Your data stays in your account
Sandboxes, templates, logs and secrets live in your VPC, encrypted with your KMS key. Weft has no access to your stack.
Compatible with the E2B SDKs
Run the code your agents write in isolated Firecracker microVMs that live in your VPC, not someone else's cloud. Keep your SDK code: point it at your stack with three environment variables.
# Point the E2B SDK at your stack
# E2B_API_URL=https://api.sandbox.example.com
# E2B_DOMAIN=sandbox.example.com
from e2b import Sandbox
sbx = Sandbox.create() # a fresh microVM
# Run code your agent wrote
sbx.files.write("analysis.py", code)
print(sbx.commands.run("python3 analysis.py").stdout)
# Share the app it built, inside your network
sbx.commands.run("npm run dev", background=True)
print(sbx.get_host(3000))
# 3000-<id>.sandbox.example.com
Built on proven pieces
Why Weft Sandboxes
Hosted sandboxes mean sending code, files and credentials to someone else's infrastructure. Weft Sandboxes runs the same workflow where your data already lives.
Sandboxes, templates, logs and secrets live in your VPC, encrypted with your KMS key. Weft has no access to your stack.
The unmodified e2b packages for Python and JavaScript work as they are. Switching takes three environment variables.
Every sandbox runs its own Linux kernel in a jailed Firecracker microVM. It cannot reach the host, the metadata service or other sandboxes.
Outbound traffic is denied by default. Allow the hosts each team needs; every connection is checked and written to an audit log.
The egress gateway adds API keys from AWS Secrets Manager to allowed requests. The key never enters the sandbox.
One CloudFormation stack with your IAM, VPC, CloudWatch and Auto Scaling. Pay AWS directly; delete the stack to remove it.
Drop-in
Weft Sandboxes speaks the API the E2B SDKs already use, and runs the same in-sandbox agent. Your code does not change.
export E2B_API_URL=https://api.sandbox.example.com
export E2B_DOMAIN=sandbox.example.com
export E2B_API_KEY=weft_sk_...
How it works
Templates are booted once and saved as snapshots, so every new sandbox starts with its tools already running.
The E2B SDK talks to your stack's API over HTTPS, inside your network.
It picks a host with room and hands it the template and the team's egress policy.
Each sandbox is a jailed Firecracker microVM on an EC2 host that scales with demand.
Every outbound connection is checked, logged, and given credentials if the policy says so.
Security
Agent-written code is untrusted by definition. Every layer assumes the sandbox is hostile.
Once a day, for online licenses, and nothing else. No code, no data, no telemetry. Offline and AWS Marketplace licenses send nothing at all.
{
"keyId": "lic_…",
"version": "0.1.0",
"region": "eu-west-1",
"peakConcurrent": 12
}
The field list is fixed in the source code and checked by a test. Licensing details
Use cases
Let LLM apps analyze data, make charts and run what they write.
Clone repos, install dependencies and run tests in a real environment.
Every app an agent builds gets its own URL inside your network.
Run many isolated attempts in parallel, on hosts that scale.
Notebooks, playgrounds and grading systems, safely contained.
Deploy
Try the whole service on a Linux machine today. With the first release, install it in your AWS account with a single CloudFormation stack.
Step 1
Enter a domain, a certificate source and your license key. The stack is designed to be ready in about 15 minutes.
Step 2
Step 3
Set three environment variables. Existing E2B SDK code runs unchanged.
You pay AWS directly. With defaults in us-east-1: about $220–230 a month for the always-on services, plus about $290 a month per On-Demand host. Spot hosts cost less.
FAQ
No, only three environment variables. A few SDK features are not supported yet (auto-resume, snapshots and fork, template steps like RUN); they return a clear error instead of misbehaving.
Only the daily license check shown above, with four fields. Offline and AWS Marketplace licenses send nothing. Your sandboxes reach only what your egress policy allows.
C8i, M8i and R8i instances with nested virtualization, or bare-metal instances. A c8i.2xlarge runs about 21 sandboxes of 512 MiB, and hosts are added automatically as demand grows.
The core is source-available under the Functional Source License: free to use, modify and self-host for anything except offering a competing service, and each release becomes Apache-2.0 two years later. The SDK, CLI and deployment templates are Apache-2.0 today.
With the first signed release, which publishes Launch Stack links for every supported Region. You can run the whole service on a Linux machine today, and every change is tested on real Firecracker microVMs with the E2B compatibility and escape suites. Watch the repository to hear when it ships, or see what is verified.
Run the whole stack on your machine in about five minutes, and be the first to know when the release is out.