# Best sandbox for Claude Code in 2026 For unattended Claude Code, Anthropic's docs point to a virtual machine with its own kernel; the best one also keeps your API key off it. **Runtime gives each Claude Code session a Firecracker microVM with its own Linux kernel, runs it as a non-root user so `--dangerously-skip-permissions` starts, and never puts the Anthropic key inside.** The key is a Runtime secret: the sandbox holds a placeholder that the host replaces only on HTTPS requests to `api.anthropic.com`. A thousand half-hour headless sessions a month, each busy for three CPU-minutes, cost $16.25 on Runtime, against $82.80 on E2B and $48.80 on Vercel Sandbox, at rates checked 23 September to 2 October 2026. ## Which isolation does Anthropic recommend for Claude Code? Anthropic's [sandbox environments page](https://code.claude.com/docs/en/sandbox-environments), read on 1 October 2026, ranks the options from a per-command sandbox to a separate machine: | Approach Anthropic lists | What it isolates | When Anthropic suggests it | | ------------------------ | ---------------------------------------- | -------------------------------------------------------------- | | Sandboxed Bash tool | Shell commands only | Fewer prompts on your own machine; "not sufficient" unattended | | Sandbox runtime | The whole process, on the host's kernel | Unattended runs without Docker | | Dev or custom container | A full environment, on the host's kernel | A standard team environment | | Virtual machine | A full operating system, its own kernel | Untrusted repositories and code; kernel-level separation | | Cloud sessions | An Anthropic-managed VM | Work from any device, with a Claude subscription | For an untrusted repository the page names "a dedicated virtual machine", and lists Firecracker microVMs among the ways to get one. It also says to "always run `--dangerously-skip-permissions` sessions inside a container, a VM, or the sandbox runtime", and that Claude Code refuses that flag as root. ## What makes a sandbox good for Claude Code? - **Its own kernel.** A container shares the host's kernel, so a kernel bug is a way out. A microVM boots its own. - **A key the session cannot leak.** Anthropic's dev container warning is that skipping permissions does not stop a malicious project from exfiltrating what is inside, "including the Claude Code credentials". With a Runtime secret, what is inside is a placeholder. - **Egress you set from outside.** `sbx.network.set({ allow: [...] })` is enforced by the host, so root in the sandbox cannot widen it, and Claude Code can be held to `api.anthropic.com` and your package registry. - **A session that may run long.** A paid Runtime sandbox runs while its lease is extended, with no session cap, and a lease that ends pauses it by default instead of throwing the work away. - **A start that does not wait for npm.** Bake Claude Code into a [custom image](/docs/images) once, and every session starts with it installed. ## What do Claude Code sessions cost on each sandbox? A thousand headless sessions a month, each 30 minutes on a 2 vCPU, 4 GiB sandbox and busy for 180 CPU-seconds while Claude reads, edits and runs tests: | Provider | Isolation | A month of sessions | Runtime costs less by | | ------------------ | ------------------------- | ------------------------------------- | --------------------------------------- | | Runtime | Firecracker microVM | $16.25 | | | Cloudflare Sandbox | A container in its own VM | $32.11 | 49% | | Vercel Sandbox | Firecracker microVM | $48.80 | 67% | | E2B | Firecracker microVM | $82.80 | 80% | | Daytona | Containers by default | $82.80 | 80% | | Modal | gVisor, a shared kernel | $118.98 | 86% | The model's tokens cost more than any of these machines; the sandbox is the part of the bill that the choice of provider decides. A session that pauses between a user's turns costs only storage while paused, at $0.08 per GB a month. ## A run on Runtime, recorded 1 October 2026 The whole setup is a secret, a sandbox and one command: ```bash no-run printf %s "$ANTHROPIC_API_KEY" | npx withruntime secrets set ANTHROPIC_API_KEY --host api.anthropic.com ``` ```ts check import { Sandbox } from "withruntime"; await using sbx = await Sandbox.create({ timeoutSeconds: 3600 }); await sbx.exec("npm install -g @anthropic-ai/claude-code", { check: true, timeoutMs: 600_000 }); console.log((await sbx.exec("claude --version")).stdout); const run = await sbx.exec( ["claude", "-p", "Write and run a FizzBuzz in Python.", "--output-format", "json"], { timeoutMs: 1_800_000, }, ); console.log(JSON.parse(run.stdout).result); ``` On 1 October 2026 we ran the install and the version check against a fresh production sandbox, without a model call: ```text npm install -g @anthropic-ai/claude-code exit 0 claude --version 2.1.287 (Claude Code) ``` The npm package installed as it is, on Ubuntu 24.04 with Node.js 24, and the CLI started as the sandbox's own user. Cloning a repository, the headless flags and copying the diff back are in [Claude Code in a sandbox](/integrations/claude-code). ## Can Claude Code use Runtime as a tool instead? Yes. Claude Code on your laptop can start and use sandboxes through Runtime's MCP server: `claude mcp add runtime -- npx -y withruntime mcp` gives it tools to create a sandbox, run commands, share a port and fork. That keeps the editor experience local and sends the risky part, running the code, to a microVM. The two directions are covered in [MCP tools](/docs/mcp#tools) and the [editors guide](/docs/editors). ## When might another sandbox fit better? - **Claude Code on the web.** With a Claude subscription, Anthropic's cloud sessions run Claude Code in an Anthropic-managed VM with nothing to set up. A sandbox you hold is for sessions your own code starts, sizes and keeps. ## Sources Checked 1 October 2026. - [Choose a sandbox environment](https://code.claude.com/docs/en/sandbox-environments): the approaches compared, the virtual machine recommendation for untrusted code, and the root and `--dangerously-skip-permissions` rules - [Development containers](https://code.claude.com/docs/en/devcontainer): the credentials exfiltration warning - Each provider's published rates, checked 23 September to 2 October 2026, as the [pricing guide](/docs/pricing) lists them - The recorded run: `@anthropic-ai/claude-code` 2.1.287 from npm, in a production sandbox on 1 October 2026