Daytona
What is Daytona?
Daytona is an isolated sandbox platform for AI platform teams that need safe execution for generated code and agent workflows. It combines Fast, Scalable, Stateful Infrastructure, Separated & Isolated Runtime Protection, Massive Parallelization, and Environment Snapshots, with SDK, RESTful API, and CLI control. Customers include LangChain, SambaNova, and Stanford's CS Department. Pricing is usage-based, with vCPU at $0.0504/h, GPU Nvidia H100 at $3.95/h, and Storage at $0.000108/h.
Last verifiedHow we evaluate
At a glance
- Daytona is best for AI platform teams who need isolated, fast sandboxes for agent code execution.
- Yes — The page advertises a RESTful API and programmatic control for creating sandboxes, executing code, and managing files and Git operations.
What changed: the core platform is no longer open source
The daytonaio/daytona repository (71,722 stars, AGPL-3.0) carries a banner as of this writing: "This repository is no longer maintained. As of June 2026, Daytona's core development has moved to a private codebase. This repository will receive no further updates, fixes, or releases." (https://github.com/daytonaio/daytona). GitHub has not flagged the repo archived: true at the API level, but the commit history backs the banner up: the last commit to main is the maintenance notice itself, dated 25 June 2026, and nothing has landed since (https://api.github.com/repos/daytonaio/daytona/commits). The repo remains public under its original AGPL-3.0 licence (v0.190.0 is the last tagged release, 23 June 2026) and will keep building and running as-is — there just won't be new features, bug fixes, or security patches shipped to it.
What's still open is a separate daytona/clients repository (SDKs, API clients, CLI/MCP tools) that is actively maintained — last push 11 September 2026 — and dual-licensed: the CLI under AGPL-3.0, everything else under Apache-2.0 (https://github.com/daytona/clients, https://raw.githubusercontent.com/daytona/clients/main/LICENSE). So a buyer who came to Daytona expecting an open-core product they could self-host and inspect end-to-end now gets open client libraries talking to a closed server. The commercial product hasn't slowed down — the changelog shows a release roughly every 1-2 weeks through September 2026 (https://www.daytona.io/changelog) — but that development now happens outside public view. There is no self-hosting documentation left on the current docs site.
What it does well: fast, isolated, usage-billed sandboxes at real scale
Daytona's pitch is sub-90ms sandbox creation with full isolation (dedicated kernel, filesystem, network stack) for running untrusted AI-generated code — a claim the vendor makes and we have not independently benchmarked, but it's specific rather than vague marketing (https://github.com/daytona). What is corroborated: several substantive, named customer case studies rather than logo-wall claims. WRITER's CTO is quoted saying Daytona now provisions roughly 300,000 sandboxes a month for their enterprise agent platform, citing 90% infrastructure-cost savings versus their prior in-house AWS Fargate build (https://www.daytona.io/customers/writer, vendor-published case study). Stanford's CS department, SambaNova, and Snorkel are also named customers with their own case studies (https://www.daytona.io/customers) — these are still vendor-published and should be read as testimonials, not audited results, but named enterprise and academic customers willing to be quoted is a stronger signal than most listings on this site can offer.
Billing is genuinely usage-based and per-second: compute at $0.0504/vCPU-hour, memory at $0.0162/GiB-hour, storage at $0.000108/GiB-hour after the first 5GB free, plus a GPU menu spanning RTX 4090 ($0.57/h) up to B200 ($3.59/h) and MI355X ($3.44/h) (https://www.daytona.io/pricing, verified 2026-09-10 per the page's own timestamp). New accounts get $200 in free compute; a startup program offers up to $50k in credits.
Security posture and transparency
Daytona runs a public SafeBase trust center (https://trust.daytona.io) that goes further than most vendors in this index: it discloses named subprocessors (AWS, OVHcloud, Latitude.sh, Lago, Stripe), a SOC 2 Type I report, and a SOC 2 Type II report the vendor says was issued 28 July 2026 by Insight Assurance covering 16 December 2025 through 15 March 2026, plus a HIPAA attestation. It also publishes a named CVE disclosure: CVE-2026-31431 ("Copy Fail"), a Linux kernel AF_ALG/algif_aead vulnerability disclosed 29 April 2026 that could theoretically let one sandbox tenant corrupt kernel page-cache content visible to a co-tenant sandbox on multi-tenant hosts. Daytona states it remediated across all regions within 12 hours, found no evidence of exploitation, and confirms its Sysbox container-isolation boundary was not breached (https://trust.daytona.io, vendor security-advisory update). Publishing a CVE against your own infrastructure, with a specific remediation timeline, is unusual disclosure and worth noting as a positive signal — though it is self-reported and we have no independent confirmation of the 12-hour figure.
Company size and funding
Daytona (legally Daytona Platforms Inc.) was founded in 2023 by a team with prior experience building Codeanywhere. Disclosed funding is a $2M pre-seed round (announced November 2023, per PR Newswire and TechCrunch coverage) and a $5M seed round (announced June 2024, led by Upfront Ventures per Dot LA's newsletter coverage) — roughly $7M total across the two rounds (https://www.daytona.io/press). We found no publicly reported funding round since June 2024; that is an absence in what we could find, not a claim that none occurred. The product pivoted from a self-hosted "development environment manager" (its original open-source positioning through 2024) to AI-sandbox infrastructure, which is the product described throughout this listing.
How much does Daytona cost?
| Plan | Price | What's included |
|---|---|---|
| Storage: GiB | $0.000108/h |
|
Frequently asked questions
What is Daytona?
Daytona is an isolated sandbox platform for AI platform teams that need safe execution for generated code and agent workflows. It combines Fast, Scalable, Stateful Infrastructure, Separated & Isolated Runtime Protection, Massive Parallelization, and Environment Snapshots, with SDK, RESTful API, and CLI control. Customers include LangChain, SambaNova, and Stanford's CS Department. Pricing is usage-based, with vCPU at $0.0504/h, GPU Nvidia H100 at $3.95/h, and Storage at $0.000108/h.
How much does Daytona cost? Is it free?
Daytona has 5 paid plans: Compute: vCPU at $0.0504/h, Compute: GPU Nvidia H100 at $3.95/h, Compute: GPU Nvidia RTX PRO 6000 at $3.03/h.
What is Daytona used for? Who is it for?
Daytona is used for Fast, Scalable, Stateful Infrastructure, Separated & Isolated Runtime Protection, and Massive Parallelization. It's built for AI platform engineers, Developer tooling teams, and ML and agent teams.
Does Daytona have an API and what does it integrate with?
The page advertises a RESTful API and programmatic control for creating sandboxes, executing code, and managing files and Git operations. It integrates with Git, Slack, Google, GitHub, Claude, and 3 more.
Editor's read
Check whether your workload needs self-hosted deployment or customer-managed compute before committing. Daytona also prices by usage, so verify expected vCPU, GPU, memory, and storage consumption against the hourly rates.
