Runtime changelog, 25 September 2026
What shipped in Runtime Cloud on 25 September 2026: sandboxes from a custom image start in half a second; a new console; a 100-hour free trial; sandboxes up to 16 vCPUs and 64 GiB; faster network for paid sandboxes; outbound UDP to any port; 50 sandboxes at once for a new paid account, then 100; rules on a secret; your own upstream proxy; private preview links work for every client; previews answer again after a wake; long responses are no longer cut at 150 seconds; downloads arrive whole or fail loudly; remote MCP sign-in is found automatically; custom images get sudo, adduser and useradd; forks and snapshot copies keep their labels; the audit log records every creation; a blocked account says so; close your account yourself; usage per run; adapter and CLI fixes, in withruntime 0.7.0; rotate a preview token from the CLI; the CLI refuses an option it does not take; ctrl-C on runtime sandbox exec stops the command in the sandbox; clearer CLI answers; a create that waits for room says so; a misspelled create option is a TypeScript error; and custom domains verify as soon as the record is published.
Sandboxes from a custom image start in half a second
Once an image is ready, a sandbox of the default size created from it starts from a started copy of the image: 481 ms from create to running at the median, from 3.7 s. See fast starts.
A new console
Home shows what runs now, with live CPU and memory and what just happened across every product. New, or ⌘K, finds any page or resource and starts anything, showing the command that does it. A sandbox's page opens a terminal in the browser and has Pause, Wake, Snapshot, Fork and Stop; Images and Volumes have their own pages; Usage & billing says how long your credit lasts and charts daily spend by product. See your account.
A 100-hour free trial
The free trial is now 100 hours of sandbox time, from 50, still with no card. Accounts already on the trial get the extra hours too; hours already used still count. See the free trial.
Sandboxes up to 16 vCPUs and 64 GiB
A paid sandbox can now be as large as 16 vCPUs and 64 GiB of memory, at the same per-unit rates; a trial sandbox stays at 2 vCPU and 4 GiB. See pricing.
Faster network for paid sandboxes
A paid sandbox moves up to 500 Mbit/s, 200 Mbit/s sustained after its first 10 GiB, and 500 GiB a day. See the sandbox environment.
Outbound UDP to any port
Paid sandboxes send UDP to any public address and port: HTTP/3 and QUIC, DNS to a resolver you choose, time sync, game and media servers, WireGuard and other VPN clients. Private addresses are refused, a sandbox sends at most 50,000 datagrams a second, and a flow that gets no answer after 256 datagrams is closed. Trial sandboxes send TCP only. See networking.
50 sandboxes at once for a new paid account, then 100
A paid account runs up to 50 at once until 7 days after its first top-up clears or $50 of paid use has settled, whichever comes first, then 100. See pricing.
Rules on a secret
On a paid account, a secret can name the methods and paths it goes to, such as GET /repos/acme/*; a request no rule allows goes out without it. See security.
Your own upstream proxy
A paid account can send its sandboxes' traffic, or only the hosts it names, through its own HTTP or HTTPS proxy, with one of its secrets as the proxy's password. Runtime's own checks still come first, and a proxy that fails refuses the connection rather than going direct. See networking.
Private preview links work for every client
A link that carries its token now serves curl, fetch and WebSockets directly; only a browser's page load is redirected to set a cookie. The cookie lasts as long as its token, and a stopped sandbox's preview answers 404 (410 once deleted) instead of asking the client to retry forever. The MCP server's runtime_sandbox_previews_rotate refuses a preview's old tokens and returns a new one.
Previews answer again after a wake
For a short time on 25 September, a preview of a sandbox that had been paused and woken answered 503 waking instead of reaching its server. A visit to a paused sandbox's private preview now reaches the server in 3.99 s at the median. See speed.
Long responses are no longer cut at 150 seconds
Downloads, preview streams and other responses longer than two and a half minutes used to end there.
Downloads arrive whole or fail loudly
The API now sends every file's length first. A download interrupted on our side is read again instead of ending short. In withruntime 0.7.0, files.read checks the length (and a small file's SHA-256), reads a short answer again and then raises download_incomplete; files.readStream (read_stream in Python) streams a file of any size and raises if it ends short; and runtime sandbox cp writes to a partial file and renames it only when whole.
Remote MCP sign-in is found automatically
A connector that meets the MCP server's 401 now finds where to sign in, including clients written to the March 2025 MCP specification.
Custom images get sudo, adduser and useradd
Every image Runtime builds, from a public image too, gives the sandbox user passwordless sudo, and the base image now carries adduser and useradd. A command in a sandbox from an image starts in the image's last WORKDIR (inside /workspace). Build logs number only the steps they log.
Forks and snapshot copies keep their labels
A fork's copies, a snapshot and a sandbox created from it take the source's labels unless you name others. Names are never copied.
The audit log records every creation
Each resource created writes one resource.created entry with its kind, name, labels and funding, and a rules change is logged only when the rules change. See teams.
A blocked account says so
When a payment is disputed or under review, a create answers account_blocked (402) with the reason and what clears it, instead of insufficient_funds. In withruntime 0.7.0 both SDKs raise AccountBlockedError.
Close your account yourself
An owner closes the account at Close account or with POST /v1/account:close; runtime account close arrived in withruntime 0.7.0. See teams.
Usage per run
GET /v1/usage now gives each resource's name, start time, size and billed running time. In withruntime 0.7.0, runtime usage --csv exports one row per resource to the microdollar.
Adapter and CLI fixes, in withruntime 0.7.0
E2B's getHost(port) answers at once, as E2B's does, instead of throwing. The AI SDK harness, ComputeSDK, Harbor and Inspect adapters report a timed-out command as exit code 124 and a signal as 128 plus its number, as a shell does. Piped input to runtime sandbox shell ends the shell when it runs out. Secret rules and the upstream proxy get runtime secrets set --allow, runtime network upstream-proxy and matching SDK methods.
Rotate a preview token from the CLI
In withruntime 0.7.0, runtime sandbox preview rotate <id> <port> refuses every token given out for a private port and prints the new one, as previews.rotate(port) does in the SDKs.
The CLI refuses an option it does not take
In withruntime 0.7.0, runtime sandbox create --memory-mib 8192 stops with "Did you mean --memory?" and creates nothing; before, an unknown option was ignored. --help after any command prints its help instead of running it, and sandbox create and run take --cpu, --cpu-floor, --max-cost and --max-total-cost, as the SDKs do.
Ctrl-C on runtime sandbox exec stops the command in the sandbox
It used to stop only the CLI, and the command ran on. A connection that drops mid-command is now picked up where it stopped, output skipped by a slow reader is always reported as lost, and exec by id makes one request instead of two, about 100 ms sooner. In the SDKs, a streamed exec that is cancelled stops its command. In withruntime 0.7.0.
Clearer CLI answers
runtime whoami names the organization, your role and what you can spend; runtime usage shows what was used apart from what refunds returned; sandbox cp into dir/ keeps the file's name and makes missing folders; a refused request no longer asks you to report it. In withruntime 0.7.0.
A create that waits for room says so
When every trial slot is taken, runtime sandbox create and run now print why on standard error instead of waiting up to two minutes in silence. In the SDKs, onCapacityWait in JavaScript and on_capacity_wait in Python hear each wait, and Sandbox.create takes waitForCapacityMs as runtime.sandboxes.create does. In withruntime 0.7.0.
A misspelled create option is a TypeScript error
In withruntime 0.7.0, Sandbox.create() accepts only the options the API takes, so { vcpus: 2 } fails the typecheck instead of the request. The package now asks for Node 22.12 or later, the first release where require("withruntime") works without a flag.
Custom domains verify as soon as the record is published
Verification used to keep answering "No TXT record" for up to half an hour after you added it.