megachangelog
Announcement

Vercel Sandbox now generally available for AI agents

Vercel Sandbox is now generally available, providing a secure execution layer for AI agents to run untrusted code in isolated microVMs that start in sub-seconds and tear down automatically. The company has open-sourced the Sandbox CLI and SDK for the community to build agent infrastructure.

AI agents are changing how software gets built. They clone repos, install dependencies, run tests, and iterate in seconds.

Despite the change in software, most infrastructure was built for humans, not agents.

Traditional compute assumes someone is in the loop, with minutes to provision and configure environments. Agents need secure, isolated environments that start fast, run untrusted code, and disappear when the task is done.

Today, Vercel Sandbox is generally available, the execution layer for agents, and we're open-sourcing the Vercel Sandbox and for the community to build on this infrastructure.CLISDK

Vercel processes over 2.7 million deployments per day. Each one spins up an isolated microVM, runs user code, and disappears, often in seconds.

To do that at scale, we built our own compute platform.

Internally code-named Hive, it’s powered by and orchestrates microVM clusters across multiple regions. When you click Deploy in , import a repo, clone a template, or run in the CLI, Hive is what makes it feel quick.Firecrackerv0vercel

Sandbox brings that same infrastructure to agents.

Agents don’t work like humans. They spin up environments, execute code, tear them down, and repeat the cycle continuously.

That shifts the constraints toward isolation, security, and ephemeral operation, not persistent, long-running compute.

Agents need:

We’ve spent years solving these problems for deployments. Sandbox applies the same approach to agent compute.

provides on-demand Linux microVMs. Each sandbox is isolated, with its own filesystem, network, and process space.Vercel Sandbox

You get access, package managers, and the ability to run the same commands you’d run on a Linux machine.sudo

Sandboxes are ephemeral by design. They run for as long as you need, then shut down automatically, and you only pay for active CPU time, not idle time.

This matches how agents work. A single task can involve dozens of start, run, and teardown cycles, and the infrastructure needs to keep up.

Roo Code builds AI coding agents that work across Slack, Linear, GitHub, and their web interface. When you trigger an agent, you get a running application to interact with, not just a patch.

Snapshots changed their architecture. They snapshot the environment so later runs can restore a known state instead of starting from scratch, skipping repo cloning, dependency installs, and service boot time.

Blackbox AI built Agents HQ, a unified orchestration platform that integrates multiple AI coding agents through a single API. It runs tasks inside Vercel Sandboxes.

This supports horizontal scaling for high-volume concurrent execution. Blackbox can dispatch tasks to multiple agents in parallel, each in an isolated sandbox, without resource contention.

Explore the to get started, and check out the .documentationopen-source SDK

Read more

Built on our compute platform

Why agents need different infrastructure

What is Vercel Sandbox?

How teams are using Sandbox

Create your first sandbox with one command in the CLI

  • Sub-second starts for thousands of sandboxes per task

  • Full isolation when running untrusted code from repositories and user input

  • Ephemeral environments that exist only as long as needed

  • Snapshots to restore complex environments instantly instead of rebuilding

  • Fluid compute with Active CPU pricing for cost and performance efficiency

Roo Code

Blackbox AI

sandboxcomputeai-agentsinfrastructuresecurity

Source: original entry ↗

More from Vercel

Follow Vercel to get its new changes in your feed and email digest.

Feature

OpenAI Decisions API now available on AI Gateway

OpenAI's Decisions API is now accessible through Vercel's AI Gateway with an OpenAI-compatible endpoint, enabling decision models to answer typed questions and return probabilities, choices, and scores for routing, triage, and guardrails use cases. Support is available across the OpenAI SDK, AI SDK, HTTP API, and CLI with the latest versions.

ai-gatewayopenaiapidecisionssdks
Feature

Timestamp attributes now supported in Vercel Flags

Vercel Flags now supports timestamp attributes for entities, allowing you to create time-based targeting rules. Use this feature to run limited-time campaigns, show content between specific dates, or target users based on registration date.

flagstargetingfeaturetimestampscampaigns
Feature

Glyph Cluster now available in stealth on AI Gateway

Glyph Cluster, a reasoning model for coding and long-context analysis, is now available as a stealth model on Vercel's AI Gateway for Pro and Enterprise plan teams with purchased AI Gateway credits at no cost during the stealth period. The model supports function calling, streams responses, and can be accessed via AI SDK, OpenAI-compatible APIs, and coding agents.

ai-gatewaymodelscodingstealth
See all Vercel changes →