The agent sandbox meter has not converged
The agent's execution sandbox has become a billable unit at roughly ten corpus vendors, but nobody agrees what the unit is — seven distinct shapes are live simultaneously and only per-vCPU-time plus per-memory-time has more than one adopter. The shapes are not inter-convertible without knowing a sandbox's core count, duration and now its region.
What's happening — and why
What's happening: agents now hold long-lived stateful compute, which neither a token meter nor a request meter prices. So vendors started billing the sandbox — and each picked a different unit.
The divergence is structured, not random. Infrastructure-shaped meters bill for capacity held: per-vCPU-second, per-GB-hour of provisioned memory. Session-shaped meters bill for agent time: a flat fee per container session with a billing window, or a fee per block of runtime. Perplexity charges $0.03 per container session documented as covering up to 20 minutes of active use for billing purposes, explicitly a billing window and not a runtime cap. Linear charges $0.25 per 20-minute block. Vercel charges $0.128 per hour of Active CPU plus $0.0212 per GB-hour of provisioned memory — and, since August 2026, about 38% more if the workload runs in Paris or San Francisco than in Cleveland.
The two families are not inter-convertible without knowing a sandbox's core count and duration, which is exactly what a buyer does not know before deployment — and the regional multiplier adds a third unknown.
The open question is which family wins. If the session shape spreads, the sandbox becomes its own unit. If vendors fall back to vCPU-time, it was never a new unit at all — only cloud compute at a multiplier, which is what Modal already says out loud at roughly 3x its own standard function rates.
How it works
Evidence over time
14 supporting · 3 counter — hover or tap a point for detail, click to jump to the row.
Evidence
| Company | Date | What happened |
|---|---|---|
| Perplexity | Jul 2026 | Added a fifth Agent API tool, `sandbox`, at $0.03 per container session — the docs are explicit that "a session covers up to 20 minutes of active use for billing purposes; this is the billing window, not a runtime cap." The changes record calls it Perplexity's first meter that counts neither tokens nor requests. SDK search queries issued from inside the sandbox bill separately at $0.005, halved to $0.0025 on 2026-07-29 while the $0.03 per-session fee was left untouched. The only flat-per-session sandbox price in the corpus. |
| Anthropic | Jun 2026 | Claude Managed Agents bills $0.08 per session-hour of runtime as a second meter on top of standard token rates, measured to the millisecond and accruing only while session status is "running" — and it explicitly REPLACED Code Execution container-hour billing, so Anthropic has already changed its own sandbox unit once. Restated on the API pricing page at the 2026-07-23 capture. The only per-session-hour price in the corpus. |
| Modal | Jul 2026 | Shipped a dedicated Sandbox + Notebooks rate card at $0.00003942/core/sec CPU and $0.00000667/GiB/sec memory (= $0.142/core-hr, $0.024/GiB-hr) — roughly 3x the standard function rates — while GPU on sandboxes still follows the standard per-second card. The same release itemised region selection at 1.5-1.75x and non-preemptible execution at 3x, so Modal frames the sandbox not as a new unit but as ordinary compute with a multiplier. |
| Together AI | Jul 2026 | Code Sandbox published at $0.0446/vCPU-hour plus $0.0149/GiB-hour, a two-part compute-plus-memory unit, confirmed unchanged week-over-week alongside dedicated inference and GPU-cluster rates. The cleanest example of the plurality shape stated in hours rather than seconds, which is itself a comparison tax: three of the four vendors using this shape denominate per second. |
| Novita AI | Jun 2026 | The earliest sandbox meter in the corpus (Agent Sandbox live on the pricing page's own tab by the 2025-08-04 Wayback snapshot) began publishing its underlying per-unit rate card on 2026-06-24: $0.0000098/vCPU-second, $0.0000032/GiB-second and $0.00009/GB-hour with the first 60 GB included, alongside a $100 / 90-day free-credit offer. Novita's own worked example prices a 5-minute coding-agent task on 1 vCPU + 512 MiB at roughly $0.0034. Unchanged at the 2026-07-21 and 2026-07-29 captures. |
| Upstash | Mar 2026 | Box prices agent sandboxes per ACTIVE CPU hour — $0.10 Small / $0.20 Medium / $0.40 Large — with idle boxes costing nothing and freezing automatically, plus storage at $0.10/GB/month. The vendor's own worked example: "using 100% of 2 cores for one hour costs $0.2, while using 10% of a single core for one hour costs $0.01." A flat Keep-Alive always-on mode was added in June 2026 at $8/$16/$32 per month, replacing both CPU and storage billing on that box — two different units for the same product. Free tier 10 concurrent boxes / 5 CPU hours per month; the page still carries a "pricing may change" Developer Preview banner. |
| LangChain / LangSmith | Jul 2026 | Sandbox rates were re-denominated out of dollars into proprietary LCU/LSU units at exactly the prior price (0.0384 LCU/vCPU-hr x $1.50 = $0.0576/vCPU-hr, the previously published rate), inside a wider collapse of a seven-meter rate card into two normalised units. The unit shape is unchanged; its comparability to other vendors is gone. Seats held at $0 Developer / $39 Plus. |
| OpenAI | Jul 2026 | The GPT-5.6 API refresh added Containers tool pricing: 1 GB for $0.03 or 64 GB for $1.92 per container — a flat price tiered by container SIZE, not time — with the pricing table noting the SKU moves to per-20-minute-session-per-container billing from March 31, 2026, a date already past at capture, so both shapes are documented on the page at once. The $0.03 figure is identical to Perplexity's per-session fee and the 20-minute window identical to Perplexity's billing window. |
| Upstash | Aug 2026 | The unit stabilised without converging. Box dropped the "Upstash Box is in Developer Preview! APIs and pricing may change" banner that had been live since at least 2026-07-22, with no "generally available" language replacing it — the caveat was simply removed. In the same capture Keep Alive stopped being a fourth top-level plan card next to Free / Pay as You Go / Enterprise and became a size toggle inside the Pay-as-You-Go card, which narrows but does not close the two-units-for-one-product gap this trend cited: Box is still sold either per ACTIVE CPU hour ($0.10/$0.20/$0.40 Small/Medium/Large) or at a flat $8/$16/$32 a month. Every rate unchanged, including $0.10/GB/month storage. A vendor removing its own "pricing may change" disclaimer while keeping two incompatible meters for the same box is the cleanest evidence that the divergence is settled-in rather than transitional. |
| Vercel | Aug 2026 | A tenth vendor with a sandbox product and still no tenth shape — Vercel rations rather than prices it. Concurrent Sandboxes rose from 2,000 to 10,000 on Pro and Enterprise, and the fixed vCPU allocation rate of 200/min on Pro was replaced by a dynamic quota ramping to 5,000/min, both at unchanged plan prices, in the same release that cut v0 Mini/Pro token rates and added a Trace Drains SKU. Vercel publishes no sandbox-specific per-unit rate: the capacity is governed by plan quota and the resources bill against its general Active-CPU/provisioned-memory card. That is Cognition's posture (quota rationing, no published sandbox unit) arriving at a platform vendor — which counts against convergence, not for it. |
| Perplexity | Aug 2026 | The flat-per-session price is the most stable number in the cluster. Perplexity's Agent API tool card moved twice in seventeen days — web_search and fetch_url were halved on 2026-07-29, then fetch_url doubled back to $0.0005 on 2026-08-14, a full round trip corroborated by the docs' own worked example rising from $0.00675 to $0.007 — and the $0.03 sandbox per-session fee did not move on either occasion. The only vendor in the corpus with a flat-per-session sandbox meter has now held it through two repricings of the tools immediately adjacent to it. |
| Composio | Jul 2026 | Two of the six metered dimensions replacing its single tool-call meter (effective 2026-08-15, existing customers grandfathered to 2026-12-31) are sandbox GB-hr and filesystem GB — storage-shaped units for the same capability Perplexity sells per session and Anthropic per session-hour. The only vendor in the corpus pricing a sandbox primarily on bytes held rather than on compute or time. |
| Vercel | Aug 2026 | The infrastructure-shaped family gains a GEOGRAPHIC dimension, pushing the two families further apart rather than closer. Vercel Sandbox expanded from iad1 to four regions and disclosed a ~38% regional price gap: iad1/cle1 hold at $0.128/hr Active CPU and $0.0212/GB-hr Provisioned Memory while cdg1 (Paris) and sfo1 (San Francisco) run $0.177/hr and $0.0292-$0.0294/GB-hr. A per-vCPU-time-plus-memory-time meter now also varies by placement, so converting it to a session price requires knowing the region as well as the core count and duration. |
| Linear | Aug 2026 | A NEW ADOPTER in the session-shaped family, at the cleanest price point yet: $0.25 per 20-MINUTE BLOCK of sandbox runtime, billed alongside model tokens at provider-published rates with no markup. This is the same shape as Perplexity's $0.03-per-session 20-minute billing window and OpenAI's Containers, but priced as a repeating block rather than a single session fee — a seventh distinct shape, and the second vendor to choose 20 minutes as the quantum. |
Counterexamples
- E2B · Jul 2026 — The pure-play bounds the whole claim. E2B is a sandbox company, so its unit is a product decision rather than a packaging experiment — and it uses the plurality shape: $0.000014/s per vCPU (the default 2-vCPU sandbox is $0.000028/s) plus $0.0000045/GiB-second RAM and storage, on a $0 Hobby / $150-per-month Pro access fee that grants ceilings, not credits. Per-vCPU rates have not moved across the full tracked range. If the generalist platforms converge on this shape, the "agent sandbox meter" was never a new unit — it was E2B's unit, and cloud compute's before that.
- Fireworks · Jul 2026 — One of the most active packaging movers in the corpus declined the meter entirely. In the same fortnight it shipped Fire Pass (a zero-per-token non-production pass, upgraded on 2026-07-29 to grant Kimi K3 Fast at a 1M-token context) and a Serverless Training API metered across four new token dimensions ($0.66-$32.55 per 1M by stage and model) — but added no sandbox dimension. A vendor willing to add four meters in a week and not this one is evidence the unit is optional, not inevitable.
- Cognition (Devin) · Jul 2026 — Sells cloud agent sessions and publishes no per-sandbox rate at all. Devin Cloud sessions became paid-only at the 2026-07-21 plan-table split, but they are rationed by plan-level quota (Max advertises a "weekly allowance with no daily cap", up to 10 concurrent sessions) with Enterprise billed in Agent Compute Units "at the rate set in their order form". Prices held at $0/$20/$200 and $80 + $40 per full dev seat. The agent-session vendor most exposed to sandbox cost is the one that publishes no sandbox unit.
Trivia
-
The unit shapes diverge but the price level does not, which is why the non-convergence is easy to miss. Price 20 minutes of a small sandbox three ways and the answers land within about 35% of each other on three incompatible meters: Perplexity charges a flat $0.03 per session with a 20-minute window (2026-07-21); Anthropic's $0.08 per session-hour (2026-06-15) works out to $0.027; E2B's default 2-vCPU/512-MiB sandbox at $0.000028/s compute plus $0.0000045/GiB-s memory comes to about $0.036. OpenAI's Containers price for a 1 GB container is also exactly $0.03. The convergence is illusory — Perplexity's price is invariant to cores and duration, Anthropic's scales with wall-clock, and E2B's scales with cores times seconds, so the ranking flips the moment the workload changes shape.
-
Anthropic is the only vendor in the corpus that has already replaced its own sandbox unit: the Claude Managed Agents meter announced 2026-06-15 — $0.08 per session-hour, measured to the millisecond and accruing only while session status is "running" — explicitly superseded Code Execution container-hour billing. LangSmith did something subtler on 2026-07-21, re-denominating its sandbox rate out of dollars into its own currency at exactly the prior price (0.0384 LCU x $1.50 = $0.0576 per vCPU-hr), which removed the number from cross-vendor comparison without changing what it costs.
-
The sandbox meter is older than the agent-pricing debate around it. The earliest instance in the corpus is Novita's Agent Sandbox, live on a per-vCPU-second and per-GiB-second rate card by 2025-08-04 — seven months before Upstash Box (2026-03-09) and eleven before Perplexity's per-session price — and pure per-second compute is still the plurality shape at 4 of the 9 vendors. Converted to a common denominator, four of them land in a narrow band (Novita $0.035/vCPU-hr, Together AI $0.0446, E2B $0.050, LangSmith $0.0576) while Modal deliberately sits 2.4-4x above at $0.142/core-hr, which it describes as roughly 3x its own standard function rate.
For buyers
You cannot compare sandbox pricing across vendors on the rate card alone, so do not try. Run the same representative agent task on each candidate and compare the invoice, because a per-session fee and a per-vCPU-second rate produce wildly different bills for the same work depending on concurrency and idle time. Two specific traps: a billing window is not a runtime cap, so a 30-second call and a 19-minute call can cost the same; and provisioned-memory meters bill for capacity held, not capacity used, so an over-provisioned sandbox that sits idle still costs money. If you deploy multi-region, price each region — the same Vercel sandbox costs about 38% more in Paris than in Cleveland.
For vendors
Whichever family you choose, publish the conversion. The buyer's real problem is not your price level but their inability to forecast it, and the vendor that ships a worked example — this agent task, this duration, this bill — removes the single biggest obstacle to adoption. If you bill infrastructure-shaped, publish a typical session cost. If you bill session-shaped, publish what the window covers and what happens when a session exceeds it. The session shape is winning on legibility even where it is more expensive, because it is the only one a buyer can budget before deploying.
Outlook — what to watch
The divergence widened rather than converged in the latest window, on both families at once. The session family gained a new adopter and a seventh shape — Linear's $0.25 per 20-minute block, the same 20-minute quantum Perplexity chose but charged as a repeating block rather than a one-off session fee. The infrastructure family got harder to convert, with Vercel adding a regional multiplier on top of an already two-dimensional meter. So the open question is no closer to an answer, and the cost of the divergence to buyers has gone up. Convergence would most likely arrive through an agent framework standardising a unit rather than through vendors agreeing.
Bottom line
Ten vendors bill the agent sandbox and seven different units are live at once, split into two families that cannot be converted into each other without knowing a sandbox's cores, duration and region. Benchmark by running the workload, not by reading the rate card.
FAQ
Why do agent sandboxes have so many different prices?
Because agents hold long-lived stateful compute, which neither a token meter nor a request meter prices, so each vendor invented its own unit. Seven shapes are live simultaneously and only per-vCPU-time plus per-memory-time has more than one adopter.
Is a per-session sandbox fee cheaper than per-vCPU-second?
It depends entirely on your concurrency and idle time, and the two are not convertible without knowing the sandbox's core count and duration — which you generally do not know before deploying. The only reliable comparison is running the same representative task on each and comparing invoices.
What is a billing window?
A minimum unit of charge, not a runtime limit. Perplexity documents its $0.03 sandbox fee as covering up to 20 minutes of active use for billing purposes and states explicitly that this is the billing window, not a runtime cap — so a 30-second session and a 19-minute one cost the same.
Is the sandbox really a new billing unit?
That is the open question. If the session shape spreads it becomes its own unit; if vendors fall back to vCPU-time it was never new, only cloud compute at a multiplier — which Modal already says out loud, pricing sandboxes at roughly 3x its own standard function rates.