Tech riderRev. 5 Oct 2026
Anthropic Sandbox Runtime
- 1Runs onLinux, Mac, self-hosted, Windows
- 2CostsFree plan
- 3Isolation methodcontainer
- 4Network controlsYes
- 5API or CLI accessYes
- 6Deploymentself hosted
6 lines stated Written from the maker's own pages: github.com

Overview
Anthropic Sandbox Runtime is ranked #7 of 22 in sandbox software on Specifiction. It runs on Linux, macOS, Self-hosted, Windows. There is a free plan.
Anthropic Sandbox Runtime plans and pricing
All plansAnthropic Sandbox Runtime Free Open source research preview · no paid plans or usage limits stated github.com · 5 Oct 2026
Compared on sandbox software
- Isolation method
- containergithub.com
- Network controls
- Yesgithub.com
- API or CLI access
- Yesgithub.com
- Deployment
- self_hostedgithub.com
Facts
- Purpose
- Anthropic Sandbox Runtime (srt) enforces filesystem and network restrictions on arbitrary processes at the OS level without requiring a container.github.com · 5 Oct 2026
- Availability
- The project is an open source research preview licensed under Apache-2.0.github.com · 5 Oct 2026
- How to install
- The README gives `npm install -g @anthropic-ai/sandbox-runtime` as the installation command.github.com · 5 Oct 2026
- Use cases
- The README says srt can sandbox agents, local MCP servers, bash commands, and arbitrary processes, and can be used as a CLI tool or library.github.com · 5 Oct 2026
- Filesystem controls
- Filesystem configuration supports read and write restrictions, with writes denied by default unless paths are explicitly allowed.github.com · 5 Oct 2026
- Platforms
- The project supports macOS and Linux, and lists Windows support as alpha.github.com · 5 Oct 2026
- Platform mechanisms
- The README says macOS uses sandbox-exec, Linux uses bubblewrap, and Windows uses a dedicated local sandbox account with Windows Filtering Platform egress filtering.github.com · 5 Oct 2026
- Linux dependency
- Linux requires bubblewrap, socat, and ripgrep; macOS requires ripgrep.github.com · 5 Oct 2026
- Windows setup
- Windows requires a one-time elevated `windows-install` step, while the helper executable is bundled with the npm package.github.com · 5 Oct 2026
- Violation monitoring
- On macOS, srt can tap the system sandbox violation log store for real-time alerts; Linux bubblewrap does not provide built-in violation reporting.github.com · 5 Oct 2026
- Security limitation
- The README says network filtering restricts reachable domains but does not otherwise inspect traffic through the proxy, so users are responsible for allowing only trusted domains.github.com · 5 Oct 2026
- Linux limitation
- Linux network filtering relies on proxy environment variables, so programs that ignore them may be unable to connect to the internet.github.com · 5 Oct 2026
- Windows limitation
- On Windows, tools using schannel with certificate revocation checking enabled by default can fail because revocation requests are blocked by the egress fence.github.com · 5 Oct 2026
- Preview status
- The README describes the runtime as an early research preview developed for Claude Code and warns that APIs and configuration formats may evolve.github.com · 5 Oct 2026
- Interfaces
- It is available as both a command-line tool and a library, installed from npm as @anthropic-ai/sandbox-runtime.github.com · 5 Oct 2026
- Operating systems
- The project documents macOS, Linux, and Windows support; Windows is marked alpha.github.com · 5 Oct 2026
- Platform implementation
- It uses sandbox-exec on macOS, bubblewrap on Linux, and a dedicated local user account with Windows Filtering Platform and filesystem ACLs on Windows.github.com · 5 Oct 2026
- Monitoring
- The runtime tracks sandbox violations, and on macOS it can tap into the system sandbox violation log store for real-time alerts.github.com · 5 Oct 2026
- Integrations
- The README shows using srt to sandbox Model Context Protocol servers and documents a Java agent for JVM tools on macOS and Linux.github.com · 5 Oct 2026
- Security caveat
- The project warns that enabling weaker nested sandboxing on Linux considerably weakens security and should be used only with additional isolation.github.com · 5 Oct 2026
- Linux requirements
- Linux requires bubblewrap, socat, and ripgrep, and some configurations also require additional system setup.github.com · 5 Oct 2026
- Windows limitations
- On Windows, per-user tool installations may not be accessible to the sandbox account, and some schannel clients can fail when certificate revocation checks are enabled.github.com · 5 Oct 2026
- Intended users
- Anthropic describes the release as an early open source preview for the broader ecosystem to build more secure agentic systems; APIs and configuration formats may evolve.github.com · 5 Oct 2026
- Maker
- Anthropic describes itself as an AI safety and research company that builds reliable, interpretable, and steerable AI systems.anthropic.com · 5 Oct 2026
Best Anthropic Sandbox Runtime alternatives
See all 20 All accessCh 01 ANY.RUN Free planFree trialAndroid Free to start8.0 All accessCh 02 Daytona Free planFree trialAPI Free to start7.6 All accessCh 03 Northflank Free planAPILinux Free to start7.4 All accessCh 04 Zscaler Private Access AndroidiOS 7.4 All accessCh 05 Docker Desktop Free planLinuxMac from $9/mo7.3 All accessCh 06 microsandbox Free planAPILinux from $49/mo7.2
Where it ranks on Specifiction
- Best Sandbox Software in 2026#7 of 22
Is Anthropic Sandbox Runtime yours?
Claim it for free: prove the domain, then correct facts, plans and screenshots. An editor reviews every change.
Sources
- github.com/anthropics/sandbox-runtime· checked 5 Oct 2026
- anthropic.com/company· checked 5 Oct 2026





