Products#Agents#Runtime#Sandbox#Cloud
Alibaba Cloud details Agent Sandbox: 100k sandboxes a minute, 180ms P99 cold starts
Alibaba Cloud detailed Agent Sandbox at Yunqi: MicroVM isolation, 100k sandboxes per minute, sub-180ms P99 cold starts, and an E2B-compatible API.

At its 2026 Yunqi Conference, Alibaba Cloud laid out the architecture of Agent Sandbox — an execution environment that hands each agent “a clean computer.” Per 机器之心’s deep dive, it isolates sandboxes with MicroVMs, can create 100,000 of them per minute per region, and keeps a million sandboxes online simultaneously. The product has been in public beta since April 2026, and MiniMax’s MaxClaw and MaxHermes already use it as their execution environment.
The facts
- Performance: P99 cold start under 180ms (from pre-warmed templates), hot start under 20ms, and deep-sleep wake under 600ms.
- Pricing: three tiers, billed per second, disk-only fees during deep sleep — economy at ¥0.060 per vCPU-hour plus ¥0.030 per GiB-hour, general at ¥0.078 and ¥0.039, performance at ¥0.120 and ¥0.060. The company claims TCO reductions of up to 70% (vendor figure).
- Interfaces: two ways in — an E2B-compatible developer API and a Kubernetes API, so existing code moves over with minimal changes.
- Security design: MicroVM isolation, an Agent Identity system, non-root execution, read-only root filesystem, VPC and NetworkPolicy controls, plus memory checkpoints with Fork/Replay for reusing session state.
Our take
“Give the agent a computer” is turning from a self-built engineering project into shelf-ware — DeepSeek’s DSec sandbox platform is on the same path: published performance numbers, per-second billing, and E2B compatibility mean migrating off E2B or your own Firecracker fleet is mostly validation work, not a rewrite. For teams running fleets of short-lived agents — scraping, evals, code execution — price it directly: multiply your sandbox creation rate by average task duration across the three tiers and compare against your current bill before moving. One caution: the performance figures are the vendor’s own production numbers, and your workload may not fit their distribution.