E2B
by E2B
Firecracker microVM sandboxes that boot in under 200ms so AI agents can run code safely.
E2B is a cloud runtime that gives AI agents an isolated place to execute code. Each sandbox is a Firecracker microVM that boots in under 200 milliseconds, runs up to 24 hours, and gives the agent a filesystem, shell, package installation and browser automation, so teams do not have to build container isolation and lifecycle management themselves.
E2B is a cloud runtime that gives AI agents a secure, isolated place to execute code. Each sandbox is a Firecracker microVM with full isolation, boots in under 200 milliseconds with no cold start, and can run for up to 24 hours — the combination that makes it usable for interactive agent loops rather than only batch jobs. Inside a sandbox an agent gets a full filesystem, shell access, arbitrary package installation, file upload and download, and browser automation, and can execute Python, JavaScript, Ruby, C++ or anything else it can install. Teams reach it through Python and TypeScript SDKs that slot into LangChain, OpenAI and Anthropic tool-calling, or build custom sandbox templates preloaded with their own dependencies. The problem it removes is specific: running model-generated code on your own infrastructure means either trusting that code or building isolation, lifecycle management and cleanup yourself, and most teams find the second option becomes a platform project. E2B's core is Apache-2.0 licensed with roughly 13,400 GitHub stars and active development through August 2026, and it can be self-hosted, run bring-your-own-cloud on AWS or GCP, or deployed on-premises — though on-premises means operating the full control plane, which is closer to running a platform than consuming a service. The company reports SOC 2 Type 2 certification with HIPAA and business associate agreements at the enterprise tier. Founded in 2023 in San Francisco by Vasek Mlejnsky and Tomas Valenta, it raised a $21 million Series A led by Insight Partners bringing total funding to $32 million, and names Perplexity, Hugging Face, Manus, Groq, Lindy, LMArena, Genspark and JPMorgan Chase among its users.
Platform and AI infrastructure teams shipping agents that execute model-generated code, who would otherwise spend a quarter building sandbox isolation and lifecycle management in-house.
Hardware-isolated execution for untrusted model-generated code, available in under 200 milliseconds, without building or operating the isolation layer yourself.
At a Glance
- Category
- Infrastructure & Cloud
- Pricing
- Freemium, Subscription, Usage-based
- Target Market
- CTOs, Platform Engineers, AI Infrastructure Teams, Enterprise Developers, Data Scientists
- Deployment
- Cloud-first, Open-source, Self-hosted, Hybrid, Multi-cloud
- Founded
- 2023
- Headquarters
- San Francisco, United States
- Customers
- 88% of the Fortune 100 signed up; hundreds of millions of sandbox sessions supported (company-stated, Series A announcement)
Key Features
- ✓Firecracker microVM isolation
Every sandbox is a separate microVM with hardware-level isolation, so untrusted generated code cannot reach the host or other tenants.
- ✓Sub-200ms cold start
Sandboxes initialise in under 200 milliseconds with no cold start, which is what makes interactive agent loops feasible rather than batch-only.
- ✓Long-running sessions
Sandboxes persist for up to 24 hours on paid tiers, so multi-step agent tasks keep filesystem and process state across a session.
- ✓Full environment access
Agents get a filesystem, shell, arbitrary package installation, file upload and download, and browser automation inside the sandbox.
- ✓Custom sandbox templates
Teams pre-bake images with their own dependencies so agents start with the right toolchain instead of installing it every run.
- ✓Python and TypeScript SDKs
Both SDKs integrate directly with LangChain, OpenAI and Anthropic tool-calling, so wiring a sandbox into an existing agent is short.
- ✓Flexible deployment
Managed cloud, bring-your-own-cloud on AWS or GCP, or full on-premises deployment for teams that cannot send code off-network.
Capabilities
Use Cases
- •Code interpreter inside a product
A SaaS product runs user- or model-generated analysis code in isolation so a bad script cannot affect other tenants.
- •Autonomous coding agents
An agent writes code, runs it, reads the error output and iterates inside a disposable environment that is thrown away afterwards.
- •Data analysis over uploaded files
Customer spreadsheets are uploaded into a sandbox where generated pandas code runs without touching production systems.
- •Browser and computer-use automation
Agents drive a real browser inside the sandbox to complete tasks that have no API available.
- •Regulated deployment via BYOC
A financial institution runs the same sandbox runtime inside its own AWS or GCP account so code never leaves its boundary.
Ideal For
Best For
- ✓Agents that must execute untrusted model-generated code without risking the host environment
- ✓Data analysis and code interpreter features inside a product, where users' code must not reach shared infrastructure
- ✓Long-running agent tasks needing persistent state across a session, up to 24 hours per sandbox
- ✓Browser automation and computer-use agents that need a real environment rather than an API mock
- ✓Teams with strict data requirements who need bring-your-own-cloud on AWS or GCP, or full self-hosting
Not Ideal For
- ✗Simple deterministic function calls that never execute generated code — a serverless function is cheaper and simpler than a microVM
- ✗Teams without platform engineering capacity choosing the on-premises route, which requires running the entire control plane and is closer to self-hosting than to managed BYOC
- ✗Very cost-sensitive high-volume workloads, where per-second CPU and RAM metering on top of a $150/month Pro subscription adds up faster than expected
- ✗Anyone needing self-serve access to HIPAA coverage or enterprise compliance features, which require a sales conversation rather than a signup
Integrations
Deployment
Market & Ratings
88% of the Fortune 100 signed up; hundreds of millions of sandbox sessions supported (company-stated, Series A announcement)
Market Analysis
Pros
- ✓Firecracker microVM isolation is a genuinely stronger security boundary than the container isolation most competitors ship
- ✓Sub-200ms starts with no cold start make it viable inside interactive agent loops, not only batch workloads
- ✓Apache-2.0 core with roughly 13,400 GitHub stars and a real self-hosting path reduces vendor lock-in
- ✓Deployment range is unusually broad: managed cloud, BYOC on AWS and GCP, or full on-premises
- ✓Credible adoption — Perplexity, Hugging Face, Groq, Manus, LMArena and JPMorgan Chase are named users
Cons
- ✗The on-premises option requires operating the full control plane yourself, which is closer to running a platform than consuming a managed service and is a significant operational burden
- ✗BYOC is limited to AWS and GCP, so Azure-standardised organisations have no bring-your-own-cloud path
- ✗Per-second CPU and RAM metering stacked on a $150/month Pro fee makes cost modelling harder than a flat per-sandbox price, and high concurrency escalates quickly
- ✗HIPAA coverage and enterprise compliance require a sales conversation rather than self-serve access, which slows evaluation for regulated buyers
- ✗There is effectively no independent review-site coverage — most third-party comparisons are written by competing sandbox vendors, so buyers should discount them accordingly
Pricing
Hobby
$0
- ✓$100 one-time usage credit
- ✓1-hour max sandbox sessions
- ✓20 concurrent sandboxes
- ✓10 GiB storage
- ✓Community support
Pro
From $150/mo
- ✓24-hour max sandbox sessions
- ✓100 concurrent sandboxes (up to 1,100 purchasable)
- ✓Customisable CPU and RAM
- ✓20 GiB storage
Ultimate (Enterprise)
Contact for pricing
- ✓BYOC on AWS and GCP
- ✓On-premises deployment
- ✓HIPAA and business associate agreements
- ✓Custom rates
- ✓Dedicated support
The subscription is a platform fee on top of metered consumption, not an all-in price: Hobby is free with a one-time $100 usage credit and Pro is $150/month, and both then bill per second of running sandbox — CPU at roughly $0.000014 to $0.000112 per second depending on vCPU count and RAM at about $0.0000045 per GiB per second. Session limits and concurrency, not features, are the real tier boundary (1 hour and 20 concurrent sandboxes on Hobby versus 24 hours and 100 on Pro, expandable to 1,100). BYOC on AWS or GCP, on-premises deployment and HIPAA business associate agreements are all gated behind the quote-only Ultimate tier.
Security & Compliance
Connect
Sources
This page was written from 7 sources, 4 on domains other than e2b.dev.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
ZML/LLMD
Free, Python-free LLM inference server that runs open models on NVIDIA, AMD, Google TPU, Intel and Apple chips from one binary
Lambda
GPU cloud and AI factories for training and inference — on-demand NVIDIA instances to single-tenant superclusters
Anyscale
Managed Ray platform for scaling AI data processing, training, inference and RL across thousands of GPUs on any cloud
Chroma
Open-source (Apache 2.0) vector and hybrid search database for AI, with a serverless Chroma Cloud on object storage