# Sandbox0

Official pricing: https://sandbox0.ai/pricing  
Category: agent-sandbox · Isolation: gvisor

## Pricing regimes (raw)

- **Sandbox0 Cloud, memory-only meter (CPU included)** (resource): $0/vCPU-h, $0.015/GiB-h
- **Managed Agents (Sandpi Platform): sandbox runtime free, pay model tokens + 5% top-up fee** (resource): $0/vCPU-h, $0/GiB-h [alt]

## Features

Yes: snapshots, fork/clone, pause/resume, persistent disk, idle auto-stop, ≥24 h sessions, custom image (Docker or snapshot), start from your own snapshot, your own Docker/OCI image, Docker inside, root, browser, desktop GUI, code interpreter, preinstalled agents, SSH, HTTPS preview URLs, egress allowlist, open internet, self-hosting, open source, Python, Node.js, credential injection, HTTP method/path egress rules, wake on request, live resize, live fork (no pause), memory fork, webhooks, audit logs, automatic snapshots, snapshots on demand, agent harness API, gVisor or VM (no shared kernel), inbound access rules, secret proxy, secret proxy for any API

No: memory snapshots, volumes, full VM (own kernel), nested virtualization, computer-use API, browser + desktop control, anti-bot stealth, CAPTCHA solving, residential IPs, public IPv4, raw TCP inbound, static egress IP, BYOC, SOC 2, HIPAA, SSO, GPU, arm64, Windows, macOS, GPU desktop, EU data residency, MCP server, hosted agent API (their own agent), fast boot (benchmarked), firewall inside (nftables), extra volumes, shared volumes

Unknown: everything else. Evidence (source + quote) per feature: https://battleships.dev/data/providers/sandbox0.json → feature_evidence

## Caveats

- CPU is not billed and not user-settable: it is derived from the memory limit by an unpublished ratio. ram_per_vcpu [2,null] is inferred (vendor comparison row 2 vCPU/4 GiB, DAX host view 8 CPU/16 GiB); if the real ratio gives fewer vCPU per GiB, a CPU-hungry workload needs more memory and costs more.
- Egress is free 'for now' (explicitly temporary); ingress and object-store GET/PUT free.
- Persistent rootfs and rootfs snapshots are billed as byte-time at $0.02/GiB-month prorated hourly over 730 h, whether the sandbox is running or paused. Default rootfs size 8 GiB (300 MiB-1 TiB); whether billing is on provisioned size or bytes written is not stated (engine uses workload disk/snapshot GiB). Experimental memory-pause checkpoints: storage billing not documented.
- Default quota 20 running sandboxes per team; increases free on request but subject to approval.
- Top-up funded: running sandboxes auto-pause (filesystem-only, processes lost) when unpaid usage reaches 10% of the last top-up.
- Burst start at 100 concurrent is slow (median ~14.9 s, ComputeSDK score 0) although single cold start is ~0.8 s.
- Self-hosting: Apache-2.0 core on your own Nomad + PostgreSQL + S3, no licence fee published and no paid support/enterprise tier found; cost = your own infra (not modelled).
- Managed Agents (Sandpi Platform) mode excludes LLM token spend and the 5% top-up fee, which the engine does not model.
- Regions not published (docs examples use aws-us-east-1); no GPUs, no public IPv4, no free tier or credits found.
- vCPU derivation re-checked 2026-09-28: template docs say "CPU is platform-derived from memory and is intentionally absent from the public API" (ratio unpublished); the vendor's own comparison table on sandbox0.ai/pricing lists Sandbox0 allocation as "2 vCPU / 4 GiB" at $10.95 per GiB-month, which supports ram_per_vcpu [2,null] (a 4 vCPU request is billed as 8 GiB). Compute shows $0 because the only meter is memory; the whole bill is in the memory line.

## How this provider charges


Sandbox0 bills **memory only**. There is no CPU line: compute is $0.015 per GiB-hour of the configured memory limit,
per second, and CPU is "platform-derived from memory" by an unpublished ratio. Persistent rootfs and rootfs snapshots
cost $0.02/GiB-month as byte-time. Network and object-store requests are $0 ("egress free for now"). There is no plan
fee and no published free credit. Beyond the cloud meter there are two other regimes: the Apache-2.0 self-hosted runtime
(your own infra, no licence fee found), and Managed Agents (Sandpi Platform), where the sandbox is free and you pay model
tokens plus a 5% top-up fee.

Base rate: $0.015/GiB-h (≈$0.000004167/GiB-s). 4 vCPU / 8 GiB = 8 × 0.015 = **$0.12/h**, assuming a 4-vCPU
allotment at 8 GiB (inferred, see Gotchas).

## Regime table

| Regime | When it applies | How billed | Numbers | Source |
|---|---|---|---|---|
| Cloud pay-as-you-go (running) | Default; sandbox running | Configured memory limit × wall-clock seconds; CPU not billed; no 1 h minimum, no start fee | $0.015/GiB-h; $0 per vCPU | https://sandbox0.ai/pricing |
| Top-up funding / debt auto-pause | All cloud accounts | Account funded by top-ups; running sandboxes are **auto-paused** (filesystem-only) once unpaid usage reaches 10% of the last successful top-up | Top-up minimum unpublished | https://sandbox0.ai/docs/sandbox/pause-resume.md |
| Paused (filesystem-only, default) | `pause`, `ttl` expiry, billing pause | Compute stops; RootFS kept and billed as storage; processes/memory lost | $0 compute + $0.02/GiB-mo | https://sandbox0.ai/pricing, pause-resume doc |
| Paused with memory (experimental) | `memory: true` on supporting deployments | Compute stops; storage billing of the memory checkpoint not documented | null | pause-resume doc |
| `hard_ttl` expiry | Hard timeout set | Sandbox identity and RootFS deleted → all billing stops | $0 after | pause-resume doc |
| Persistent rootfs | Always, running or paused | Byte-time, prorated hourly over a 730 h month; default rootfs 8 GiB (300 MiB–1 TiB) | $0.02/GiB-mo | https://sandbox0.ai/pricing, template/configuration.md |
| Rootfs snapshots / forks | Named snapshots, CoW forks | Same byte-time meter as rootfs; each fork is a new sandbox billed on its memory | $0.02/GiB-mo | https://sandbox0.ai/pricing |
| Network + requests | Ingress, egress, object-store GET/PUT | Free; egress explicitly "for now" | $0 | https://sandbox0.ai/pricing |
| Default quotas | Every team | Admission limits, not billing; increases free on request (approval needed) | 20 running sandboxes (paused don't count), 5 claims/s, 100 API req/s (burst 200) | https://sandbox0.ai/pricing |
| Managed Agents (Sandpi Platform) | Hosted agent runs (Codex, Claude Code, Pi, Kimi Code, ZCode) | Sandbox runtime not charged; model tokens at provider rates from prepaid credit; 5% fee on each top-up | $0 sandbox; +5% on top-ups | https://sandbox0.ai/managed-agents |
| Self-hosted (open source) | Run the Apache-2.0 runtime on your own Nomad + PostgreSQL + S3 | No licence fee or paid tier found; you pay your own infra | $0 licence | https://github.com/sandbox0-ai/sandbox0, https://sandbox0.ai/docs/sandbox/self-hosted.md |

No dated price changes found; the pricing page's competitor table is marked "checked 2026-09-21".

## Gotchas

1. **CPU isn't billed, but you can't pick it either.** CPU comes from the memory limit by an unpublished ratio. The vendor's
   comparison uses 2 vCPU / 4 GiB, and the ComputeSDK DAX run saw 8 CPUs / 16 GiB, which suggests about 1 vCPU per 2 GiB
   (inferred, not documented). A CPU-heavy, memory-light workload may need to buy memory just to get cores.
2. **Idle running time costs full price.** Billing is on the configured memory limit, not on usage. Set `ttl` so idle sandboxes auto-pause.
3. **Default pause loses processes.** Filesystem-only pause is the default. Memory pause is experimental.
4. **Storage bills in every state.** Rootfs and snapshots accrue $0.02/GiB-mo until `hard_ttl` or delete. It isn't stated whether
   the default 8 GiB rootfs bills on provisioned size or on bytes written.
5. **Egress is free "for now"**, which leaves room for a future charge.
6. **Top-up debt auto-pauses production.** Once unpaid usage reaches 10% of your last top-up, running sandboxes pause.
7. **Default concurrency is only 20.** Raising it is free but needs approval.
8. **Bursts are slow.** ComputeSDK median time-to-interactive for a 100-sandbox burst was about 14.9 s (score 0), against a ~0.8 s single cold start.
9. **There is no free tier or credit** on the cloud.
10. **Managed Agents "free sandbox"** only covers runs on Sandpi. You still pay LLM tokens plus 5%.

## Worked example

Workload: 4 vCPU / 8 GiB, 50 concurrent × 8 h/day × 22 days = **8,800 sandbox-hours**, 30% CPU, 50 GiB snapshots,
100 GiB egress. Sandboxes paused between shifts.

- Compute: 8,800 h × 8 GiB × $0.015 = **$1,056.00**. The 30% CPU figure changes nothing because billing is on the memory limit.
- Snapshots/rootfs: 50 GiB × $0.02 = **$1.00**. If each sandbox's default 8 GiB rootfs is also billed on provisioned size,
  add 50 × 8 GiB × $0.02 = $8.00.
- Egress: 100 GiB × $0 = **$0** (current promotional rate).

| Regime | Feasible? | Monthly total |
|---|---|---|
| Cloud PAYG | Yes, after a free quota increase (50 > 20 default) | **$1,057.00** (up to $1,065.00 with rootfs on provisioned size) |
| Cloud, left running idle 24 h/day instead of pausing | Yes | 50×24×22×$0.12 + $1 = **$3,169.00** |
| Managed Agents (Sandpi) | Only if the workload is agent runs on their harnesses | $0 sandbox + LLM tokens + 5% top-up fee |
| Self-hosted | Yes | $0 licence + your own servers, S3 and ops |
