# OpenAI Containers (Code Interpreter / Hosted Shell)

Official pricing: https://developers.openai.com/api/docs/pricing  
Category: agent-sandbox · Isolation: vm

## Pricing regimes (raw)

- **Responses API container (Code Interpreter / Hosted Shell), per minute with 5-min minimum** (sizes): memory_limit 1g ? vCPU/1 GiB $0.09/h; memory_limit 4g ? vCPU/4 GiB $0.36/h; memory_limit 16g ? vCPU/16 GiB $1.44/h; memory_limit 64g ? vCPU/64 GiB $5.76/h
- **Agents API OpenAI-hosted sandbox (public beta), small/medium/large at container rates** (sizes): small 1 vCPU/1 GiB $0.09/h; medium (default) 2 vCPU/4 GiB $0.36/h; large 4 vCPU/16 GiB $1.44/h [beta]
- **Codex Cloud task VM (bundled in ChatGPT seat; tokens/credits only)** (sizes): Plus / Edu Plus task VM 2 vCPU/8 GiB $null/h; Pro / Business / Enterprise / Edu task VM 4 vCPU/16 GiB $null/h [alt]
- **ChatGPT agent mode / Work cloud browser (per message, credits)** (sizes): cloud computer + browser (size unpublished) ? vCPU/? GiB $null/h [alt]

## Features

Yes: idle auto-stop, ≥24 h sessions, full VM (own kernel), browser, desktop GUI, computer-use API, code interpreter, browser + desktop control, egress allowlist, self-hosting, SOC 2, HIPAA, SSO, Python, Node.js, Go, Java, credential injection, EU data residency, agent harness API, gVisor or VM (no shared kernel), secret proxy, secret proxy for any API

No: snapshots, memory snapshots, fork/clone, pause/resume, persistent disk, volumes, custom image (Docker or snapshot), start from your own snapshot, your own Docker/OCI image, Docker inside, nested virtualization, root, anti-bot stealth, CAPTCHA solving, residential IPs, preinstalled agents, SSH, public IPv4, HTTPS preview URLs, custom domains, raw TCP inbound, open internet, static egress IP, private networking, BYOC, open source, GPU, arm64, Windows, macOS, GPU desktop, HTTP method/path egress rules, wake on request, live resize, live fork (no pause), memory fork, MCP server, automatic snapshots, snapshots on demand, hosted agent API (their own agent), inbound access rules, firewall inside (nftables), extra volumes, shared volumes

Unknown: everything else. Evidence (source + quote) per feature: https://battleships.dev/data/providers/openai-containers.json → feature_evidence

## Caveats

- Model input/output tokens are billed separately and are not in this estimate; for short runs they often exceed container cost.
- vCPU per Responses container tier is not published; the engine matches container-session on RAM only. The Agents API beta mode publishes 1/2/4 vCPU for 1/4/16 GB at the same rates (suggestive, not confirmed for Responses containers). 64 GB tier vCPU unknown.
- Per-minute billing with 5-minute minimum applies to 'eligible' sessions since 2026-06-02 ('eligible' undefined); 2026-03-31 to 2026-06-01 each session was billed in full 20-minute blocks; before that $0.03-$1.92 per container.
- Whether idle minutes until the 20-minute expiry are billed is undocumented; delete containers explicitly (DELETE /v1/containers/{id}). See knob idle_expiry_tail.
- No snapshots or persistence: an expired container's data is 'discarded â€¦ not recoverable'. No documented max lifetime; keeping a container alive requires touching it at least every 20 minutes (or a larger expires_after.minutes, max undocumented).
- Outbound network is disabled by default; enabling requires an admin-configured org allow list plus a per-request network_policy allowlist. domain_secrets inject credentials via a sidecar. No inbound ports/URLs.
- Only rate limit published: Code Interpreter '100 RPM per org'. No container concurrency cap, no usage-tier table, nothing for hosted shell.
- Disk size of containers not published ('ephemeral block storage').
- Isolation: documented only as 'a fully sandboxed virtual machine'; hypervisor (gVisor/Firecracker/etc.) not named.
- EU/US regional processing documented for the Code Interpreter tool; hosted shell not listed separately; whether the 10% data-residency uplift applies to containers is unknown.
- Agents API hosted sandbox (beta mode): US-only data residency, no ZDR, 1-hour non-configurable keep-alive expiry; billing granularity inferred from the container rate card.
- Codex Cloud and ChatGPT agent mode (alt modes) have no compute price: compute is bundled into ChatGPT seats and consumed as token credits (~$0.04/credit derived) under unpublished 5-hour/weekly limits; no public API, so not a substitute for a programmable sandbox.
- Assistants API code interpreter ($0.03/session, 1-hour session) shut down 2026-08-26; not modelled.
- soc2/hipaa/sso left null: not re-verified in this pass (previous card had soc2 true).

## How this provider charges


OpenAI runs code for agents in several places. Only the API containers have a published compute price; the rest are bundled into ChatGPT plans or run on your own compute.

| Regime | When it applies | How billed | Numbers | Source |
|---|---|---|---|---|
| Container session (Code Interpreter, Hosted Shell) | Responses API tools | Per minute with a 5-minute minimum for "eligible" sessions (since 2026-06-02); otherwise per 20-minute session | 1 GB $0.03, 4 GB $0.12, 16 GB $0.48, 64 GB $1.92 per 20 min = $0.09 / $0.36 / $1.44 / $5.76 per hour | https://developers.openai.com/api/docs/pricing |
| Agents API hosted sandbox (public beta since 2026-09-10) | `environment: openai_hosted` in the Agents API (`OpenAI-Beta: agents=v1`) | "Standard container rates" | small 1 vCPU / 1 GB, medium 2 vCPU / 4 GB (default), large 4 vCPU / 16 GB: the only published vCPU figures for OpenAI containers | https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted |
| Codex Cloud tasks | ChatGPT plans, no API key access | Seat + usage credits, no compute charge | Task VM 2 vCPU / 8 GiB / 8 GiB disk on Plus; 4 vCPU / 16 GiB / 32 GiB on Pro, Business, Enterprise, Edu; state kept up to 7 days | https://learn.chatgpt.com/docs/pricing |
| ChatGPT agent mode | ChatGPT plans | Credits per message | Cloud computer + browser, size unpublished; no API | ChatGPT plan pages |
| Model tokens | always | per token | model-specific, usually more than the compute | https://developers.openai.com/api/docs/pricing |

## Gotchas
- Memory is the only size setting for API containers; vCPU and disk per tier are not published (the Agents API sizes are the only official vCPU numbers).
- A container expires 20 minutes after its last activity; any API call refreshes it, so long sessions are possible with keep-alive calls. Whether the idle minutes before expiry are billed is not published.
- An Agents API sandbox is deleted after about 1 hour without activity (not configurable). No snapshots, no pause/resume, no custom images; setup reruns every session.
- Outbound network is off by default and needs an org allowlist; secrets can be injected per allowed domain. No inbound access. Debian 12, no sudo.
- The Agents API is US-only and has no Zero Data Retention; Code Interpreter runs in the US or EU.
- The Agents SDK's own sandboxes run on your machine or on other providers (E2B, Modal, Daytona...): OpenAI sells no compute there. The Assistants API code interpreter was removed on 2026-08-26.
- Code Interpreter is limited to 100 requests per minute per organization; no concurrency cap is published.

## Worked example
200k one-minute runs, each in a fresh 1 GB container: 200k x 5 min x $0.0015/min = $1,500. Packed 50 runs per container (50 min each): 4,000 x 50 min x $0.0015 = $300. 100 agents x 8 h on the 4 GB tier: 800 h x $0.36 = $288 a day, before model tokens.

Sources: https://developers.openai.com/api/docs/pricing, https://developers.openai.com/api/docs/guides/tools/code-interpreter, https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted, https://learn.chatgpt.com/docs/pricing
