E2B
E2B is an open-source cloud runtime that gives AI agents isolated Linux sandboxes for running untrusted, model-generated code. Python and JavaScript SDKs, a free Hobby tier, and a Pro plan at $150 per month plus per-second usage.
What is E2B?
E2B is cloud infrastructure, not a consumer assistant: it exists so that developers building AI agents can let a model run code without putting their own systems at risk. Its unit of work is the Sandbox, an isolated Linux virtual machine created by a single SDK call, then paused, resumed or destroyed when the job is done. Isolation rests on Firecracker, the microVM technology designed to run untrusted workloads, and the site claims start-up under 200 ms for a sandbox in the same region as the client, with no cold starts.
Inside that sandbox an agent gets a genuine computer rather than a snippet evaluator: a terminal, a full filesystem, internet access, a browser, package installation, file upload and download. Sessions run up to one hour on the free tier and up to 24 hours on Pro, with 20 and 100 concurrent sandboxes respectively, and paid concurrency reaching 1,100.
The platform is deliberately model-agnostic. E2B publishes worked examples for OpenAI, Anthropic, Mistral, Llama, LangChain and LlamaIndex among others, and states plainly that there are no lock-ins. Around the execution core sit custom sandbox templates, snapshots, forking, persistence, volumes, an MCP gateway, Git integration, SSH access, metrics and OpenTelemetry export.
Five use cases lead the site: deep research agents, AI data analysis and visualisation, coding agents, vibe coding, reinforcement learning and computer use. The reinforcement-learning case explains the architecture best — running tens of thousands of concurrent sandboxes to evaluate reward functions is not something a shared runtime can do.
Deployment is flexible: E2B's own cloud, bring-your-own-cloud inside an AWS, GCP or Azure account or VPC, on-premises, or self-hosted from the public GitHub repository. The SDKs, the infrastructure and the observability dashboard are open source.
The publisher is FOUNDRYLABS, INC., a Delaware corporation based in San Francisco. Named customers with published case studies include Genspark, Hugging Face, Manus, Groq, Lindy, Gumloop, Rogo and Perplexity.
What it does
- Run LLM-generated code without exposing your own infrastructure
- Give an agent a full computer: terminal, filesystem, browser and internet access
- Analyse data and generate charts inside an isolated environment
- Launch thousands of concurrent sandboxes to evaluate reinforcement-learning reward functions
- Act as the runtime for AI-generated applications and vibe-coded apps
- Run agent-triggered tests and CI/CD jobs
- Expose sandboxed tools to a model through the MCP gateway
When to use E2B / When not to
A quick filter to help you decide if E2B is the right fit.
When to use E2B
- Engineering teams shipping agentic products that must execute untrusted, model-generated code in production
- AI research labs running experiments at scale — Hugging Face used E2B to launch hundreds of concurrent sandboxes for Open R1
- Companies that need code execution to scale hard: Genspark reports thousands of concurrent sessions on E2B
- Early-stage startups, who can apply for $20,000 in usage credits and a Pro membership
- Enterprises with data residency constraints, thanks to EU and US regions, bring-your-own-cloud and on-premises deployment
When not to use E2B
- Non-developers: there is no no-code path, everything runs through an SDK, the CLI or the API
- Anyone wanting a mobile or desktop app — E2B ships neither, nor a browser extension
- Teams needing long sessions or high concurrency for free: the Hobby tier caps at one hour and 20 sandboxes
- Projects with a fixed, predictable budget, since per-second usage is billed on top of every plan
- Users who need EU data residency without paying, as the EU cluster starts at the Pro tier
How to use E2B
A typical end-to-end flow, from setup to results.
- Create an E2B account — sign-up goes through GitHub
- Collect your API key from the dashboard and add it to your .env file
- Install the SDK for your language, either the JavaScript package or the Python one
- Create a sandbox from your own code and run a first snippet inside it
- Wire the sandbox to your model by exposing code execution as a tool the LLM can call
- Start from a worked example if you use Vercel AI SDK, OpenAI, Anthropic, Mistral, Ollama, LangChain, LangGraph, LlamaIndex or Autogen
- Pre-install the packages and system libraries you need by building a custom sandbox template, or install them while the sandbox runs
- Manage running sandboxes from the CLI: authenticate, create, list, connect, execute commands, shut down
- Spend the $100 in credits granted to every new account before committing to a paid plan
- Browse the cookbook and the open-source example repositories for full applications
Pros & Cons
Pros
- Firecracker microVM isolation — proven technology for untrusted workloads, not a container shortcut
- Open source, with documented self-hosting and no lock-in to any model provider
- Broad and genuinely documented product surface: templates, volumes, snapshots, MCP, CLI, telemetry
- Pricing published in full, down to the per-second cost of each vCPU and each GiB of memory
- A free tier you can actually work with: $100 in credits, 20 concurrent sandboxes, no credit card
- Named customer references backed by published case studies
- Sovereignty options: EU region, bring-your-own-cloud and on-premises deployment
Cons
- No security certification you can read: the trust centre is a JavaScript-rendered report and no page states SOC 2 or ISO in plain text
- No published data processing agreement and no subprocessor list
- Legal pages predate the current offering — privacy policy dated 8 April 2024, terms 4 December 2024
- Nothing is said about model training, while the terms take a very broad licence over submitted data
- Adoption figures contradict each other across pages: 94% versus 88% of the Fortune 100, 7M+ versus 3M+ monthly downloads
- Role-based access control is still advertised as coming soon
- Total cost is hard to anticipate: a flat subscription plus per-second usage, with a separate calculator needed
Pricing & Plans
E2B offers a permanent free plan. The Hobby tier costs nothing to open, requires no credit card and includes $100 of one-time usage credits. The lowest paid entry point is the Pro plan at USD 150 per month. Usage is billed separately on every tier, per second of running sandbox, so the monthly subscription should be read as a floor rather than a total.
- $100 in one-time credits
- community support
- sessions of up to one hour
- up to 20 concurrent sandboxes
- 10 GiB of storage included
- no credit card required
- everything in Hobby
- configurable sandbox CPU and RAM
- sessions of up to 24 hours
- up to 100 concurrent sandboxes
- extra concurrency purchasable up to 1
- 100
- 20 GiB of storage included
- paid through Stripe
- custom terms negotiated on contact
Data, GDPR & hosting
A consolidated view of how E2B handles your data.
GDPR overview
E2B never claims GDPR compliance. The privacy policy mentions the regulation once, to note that European Union residents may have additional rights under it. It does reason in explicit legal bases — performance of the contract for account data, consent for the newsletter and usage analytics — but most of the rights it details belong to US state laws, from California to Virginia. No Article 27 representative is designated, no data protection officer is named, and the single contact point is a general address. No data processing agreement is published or offered, and no subprocessor list exists. The linked trust centre renders entirely in JavaScript and shows nothing. On the enterprise side, EU regions are presented as a way to meet data residency rules and the EU AI Act. Guidaio therefore records N: an absence of claim, not a finding of non-compliance.
Who owns the data?
The terms call anything you send into the platform a Submission, and responsibility for it stays with you: you must hold the rights to it. In exchange you grant FOUNDRYLABS, INC. a perpetual, irrevocable, worldwide, non-exclusive, fully paid-up and royalty-free licence to use, reproduce, perform, modify, adapt, transmit, exploit and create derivative works from it — not only to deliver the service to you, but to operate the company's business generally. Outside its open-source components, E2B owns the site, the service and their content. Feedback and suggestions you send are covered by a similar perpetual, royalty-free licence.
Reuse rights
The terms give the end user no reuse right over E2B's own material. Outside the open-source components, the site, the service, the interfaces and the content remain the property of FOUNDRYLABS, INC., and you receive only a non-exclusive, non-transferable, revocable licence to access and use them while your account is active — a licence that terminates automatically if you breach the terms or your account is deleted. Copying, distributing, reselling, renting, framing or reverse-engineering the service is prohibited, as is developing anything competitive with it or building third-party applications against it without written consent. Data you submit yourself remains yours to use freely; what you may not repurpose without permission is anything belonging to E2B.
Data retention & training
Hosting summary
By default, processing happens in the United States. The privacy policy is explicit that data may be transferred to, stored in and processed outside your own jurisdiction, and it names the USA specifically. For customers who need something else, E2B runs a shared EU cluster, available from the Pro tier upwards and switched on by contacting support; the enterprise page presents US and EU regions as the way to satisfy data residency rules and the EU AI Act. Beyond the managed cloud, three sovereign options exist: bring-your-own-cloud inside your own AWS, GCP or Azure account or VPC, on-premises deployment, and self-hosting from the public GitHub repository. What the site does not provide is any detail underneath that. No datacentre is named, no hosting provider is identified in the legal pages, and no subprocessor list is published. The marketing domain itself resolves to a US anycast address, which says nothing about where sandboxes actually run.
Things to keep in mind
Risks and trade-offs to weigh before adopting E2B.
- The licence you grant over submitted data is perpetual, irrevocable and worldwide, and covers derivative works — read it before piping sensitive material into a sandbox
- Nothing on the site says whether your data feeds model training, and no opt-out is documented; silence is not a guarantee
- Security claims cannot be checked: the trust centre shows nothing without a browser, and no certification appears in plain text anywhere
- Per-second billing on top of a subscription turns a runaway agent into a financial risk, not just a technical one — a loop keeps the meter running
- Charges are non-refundable, including when E2B terminates or modifies the service
- Without a data processing agreement or a subprocessor list, a regulated organisation has little to hand its compliance team
- Sandboxing removes the fear of running generated code, which makes it easier to stop reading that code — the isolation protects your infrastructure, not your judgement
Setup & Integrations
Technical difficulty
Straightforward for a developer, out of reach for anyone else. Four documented steps take you from account to first executed snippet: sign up through GitHub, copy the API key into a .env file, install one package, then create a sandbox and run code. Worked examples cover nine LLM ecosystems and frameworks. Reported integration times are short — one hour at Rogo, one week at Lindy with a single engineer working in spare cycles. Difficulty rises with custom templates, bring-your-own-cloud and self-hosting, which assume real infrastructure skills.
Deployment
Integrations
Supported languages
Behind E2B
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Alternatives
Tools that compete with or complement E2B.
Frequently asked questions
Do I need to know how to code to use E2B?
Is there a free plan?
What does the first paid plan cost?
Can my data stay in Europe?
Does E2B train models on customer data?
Can I self-host E2B?
What is the minimum age?
Is there a mobile app?
Are payments refundable?
How long can a single sandbox run?
Should you pick E2B?
E2B answers a narrow question well: where does an AI agent run the code it has just written? Rather than trusting a container or a shared interpreter, it hands each task a Firecracker microVM — the isolation technology built for untrusted workloads — and gives the agent a real machine inside it, with terminal, filesystem, network and browser. The product around that core is unusually complete for a company this young, with templates, volumes, snapshots, an MCP gateway, telemetry export and a CLI, all documented in depth.
Two things set it apart commercially. Pricing is published in full, down to the cost of a vCPU-second, which is rare in agent infrastructure and makes the platform genuinely comparable. And the open-source positioning is not decorative: the SDKs and infrastructure are public, self-hosting is documented, and bring-your-own-cloud and on-premises deployment mean a team can leave without rewriting everything.
The reservations sit on the governance side, and they are real. There is no published data processing agreement, no subprocessor list, and no certification anyone can read without a browser. The legal pages predate the current offering by well over a year. Most notably, the terms take a very broad, perpetual licence over whatever you submit, while saying nothing at all about model training and offering no opt-out. For a platform whose entire purpose is to receive other people's code and data, that silence is the gap worth closing.
E2B is a strong technical choice for engineering teams putting agents into production, and a comfortable one for research groups and funded startups, who have credit programmes waiting for them. Teams in regulated industries should get the data governance questions answered in writing before they commit.
- Choosing a selection results in a full page refresh.
- Opens in a new window.