Firecracker sandboxes for AI agents
Run untrusted, AI-generated code in an isolated Linux microVM that starts in about a second. Call it from Python, TypeScript or any MCP client. Billed per second from a crypto balance — no subscription, no minimum, no KYC.
$1 free to try — confirm your email and it's added to your first sandbox, no top-up needed
pip install eqvps
export EQVPS_API_KEY="<your API token>"
python -c "from eqvps import Sandbox; s = Sandbox.create(); print(s.run('print(2+2)').stdout); s.kill()"TypeScript: npm i @eqvps/sdk · MCP: https://mcp.eqvps.com/mcp
Why not Docker or your own server?
A sandbox is for running untrusted code — a stranger's GitHub repo, a package you haven't read, code an AI just wrote — somewhere it can't reach anything of yours.
On your laptop or server
- Runs next to your SSH keys, API tokens and .env files
- Can read your databases, source code and browser sessions
- A container shares the host kernel — one escape and it's on your machine
- Whatever it installs or leaves running stays with you
In an EQVPS sandbox
- Its own Firecracker microVM: separate kernel, CPU, RAM and disk
- Nothing of yours inside — only the files and env vars you pass in
- Outbound internet for pip, npm and git; no SSH, no inbound ports
- kill() deletes the VM and its disk — nothing is left behind
Rule of thumb: if you didn't write it and haven't read it, run it in a sandbox first.
Use cases
AI code execution and testing code in isolation — each one is a few SDK lines or MCP calls.
Check an unfamiliar GitHub project
Clone it, install the dependencies and run the tests. If the code turns out to be hostile, all it sees is an empty VM.
sb = Sandbox.create(tariff="standard")
r = sb.exec(
"git clone https://github.com/owner/repo app"
" && cd app && pip install -r requirements.txt"
" && pytest -q", background=True).wait()
print(r.exit_code); sb.kill()Run tests without touching production
PHP with Composer and PHPUnit, Python with pytest, Node with npm test — on a clean machine instead of your server. Root and apt are available.
# app/ = your repo (git clone or sb.upload)
sb.exec("apt-get update -qq && apt-get install -y -qq"
" php-cli php-xml php-mbstring composer",
background=True).wait()
sb.exec("cd app && composer install -q"
" && vendor/bin/phpunit", background=True).wait()A throwaway PostgreSQL or Node for a migration or build
Install a database with apt, try the migration, build the frontend, then delete everything in one call. Take standard or bigger for a database.
sb = Sandbox.create(tariff="standard")
sb.exec("apt-get update -qq && apt-get install -y -qq"
" postgresql", background=True).wait()
sb.exec("runuser -u postgres -- createdb app")
sb.exec("cd app && npm ci && npm run migrate"
" && npm run build", background=True).wait()An AI coder that tests its own work
The agent creates a sandbox, writes the code, runs the tests, fixes what failed and kills the sandbox once everything passes.
create_sandbox {"tariff": "small"}
upload_file app/main.py, app/test_main.py
exec_command "cd app && pytest -q" → 2 failed
upload_file app/main.py (fixed)
exec_command "cd app && pytest -q" → passed
kill_sandboxYour first sandbox in 4 steps
- 01
Sign up
Email only — or let your agent call register_account over MCP. No card, no KYC.
- 02
Create an API token
Dashboard → Settings → API tokens.
- 03
Install the SDK
pip install eqvps or npm i @eqvps/sdk, then set EQVPS_API_KEY.
- 04
Run code
Sandbox.create() → run() → kill(). Your $1 trial covers the first runs.
What you get
Firecracker isolation
Every sandbox is its own microVM with its own kernel, disk and CPU/RAM limits — not a shared container.
Ready in about a second
Python 3.12 with pip, Node.js 22 with npm, bash, git and curl. Outbound internet works; no inbound ports.
Per-second billing, no floor
Pay only for allocated vCPU and RAM while it runs. No subscription, no monthly minimum.
MCP sandbox, built in
create_sandbox, run_code and exec_command are MCP tools — Claude Code, Cursor and other clients use them as is.
No-KYC, crypto balance
Email-only account and a prepaid balance in USDC, USDT, BTC, XMR and more — the same balance as your VPS.
Ephemeral or persistent
Throwaway sandboxes for one task, or persistent ones that keep their disk for up to 30 days. Env vars and spending limits included.
Pricing
$0.040 per vCPU-hour + $0.013 per GiB-hour, billed per second (minimum 60 s). Persistent sandboxes are billed per started hour, and a month never costs more than the cap in the last column.
| Tariff | vCPU | RAM | Disk | Network | Per hour | Persistent, month max |
|---|---|---|---|---|---|---|
| micro | 0.25 | 512 MB | 3 GB | 50 Mbit/s | $0.0165 | $9.03 |
| small | 0.5 | 1 GB | 5 GB | 100 Mbit/s | $0.0330 | $18.07 |
| standard | 1 | 2 GB | 10 GB | 200 Mbit/s | $0.0660 | $36.14 |
| plus | 2 | 4 GB | 15 GB | 300 Mbit/s | $0.1320 | $72.27 |
| pro | 4 | 8 GB | 20 GB | 400 Mbit/s | $0.2640 | $144.54 |
| max | 8 | 16 GB | 40 GB | 500 Mbit/s | $0.5280 | $289.08 |
The last column is a ceiling, not a fixed price: a persistent sandbox that runs only part of the month costs less.
Persistent sandbox: an AI dev environment
For long agent tasks and projects you come back to: the disk, installed packages and files stay for up to 30 days, and you reconnect by sandbox ID.
How the cap works: a running persistent sandbox is billed per started hour, and a calendar month never costs more than hourly × 730 h − 25%. Example, standard: $0.0660/h, so at most $36.14 a month — 10 days around the clock cost $15.84.
sb = Sandbox.create(mode="persistent", tariff="standard")
print(sb.id) # keep it — disk lives up to 30 days
# … tomorrow, from any machine:
sb = Sandbox.connect("sb_…")
sb.exec("cd app && git pull && pytest -q")A complement to your VPS, not a replacement
Same account, same balance — use each for what it is built for.
VPS — a server that stays
SSH, a public IP, open ports and services that run for months: a website, a bot, a database.
Sandbox — disposable compute for AI
Create → run → delete. No SSH and no inbound ports by design: commands and files go through the API, MCP or SDK.
Use it from your MCP client
Connect once, then ask your agent in plain words — it creates the sandbox, runs the code and deletes it.
claude mcp add --transport http eqvps https://mcp.eqvps.com/mcp \
--header "Authorization: Bearer $EQVPS_API_KEY"Create a small sandbox, run print(2 + 2) in Python, show me the output and delete the sandbox.FAQ
What is an EQVPS sandbox?
A small Linux microVM (Firecracker) that you create through the API, SDK or MCP to run code you do not want on your own machine — AI-generated scripts, tests, data jobs. It starts in about a second and is deleted when you are done.
How is it isolated?
Each sandbox is a separate Firecracker microVM with its own kernel, disk and CPU and memory limits. Outbound internet is open; there are no inbound ports and no SSH — commands and files go through the API.
How much does it cost? Is there a free trial?
$0.040 per vCPU-hour plus $0.013 per GiB-hour, billed per second; the smallest tariff is $0.0165 per hour. A new account gets $1 of free sandbox credit on its first sandbox (one per person), valid for 14 days. The trial is credited after you confirm your email with a 6-digit code.
Do I need KYC or a card?
No. Sign up with an email and top up a prepaid balance in crypto (or by card on the payment page). The same balance pays for sandboxes and VPS.
Can my AI agent use it on its own?
Yes. Over MCP an agent can register, check prices with sandbox_pricing, create a sandbox and run code without a human. From code, use the Python or TypeScript SDK.
Can I SSH into a sandbox or open a port?
No, by design: a sandbox has no SSH and no inbound ports — commands and files go through the API, MCP or SDK, and outbound internet works. For SSH, a public IP and long-running services, use an EQVPS VPS on the same balance.
Try it now — the first $1 is on us
No subscription, no KYC. Sign up, create a token and run your first sandbox in a few minutes.