> ## Documentation Index
> Fetch the complete documentation index at: https://docs.agentium.in/llms.txt
> Use this file to discover all available pages before exploring further.

# Choose a sandbox backend

> Compare local execution, E2B, and Daytona, including ownership and cancellation.

Choose the execution environment before exposing a code or shell tool. `SandboxAgent` manages a workspace; `CloudSandbox` is the port used by remote adapters.

| Backend | Setup | Ownership and limits |
| - | - | - |
| [Local](/sandbox/local) | `SandboxAgent({ backend: "unix-local" })` | Trusted code on the host; temporary workspace, process-group cancellation, bounded output |
| [E2B](/sandbox/e2b) | `E2BSandbox`, optional `@e2b/code-interpreter@2.8.0` | Adapter creates and kills its remote session; sandbox lifetime is separate from operation timeout |
| [Daytona](/sandbox/daytona) | `DaytonaSandbox`, optional `@daytona/sdk@0.220.0` | Adapter creates and deletes its sandbox; language fixed at creation |
| Custom remote | Implement `CloudSandbox`, pass `backend: "remote"` | Host defines provider-specific isolation and lifecycle |

V4 rejects the unimplemented `docker` selector. Local execution runs with the host user's privileges; a temporary directory is not OS isolation.

## Workspace or agent tools?

Use [SandboxAgent](/features/sandbox-agent) when application code explicitly manages a workspace and calls `run`, `shell`, `readFile`, and `writeFile`. Use [sandbox toolkits](/features/sandbox-toolkits) when a model should call those operations through tools. Tool approval and execution policy still belong in the Agent or harness that exposes them.

A [workspace review harness](/examples/harness-workspace) can read selected source files without enabling code execution at all.

## Remote failure handling

A request timeout or cancellation may stop local waiting while provider work continues. Inspect the provider before repeating an operation with effects. Both remote adapters serialize starts and close owned sandboxes; missing-file responses become null, while authentication and network errors remain failures. Output bounds are not provider memory quotas.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.