Compare · Fig. C.1

Where engrams sits.

Hosted sandbox APIs run the VMs for you. Development-environment products give people a workspace at their editor. engrams is the third thing: sandboxes for agents, on infrastructure you run.

engramsHosted sandbox APIs (E2B, Modal Sandboxes)Development environments (Coder)
Who runs itYou, in your cloud or on your hardwareThe vendorYou
Built forAgents; a person can open a shell or IDE into a session, but the session is the agent'sAgents and code execution, through an SDKPeople at their editors
IsolationA Firecracker microVM per session, on KVMA microVM or container per sandbox, vendor-managedWhatever the workspace template provisions: a VM, a pod, a container
Pause and resumeSnapshot to content-addressed chunks on idle; restore in under 100 ms on the same host, one to two seconds elsewherePause and resume within the vendor's limits and pricing tiersStop and start the workspace; state depends on the template
ForkA manifest copy of a few kilobytes; the fork shares every chunk until it writesVaries by vendorNot a session concept
Agent runtimeClaude Code and Codex mounted by the host at boot; never in your imageBring your own, inside the sandboxAgents run as workspace processes
Your imageAny Linux image with /bin/sh, built with docker buildA vendor image format or a Dockerfile, per vendorA Terraform template
CloudGKE or EKS, GCS or S3, with Terraform and Helm in the repositoryThe vendor'sAny
Product surfaceDashboard, tasks and profiles, Slack, pull request review, CLI, API, connectorsSDK and dashboardDashboard, templates, CLI, IDE integrations
LicenseAGPL-3.0Proprietary serviceAGPL-3.0 with a paid tier
Sec. 1When to pick the others

Pick the other thing when it fits.

If you do not want to run infrastructure, a hosted sandbox API is the right call: you get sandboxes in a minute, and you pay per second. engrams asks you for a Kubernetes cluster with a KVM node pool, a Postgres, a bucket, and someone to run them.

If the people on your team are the ones who need the environment, at their editors, all day, a development-environment product is built for exactly that. engrams gives a person a shell into an agent's session; it does not give them a workspace.

If your hosts cannot run KVM, engrams has no production mode for you. It does not run sessions as containers.