Best sandbox for Claude Code in 2026
For unattended Claude Code, Anthropic's docs point to a virtual machine with its own kernel; the best one also keeps your API key off it.
Runtime gives each Claude Code session a Firecracker microVM with its own
Linux kernel, runs it as a non-root user so --dangerously-skip-permissions
starts, and never puts the Anthropic key inside. The key is a Runtime
secret: the sandbox holds a placeholder that the host replaces only on HTTPS
requests to api.anthropic.com. A thousand half-hour headless sessions a
month, each busy for three CPU-minutes, cost $16.25
on Runtime, against $82.80 on E2B and
$48.80 on Vercel Sandbox, at rates checked
23 September to 2 October 2026.
Which isolation does Anthropic recommend for Claude Code?
Anthropic's sandbox environments page, read on 1 October 2026, ranks the options from a per-command sandbox to a separate machine:
| Approach Anthropic lists | What it isolates | When Anthropic suggests it |
|---|---|---|
| Sandboxed Bash tool | Shell commands only | Fewer prompts on your own machine; "not sufficient" unattended |
| Sandbox runtime | The whole process, on the host's kernel | Unattended runs without Docker |
| Dev or custom container | A full environment, on the host's kernel | A standard team environment |
| Virtual machine | A full operating system, its own kernel | Untrusted repositories and code; kernel-level separation |
| Cloud sessions | An Anthropic-managed VM | Work from any device, with a Claude subscription |
For an untrusted repository the page names "a dedicated virtual machine", and
lists Firecracker microVMs among the ways to get one. It also says to "always
run --dangerously-skip-permissions sessions inside a container, a VM, or the
sandbox runtime", and that Claude Code refuses that flag as root.
What makes a sandbox good for Claude Code?
- Its own kernel. A container shares the host's kernel, so a kernel bug is a way out. A microVM boots its own.
- A key the session cannot leak. Anthropic's dev container warning is that skipping permissions does not stop a malicious project from exfiltrating what is inside, "including the Claude Code credentials". With a Runtime secret, what is inside is a placeholder.
- Egress you set from outside.
sbx.network.set({ allow: [...] })is enforced by the host, so root in the sandbox cannot widen it, and Claude Code can be held toapi.anthropic.comand your package registry. - A session that may run long. A paid Runtime sandbox runs while its lease is extended, with no session cap, and a lease that ends pauses it by default instead of throwing the work away.
- A start that does not wait for npm. Bake Claude Code into a custom image once, and every session starts with it installed.
What do Claude Code sessions cost on each sandbox?
A thousand headless sessions a month, each 30 minutes on a 2 vCPU, 4 GiB sandbox and busy for 180 CPU-seconds while Claude reads, edits and runs tests:
| Provider | Isolation | A month of sessions | Runtime costs less by |
|---|---|---|---|
| Runtime | Firecracker microVM | $16.25 | |
| Cloudflare Sandbox | A container in its own VM | $32.11 | 49% |
| Vercel Sandbox | Firecracker microVM | $48.80 | 67% |
| E2B | Firecracker microVM | $82.80 | 80% |
| Daytona | Containers by default | $82.80 | 80% |
| Modal | gVisor, a shared kernel | $118.98 | 86% |
The model's tokens cost more than any of these machines; the sandbox is the part of the bill that the choice of provider decides. A session that pauses between a user's turns costs only storage while paused, at $0.08 per GB a month.
A run on Runtime, recorded 1 October 2026
The whole setup is a secret, a sandbox and one command:
Terminalprintf %s "$ANTHROPIC_API_KEY" | npx withruntime secrets set ANTHROPIC_API_KEY --host api.anthropic.comTypeScriptimport { Sandbox } from "withruntime";await using sbx = await Sandbox.create({ timeoutSeconds: 3600 });await sbx.exec("npm install -g @anthropic-ai/claude-code", { check: true, timeoutMs: 600_000 });console.log((await sbx.exec("claude --version")).stdout);const run = await sbx.exec( ["claude", "-p", "Write and run a FizzBuzz in Python.", "--output-format", "json"], { timeoutMs: 1_800_000, },);console.log(JSON.parse(run.stdout).result);On 1 October 2026 we ran the install and the version check against a fresh production sandbox, without a model call:
textnpm install -g @anthropic-ai/claude-code exit 0claude --version 2.1.287 (Claude Code)The npm package installed as it is, on Ubuntu 24.04 with Node.js 24, and the CLI started as the sandbox's own user. Cloning a repository, the headless flags and copying the diff back are in Claude Code in a sandbox.
Can Claude Code use Runtime as a tool instead?
Yes. Claude Code on your laptop can start and use sandboxes through Runtime's
MCP server: claude mcp add runtime -- npx -y withruntime mcp gives it tools to
create a sandbox, run commands, share a port and fork. That keeps the editor
experience local and sends the risky part, running the code, to a microVM. The
two directions are covered in MCP tools and the
editors guide.
When might another sandbox fit better?
- Claude Code on the web. With a Claude subscription, Anthropic's cloud sessions run Claude Code in an Anthropic-managed VM with nothing to set up. A sandbox you hold is for sessions your own code starts, sizes and keeps.
Sources
Checked 1 October 2026.
- Choose a sandbox environment:
the approaches compared, the virtual machine recommendation for untrusted
code, and the root and
--dangerously-skip-permissionsrules - Development containers: the credentials exfiltration warning
- Each provider's published rates, checked 23 September to 2 October 2026, as the pricing guide lists them
- The recorded run:
@anthropic-ai/claude-code2.1.287 from npm, in a production sandbox on 1 October 2026