Runtime changelog, 27 September 2026
What shipped in Runtime Cloud on 27 September 2026: settings in the sidebar; security and compliance page; a nightly off-site copy of the database; two-step sign-in; faster wakes, snapshots and stops; an uptime promise, paid automatically; idle sandboxes pause themselves; account-wide keys; withruntime 0.8.2; switch from Blaxel in one import; start a sandbox from the browser; withruntime 0.7.2; and a changelog page for every day, and a feed.
Settings in the sidebar
Open Settings and the sidebar lists its pages in three groups, Developers, Team and Security, with a way back to where you were. Referrals stay on Usage & billing and Support in the account menu.
Security and compliance page
One page for a security review: where data lives and the certifications of the companies that hold it, isolation, encryption, sign-in, recovery, and how Runtime is run, with the date each recurring check was last done. See security and compliance, or withruntime.com/trust.
A nightly off-site copy of the database
Encrypted to a key held offline and kept 30 days in Backblaze, locked against early deletion.
Two-step sign-in
Turn on a code from an authenticator app after every sign-in, whichever way you sign in, under Settings → Two-step sign-in. Owners can require it of everyone in the account. See two-step sign-in.
Faster wakes, snapshots and stops
A paused sandbox runs its next command 588 ms after the call that wakes it at the median, down from 980 ms; a snapshot of a running sandbox is ready in 3.49 s, down from 6.54 s; a preview visit to a paused sandbox answers in 0.47 s, down from 0.77 s; and a stop answers the moment the sandbox is frozen. See speed.
An uptime promise, paid automatically
Paid accounts are promised 99% API uptime every calendar month, measured by the outside check on the status page. A month below it gives every paid account 10% of that month's charges back as service credit in the first week of the next month, with no claim to file. The terms now give 30 days' emailed notice before we end an account without cause, and the liability floor is $1,000 instead of $100. See the Uptime Promise.
Idle sandboxes pause themselves
A new sandbox pauses after 60 seconds with nothing happening in it, used or not (a persistent one only if you set an idle time), and pays only paused storage until the next request wakes it. A command or terminal still running, an open preview, port, SSH or tunnel connection, network traffic or CPU use keeps it awake. idlePauseSeconds now goes as low as 10 seconds, and 0 still turns it off. Sandboxes made before today keep their settings. See pause when idle.
Account-wide keys
An owner or admin can make a key that sees and uses every sandbox, snapshot, image and volume in the account, whichever key made it, as a Blaxel workspace key does: choose Everything in the account at API keys, switch an existing key from its row, or approve runtime keys create --account-wide. getOrCreate with a name another key holds then returns that sandbox. Keys made without it are unchanged. See keys in a team.
withruntime 0.8.2
runtime keys create --account-wide makes an account-wide key from the command line. Large file writes send eight chunks at once in both SDKs, so a big upload finishes sooner: 100 MB took 11 s instead of 17 from a 12.6 MB/s connection.
Switch from Blaxel in one import
Code written for Blaxel's sandbox SDK runs on Runtime after changing @blaxel/core to withruntime/blaxel (withruntime 0.8.0), or in Python blaxel.core to withruntime.blaxel (0.8.1). Processes, files, previews, snapshots, forks and the code interpreter carry over, and standby becomes a pause that keeps memory and processes until the next call wakes it. A switch from Blaxel now earns the switching credit: run runtime switch --from blaxel before your first top-up, and that top-up is matched, up to $100. See Runtime vs Blaxel.
Start a sandbox from the browser
A new account's Home offers Start a sandbox beside the agent prompt. It opens the sandbox with a shell running in the page, runs on the free hours, and pauses after an idle minute. It acts as an agent named Console, one for each member, shown on the API keys page like any other. See Get started.
withruntime 0.7.2
A directory download (files.download, runtime sandbox cp) can no longer write outside the folder you gave it: a link in the sandbox that leads outside, or a file written through one, is refused with unsafe_archive, and links that stay inside arrive intact. A custom network policy in the Vercel AI SDK harness that allows nothing now turns the internet off, as deny-all does. runtime sandbox exec … --json -- tool --json passes the second --json to the tool, and a streamed command that times out says 24 hours, its real limit. The Harbor and Inspect adapters build images with the current image builder. Update with npm i withruntime@latest or pip install -U withruntime.
A changelog page for every day, and a feed
Each day's changes have a page of their own at withruntime.com/changelog, every entry has a link, and the RSS feed carries each one. The glossary adds fifteen cloud terms, from vCPU to egress fees, and every price, limit and speed on the guides and question pages is now filled in from one source, so a change reaches every page at once.