Skip to content
New: the SDK and admin CLI are on npm. @weftsh/sandbox →

Compatible with the E2B SDKs

Secure sandboxes for AI agents, in your own AWS account

Run the code your agents write in isolated Firecracker microVMs that live in your VPC, not someone else's cloud. Keep your SDK code: point it at your stack with three environment variables.

  • Runs in your AWS account
  • Egress denied by default
  • Source available
agent.py
# Point the E2B SDK at your stack
# E2B_API_URL=https://api.sandbox.example.com
# E2B_DOMAIN=sandbox.example.com

from e2b import Sandbox

sbx = Sandbox.create()   # a fresh microVM

# Run code your agent wrote
sbx.files.write("analysis.py", code)
print(sbx.commands.run("python3 analysis.py").stdout)

# Share the app it built, inside your network
sbx.commands.run("npm run dev", background=True)
print(sbx.get_host(3000))
# 3000-<id>.sandbox.example.com

Built on proven pieces

  • Firecracker microVMs
  • AWS CloudFormation
  • Sigstore-signed releases
  • Rust & TypeScript
  • E2B SDK compatible

Why Weft Sandboxes

Give your agents a computer, not your data

Hosted sandboxes mean sending code, files and credentials to someone else's infrastructure. Weft Sandboxes runs the same workflow where your data already lives.

Your data stays in your account

Sandboxes, templates, logs and secrets live in your VPC, encrypted with your KMS key. Weft has no access to your stack.

No new SDK to learn

The unmodified e2b packages for Python and JavaScript work as they are. Switching takes three environment variables.

Real isolation for untrusted code

Every sandbox runs its own Linux kernel in a jailed Firecracker microVM. It cannot reach the host, the metadata service or other sandboxes.

You decide what agents can reach

Outbound traffic is denied by default. Allow the hosts each team needs; every connection is checked and written to an audit log.

Secrets agents use but never see

The egress gateway adds API keys from AWS Secrets Manager to allowed requests. The key never enters the sandbox.

It's your infrastructure

One CloudFormation stack with your IAM, VPC, CloudWatch and Auto Scaling. Pay AWS directly; delete the stack to remove it.

Drop-in

Switch in three lines

Weft Sandboxes speaks the API the E2B SDKs already use, and runs the same in-sandbox agent. Your code does not change.

  • Commands, streaming output, files and directory watches
  • Interactive terminals, background processes, pause and resume
  • Custom templates from any container image or Dockerfile
  • Tested with the Python and JavaScript SDKs on every change
See the full compatibility matrix
.env
export E2B_API_URL=https://api.sandbox.example.com
export E2B_DOMAIN=sandbox.example.com
export E2B_API_KEY=weft_sk_...

How it works

One stack, entirely in your account

Templates are booted once and saved as snapshots, so every new sandbox starts with its tools already running.

  1. 1

    Your app calls the SDK

    The E2B SDK talks to your stack's API over HTTPS, inside your network.

  2. 2

    The control plane places it

    It picks a host with room and hands it the template and the team's egress policy.

  3. 3

    A microVM runs the code

    Each sandbox is a jailed Firecracker microVM on an EC2 host that scales with demand.

  4. 4

    The gateway guards egress

    Every outbound connection is checked, logged, and given credentials if the policy says so.

Security

Built for code you don't trust

Agent-written code is untrusted by definition. Every layer assumes the sandbox is hostile.

  • Own kernel per sandbox. Firecracker microVMs through the jailer: separate user, chroot, cgroups and rate limits.
  • No path to the host. The metadata service, host addresses and other sandboxes are unreachable; an escape-attempt suite checks it.
  • Deny-by-default egress, DNS included. Names outside the policy don't even resolve, so DNS can't carry data out.
  • Signed supply chain. Releases are Sigstore-signed, and the stack refuses images and AMIs that don't match the signed manifest.
Read the threat model

Exactly what leaves your account

Once a day, for online licenses, and nothing else. No code, no data, no telemetry. Offline and AWS Marketplace licenses send nothing at all.

{
  "keyId": "lic_…",
  "version": "0.1.0",
  "region": "eu-west-1",
  "peakConcurrent": 12
}

The field list is fixed in the source code and checked by a test. Licensing details

Use cases

What teams build with it

Code interpreters

Let LLM apps analyze data, make charts and run what they write.

Coding agents

Clone repos, install dependencies and run tests in a real environment.

Live previews

Every app an agent builds gets its own URL inside your network.

Evals and batch jobs

Run many isolated attempts in parallel, on hosts that scale.

Untrusted user code

Notebooks, playgrounds and grading systems, safely contained.

Deploy

From one stack to sandboxes

Try the whole service on a Linux machine today. With the first release, install it in your AWS account with a single CloudFormation stack.

Step 1

Launch the stack

Enter a domain, a certificate source and your license key. The stack is designed to be ready in about 15 minutes.

Step 2

Create a team

weft-sandbox teams create research
weft-sandbox egress set <team> policy.json

Step 3

Point your code at it

Set three environment variables. Existing E2B SDK code runs unchanged.

Transparent running costs

You pay AWS directly. With defaults in us-east-1: about $220–230 a month for the always-on services, plus about $290 a month per On-Demand host. Spot hosts cost less.

Cost breakdown

FAQ

Questions teams ask first

Do I have to change my code?+

No, only three environment variables. A few SDK features are not supported yet (auto-resume, snapshots and fork, template steps like RUN); they return a clear error instead of misbehaving.

Does anything leave my AWS account?+

Only the daily license check shown above, with four fields. Offline and AWS Marketplace licenses send nothing. Your sandboxes reach only what your egress policy allows.

Which AWS instances does it run on?+

C8i, M8i and R8i instances with nested virtualization, or bare-metal instances. A c8i.2xlarge runs about 21 sandboxes of 512 MiB, and hosts are added automatically as demand grows.

Is it open source?+

The core is source-available under the Functional Source License: free to use, modify and self-host for anything except offering a competing service, and each release becomes Apache-2.0 two years later. The SDK, CLI and deployment templates are Apache-2.0 today.

When can I install it in AWS?+

With the first signed release, which publishes Launch Stack links for every supported Region. You can run the whole service on a Linux machine today, and every change is tested on real Firecracker microVMs with the E2B compatibility and escape suites. Watch the repository to hear when it ships, or see what is verified.

Give your agents a computer, not your data

Run the whole stack on your machine in about five minutes, and be the first to know when the release is out.