Give every agent its own computer. Each sandbox is a full Linux VM with its own kernel, created in under a second through an API. Pause to zero when idle, fork a running machine, and mount your own S3 buckets with no egress fees.
CreateOS Sandbox gives every agent, and every piece of code your team did not write, its own computer.
A sandbox is a disposable Linux virtual machine your product creates on demand through an API, in under a second. It has its own kernel, its own filesystem and its own network identity. Nothing is shared with the host or with another tenant, and there is no setting that turns that off by accident.
Independently benchmarked by ComputeSDK on 14 August 2026: 0.34 seconds to a running machine, fastest of the 26 providers measured, and 100 percent success with 100 sandboxes launched at once.
WHAT ONE SANDBOX DOES
Start and destroy on an API call. Create from TypeScript, the CLI, MCP or REST. An agent can provision its own machine through a tool call.
Pause to zero, resume in place. Pause is a snapshot, not a shutdown. Full guest state freezes to disk and compute billing stops. Resume restores processes and memory exactly as they were. Auto-pause on idle is configurable from 60 to 86,400 seconds.
Fork a running machine. Copy a live sandbox mid-run to branch an agent's state.
Private sandbox network. Sandboxes find each other by name over a private network, so a team of agents can work together without crossing the public internet.
Live web URL. Expose an HTTP service from anything you run, for preview links and demos.
Bring your own storage. Mount Amazon S3, MinIO or Cloudflare R2 as a filesystem. No egress fees, at any volume.
Bring your own image. Run your Docker image, or build templates for ML, deep learning and DevOps workloads.
ISOLATION YOU CAN PROVE
A real machine boundary. Every sandbox is a Firecracker micro-VM running its own Linux kernel. Code inside one sandbox cannot see the host, another tenant or your network.
Contained by default. Even a guest-kernel compromise stays inside that one micro-VM. The host kernel is not in the blast radius.
Egress you control. Outbound traffic runs against a kernel-enforced allowlist using eBPF. No inbound by default, and you can read exactly what was blocked.
Environment and firewall management. Set environment variables and egress rules per sandbox, with a data cap per machine.
THE SPEC
Shapes. From a quarter of a CPU up to 8 CPUs and 16 GB of RAM, with 10 to 60 GB of disk.
Regions. USA, EMEA, MENA and APAC, live today.
Runtimes preinstalled. Ubuntu 26.04 with Node.js LTS, Bun, Python 3.12 with pip and uv, Go 1.26 and Rust 1.83 stable.
Deployment. Our cloud, your cloud, or self-hosted on your own machines.
Compliance. Inside the NodeOps ISO/IEC 27001 and SOC 2 Type II scope.
Scale. More than 190,000 sandboxes created since June 2026.
WHO IT IS FOR
AI coding tools and app builders. Run what the model wrote and hand the user a live preview link.
Agents that run for hours. Pause while an agent waits on a person. Resume exactly where it stopped.
Customer-written code. Plugins, scripts and integrations. One customer's code cannot see another customer's machine.
Chat and analytics on customer data. Your model writes the query, the sandbox runs it, your application never touches the data.
Agent teams. Every agent on its own machine, talking to the others privately by name.
Evals at volume. Hundreds of short-lived machines a day, created and destroyed automatically.
NOT FOR YOU IF
You only ever run code your own team wrote and reviewed.
You need GPUs. We do not offer GPU sandboxes.
Highlights
Real isolation, not a shared kernel. Every sandbox is a Firecracker micro-VM running its own Linux kernel, so code inside one cannot see the host, another tenant or your network. Even a guest-kernel compromise stays inside that one machine. Outbound traffic runs against a kernel-enforced eBPF allowlist with no inbound by default, and you can read exactly what was blocked.
Fast to start, and cheap to leave running. Independently benchmarked by ComputeSDK on 14 August 2026 at 0.34 seconds to a running machine, fastest of the 26 providers measured, with 100 percent success on 100 launched at once. Pause is a snapshot, not a shutdown: guest state freezes to disk and compute billing stops, then resume restores processes and memory exactly as they were.
Built for agents, deployed where you need it. Create, fork and destroy sandboxes from TypeScript, the CLI, MCP or REST, so an agent can provision its own machine through a tool call. Sandboxes reach each other privately by name. Mount your own S3, MinIO or R2 with no egress fees. Run in USA, EMEA, MENA or APAC, in your own cloud, or self-hosted on your own hardware.
AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
Pricing is based on the duration and terms of your contract with the vendor. This entitles you to a specified quantity of use for the contract duration. If you choose not to renew or replace your contract before it ends, access to these entitlements will expire.
Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator to estimate your infrastructure costs.
Up to 48 cores and 48 GB of memory, with a monthly credit allowance and a 1.2x multiplier on credit top-ups. For teams putting agent code execution into production on a single product.
$10.00
Pro
Up to 1,000 cores and 1,000 GB of memory, with a monthly credit allowance and a 1.5x multiplier on credit top-ups. For teams running sandboxes at scale across several products.
$75.00
Enterprise
Up to 2,000 cores and 1 TB of memory, from 20,000 credits, with a 5x multiplier on credit top-ups. Adds deployment in your own cloud or self-hosted, and region selection across USA, EMEA, MENA and APAC. Available exclusively via private offer.
You pick one of three contract tiers sized by compute capacity. Each tier sets a ceiling on cores and memory, bundles a monthly credit allowance, and applies a multiplier to credit top-ups. Beginner caps at 48 cores and 48 GB for a single product. Pro raises the ceiling to 1,000 cores and 1,000 GB across several products. Enterprise reaches 2,000 cores and 1 TB, starts from a set credit amount, and adds self-hosted or own-cloud deployment plus region selection. You buy Enterprise only through a private offer. Credits fund per-second usage as you run sandboxes.
Top-of-mind questions for buyers
What does a credit buy, and how do cores and memory map to usage?
Credits fund per-second sandbox usage. You are billed per vCPU-hour, per GiB-RAM-hour, and per GB-hour of storage while a sandbox runs. The core and memory caps in each tier set the ceiling on how much compute you can run at once, not a flat allotment.
Am I charged when a sandbox is paused or idle?
Pausing a sandbox snapshots its state and stops vCPU billing. Memory and storage charges continue while paused, since your state stays preserved on disk. You can set an inactivity timeout so idle sandboxes auto-pause and hold their place without a running compute bill.
How does Enterprise differ from Beginner and Pro beyond the higher caps?
Enterprise adds deployment in your own cloud or self-hosted machines, where sandboxes and compute stay in your environment while the vendor runs the control plane. It also lets you select regions across USA, EMEA, MENA and APAC. It starts from a set credit amount and is sold only through a private offer.
createos.sh+1
Helpful?
Vendor refund policy
Subscriptions purchased through AWS Marketplace are non-refundable once the contract term begins, except where required by law. For questions about a charge or a subscription, contact business@nodeops.xyz and we will work with you and AWS Marketplace to resolve it.
How can we make this page better?
Tell us how we can improve this page, or report an issue with this product.
Give us feedbackReport a problem with this product or seller
Legal
Vendor terms and conditions
Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA).
Content disclaimer
Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.
SaaS delivers cloud-based software applications directly to customers over the internet. You can access these applications through a subscription model. You will pay recurring monthly usage fees through your AWS bill, while AWS handles deployment and infrastructure management, ensuring scalability, reliability, and seamless integration with other AWS services.
Email support is included with every subscription at business@nodeops.xyz, with a target first response within one business day. Onboarding covers SDK and CLI integration, custom template builds, egress allowlist policy, and mounting your own S3, MinIO or Cloudflare R2 storage, across our cloud, your cloud and self-hosted deployments. Documentation, the TypeScript SDK reference and runnable examples are public. Annual contracts add a named technical contact, and we will benchmark your own workload on your shape, in your region, and publish the result with you. Faster response targets and dedicated capacity are available under a private offer.
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.
An AI execution layer for the enterprise. Agents get named owners, cited context from your own documents, isolated sandboxed runs, and an immutable audit log of every action. Deploy in CreateOS cloud, inside your VPC, or fully on-premise.
This product has charges associated with it for providing seller premium support. The Oracle Linux 10 instance is pre-configured and hardened to the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) standard, delivering enhanced security over a baseline image. Benefit from a fully maintained hardened image with regular STIG updates, security patches, and hotfixes, along with limited premium OS support to assist with troubleshooting, optimization, and compliance guidance. This makes it an ideal choice for companies that require a secure, compliance-ready, production-quality OS backed by expert assistance.
This product has charges associated with it for providing seller premium support. The Oracle Linux 8 instance is pre-configured and hardened to the Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG) standard, delivering enhanced security over a baseline image. Benefit from a fully maintained hardened image with regular STIG updates, security patches, and hotfixes, along with limited premium OS support to assist with troubleshooting, optimization, and compliance guidance. This makes it an ideal choice for companies that require a secure, compliance-ready, production-quality OS backed by expert assistance.
Be the first to review this product. We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.