# Vercel Sandbox

Official pricing: https://vercel.com/docs/sandbox/pricing  
Category: agent-sandbox · Isolation: firecracker

## Pricing regimes (raw)

- **On-demand, iad1 / cle1 / pdx1 (base rate)** (resource): $0.128/vCPU-h, $0.0212/GiB-h
- **Region pinned: bom1 (Mumbai)** (resource): $0.14/vCPU-h, $0.0232/GiB-h
- **Region pinned: yul1 (Montreal)** (resource): $0.147/vCPU-h, $0.0243/GiB-h
- **Region pinned: sin1 (Singapore) / arn1 (Stockholm)** (resource): $0.16/vCPU-h, $0.0266/GiB-h
- **Region pinned: dub1 (Dublin)** (resource): $0.168/vCPU-h, $0.0278/GiB-h
- **Region pinned: icn1 (Seoul)** (resource): $0.169/vCPU-h, $0.028/GiB-h
- **Region pinned: hkg1 (Hong Kong)** (resource): $0.176/vCPU-h, $0.0292/GiB-h
- **Region pinned: lhr1 (London) / cdg1 (Paris)** (resource): $0.177/vCPU-h, $0.0292/GiB-h

## Features

Yes: snapshots, fork/clone, pause/resume, persistent disk, volumes, ≥24 h sessions, custom image (Docker or snapshot), start from your own snapshot, your own Docker/OCI image, full VM (own kernel), Docker inside, root, preinstalled agents, SSH, HTTPS preview URLs, egress allowlist, open internet, static egress IP, private networking, SOC 2, HIPAA, SSO, Python, Node.js, credential injection, HTTP method/path egress rules, live resize, live fork (no pause), EU data residency, spend limits, MCP server, automatic snapshots, snapshots on demand, fast boot (benchmarked), gVisor or VM (no shared kernel), inbound access rules, firewall inside (nftables), secret proxy, secret proxy for any API, extra volumes, shared volumes

No: memory snapshots, idle auto-stop, nested virtualization, browser, desktop GUI, computer-use API, code interpreter, browser + desktop control, anti-bot stealth, CAPTCHA solving, residential IPs, public IPv4, raw TCP inbound, self-hosting, BYOC, open source, GPU, arm64, Windows, macOS, GPU desktop, wake on request, memory fork, agent harness API, hosted agent API (their own agent)

Unknown: everything else. Evidence (source + quote) per feature: https://battleships.dev/data/providers/vercel-sandbox.json → feature_evidence

## Caveats

- Memory is billed on provisioned size for the whole session wall-clock (idle included); only CPU is active-billed. There is no idle auto-stop: sessions run until the timeout (default 5 min, extendable to plan max) or stop().
- Regional rates taken from the regionalPricing data embedded in the pricing page (fetched 2026-09-28); per-region data-transfer and drive rates also differ, but the card network block uses iad1 ($0.15/GB).
- Hobby included_usd (12.55) is a dollar-equivalent of unit quotas at iad1 rates; Hobby cannot incur overage (hard stop), and the 15 GB snapshot quota is lifetime, not monthly.
- Pro egress: free 1,000 GiB is the Flat Rate CDN included tier, shared with the team's CDN/Fast Data/Blob transfer; beyond it Vercel moves you to a higher tier ($20/mo for 50 TB) the next cycle rather than per-GB. egress_gib 0.15 is the on-demand/Enterprise iad1 rate. Enterprise has no free bundle.
- Exposed-port traffic is billable in both directions; downloads from the internet are free since 2026-07-17.
- Persistence is on by default: every stop creates a new filesystem snapshot ($0.08/GB-month, daily-average metering since 2026-08-31) that expires 30 days after last use by default and survives sandbox deletion. Without keepLastSnapshots {count:1} retained GiB can be many times the live filesystem size. Whether snapshot size is full, incremental or compressed is undocumented.
- Active CPU metering granularity is unpublished (granularity_s null). min_billed_seconds 60 applies to provisioned memory only (1-minute minimum increments per session).
- Max session 24 h (Pro/Ent; 5 h before 2026-06-16), 45 min Hobby; sessions resume automatically from snapshot, but processes/memory are lost on every restart.
- Pro $20 credit is shared with other Vercel usage (Functions, CDN, etc.), so it may not be available to Sandbox.
- Spend management is soft; its only automatic action pauses production deployments, and docs do not state that it stops running sandboxes. Checks run every few minutes.
- Enterprise platform fee, discounts and commitment minimums are unpublished.
- Drives (beta): $0.05/GB-month logical used size + $0.0015/GB reads + $0.004/GB writes in iad1 (regional); not modelled in the card.
- No dedicated public IPv4; static egress IPs only via Enterprise Secure Compute. 'ssh' is the CLI 'sandbox connect' shell over the Vercel API, not a real sshd.
- open_source=false refers to the platform; the SDK, CLI and managed image Dockerfiles are open source.
- No hpc CPU benchmark available for Vercel (cpu_runs_s null); computesdk dax env reported 8 logical CPUs / 16.25 GiB.
- Verifier 2026-09-28: Hobby plan set trial_only (engine skips it): it is a hard-capped, non-commercial free allotment with no pay-as-you-go overage, so it cannot be the cheapest 'plan' for a paid workload. Small workloads that fit entirely inside the Hobby quotas would cost $0 there.
- vCPU allocation-rate quotas (Hobby 20-40 vCPU/min; Pro/Enterprise 150 vCPU/min ramping +500/min to 5,000/min) and the 20/s deletion quota are not modelled (https://vercel.com/docs/sandbox/pricing).
- Engine applies min_billed_seconds=60 to CPU as well as memory; Vercel documents the 1-minute minimum for provisioned memory only, so very short sessions are slightly overestimated.
- Per-region data transfer and drive charges differ even where CPU/RAM are equal (e.g. transfer cpt1 $0.28, icn1 $0.35, gru1 $0.22, bom1 $0.20, hkg1/kix1/hnd1/sin1/syd1 $0.16 vs $0.15/GB elsewhere; drive $0.05-$0.0891/GB-month; reads $0.0015-0.0021/GB, writes $0.004-0.0056/GB). The card applies the $0.15/GB base rate to every region mode; drive storage/IO is not modelled and is separate from snapshot $0.08/GB-month. Calculator check of all 19 regions matched the docs table (patch v5-calculators, 2026-09-28).
- Retained state: the 2026-03-26 persistent-sandboxes beta post says automatically persisted state on stop "is not charged"; the current pricing page bills Snapshot Storage at $0.08/GB-month for snapshots (explicit snapshots page) and does not say whether automatic persistence is billed. The card applies $0.08 to all retained state (conservative); automatic persistence may be free. Network: downloads from the internet are free, but outbound data AND all traffic to/from exposed ports (requests and responses) are billable. Memory rate history: $0.0106/GB-h on 2026-01-20, $0.0212 by 2026-02-12 (exact day unknown). (patch v8-history, re-checked vercel.com/docs/sandbox/pricing and the changelog 2026-09-28)
- Re-verified 2026-09-28 (https://vercel.com/docs/sandbox/pricing, last_updated 2026-09-10): max session duration Hobby 45 min, Pro 24 h, Enterprise 24 h (changelog "Vercel Sandbox can now run for up to 24 hours" replaced the old 5 h cap); the limit is per session and resets on stop/resume. Pro max_session_h 24 is correct.
- Features check 2026-09-28: nested_virt null -> false. Docs: "Each sandbox runs in its own Firecracker microVM with a dedicated kernel" (vercel.com/docs/sandbox/concepts); Firecracker test_nv.py asserts guests have no nested virtualization (/dev/kvm absent).
- Resolved 2026-09-29: automatic persistence snapshots ARE billed as Snapshot Storage ($0.08/GB-month); the earlier 'automatic persistence may be free' uncertainty (2026-03-26 beta post) is superseded by the current persistent-sandboxes doc. snapshot_gib_month 0.08 applies to all retained state.
- Fork semantics: Sandbox.fork() of a running source forks its latest saved snapshot, not live memory (memory_snapshot_fork false confirmed; fork_running stays null because the live state is not carried).

## How this provider charges


As of 2026-09-28. Primary source: https://vercel.com/docs/sandbox/pricing (last_updated 2026-09-10). The per-region rates come from the page's embedded `regionalPricing` data, saved to `research/raw/vercel_com_docs_sandbox_pricing_regional.txt`. The page only shows them behind a region selector and doesn't render them as text.

The model has two meters. **CPU is billed only while it is actively executing.** I/O waits and LLM waits are free. The rate is $0.128 per vCPU-hour in iad1, which is high. **Memory is billed on the provisioned size for the whole wall-clock session**, with a 1-minute minimum increment. RAM is fixed at 2 GB per vCPU. Everything else is metered on top: creations, data transfer, snapshots, and drives. Rates depend on the region you pin.

## Regime table

| # | Regime | When it applies | How billed | Numbers | Source |
|---|---|---|---|---|---|
| 1 | **Hobby free allotment** | Hobby plan ($0). Only one Hobby team per account | Unit quotas, not dollars. **Hard stop, no overage:** once any quota is exceeded, sandbox creation is paused "until 30 days have passed since you first used the feature" | 5 Active-CPU h, 420 GB-h memory, 5,000 creations and 20 GB transfer per month. 15 GB snapshot and 15 GB drive storage for the **lifetime** of the account, plus 30 GB drive reads and 30 GB drive writes per month. Max 4 vCPU / 8 GB, 10 concurrent, **45-min sessions**, vCPU allocation rate 20→40/min | https://vercel.com/docs/sandbox/pricing |
| 2 | **Pro on-demand (iad1 / cle1 / pdx1 base)** | Pro plan in the three cheapest regions | Active CPU per vCPU-h, plus provisioned memory per GB-h | $0.128 per Active-CPU-h and $0.0212 per GB-h. A 4 vCPU / 8 GB sandbox costs $0.6816/h at 100% CPU, **$0.1696/h when idle but running**, and $0.2208/h at Vercel's own 10%-utilisation assumption | same |
| 3 | **Pro platform fee as credit** | Pro | $20/mo platform fee includes $20/mo usage credit that applies across **all** Vercel products (Functions, CDN, Blob…). The credit expires at month end with no rollover. Usage beyond it is billed on demand | Fee $20, credit $20, 1 deploying seat included. Extra deploying seats cost $20/mo each; viewer seats are free | https://vercel.com/docs/plans/pro-plan |
| 4 | **Regional price tiers** | Any sandbox pinned to a non-base region. Region is chosen per sandbox or as a project default. There are 19 regions | CPU, memory, data transfer and drive rates all vary by region. Creations and snapshot storage are the same everywhere | CPU / memory ranges from **$0.128 / $0.0212** (iad1, cle1, pdx1) to **$0.221 / $0.0366** (gru1), which is ×1.73. Others: bom1 0.140/0.0232, yul1 0.147/0.0243, sin1 and arn1 0.160/0.0266, dub1 0.168/0.0278, icn1 0.169/0.0280, hkg1 0.176/0.0292, lhr1 and cdg1 0.177/0.0292, sfo1 0.177/0.0294, syd1 0.180/0.0298, fra1 0.184/0.0304, cpt1 0.200/0.0332, kix1 and hnd1 0.202/0.0334 | raw regional dump; https://vercel.com/docs/sandbox/pricing#regional-pricing |
| 5 | **Active CPU vs provisioned memory split** | Always | CPU: time actually executing, excluding I/O wait. Memory: GB × wall-clock hours of the session, **idle included** | Metering granularity for Active CPU is not published. Memory has a 1-minute minimum per session ("to account for sandbox lifecycle management") | https://vercel.com/docs/sandbox/pricing#provisioned-memory |
| 6 | **Idle-but-running session** | Session open while the agent waits (LLM calls, user think-time) until timeout or `stop()` | Memory only. There is **no idle auto-stop**: the session runs until its wall-clock timeout (default 5 min, extendable up to the plan maximum) | 4 vCPU / 8 GB: $0.1696/h in iad1, $0.2352/h in sfo1 | https://vercel.com/kb/guide/vercel-sandbox-duration-and-persistence |
| 7 | **Stopped, persistent (default)** | After `stop()` or timeout on a persistent sandbox | No compute. The filesystem is auto-snapshotted and billed as snapshot storage | $0.08/GB-month, the same in all regions. Since 2026-08-31 it is computed from each day's average usage | https://vercel.com/docs/sandbox/concepts/persistent-sandboxes ; https://vercel.com/changelog/vercel-sandbox-now-calculates-snapshot-storage-costs-daily |
| 8 | **Stopped, non-persistent** | `persistent:false` / `--non-persistent` | $0. The filesystem is discarded, and the sandbox object is removed after 14 days of inactivity | $0 | https://vercel.com/docs/sandbox/concepts/persistent-sandboxes |
| 9 | **Snapshot retention** | Every automatic stop-snapshot and every manual `snapshot()` | Each stop creates a **new** snapshot. Snapshots expire 30 days after last use by default and can be set to never expire. `keepLastSnapshots` (1–10) bounds how many are kept. **Snapshots survive sandbox deletion and keep billing.** They are region-bound | $0.08/GB-month. Whether size is billed as full, incremental or compressed is **not documented** | https://vercel.com/docs/sandbox/concepts/snapshots |
| 10 | **Creation fee** | Every `Sandbox.create()`. Resuming a persistent sandbox (a new session) is **not** a creation | Per call | $0.60 per 1M ($0.0000006 each). Hobby: 5,000/month | https://vercel.com/docs/sandbox/pricing#sandbox-creations |
| 11 | **Data transfer: Hobby** | Hobby | Included quota, then hard stop | 20 GB/month | pricing page |
| 12 | **Data transfer: Pro via Flat Rate CDN** | Pro (Flat Rate CDN enabled). Sandbox transfer is covered by the tier | The capacity tier is **shared with CDN requests, Fast Data Transfer and Blob transfer**. Exceeding it moves you to a higher tier **starting next cycle**, and a one-day spike does not trigger an upgrade. Fair-use rules apply: bulk transfer is out of scope | Included tier: 1 TB + 1M CDN requests. Paid tiers: $20/mo (10M requests, 50 TB), $100/mo (50M, 50 TB), $300/mo (150M, 50 TB). Above the top tier, or if Flat Rate CDN is disabled, you pay the on-demand regional rate | https://vercel.com/docs/pricing/flat-rate-cdn |
| 13 | **Data transfer: Enterprise / on-demand** | Enterprise, or Pro with Flat Rate CDN off | Per GB outbound to the internet, **plus both directions of exposed-port traffic**. Downloads from the internet have been free since 2026-07-17 | iad1 $0.15/GB. Other regions: cpt1 $0.28, gru1 $0.22, bom1 $0.20, icn1 **$0.35**, and several at $0.16 | pricing page; https://vercel.com/changelog/data-downloaded-by-vercel-sandbox-is-now-free |
| 14 | **Drives (public beta)** | Optional persistent network storage, up to 4 per sandbox | Storage is billed hourly on **logical used size** (not provisioned size), plus per-GB reads and writes. Rates are regional | iad1: $0.05/GB-month, reads $0.0015/GB, writes $0.004/GB. gru1: $0.0891, $0.0021 and $0.0056 | pricing page; raw regional dump |
| 15 | **Secure Compute (static egress IP / VPC)** | Enterprise only. Pricing is "contact account team" | Sandbox attached via `networkId`. Internet-bound traffic is billed as Private Data Transfer. Traffic over VPC peering is free | Private Data Transfer $0.15/GB (iad1; $0.16 in sfo1). The network fee is unpublished | https://vercel.com/docs/sandbox/concepts/secure-compute ; https://vercel.com/docs/networking/secure-compute |
| 16 | **Enterprise (incl. Flexible Commitment)** | Contract | Same published unit rates as Pro. Custom quotas and platform fee. Flex Commitment is a prepaid balance (units worth $1) that usage draws down | Platform fee, discount and minimum unpublished. Max 32 vCPU / 64 GB, 10,000 concurrent (more via sales), control plane 100k req/min | https://vercel.com/docs/pricing/flex-commit |
| 17 | **Session cap / long-running** | Pro/Enterprise sessions > 24 h. The cap was 5 h before 2026-06-16 | Hard stop at the cap. A new session auto-resumes from the snapshot on the next SDK call. Processes are lost, and you pay for a snapshot plus a reboot | 24 h per session (Hobby 45 min). Sandbox lifetime is unbounded | https://vercel.com/changelog/vercel-sandbox-can-now-run-for-up-to-24-hours |
| 18 | **Spend management** | Pro and Enterprise Flex | **Soft by default.** Alerts at 50/75/100%. New customers get notifications at $200/cycle by default. The optional action is "Pause Production Deployments", checked every few minutes. Docs **do not say it stops running sandboxes or blocks sandbox creation** | none | https://vercel.com/docs/spend-management |

Plan sizing rules. vCPUs can be 1 or an even number from 2 to 32. Memory is always 2 GB per vCPU and cannot be chosen separately. Disk is a fixed 64 GB NVMe at no charge (32 GB on deprecated runtimes). Maximum size is 4 vCPU on Hobby, 8 on Pro and 32 on Enterprise. vCPU allocation rate on Pro and Enterprise starts at 150/min and ramps +500/min up to 5,000/min; it resets after 10 idle minutes.

## Gotchas

1. **Memory, not CPU, dominates for agent workloads.** At 30% CPU utilisation, memory is 52% of the compute bill for a 4 vCPU / 8 GB sandbox ($0.1696/h against $0.1536/h of CPU). An idle session still costs $0.17/h, and nothing stops it except the timeout. "Active CPU pricing" does not make idle sandboxes free.
2. **Active CPU is expensive per unit.** $0.128/vCPU-h is about 2.5× E2B's allocated rate. Once CPU utilisation goes above roughly 40%, active-CPU billing loses its edge. At 100% CPU a 4 vCPU / 8 GB sandbox costs $0.68/h.
3. **Region pinning costs up to 73% more.** gru1 is 1.73× iad1 on both CPU and memory. EU regions (fra1, cdg1, lhr1, dub1, arn1) cost 1.25–1.44× iad1. Snapshots are region-bound, and failover loads them cross-region.
4. **Persistence is on by default, and every stop mints a new snapshot.** Without `keepLastSnapshots: {count: 1}`, snapshots accumulate for 30 days after last use. **They survive sandbox deletion and keep billing.** Deleting sandboxes does not stop snapshot charges. Whether a snapshot is billed at full or incremental size is undocumented.
5. **Pro egress "included" is really the Flat Rate CDN tier.** The 1 TB is shared with your website's CDN traffic. Exposed-port traffic counts **in both directions**, so a preview server's inbound requests are billable. Overshooting moves you up a tier **the next month** ($20 for 50 TB). Enterprise pays $0.15–0.35/GB with no bundle.
6. **Hobby is a hard wall, not a trial credit.** Once any quota is exceeded, creation stops for the rest of the 30-day window. The limits are a 45-minute session cap, 10 concurrent sandboxes and only 5 CPU-hours a month. There is no pay-as-you-go option on Hobby.
7. **The Pro $20 credit is shared with the rest of Vercel.** If your site uses Functions or CDN, the credit may already be gone before any sandbox runs.
8. **The spend cap is not a sandbox kill-switch.** "Pause Production Deployments" pauses production deployments. Docs don't say it stops running sandboxes, and the check runs every few minutes.
9. **The 24-hour session cap forces a daily reboot of long-lived agents.** Memory and processes are lost, and each restart writes another snapshot. Before June 2026 the cap was 5 h.
10. **The 1-minute memory minimum** makes very short runs slightly more expensive: a 5-second run is billed 60 s of memory. The metering granularity of Active CPU is not published.
11. **Regional CPU/memory ratios aren't uniform.** sfo1 memory is ×1.387 while CPU is ×1.383, and CPU and memory are each rounded per region. Use the exact table rather than a single multiplier.

## Worked example

The workload is 4 vCPU / 8 GiB, 50 concurrent sandboxes × 8 h/day × 22 days. That gives **8,800 sandbox-hours**, 30% CPU utilisation, 50 GiB of retained snapshots and 100 GiB of egress.

- Active CPU = 8,800 h × 4 vCPU × 0.30 = **10,560 vCPU-h**
- Memory = 8,800 h × 8 GB = **70,400 GB-h**. Sessions are 8 h, so the 1-minute minimum doesn't matter.
- An 8 h session is under Pro's 24 h cap, so no restarts are needed. On Hobby it is impossible: the 45 min cap would force 11 restarts per session, only 10 concurrent sandboxes are allowed, and the 5 CPU-h quota is 0.05% of what's needed.
- Creations: 50 (reused persistent sandboxes) to 1,100 (fresh each day), costing ≤ $0.0007. This is negligible.
- Snapshots: 50 GiB × $0.08 = **$4.00** (assumes `keepLastSnapshots: 1` so only ~1 GiB per sandbox is retained).
- Egress, 100 GiB: $0 on Pro because it fits the included 1 TB Flat Rate CDN tier, assuming the site's other CDN traffic leaves headroom. On Enterprise it costs 100 × the regional rate.
- Pro $20 fee: fully credited against usage (usage is well above $20), so the bill equals usage. Add $20 for each extra deploying seat.

| Regime / region | Active CPU $ | Memory $ | Snapshots | Egress | **Monthly total** |
|---|---|---|---|---|---|
| Hobby | none | none | none | none | **not possible** (limits) |
| Pro, iad1 / cle1 / pdx1 | 1,351.68 | 1,492.48 | 4.00 | 0 | **$2,848.16** |
| Pro, bom1 | 1,478.40 | 1,633.28 | 4.00 | 0 | **$3,115.68** |
| Pro, yul1 | 1,552.32 | 1,710.72 | 4.00 | 0 | **$3,267.04** |
| Pro, sin1 / arn1 | 1,689.60 | 1,872.64 | 4.00 | 0 | **$3,566.24** |
| Pro, dub1 | 1,774.08 | 1,957.12 | 4.00 | 0 | **$3,735.20** |
| Pro, icn1 | 1,784.64 | 1,971.20 | 4.00 | 0 | **$3,759.84** |
| Pro, hkg1 | 1,858.56 | 2,055.68 | 4.00 | 0 | **$3,918.24** |
| Pro, lhr1 / cdg1 | 1,869.12 | 2,055.68 | 4.00 | 0 | **$3,928.80** |
| Pro, sfo1 | 1,869.12 | 2,069.76 | 4.00 | 0 | **$3,942.88** |
| Pro, syd1 | 1,900.80 | 2,097.92 | 4.00 | 0 | **$4,002.72** |
| Pro, fra1 | 1,943.04 | 2,140.16 | 4.00 | 0 | **$4,087.20** |
| Pro, cpt1 | 2,112.00 | 2,337.28 | 4.00 | 0 | **$4,453.28** |
| Pro, kix1 / hnd1 | 2,133.12 | 2,351.36 | 4.00 | 0 | **$4,488.48** |
| Pro, gru1 | 2,333.76 | 2,576.64 | 4.00 | 0 | **$4,914.40** |
| Enterprise, iad1 | 1,351.68 | 1,492.48 | 4.00 | 15.00 | **$2,863.16 + unpublished platform fee/commit** |
| Enterprise, icn1 (priciest egress) | 1,784.64 | 1,971.20 | 4.00 | 35.00 | **$3,794.84 + platform fee** |

Sensitivity variants (Pro, iad1):

- **Default snapshot retention (no `keepLastSnapshots`).** Each daily stop leaves a new snapshot that expires 30 days after creation, so roughly 22 are live per sandbox. If each is billed at its full ~1 GiB, that is about 1,100 GiB × $0.08 = **$88**, not $4. This is unverified because snapshot size accounting is undocumented.
- **100% CPU utilisation:** 8,800 × $0.6816 = **$5,998.08**.
- **10% CPU utilisation** (Vercel's own example assumption): 8,800 × $0.2208 = **$1,943.04**.
- **Forgot to stop (sessions kept alive 24/7, restarted at the 24 h cap):** 50 × 730 h × (4 × 0.3 × 0.128 + 0.1696) = 36,500 × $0.3232 = **$11,796.80**, plus snapshots.
- **Stopped time** (the other 16 h/day and weekends) costs only snapshot storage. Non-persistent sandboxes cost $0.
