# Nebius ConTree (Token Factory Sandboxes)

Official pricing: https://tokenfactory.nebius.com/sandboxes/about  
Category: agent-sandbox · Isolation: vm

## Pricing regimes (raw)

- **Sandboxes beta (free, per-command microVM executions)** (resource) [beta]

## Features

Yes: snapshots, fork/clone, persistent disk, idle auto-stop, custom image (Docker or snapshot), start from your own snapshot, your own Docker/OCI image, full VM (own kernel), root, egress allowlist, SOC 2, Python, Node.js, EU data residency, scoped API keys, MCP server, automatic snapshots, snapshots on demand, gVisor or VM (no shared kernel), firewall inside (nftables)

No: memory snapshots, pause/resume, volumes, ≥24 h sessions, Docker inside, nested virtualization, systemd, browser, desktop GUI, computer-use API, code interpreter, browser + desktop control, anti-bot stealth, CAPTCHA solving, residential IPs, preinstalled agents, SSH, public IPv4, HTTPS preview URLs, custom domains, raw TCP inbound, static egress IP, private networking, self-hosting, BYOC, open source, HIPAA, SSO, GPU, arm64, Windows, macOS, GPU desktop, credential injection, HTTP method/path egress rules, wake on request, live resize, live fork (no pause), memory fork, webhooks, agent harness API, hosted agent API (their own agent), inbound access rules, secret proxy, secret proxy for any API, extra volumes, shared volumes

Unknown: everything else. Evidence (source + quote) per feature: https://battleships.dev/data/providers/nebius-contree.json → feature_evidence

## Caveats

- Product is in BETA and FREE ('runs don't consume your credits'); rates of 0 reflect the beta, not a sustainable price. Post-beta pricing is unpublished; the homepage promises 'pay per execution, not idle' and the API returns a per-operation cost field.
- Execution model differs from long-lived sandboxes: each command is its own microVM; the filesystem (not memory/processes) is committed as an immutable image after every non-disposable run, and later commands branch from any image. No services, no inbound network, no SSH.
- No vCPU/RAM sizing in the API; the 4 vCPU/8 GiB workload shape cannot be requested. Writable layer default 12 GiB (included_disk_gib).
- Beta limits: 50 simultaneously running operations; untagged unreferenced images may be deleted after 180 days; access by application; no personal/sensitive data.
- max_session_h 1 is the per-operation timeout from the API spec example (3600 s); real limit unverified.
- The API spec's default base URL is now https://api.tokenfactory.nebius.com/sandboxes. Token Factory's own front-end config maps that host to eu-north1 (Finland), so EU is still the inference, and the docs still don't state a region. No region choice for Sandboxes.
- Outbound internet: API networking.enabled defaults true but the blog says it 'may depend on deployment configuration'; only on/off control (no allowlist).
- Nebius holds SOC 2 Type II / ISO 27001 at company level, but beta terms exclude sensitive data, so compliance flags are left null.
- Launched as ConTree early access 2026-02-19 (contree.dev blog); became Nebius Token Factory 'Sandboxes' beta 2026-05-19. SDK/CLI/MCP are Apache-2.0; service is closed.
- Free during beta; no paid rate published, so not priced.
- Re-checked 2026-09-28: tokenfactory.nebius.com/sandboxes/about and docs.tokenfactory.nebius.com/sandboxes/overview publish no rate (beta; pricing questions go to contree@nebius.com). Kept unpriced: free beta, not a missing number.
- The writable layer is configurable per execution (resources_limits.max_layer_bytes, default 12 GiB). CPU and RAM are still not selectable.
- A running operation's VM can host extra subprocesses (POST /operations/{id}/subprocesses) with stdin kept open, so one VM can serve several processes until the operation's timeout. The model is still batch-style: no inbound network, and only the filesystem persists.

## How this provider charges


ConTree comes from Nebius AI R&D. It is a VM-isolated execution service with Git-like branching: **each command runs in its own microVM**, and
the resulting filesystem is committed as an immutable image that later commands can branch from.
- Launched as early access on **2026-02-19** (https://contree.dev/blog/contree-eap-announcement/; first blog post 2026-01-12).
- Since **2026-05-19** it has been the **Sandboxes (Beta)** product inside Nebius Token Factory (https://contree.dev/blog/contree-joins-token-factory/).
- Launch channel was its own blog; no HN or Product Hunt post was found.

**Current price: free.** "Free while in beta — runs don't consume your credits" (https://tokenfactory.nebius.com/sandboxes/about).
No post-beta prices are published. The homepage says "Pay per execution, not idle", and each API operation result includes a `cost` field.

## Regime table

| Regime | When it applies | How billed | Numbers | Source |
|---|---|---|---|---|
| Sandboxes Beta | Nebius account + approved beta request | Free (list); runs don't consume Token Factory credits | $0; 50 simultaneously running operations (raisable on request) | https://tokenfactory.nebius.com/sandboxes/about, https://docs.tokenfactory.nebius.com/sandboxes/overview.md |
| Execution (non-disposable) | Default `POST /instances` | Free in beta; microVM exists only for the command; filesystem diff saved as a new image | Startup 0.4–2 s (cached rootfs); writable layer default 12 GiB; output capped at 10 MiB per stream | https://contree.dev/, https://eu-north.nebius.computer/static/api.yaml |
| Disposable execution | `disposable: true` | Free in beta; no snapshot stored | — | API spec |
| Image / checkpoint storage | Every non-disposable run | Free in beta | Untagged, unreferenced images may be deleted after 180 days | overview.md |
| Inspect (ls/cat/grep/download) | Browsing any image | "Zero compute cost" (no VM) | — | https://contree.dev/ |
| EAP (pre-May 2026) | Legacy ConTree tokens | Free early access; tokens valid until expiry | — | contree-joins-token-factory blog |
| Post-beta GA | Future | Unpublished ("pay per execution") | null | https://contree.dev/ |
| Egress | Outbound, if enabled | Not published | null | — |

## Gotchas

1. **It's a batch execution model, not a long-lived sandbox.** There are no inbound ports, SSH or services, and memory/processes are never preserved. Only the filesystem carries over between commands.
2. **You can't choose instance size.** The API has no vCPU/RAM parameters, so a 4 vCPU / 8 GiB workload shape can't be guaranteed.
3. **Beta limits:** 50 concurrent operations; access requires approval; no personal or sensitive data allowed; untagged images may be garbage-collected after 180 days.
4. **Every non-disposable run stores a diff snapshot.** It's free now but likely billable after beta. Use `disposable` for tests and linters.
5. **Per-operation timeout:** the API spec example shows a 3600 s maximum (token-level limit, unverified). Long agent sessions are chains of commands.
6. **Region is unclear.** The API spec is served from `eu-north.nebius.computer`; EU is inferred, not documented.

## Worked example

Workload: 4 vCPU / 8 GiB, 50 concurrent × 8 h/day × 22 days = **8,800 sandbox-hours**, 30% CPU, 50 GiB snapshots, 100 GiB egress.

- Closest analogue: 50 agents each running a chain of commands through an 8-hour shift. State persists as filesystem images, and compute is only consumed while commands run.
- Concurrency: 50 fits the beta limit of 50 simultaneous operations exactly.
- Size: 4 vCPU / 8 GiB cannot be requested, since the VM shape is platform-defined.
- Snapshots: every run's filesystem is kept as images. Storage is free in beta, and untagged images are garbage-collected after 180 days.

| Regime | Feasible? | Monthly total |
|---|---|---|
| Sandboxes Beta | Partly: concurrency 50 OK; shape not selectable; no services, inbound traffic or memory state; approval needed | **$0** (compute, snapshots). Egress price unpublished (treated as $0). |
| Post-beta | Unknown | **unknown** (pricing unpublished) |
