Runtime changelog, 24 September 2026
What shipped in Runtime Cloud on 24 September 2026: disk bursts; volumes and snapshots are backed up off their server; faster default starts; python data tools are ready; identity and file permissions; the code interpreter speaks seven languages; watch files; record the desktop; MCP servers in a sandbox; fixes; terminals; stopping a sandbox keeps what it wrote to its volumes; mount your own bucket; single sign-on, free on every account; SCIM directory sync; identity tokens for code in a sandbox; custom domains, TCP ports, dedicated outbound addresses and private networks; MCP tools are renamed, a breaking change; runtime_sandbox_exec takes a command as a list; extending a sandbox answers with its new end; the saving a month says what it is projected from; CLI fixes, in withruntime 0.6.0; runtime compare prices the free trial at the standard rates; large command output comes back whole in the drop-ins; and the status page says when a window is longer than its record.
Disk bursts
A sandbox now writes at about 250 MB/s for up to 30 seconds before settling at about 40 MB/s, so installs, builds and test runs finish sooner. In a measurement a sandbox wrote at 200 MB/s instead of 38 (now up to about 1 GB/s, with no burst to run out). See the sandbox environment.
Volumes and snapshots are backed up off their server
Every kept snapshot is copied off its server, encrypted with your organization's own key, and a volume is backed up daily and on request, then restored as a new volume (runtime volume backup, runtime volume restore). See storage and backups.
Faster default starts
In matched 20-run public-API measurements, the default 2 vCPU / 4 GiB memory / 4 GiB disk sandbox reached running in 207 ms median (620 ms p95), and took 351 ms median from create through the first Python result (815 ms p95). Both runs had zero errors. See speed for the before figures and scope; Python execution itself did not get faster.
Python data tools are ready
The current default image includes NumPy, pandas and matplotlib. Imports and PNG plotting were checked in a live sandbox. Retained sandboxes keep their existing image.
Identity and file permissions
A new sandbox on the current default image receives its current lease's identity-token environment before its first accepted command. File writes apply the requested mode, including executable scripts; the default remains 0644.
The code interpreter speaks seven languages
Python, JavaScript, TypeScript, R, Java, Bash and Go, each keeping its state between cells (Go keeps its declarations and runs each cell as a program). R plots come back as PNG and R data frames and JavaScript arrays of objects as tables, and display returns any file as a result. R, Java and Go install themselves the first time you use them. See JavaScript.
Watch files
sbx.files.watch, runtime sandbox watch and runtime_sandbox_files_watch stream create, write, remove, rename and chmod events for a directory, with include and exclude globs, batches, a rate cap that says when it drops events, and a cursor that loses nothing across a pause.
Record the desktop
sbx.desktop.recordings records the screen to MP4 and fetches it; a recording is bounded in CPU, bit rate and size and stops before the disk fills.
MCP servers in a sandbox
runtime sandbox mcp and sbx.mcp start GitHub, Postgres, a Playwright browser, filesystem, fetch and nine more MCP servers in a sandbox in one call, each at an authenticated URL your agent connects to; secret settings come from Runtime secrets, so the server never holds the value. GET /v1/mcp/catalog lists them with their licences.
Fixes
A sandbox created from an image with a start command now runs it and waits for its ready check, as the images guide says. A program in the image's own PATH (python in python:3.12-slim) is found by exec. The desktop starts: its first start installs it, and open reports a missing browser instead of "Opened". Deleting an image no longer leaves it in deleting. An uploaded file keeps its permissions, and a written one is 644, not 600. The CLI, from withruntime 0.6.0, passes piped input to exec, says so and exits non-zero if output was lost, makes the --out-dir of run-code, and marks symbolic links in files. An egress secret's placeholder is in the environment of every command from the moment the secret is set, including in a sandbox made a second ago. A preview visited just after its sandbox paused wakes it instead of answering 502. A trial sandbox's network rules no longer say it may reach ports beyond 80 and 443.
Terminals
An organization may hold 64 terminals open, 12 in one sandbox (it was 8).
Stopping a sandbox keeps what it wrote to its volumes
A write made just before runtime sandbox stop could be lost; the sandbox now writes its volumes out first.
Mount your own bucket
An Amazon S3, Cloudflare R2 or Google Cloud Storage bucket appears as a directory in a sandbox (runtime sandbox mount, sbx.mounts.add). The sandbox never holds the bucket's key: Runtime's egress proxy signs each request with it. See mount your own bucket.
Single sign-on, free on every account
Sign in through Okta, Microsoft Entra ID, Google Workspace or any SAML or OIDC provider, prove your email domain with a DNS record, and require single sign-on for your members. See single sign-on.
SCIM directory sync
Your identity provider adds people, sets their roles through groups, and removes them the moment they leave, which revokes every key they made.
Identity tokens for code in a sandbox
A sandbox gets a short-lived OIDC token naming itself, its organization and its image, and trades it for AWS or Google Cloud credentials with no stored key. See identity tokens.
Custom domains, TCP ports, dedicated outbound addresses and private networks
Custom domains, TCP ports, dedicated outbound addresses and private networks, for paid accounts. Serve a sandbox's port at your own hostname with automatic HTTPS (runtime domain add), open a public TCP port to a database or game server (runtime port open), send from an address of your own for allow-lists (runtime address reserve), and reach your sandboxes from your own network over WireGuard (runtime tunnel). See networking.
MCP tools are renamed, a breaking change
Every tool now carries its product's name, as the CLI does: runtime_exec is runtime_sandbox_exec, runtime_files_read is runtime_sandbox_files_read, runtime_sandboxes_create is runtime_sandbox_create, and images, volumes and snapshots are runtime_image_*, runtime_volume_* and runtime_snapshot_*. Every sandbox tool names its sandbox id. The old names are gone: a call to one fails and its error names the new one. Restart your agent, or run /mcp in Claude Code, so it lists the tools again, and change any permission rule or prompt that names an old tool. The whole table is in MCP.
runtime_sandbox_exec takes a command as a list
runtime_sandbox_exec takes a command as a list as well as a string; a list runs without a shell, as argv does.
Extending a sandbox answers with its new end
POST /v1/sandboxes/{id}:extend, runtime_sandbox_manage with extend and runtime sandbox extend returned the expiry from before the extension; they now wait for the server to confirm the new lease and return it.
The saving a month says what it is projected from
When your first sandbox in the window is more recent than the window, the note of GET /v1/usage/compare and runtime_usage_compare says how many days the monthly figure is projected from, and so does runtime compare from withruntime 0.6.0.
CLI fixes, in withruntime 0.6.0
runtime sandbox logs without -f prints what the process has written so far and returns; runtime usage prints a summary in dollars (--json keeps every figure); a sandbox's name works in every runtime sandbox command and --sandbox filter, not only ssh and port-forward; and runtime mcp exits at once when its client stops it.
runtime compare prices the free trial at the standard rates
Sandboxes the trial ran are priced at what the same work costs on paid credit, and the output says how many ran on the trial, so the saving it reports is the one you get after the trial.
Large command output comes back whole in the drop-ins
commands.run in withruntime/e2b, and process.exec, codeRun and findFiles in withruntime/daytona, return all of a command's output however large it is, in JavaScript and Python.
The status page says when a window is longer than its record
Until the record covers a whole window, withruntime.com/status shows that window as not yet and says how much of it the record covers, and /status.json gives it null with complete: false and covered_hours.