Daytona
Infrastructure that gives AI agents isolated, persistent sandboxes in under 90 milliseconds, with container, VM, Windows and GPU options, desktop computer use and OpenTelemetry tracing.
Daytona is infrastructure for running AI-generated code. It gives an agent a sandbox, an isolated computer with its own kernel, filesystem, network stack and allocated CPU, memory and disk, created in under 90 milliseconds and driven through SDKs, an API, a CLI or an MCP server. Sandboxes run as Linux containers by default, with Linux VM, Windows and GPU sandboxes also available.
Sandboxes are persistent by default: files survive stop and start, running processes survive pause and resume on VM sandboxes, and volumes and mounted storage outlive any one sandbox; sandboxes can be snapshotted and forked. A Computer Use API gives agents mouse, keyboard, screenshots and recording on Linux and Windows desktops, with VNC for people. Per-sandbox firewalls restrict outbound traffic, secrets hold credentials, and Git, language servers and SSH are built in.
For teams, Daytona adds organizations with roles and granular permissions, SSO through OpenID Connect providers on Enterprise, an audit log, webhooks, and OpenTelemetry tracing of SDK calls and sandbox activity to the customer's own collector. Sandboxes run in shared US and EU regions or on the customer's own runner nodes through Bring Your Own Compute. The homepage says Daytona meets HIPAA, SOC 2 and GDPR standards.
Pricing is usage based and billed per second, with 200 dollars of free compute to start: about five cents per vCPU hour and under two cents per GiB of memory per hour, with GPU sandboxes on demand or preemptible.
Vendor details
Canonical URL
https://www.daytona.io
Category
Agent infrastructure
Subcategory
Code execution sandboxes
Funding status
Independent. Daytona Platforms Inc., per the site footer.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
SDKs for Python, TypeScript, Ruby, Go and Java, a REST API with OpenAPI specifications (Daytona, Toolbox and Analytics APIs), a CLI, an MCP server for Claude, Cursor and Windsurf, an agent skill, Git and language server support, webhooks, OpenTelemetry export, and guides for Claude Code, Codex, Devin, Gemini CLI, OpenClaw, OpenCode, LangChain, LangGraph, Mastra, the OpenAI Agents SDK and RL frameworks.
In practice
Your agent writes Python and you need to run it without it touching your servers. You execute each run in an isolated Daytona sandbox, then read the output to validate before showing the user.
Your agent's multi-step task keeps rebuilding its environment on every retry. You pause the Daytona sandbox between steps so it resumes with its files and running processes intact.
You need to see exactly what your agent did inside its sandbox. You turn on Daytona's OpenTelemetry tracing and send every command and file operation to your own observability stack.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
8.0 / 14 capabilities · 57%
| Integrations & Tool Calling | Partial |
|---|---|
|
An agent in a Daytona sandbox reaches outside systems through what runs inside it: Git operations clone and push repositories, secrets hold credentials and external storage can be mounted, while firewall allow lists decide which hosts it may reach. Daytona has no catalog of connectors, OAuth actions or tool gateway of its own; the tools are the customer's code. Sourcedaytona.io/docs/llms.txtread 2026-09-22 |
|
| Workflow Orchestration | Not documented |
|
Daytona manages sandboxes: it creates and resizes them, applies lifecycle rules and runs warm pools and fleet scaling, but it does not sequence, branch, retry or route an agent's steps. Its guides show agents built in LangGraph, the OpenAI Agents SDK and other frameworks doing that, and no workflow logic mixing fixed steps with agent steps is a Daytona mechanism. Sourcedaytona.io/docs/en/sandboxesread 2026-09-22 |
|
| Knowledge Grounding & RAG | Not documented |
|
Daytona runs the agent's code but keeps no retrieval structure over the customer's content. Volumes and mounted external storage are storage the agent's code reads, not an index a query returns, and the language server in a sandbox serves code intelligence for the files there rather than company knowledge. Nothing Daytona provides indexes, refreshes or permissions the customer's sources. Sourcedaytona.io/docs/llms.txtread 2026-09-22 |
|
| Human Oversight & Guardrails | Not documented |
|
No approval step, consent checkpoint or escalation to a person is documented for work in a sandbox. VNC, a web terminal and SSH let a person watch a sandbox and step in by hand, and a firewall on each sandbox (allow lists or block all, with organization tiers that sandbox settings cannot override) restricts what an agent's code can reach. The first is access and the second is isolation; neither holds an agent's action for review. Sourcedaytona.io/docs/en/network-limitsread 2026-09-22 |
|
| Security, Identity & Governance | Full |
|
Identity and access controls are named. Organizations sign in through OpenID Connect providers such as Google Workspace, Microsoft Entra ID and Okta, with provisioning and membership handled at sign in (Enterprise). Collaborative organizations have owner and member roles plus granular assignments by resource, such as SSO Admin and access to the audit log, and API keys carry permissions and scopes, with managed child keys. An audit log covers user and system activity, and each sandbox has firewall allow lists or block all. The homepage says Daytona meets HIPAA, SOC 2 and GDPR standards and links a Trust Center, but no report type or auditor is given. Sourcedaytona.io/docs/en/ssoread 2026-09-22 |
|
| Observability & Auditability | Full |
|
What the agent did in the sandbox is recorded step by step. SDK tracing instruments every Daytona API operation and SDK call from the customer's application, such as each command run, file written or process started, and sandbox telemetry collects traces, logs and metrics from inside the sandbox. Both export over OpenTelemetry to the customer's own collector, and Daytona keeps sandbox telemetry for three days. A separate audit log records user and system activity with the user, action and time, and logs can be streamed. The model's reasoning runs outside Daytona, and audit export is marked coming soon. Sourcedaytona.io/docs/en/observability/otel-collectionread 2026-09-22 |
|
| Memory & State Persistence | Partial |
|
Persistence is on by default at three layers. The filesystem survives stop, start and archive; memory, meaning running processes and loaded state, survives pause and resume and hot snapshots on VM sandboxes; and volumes and mounted external storage outlive any one sandbox. Sandboxes can also be forked, and the agent's code reads the restored state to carry on. Volumes are storage the code reads, though, and paused process state belongs to the machine: the buyer can resume or delete it but not review or edit it as memory, and no memory layer with a stated scope and lifetime is documented. Sourcedaytona.io/docs/en/persistenceread 2026-09-22 |
|
| Deployment & Data Residency | Full |
|
Sandboxes run in two shared regions, the United States and Europe, chosen per sandbox, or under Bring Your Own Compute, where an organization creates custom regions and attaches its own runner nodes, with an optional proxy and snapshot manager for each region, for control over data locality and compliance. Daytona's control plane manages them, and BYOC is sold on the Enterprise plan. The platform sold today is not open source to self host: the public github.com/daytonaio/daytona repository says core development moved to a private codebase in June 2026 and it receives no further updates, with its last release, v0.190.0, left public under AGPL 3.0. Sourcedaytona.io/docs/en/bring-your-own-computeread 2026-09-22 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Ready made starting points for running agents include default sandbox snapshots in several sizes, a Declarative Builder for images and an agent skill for coding agents. More than forty guides run coding agents (Claude Code, Codex, Devin, Gemini CLI, OpenClaw, OpenCode), as well as framework agents and reinforcement learning setups, in sandboxes. These are environments and walkthroughs a developer builds from, not a browsable catalog of agents a buyer adopts. Sourcedaytona.io/docs/en/agent-skillsread 2026-09-22 |
|
| Triggers & Channel Coverage | Partial |
|
Events go outward: webhooks notify the customer's endpoint when sandboxes are created or change state and when snapshots and volumes change, and automated lifecycle rules stop, pause, archive or delete idle sandboxes. Nothing starts an agent's work without the customer's code, though: there is no schedule, and a stopped sandbox does not wake on an inbound request. Sourcedaytona.io/docs/en/webhooksread 2026-09-22 |
|
| Model Flexibility & Routing | Full |
|
The customer chooses the model. Daytona's guides run agents on Claude, OpenAI Codex and the Agents SDK, Gemini, Kimi and AWS Kiro, and on open models through OpenCode and other frameworks, and GPU sandboxes serve the customer's own LLMs with vLLM or SGLang. Daytona imposes no model, and buyers bring their own providers and keys with documented guidance. Sourcedaytona.io/docs/llms.txtread 2026-09-22 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Outside callers reach Daytona through SDKs in five languages (Python, TypeScript, Ruby, Go and Java), a REST API with published OpenAPI specifications, and a CLI. The specifications cover the Daytona API, the Toolbox API inside the sandbox and an Analytics API, an MCP server lets Claude, Cursor and Windsurf manage sandboxes, and an agent skill serves coding agents. Sourcedaytona.io/docs/llms.txtread 2026-09-22 |
|
| Testing, Debugging & Optimization | Not documented |
|
Evaluations and reinforcement learning run on Daytona, but it does not score them: its guides run training with HUD, TRL, veRL and OpenEnv, and a benchmark agent across several languages, in sandboxes, and the datasets, reward functions and scoring belong to those frameworks. Daytona offers no fixtures, scoring or quality gates for a customer's agent workflows, and no comparison of agent runs. Sourcedaytona.io/docs/llms.txtread 2026-09-22 |
|
| Browser & Computer Use | Full |
|
The Computer Use API gives an agent programmatic control of a desktop in the sandbox, from mouse and keyboard to screenshots, screen recording and display operations, on Linux and Windows, with VNC so a person can watch or take over. That is control of a real interface, run remotely on Daytona's infrastructure. macOS sandboxes are offered separately at use.computer, a different site with its own API. Sourcedaytona.io/docs/en/computer-useread 2026-09-22 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Daytona released the SecretService API for organization-scoped secrets in agent sandboxes. Secrets are injected as opaque placeholders in environment variables, and the real plaintext is substituted only at the network egress layer, and only for allowed hosts.
Bears on: Security / enterprise
View sourcePricing
Usage based · $200 free compute · vCPU $0.0504/h, memory $0.0162/GiB-h
Per second compute and memory, plus metered storage
Included quota
$200 in free compute (not for GPU sandboxes) and the first 5 GiB of storage free. Beyond that, reserved vCPU, memory and disk bill per second by sandbox state.
What is public
Daytona publishes a full per resource rate card for CPU, memory, storage, Windows and GPU sandboxes, with $200 of free compute to start.
Billing mechanics
Sandboxes bill per second for the resources they reserve, by lifecycle state: vCPU, memory and disk while starting or started, disk only while paused or stopped, nothing once deleted. Credits sit in an organization wallet with free and paid balances.
Cost watchouts
Stopped and paused sandboxes still bill for reserved disk; GPU sandboxes cost far more than CPU and cannot use free credits; thousands of concurrent sandboxes for RL or evals add up quickly.
Variable cost rationale
Cost scales directly with sandbox runtime, memory, storage, and concurrency, and these workloads expand fast as teams add more agents, longer sessions, and parallel runs. The 15 minute default auto pause can add idle compute charges.
Additional watchouts
Delete or archive sandboxes you no longer need, since stopped and paused sandboxes keep billing for disk. Budget GPU work separately from the free credit.
Overage / add-ons
Pay as you go from the organization wallet: reserved vCPU, memory and disk bill per second while started; paused sandboxes bill disk only; deleted sandboxes stop billing.
Sales call required
No, self serve available
Free / trial
$200 in free compute, no credit card required; first 5 GiB of storage free; free credits not usable on GPU sandboxes
Lowest paid plan
Pay as you go usage; no fixed monthly plan
Commercial notes
Sold self serve with free compute and per second billing; Enterprise adds SSO, audit logs, BYOC custom regions and larger limits. A startup program is offered.
Key ambiguities
Total cost depends on reserved resources, how long sandboxes stay started, paused or stopped, concurrency and GPU use.
Cancellation / refund
Self serve, pay as you go usage. No fixed contract for the standard managed plan; self hosting carries no Daytona fee.
Support SLA / resale
Community support for open source and standard usage; enterprise support and governance controls are arranged separately.
Missing data
Enterprise pricing is not public.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Daytona
The closest documented capability profiles to Daytona among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- E2B8.5 / 14Fuller documented coverage on Integrations & Tool Calling and Triggers & Channel CoverageDaytona vs E2B →
- Firecrawl8.5 / 14Adds documented Human Oversight & Guardrails
- Modal8.0 / 14Adds documented Workflow OrchestrationDaytona vs Modal →
- Exa6.5 / 14Fuller documented coverage on Triggers & Channel Coverage
- Bright Data8.0 / 14Adds documented Human Oversight & Guardrails
- Hyperbrowser8.0 / 14Adds documented Workflow Orchestration and Human Oversight & Guardrails
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded