E2B
What is E2B?
E2B is a cloud sandbox platform for AI product teams that lets agents execute code, use real-world tools, and work inside full virtual computers. It includes Deep Research Agents, Computer Use Agents, Secure MCPs, and AI data analysis & visualization, and it's used by Hugging Face, Manus, Groq, and Lindy. Plans run Hobby Free, Pro $150/mo, and Ultimate Enterprise custom.
Last verifiedHow we evaluate
At a glance
- E2B is best for AI product teams who need secure sandboxed code execution for agents.
- Hobby Free; Pro $150/mo; Ultimate Enterprise Custom
What it actually is
E2B gives an AI agent a disposable Linux machine to run code, commands, or a full desktop in, then throws it away. The isolation is a real Firecracker microVM per sandbox — its own kernel, not a shared-kernel container — which is the same technology AWS uses to isolate Lambda functions from each other. That distinction matters if you're running untrusted or model-generated code: a container escape and a microVM escape are different classes of problem. E2B's own runtime README states isolation is 'at the hypervisor boundary, not the container or process boundary' (github.com/e2b-dev/runtime). Sandboxes boot from a pre-built snapshot rather than a cold kernel boot, which is what lets E2B claim sub-second startup for a returning template.
Pricing
Verified on the pricing page 2026-09-13 (e2b.dev/pricing). Hobby is free, comes with a one-time $100 usage credit, caps sessions at 1 hour and 20 concurrent sandboxes, and needs no card. Pro is $150/month base plus usage billed by the second, raises the session cap to 24 hours, and starts at 100 concurrent sandboxes (expandable to 1,100 for an added $500-$1,000/month). Compute is metered per vCPU-second and per GiB-RAM-second on both tiers at identical rates — a 2 vCPU / 4 GiB sandbox (E2B's default) costs $0.000028/s + $0.000018/s ≈ $0.000046/s, or about $0.166/hour, before the Pro base fee. Enterprise is custom-quoted and E2B's own cost calculator sets a $3,000/month minimum for it. Storage is free up to 10GiB (Hobby) or 20GiB (Pro).
Open source, and what's actually in the repo
Two repos matter here, and they're both live, not stale. e2b-dev/E2B (13,767 stars, Apache-2.0, github.com/e2b-dev/E2B) holds the Python/JS SDKs and CLI; e2b-dev/runtime (1,389 stars, Apache-2.0, formerly named e2b-dev/infra — GitHub returns a 301 redirect from the old name — github.com/e2b-dev/runtime) is the actual Firecracker orchestrator, API, and edge proxy that runs E2B Cloud. Both were pushed to within the last day as of 2026-09-13. That's a meaningfully more complete open-source offering than a vendor that open-sources only its SDK: you can read, and self-host, the thing doing the isolation, not just the client that talks to it. Self-hosting supports AWS and GCP via Terraform (github.com/e2b-dev/E2B README); Azure and a generic Linux target are explicitly listed as not yet supported. A single-machine evaluation package ('E2B Embed') runs the whole stack via Docker Compose on one host with KVM, but the runtime's own README calls it 'an evaluation package, not a production deployment pattern.'
Security and compliance posture
E2B publishes a SOC 2 Type II report (available under NDA via the Trust Center at trust.e2b.dev) and signs HIPAA Business Associate Agreements on Enterprise plans (e2b.dev/security). Managed sandbox data sits under Google Cloud's default at-rest encryption — E2B states it adds no encryption layer of its own and holds no key material — and traffic is TLS in transit. For workloads needing to stay inside a customer's own cloud account, BYOC deploys into the customer's AWS or Google Cloud VPC on Enterprise plans; E2B is explicit that this is a managed deployment into your account, not self-hosting, and that your account's own compliance posture is yours to manage, separate from E2B's SOC 2 scope. No published vulnerabilities were found for either the e2b PyPI or npm packages via OSV.dev as of 2026-09-13.
Company and funding
E2B (legal name FoundryLabs, Inc.) was founded in 2023 by Vasek Mlejnsky and Tomas Valenta. Per the company's own timeline (e2b.dev/about): pre-seed of roughly $2.5M led by Kaya VC (September 2023), a $11.5M seed led by Decibel alongside the SDK's v1.0 launch (October 2024), and a $21M Series A led by Insight Partners with Decibel, Sunflower, and Kaya (July 2025). These figures are vendor-reported; we could not corroborate them against an independent funding database or press release this run because web search was unavailable throughout this session. E2B also states 94 of the Fortune 100 have signed up for the platform and that combined SDK downloads across npm and PyPI exceed 10 million per month — both are vendor claims, not independently verified, and 'signed up for' is a materially weaker claim than 'is a paying customer of.'
How much does E2B cost?
| Plan | Price | What's included |
|---|---|---|
| Hobby | Free |
|
| Pro | $150/mo |
|
| Ultimate Enterprise | Custom |
|
Frequently asked questions
What is E2B?
E2B is a cloud sandbox platform for AI product teams that lets agents execute code, use real-world tools, and work inside full virtual computers. It includes Deep Research Agents, Computer Use Agents, Secure MCPs, and AI data analysis & visualization, and it's used by Hugging Face, Manus, Groq, and Lindy. Plans run Hobby Free, Pro $150/mo, and Ultimate Enterprise custom.
How much does E2B cost? Is it free?
E2B has a free plan, with paid tiers including Pro at $150/mo, Ultimate Enterprise at Custom.
What is E2B used for? Who is it for?
E2B is used for Deep Research Agents, Computer Use Agents, and Secure MCPs. It's built for AI product teams, Platform engineers, and Research teams.
Does E2B have an API and what does it integrate with?
E2B doesn't publish a public API. It integrates with OpenAI, Anthropic, Mistral, Llama, LangChain, and 4 more.
Editor's read
Check the session-length and concurrency ceilings before rollout: Hobby caps sandboxes at 1 hour and 20 concurrent runs, while Pro extends to 24 hours and 100 concurrent runs with extra concurrency up to 1,100. If your agent workload needs longer sessions or higher parallelism, that tier jump matters.
