Secure Code Runtime For AI Agents
Run untrusted Python in isolated sandboxes, keep multi-step workflows alive, and pay per run, priced before it starts. Modal gives agents a clean execution environment without making them manage containers, API keys, or infrastructure.
Public access today: Python 3.11, up to 1 vCPU, 1 GiB RAM, and a 5-minute sandbox lifetime. GPU sandboxes (T4 through H100) are live — see the pricing below. Custom images and setup-time provisioning are coming later.
Why Agents Reach For It
The value is not raw compute horsepower. It is giving an agent a safe, disposable, stateful place to run code when localhost execution would be risky or operationally messy.
What AI Agents Use It For
Modal Sandbox gives agents an execution layer they can call on demand, reason over, and tear down when the job is done — a safe, isolated place to run code without risking the host system.
Code Interpreter
$0.015 per sessionAgent creates a sandbox, executes user-provided code safely, captures output, and terminates. Perfect for chat-based code assistants.
sandbox/createpython:3.11 image$0.011sandbox/execrun user code$0.002sandbox/terminatecleanup$0.002Package Verification
$0.015 per testInstall dependencies in a clean sandbox, run checks or tests, and inspect failures without polluting the host environment.
sandbox/createmanaged Python 3.11 sandbox$0.011sandbox/execpip install + pytest$0.002sandbox/terminatecleanup$0.002Data Processing & Automation
$0.015+ per jobTransform files, parse data, run scripts, or execute lightweight automation steps in a sandbox the agent can inspect and control.
sandbox/createup to 1 vCPU / 1 GiB / 5 min$0.011sandbox/execrun processing step$0.002sandbox/terminaterelease sandbox$0.002Multi-Step Agent Workflows
$0.017+ per workflowCreate a persistent sandbox session, execute multiple commands across steps, inspect outputs between turns, and terminate when done.
sandbox/createcreate session$0.011sandbox/execstep 1$0.002sandbox/execstep 2$0.002sandbox/terminatedone$0.002Pricing
Two billing modes selected automatically by the requested timeout: short bursts pay a flat rate, long-lived sandboxes pay per hour.
Burst — timeout ≤ 300s
Flat rate per sandbox/create, covers the full short-lived session. Lifecycle ops at $0.002/request.
Long-lived — timeout > 300s, up to 24h
Per-hour rate × requested duration, billed upfront in one x402 settlement. No refund on early terminate — same as cloud-instance norms. Hours are exact (90min on T4 = 1.5 × $1.50 = $2.25).
| Config | Per hour | Notes |
|---|---|---|
| CPU (1 vCPU / 1 GiB) | $0.10 | Long-running batch jobs, scrapers, schedulers |
| T4 (up to 8 vCPU / 32 GiB) | $1.50 | Light inference, small models |
| L4 (up to 8 vCPU / 32 GiB) | $2.00 | Mid-tier inference |
| A10G (up to 8 vCPU / 32 GiB) | $2.50 | Stable diffusion, 7B inference |
| A100 (up to 8 vCPU / 32 GiB) | $4.00 | Training, 13B–70B inference |
| H100 (up to 8 vCPU / 32 GiB) | $8.00 | Frontier training, low-latency 70B+ |
API Reference
Base (USDC): https://blockrun.ai/api/v1/modal/
All endpoints accept POST with a JSON body. Send without a payment header to get a 402 with the exact price and payment requirements.
| Endpoint | Method | Price | Description |
|---|---|---|---|
/api/v1/modal/sandbox/create | POST | $0.010 | Create a managed Python 3.11 sandbox. Two billing modes selected by 'timeout': ≤300s = flat rate (CPU $0.01, GPU varies). >300s = per-hour billing for the full requested lifetime, no refund on early terminate. Max 24h. |
/api/v1/modal/sandbox/exec | POST | $0.001 | Execute a command inside a running sandbox. Returns stdout, stderr, and exit code. |
/api/v1/modal/sandbox/status | POST | $0.001 | Check the status of a sandbox (running or terminated). |
/api/v1/modal/sandbox/terminate | POST | $0.001 | Terminate a running sandbox and release its resources. |
Quick Start
Create a sandbox session, run code, and clean up:
# Base (USDC on Base)
curl -X POST https://blockrun.ai/api/v1/modal/sandbox/create \
-H "Content-Type: application/json" \
-d '{"image": "python:3.11", "timeout": 300}'
# Returns: 402 with price ($0.011) and Base USDC payment instructions
# Paid request — create sandbox ($0.011)
curl -X POST https://blockrun.ai/api/v1/modal/sandbox/create \
-H "Content-Type: application/json" \
-H "x-payment: <x402_payment_token>" \
-d '{"image": "python:3.11", "timeout": 300}'
# Returns: {"sandbox_id": "sb-xxx", "status": "running", ...}
# Execute code ($0.002)
curl -X POST https://blockrun.ai/api/v1/modal/sandbox/exec \
-H "Content-Type: application/json" \
-H "x-payment: <x402_payment_token>" \
-d '{"sandbox_id": "sb-xxx", "command": ["python", "-c", "print(2+2)"]}'
# Returns: {"stdout": "4\n", "stderr": "", "returncode": 0}
# Terminate ($0.002)
curl -X POST https://blockrun.ai/api/v1/modal/sandbox/terminate \
-H "Content-Type: application/json" \
-H "x-payment: <x402_payment_token>" \
-d '{"sandbox_id": "sb-xxx"}'
# Returns: {"sandbox_id": "sb-xxx", "status": "terminated"}Use the BlockRun Python SDK or TypeScript SDK to handle x402 payment automatically.
Start running agent code safely
Fund your wallet with USDC on Base and give your agent a safe place to run code. No registration, no API keys required.
Modal Sandbox API questions: isolation, GPUs, lifetime, pricing
- What is available in the public beta of Modal Sandbox?
- A managed Python image, a CPU sandbox with the lifetime and resource caps stated on this page, and GPU sandboxes across the tiers listed. Custom images and setup-time provisioning are not yet available.
- How is the Modal Sandbox API priced?
- One price to create a sandbox — flat for a short-lived CPU sandbox, higher by tier for a GPU or a longer lifetime — plus a small price per exec, status and terminate call. Lifetime is paid up front, and the 402 quotes the exact figure.
- Can I get a GPU sandbox through the API?
- Yes. Create takes a GPU type from the tiers on this page and prices the call by tier for the lifetime you request.
- Does the sandbox keep state between commands?
- Within one sandbox session, yes: create once, exec several commands, inspect stdout, stderr and exit codes between steps. Nothing persists after terminate.
- Why run untrusted agent code in Modal rather than locally?
- Model-written code is untrusted input. A sandbox keeps it off your host and your network, gives it a clean image every time, and is torn down explicitly so nothing is left running to be billed for.
- Modal Sandbox via BlockRun vs E2B, Daytona or Modal direct?
- All three sell isolated execution behind an account and a key. This is Modal's runtime reached per request with no account: an agent provisions a sandbox, runs its code and pays for that session alone.
- How do I run agent code in a Modal sandbox without a Modal account?
- Call BlockRun's sandbox endpoint. It creates a Modal sandbox, runs commands in it and tears it down, paid per request by the caller — no Modal account, key or plan.
- Can an AI agent create its own sandbox unattended?
- Yes. The create request pays for itself, so an agent with a funded balance provisions a runtime with no signup and no human in the loop.