Runtime

Best sandbox for Claude Code in 2026

For unattended Claude Code, Anthropic's docs point to a virtual machine with its own kernel; the best one also keeps your API key off it.

Runtime gives each Claude Code session a Firecracker microVM with its own Linux kernel, runs it as a non-root user so --dangerously-skip-permissions starts, and never puts the Anthropic key inside. The key is a Runtime secret: the sandbox holds a placeholder that the host replaces only on HTTPS requests to api.anthropic.com. A thousand half-hour headless sessions a month, each busy for three CPU-minutes, cost $16.25 on Runtime, against $82.80 on E2B and $48.80 on Vercel Sandbox, at rates checked 23 September to 2 October 2026.

Which isolation does Anthropic recommend for Claude Code?

Anthropic's sandbox environments page, read on 1 October 2026, ranks the options from a per-command sandbox to a separate machine:

Approach Anthropic lists What it isolates When Anthropic suggests it
Sandboxed Bash tool Shell commands only Fewer prompts on your own machine; "not sufficient" unattended
Sandbox runtime The whole process, on the host's kernel Unattended runs without Docker
Dev or custom container A full environment, on the host's kernel A standard team environment
Virtual machine A full operating system, its own kernel Untrusted repositories and code; kernel-level separation
Cloud sessions An Anthropic-managed VM Work from any device, with a Claude subscription

For an untrusted repository the page names "a dedicated virtual machine", and lists Firecracker microVMs among the ways to get one. It also says to "always run --dangerously-skip-permissions sessions inside a container, a VM, or the sandbox runtime", and that Claude Code refuses that flag as root.

What makes a sandbox good for Claude Code?

  • Its own kernel. A container shares the host's kernel, so a kernel bug is a way out. A microVM boots its own.
  • A key the session cannot leak. Anthropic's dev container warning is that skipping permissions does not stop a malicious project from exfiltrating what is inside, "including the Claude Code credentials". With a Runtime secret, what is inside is a placeholder.
  • Egress you set from outside. sbx.network.set({ allow: [...] }) is enforced by the host, so root in the sandbox cannot widen it, and Claude Code can be held to api.anthropic.com and your package registry.
  • A session that may run long. A paid Runtime sandbox runs while its lease is extended, with no session cap, and a lease that ends pauses it by default instead of throwing the work away.
  • A start that does not wait for npm. Bake Claude Code into a custom image once, and every session starts with it installed.

What do Claude Code sessions cost on each sandbox?

A thousand headless sessions a month, each 30 minutes on a 2 vCPU, 4 GiB sandbox and busy for 180 CPU-seconds while Claude reads, edits and runs tests:

Provider Isolation A month of sessions Runtime costs less by
Runtime Firecracker microVM $16.25
Cloudflare Sandbox A container in its own VM $32.11 49%
Vercel Sandbox Firecracker microVM $48.80 67%
E2B Firecracker microVM $82.80 80%
Daytona Containers by default $82.80 80%
Modal gVisor, a shared kernel $118.98 86%

The model's tokens cost more than any of these machines; the sandbox is the part of the bill that the choice of provider decides. A session that pauses between a user's turns costs only storage while paused, at $0.08 per GB a month.

A run on Runtime, recorded 1 October 2026

The whole setup is a secret, a sandbox and one command:

Terminalprintf %s "$ANTHROPIC_API_KEY" | npx withruntime secrets set ANTHROPIC_API_KEY --host api.anthropic.com
TypeScriptimport { Sandbox } from "withruntime";await using sbx = await Sandbox.create({ timeoutSeconds: 3600 });await sbx.exec("npm install -g @anthropic-ai/claude-code", { check: true, timeoutMs: 600_000 });console.log((await sbx.exec("claude --version")).stdout);const run = await sbx.exec(  ["claude", "-p", "Write and run a FizzBuzz in Python.", "--output-format", "json"],  {    timeoutMs: 1_800_000,  },);console.log(JSON.parse(run.stdout).result);

On 1 October 2026 we ran the install and the version check against a fresh production sandbox, without a model call:

textnpm install -g @anthropic-ai/claude-code   exit 0claude --version                           2.1.287 (Claude Code)

The npm package installed as it is, on Ubuntu 24.04 with Node.js 24, and the CLI started as the sandbox's own user. Cloning a repository, the headless flags and copying the diff back are in Claude Code in a sandbox.

Can Claude Code use Runtime as a tool instead?

Yes. Claude Code on your laptop can start and use sandboxes through Runtime's MCP server: claude mcp add runtime -- npx -y withruntime mcp gives it tools to create a sandbox, run commands, share a port and fork. That keeps the editor experience local and sends the risky part, running the code, to a microVM. The two directions are covered in MCP tools and the editors guide.

When might another sandbox fit better?

  • Claude Code on the web. With a Claude subscription, Anthropic's cloud sessions run Claude Code in an Anthropic-managed VM with nothing to set up. A sandbox you hold is for sessions your own code starts, sizes and keeps.

Sources

Checked 1 October 2026.

  • Choose a sandbox environment: the approaches compared, the virtual machine recommendation for untrusted code, and the root and --dangerously-skip-permissions rules
  • Development containers: the credentials exfiltration warning
  • Each provider's published rates, checked 23 September to 2 October 2026, as the pricing guide lists them
  • The recorded run: @anthropic-ai/claude-code 2.1.287 from npm, in a production sandbox on 1 October 2026

Your first 100 hoursare on us.

  • No credit card
  • Eight sandboxes at once, 2 vCPU and 4 GiB each
  • Then prepaid credit from $10, no plan fee
Claim 100 hours free