
  "label": "Node.js",
  "why": null
 },
 "lang_go": {
  "label": "Go",
  "why": null
 },
 "lang_rust": {
  "label": "Rust",
  "why": null
 },
 "lang_java": {
  "label": "Java",
  "why": null
 },
 "gpu_desktop": {
  "label": "GPU desktop",
  "why": null
 },
 "credential_injection": {
  "label": "credential injection",
  "why": null
 },
 "egress_http_rules": {
  "label": "HTTP method/path egress rules",
  "why": "Egress rules down to HTTP method and path (e.g. read-only access to one API), not just which hosts."
 },
 "wake_on_request": {
  "label": "wake on request",
  "why": null
 },
 "live_resize": {
  "label": "live resize",
  "why": null
 },
 "fork_running": {
  "label": "live fork (no pause)",
  "why": null
 },
 "memory_snapshot_fork": {
  "label": "memory fork",
  "why": null
 },
 "webhooks": {
  "label": "webhooks",
  "why": null
 },
 "scheduled_wakeups": {
  "label": "scheduled runs (cron)",
  "why": null
 },
 "audit_logs": {
  "label": "audit logs",
  "why": null
 },
 "eu_data_residency": {
  "label": "EU data residency",
  "why": null
 },
 "zero_data_retention": {
  "label": "zero data retention",
  "why": null
 },
 "scoped_api_keys": {
  "label": "scoped API keys",
  "why": null
 },
 "spend_limits": {
  "label": "spend limits",
  "why": null
 },
 "mcp_server": {
  "label": "MCP server",
  "why": null
 },
 "snapshot_auto": {
  "label": "automatic snapshots",
  "why": "The machine’s state is saved for you when it stops, sleeps or times out, and comes back on the next start, with no API call:\n• An agent that pauses mid-task picks up exactly where it was (with memory snapshots: even its running processes).\n• No checkpoint code to write, and no paying to keep machines awake just to keep their state.\n• Not the same as a disk that persists, or nightly backups."
 },
 "snapshot_on_demand": {
  "label": "snapshots on demand",
  "why": "You or your agent can checkpoint the machine whenever you want (API or CLI):\n• Save a known-good point before a risky step, and roll back if it breaks.\n• Start many new machines from one prepared snapshot: templates, fan-out, RL rollouts."
 },
 "harness_api": {
  "label": "agent harness API",
  "why": "A first-party API to run and steer a coding agent (Claude Code, Codex, OpenCode…) inside the sandbox from outside:\n• Start it with a prompt, stream its events, send follow-ups, resume its conversations.\n• You don’t build and host your own relay between your app and the agent.\n• A plain “run this command” API doesn’t count: that still leaves the harness plumbing to you."
 },
 "own_agent_api": {
  "label": "hosted agent API (their own agent)",
  "why": null
 },
 "fast_boot": {
  "label": "fast boot (benchmarked)",
  "why": "Measured, not claimed: in the ComputeSDK sandbox benchmark, 100 sandboxes started at once and 95% were ready in under 2 seconds, with at least 95% of starts succeeding.\n• Matters when you fan out: RL rollouts, evals, parallel agents. Every second of boot is paid for and waited on, thousands of times.\n• Unbenchmarked providers show as not confirmed, not as slow."
 },
 "strong_isolation": {
  "label": "gVisor or VM (no shared kernel)",
  "why": "Not a plain container sharing the host’s Linux kernel with other customers:\n• In a container, one kernel bug (Dirty Pipe, runc “Leaky Vessels”…) is enough to break out to the host and its neighbours; Linux has hundreds of syscalls to attack.\n• gVisor answers syscalls with its own memory-safe kernel and only lets a small filtered set reach the host (Google runs untrusted customer code on it); a VM or microVM puts a hypervisor in the way.\n• This protects your agents from other tenants and the host. It doesn’t stop a hijacked agent from misusing what’s inside its own machine: for that, use a secret proxy and egress rules."
 },
 "ingress_rules": {
  "label": "inbound access rules",
  "why": "The provider controls who can reach the ports you expose:\n• Private or authenticated preview URLs, IP allowlists, security groups.\n• Without it, anything the agent starts on a public port is open to whoever finds the URL."
 },
 "guest_firewall": {
  "label": "firewall inside (nftables)",
  "why": "nftables / iptables work inside the machine (root plus its own kernel or network namespace):\n• The agent can set up networking the way it will run in production, or build and test firewall and network tools.\n• Not a security boundary: an agent with root can undo its own rules. To contain an agent, use provider-side egress rules."
 },
 "secret_proxy": {
  "label": "secret proxy",
  "why": "A proxy adds your credentials to outbound requests, so the real secret never enters the machine:\n• A prompt-injected or compromised agent can’t read or leak the key: it only ever sees a placeholder.\n• Some providers cover any HTTP API you register, others only model-provider (LLM) keys.\n• Database passwords and other non-HTTP secrets usually can’t be proxied this way."
 },
 "secret_proxy_any": {
  "label": "secret proxy for any API",
  "why": "A secret proxy that covers any HTTP API you register (GitHub, Stripe, your own services), not only LLM keys:\n• The agent calls those APIs normally; the proxy adds the real credential on the way out.\n• The secret never enters the machine, so a compromised agent can’t leak it."
 },
 "volume_attach": {
  "label": "extra volumes",
  "why": "Extra persistent volumes on top of the root disk:\n• Grow storage for datasets, caches and repositories without recreating the machine.\n• Detach a volume and attach it to another machine later."
 },
 "volume_shared": {
  "label": "shared volumes",
  "why": "One volume mounted by many machines at the same time:\n• Share a dataset, model weights or a build cache across the fleet instead of copying it into each machine.\n• Hand files between agents without going through object storage."
 }
}