E2B
E2B is an open source sandbox platform that gives AI agents isolated Firecracker microVMs to run code, use tools and operate desktops, in E2B's cloud, the customer's own VPC, or self-hosted.
E2B is an open source sandbox platform that gives AI agents isolated Linux machines to work in. An agent can execute generated code, run shell commands, work with files, install packages, reach the internet or operate a desktop without touching the customer's own infrastructure. E2B provides the compute; the customer brings its own model and orchestration framework.
Every sandbox is its own Firecracker microVM with its own kernel. A sandbox can be paused and resumed later exactly as it was, filesystem and memory included, or snapshotted and forked, and volumes keep files across sandboxes. Auto-resume restarts a paused sandbox when a request arrives, and lifecycle events go to the customer's webhook. Egress can be allowed or denied per sandbox, secrets resolve at egress so they never sit in the sandbox, and an MCP gateway gives the agent more than 200 tools from the Docker MCP Catalog. E2B Desktop sandboxes add a graphical Linux desktop with screen, mouse and keyboard for computer-use agents.
E2B runs as a managed cloud on Google Cloud in US, EU and APAC regions, as BYOC inside the customer's own AWS or Google Cloud VPC on Enterprise, or self-hosted from its Apache-2.0 runtime. It states SOC 2 Type II, with the report in its Trust Center, and signs HIPAA BAAs on Enterprise.
Pricing combines a plan with per second usage: Hobby is free with a one time 100 dollar credit, Pro is 150 dollars a month for longer sessions and higher concurrency, and Enterprise is custom above a 3,000 dollar monthly minimum. The default sandbox of two vCPUs and four GiB runs about 17 cents an hour.
Vendor details
Canonical URL
https://e2b.dev
Category
Agent infrastructure
Funding status
E2B is independent. Its contracting entity is FoundryLabs, Inc., a Delaware corporation, per E2B's security page.
Company status
independent
Use cases & customers
Target customers
Deployment options
Integrations
E2B offers Python and JavaScript/TypeScript SDKs, a CLI, a REST API with an OpenAPI 3.1 specification, custom templates, and an MCP gateway inside sandboxes exposing 200+ tools from the Docker MCP Catalog. Setup guides cover Claude Code, Codex, Cursor, Devin, the OpenAI Agents SDK, the Vercel AI SDK, LangChain, CrewAI, Mastra, Google ADK, Letta and NVIDIA NeMo Gym.
In practice
Your agent writes Python and you can't safely run it on your own servers. E2B runs the model-generated code in an isolated Firecracker microVM and returns the results without touching your infrastructure.
Your coding agent's tasks run for hours across several sessions. You pause the E2B sandbox between steps and resume it later with its files, processes and variables exactly as they were.
Your agent needs to click through a real desktop app, not just call APIs. E2B Desktop gives it a graphical Linux desktop to see and control, with a live stream so your team can watch.
Sources & related URLs
Agentic Index coverage score
8.5 / 14 capabilities · 61%
| Integrations & Tool Calling | Full |
|---|---|
|
An agent in a sandbox gets actionable reach into other systems through a built-in MCP gateway that runs inside the sandbox and exposes more than 200 tools from the Docker MCP Catalog (Airtable, GitHub, Browserbase, Exa and others) or custom MCP servers through one interface, with credentials passed as secrets that resolve at egress rather than living in the sandbox. Sourcedocs.e2b.dev/mcp-gatewayread 2026-09-22 |
|
| Workflow Orchestration | Not documented |
|
No workflow logic is documented as an E2B mechanism: E2B states that the customer brings its own orchestration framework, and it provides the machine an agent's steps run on (commands, background processes, code contexts), not a runtime that sequences, branches, retries or routes those steps. Forking a sandbox copies its state, which is compute, not workflow logic. Sourcee2b.dev/llms.txtread 2026-09-22 |
|
| Knowledge Grounding & RAG | Not documented |
|
E2B does not keep a retrieval structure over the customer's content; it runs the agent's code. Files uploaded to a sandbox or volume are storage the agent's code can read, not an index a query returns, and the MCP gateway's tools reach outside knowledge sources owned by others. Sourcee2b.dev/llms.txtread 2026-09-22 |
|
| Human Oversight & Guardrails | Not documented |
|
No approval step, consent checkpoint or escalation to a person is documented for work inside an E2B sandbox. Egress control (allow and deny lists per sandbox, a customer-run proxy that fails closed, and access tokens on public URLs) restricts what an agent's code can reach, but that is isolation the developer configures, not a point where a person reviews the agent's action. Sourcee2b.dev/enterpriseread 2026-09-22 |
|
| Security, Identity & Governance | Full |
|
SOC 2 Type II compliance is stated, with the report under NDA and a current bridge letter in the Trust Center at trust.e2b.dev, a penetration test report and DPA on request, and HIPAA Business Associate Agreements on Enterprise plans. The customer-facing controls are documented beside it: every sandbox is its own Firecracker microVM with its own kernel, egress can be allowed or denied per sandbox by IP, CIDR or domain, secrets resolve at egress so no response, log or sandbox holds them, and public sandbox URLs can require a per-sandbox access token. No SSO for the console is documented, and workload identity is in private beta. Sourcee2b.dev/securityread 2026-09-22 |
|
| Observability & Auditability | Partial |
|
E2B records the sandbox rather than the agent: every lifecycle event is available through an events API and delivered as a signed webhook, sandbox metrics report CPU and memory use, template builds keep logs, and on Enterprise OpenTelemetry metrics and logs export to the customer's OTLP endpoint. Prompts, tool calls, retrieved knowledge and outputs cannot be inspected step by step in E2B, since the agent's reasoning runs outside the sandbox, and no audit log of user actions separate from runtime is documented. Sourcee2b.dev/enterpriseread 2026-09-22 |
|
| Memory & State Persistence | Partial |
|
An agent's working state carries across sessions: a paused sandbox resumes exactly as it was, filesystem and memory, running processes and loaded variables included, and is kept indefinitely until killed; snapshots and forks copy that state, volumes persist files across sandboxes, and code contexts keep interpreter variables between executions, which the agent's code reads to continue its task. This is machine state the developer manages, with no memory layer of stated types or scope that can be reviewed, edited or deleted as memory. Sourcedocs.e2b.dev/sandbox/persistenceread 2026-09-22 |
|
| Deployment & Data Residency | Full |
|
Three deployment modes share the same SDK, CLI and API: E2B Cloud on Google Cloud in US, EU and APAC regions (regions by plan listed in its FAQ); BYOC on AWS or Google Cloud, where the data plane runs in the customer's VPC and sandbox traffic, template sources, snapshots and logs never reach E2B Cloud; and self-hosting, since the runtime, control plane and Firecracker layer are Apache-2.0 with Terraform deployment. Azure is not yet supported. Sourcee2b.dev/enterpriseread 2026-09-22 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
Ready-made starting points ship with the platform: sandbox templates for Claude Code, a desktop, Docker and web app stacks, a cookbook of ready-to-run examples, setup guides for more than thirty agents and frameworks, and open source reference apps, Surf, a computer-use agent, and Fragments, a prompt-to-app builder. These are environments and examples a developer builds from, not a browsable catalog of agents a buyer adopts. Sourcedocs.e2b.dev/llms.txtread 2026-09-22 |
|
| Triggers & Channel Coverage | Full |
|
A sandbox can start without the customer's code calling it. With auto-resume set, a paused sandbox resumes when activity arrives, so an agent served from a sandbox starts on an inbound request, and E2B's guides deploy agent gateways this way, for example OpenClaw answering Telegram. Sandbox lifecycle events are also pushed to the customer's webhook, signed. No scheduler is documented. Sourcedocs.e2b.dev/sandbox/auto-resumeread 2026-09-22 |
|
| Model Flexibility & Routing | Full |
|
Compute is what E2B says it provides for agents, with the customer bringing its own model and orchestration framework; its docs connect sandboxes to any LLM and to agents and frameworks such as Claude Code, Codex, the OpenAI Agents SDK, the Vercel AI SDK, LangChain, CrewAI, Mastra and Google ADK. E2B imposes no model, so model choice stays with the customer. Sourcee2b.dev/llms.txtread 2026-09-22 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
E2B is callable from outside through Python and JavaScript/TypeScript SDKs, a CLI, a REST API described by a published OpenAPI 3.1 specification, and custom sandbox templates the customer builds, tags and versions; a public docs MCP server serves its documentation to agents. Sourcee2b.dev/llms.txtread 2026-09-22 |
|
| Testing, Debugging & Optimization | Not documented |
|
No fixtures, scoring, quality gates or comparison of agent runs are documented as E2B features. E2B is where evaluations and reinforcement learning run, not how they are scored: it lists reinforcement learning among its workloads and documents running NVIDIA NeMo Gym environments in sandboxes, but the datasets, reward functions and scoring belong to the customer's framework. Sourcee2b.dev/llms.txtread 2026-09-22 |
|
| Browser & Computer Use | Full |
|
E2B hosts real desktops an agent controls: E2B Desktop sandboxes are Ubuntu machines with an XFCE desktop and preinstalled applications, and the Desktop SDK gives the agent screenshots, mouse, keyboard and scroll, with a live VNC stream so a person can watch; the docs also cover running a cloud browser in a sandbox, and Surf is E2B's open source computer-use agent built on it. Sourcedocs.e2b.dev/use-cases/computer-useread 2026-09-22 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
E2B deprecated E2B_ACCESS_TOKEN authentication in favor of E2B_API_KEY. This is a breaking change for existing integrations: legacy access tokens stop working on August 1, 2026, and all SDK and API calls must migrate to API-key auth before then.
Bears on: MCP / tool calling / API
View sourceE2B joined the Stripe Projects developer preview so agents can discover, provision, and authenticate E2B sandboxes without manual API-key setup.
Bears on: Integrations
View sourcePricing
Free Hobby ($100 one time credit) · Pro $150/mo + per second usage
usage
Included quota
Hobby: one time $100 usage credit, 1 hour max continuous runtime, 20 concurrent sandboxes, 10 GiB storage. Pro: 24 hour continuous runtime, 100 concurrent sandboxes (600 or 1,100 with add-ons), 1 to 8 vCPU and up to 8 GiB RAM, 20 GiB storage. Compute $0.000014 per vCPU second and $0.0000045 per GiB second on every plan; the default sandbox is 2 vCPU and 4 GiB.
What is public
E2B publishes its plans, per second compute rates and concurrency add-ons, with custom Enterprise (BYOC on AWS or GCP) above a monthly minimum. The core runtime is open source under Apache 2.0.
Billing mechanics
E2B bills per second for running sandboxes (CPU and RAM metered separately), layered on a flat plan fee. Billing stops immediately on pause, kill, or timeout, and is postpaid monthly.
Cost watchouts
The $150/mo Pro fee is a fixed floor paid before any compute: it buys limits (session length, concurrency), not credits. Higher concurrency is a paid add-on. Enterprise carries a $3,000 monthly minimum. Paused sandboxes stop compute billing; storage is included.
Variable cost rationale
Per second metering means cost scales directly with sandbox count and lifetime; long lived or highly concurrent agent fleets can dwarf the subscription fee.
Additional watchouts
Budget the Pro floor against actual utilization, and size the default sandbox: at 2 vCPU and 4 GiB it runs about $0.17 an hour. No GPU sandboxes are documented.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free Hobby tier, no card ($100 one time credit, 1 hour max sessions)
Lowest paid plan
Pro $150/mo plus per second compute usage
Commercial notes
E2B has raised $34.5M+ including a $21M Series A led by Insight Partners (Jul 2025). Customers include Perplexity and Hugging Face, and E2B claims 88% of the Fortune 100 have signed up. Each sandbox is isolated in a Firecracker microVM. A startup program bundles Pro plus $20K credits.
Key ambiguities
Enterprise pricing is custom above a $3,000 monthly minimum; the add-on price for 1,100 concurrent sandboxes differs between the pricing page and the billing docs.
Missing data
Enterprise pricing is custom; the 1,100-sandbox add-on price is stated two ways across the pricing page and the billing docs.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to E2B
The closest documented capability profiles to E2B among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Daytona8.0 / 14Fuller documented coverage on Observability & AuditabilityE2B vs Daytona →
- Modal8.0 / 14Adds documented Workflow OrchestrationE2B vs Modal →
- Exa6.5 / 14A lighter documented profile than E2B
- Firecrawl8.5 / 14Adds documented Human Oversight & Guardrails
- Bright Data8.0 / 14Adds documented Human Oversight & Guardrails
- Hyperbrowser8.0 / 14Adds documented Workflow Orchestration and Human Oversight & Guardrails
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded