brig docs

Compare

Brig and cloud sandboxes

On this page

Brig runs a coding agent in a microVM on your computer, next to your project, with its login from your keychain and a network rule you write. E2B and Daytona run the agent's code in a sandbox on their servers, and you reach it through an API.

A cloud sandbox fits a product that runs code for many users. This page is about a coding agent on your own project. Brig compared puts both beside the other tools.

At a glance #

Brig E2B Daytona
Where the code runs Your Mac or Linux machine E2B's cloud, on Google Cloud Daytona's cloud, or your own compute under its control plane
Kernel One kernel per sandbox, under a hypervisor One Firecracker microVM per sandbox A container with its own namespaces by default. A VM class with its own kernel
Your project Mounted into the guest. Edits land in your files Uploaded through the API Uploaded through the API
Network An egress policy of hosts and ranges, enforced outside the guest Allow lists by address, range and hostname. A hostname rule applies on ports 80 and 443. Deny lists by address and range Block all, an address list, a domain list, or a proxy
Credentials A secret store in your keychain, delivered by name as a file. v0.5.0 adds secret brokerage, and the guest then holds a placeholder Stored with E2B, swapped into outbound HTTPS by its proxy. Private beta Stored with Daytona, swapped in by its proxy. The sandbox holds a placeholder
Agent setup Eight built-in profiles SDKs and templates SDKs and snapshots
Cost Free, Apache-2.0 A one-time credit plus usage, then a monthly plan plus usage Usage billing, with a free credit
Needs Homebrew on macOS. KVM and the runtime bundle on Linux An account and an API key An account and an API key
Open source Yes, three repositories The SDKs and the runtime repository The SDKs and the CLI. The core moved to a private codebase in June 2026

What Brig gives you #

Your code stays on your machine. The project is mounted into the guest, and the agent's edits land in your files. Nothing is uploaded, and no provider holds a copy.

Your keys stay in your keychain. Brig's secret store is your login keychain on macOS and the Secret Service on Linux. Brig v0.5.0 adds secret brokerage, and the guest then holds a placeholder in place of the real value. A cloud sandbox needs the credential on the provider's side, in its store or in the request you send it.

No account. Brig is free and Apache-2.0. A sandbox uses the memory and CPU you give it.

The agent's own interface. brig run claude opens Claude Code's full terminal interface in the sandbox, with your project at /work/<name>. A cloud sandbox runs the commands you send it.

The policy is a file on your machine. Brig's egress policy is a YAML file in your config directory, enforced at a gateway or in nftables on your machine. Enforcement says how. A provider's filter runs on the provider's side.

It works offline. --network offline runs the agent with no route out. A cloud sandbox needs a connection to the provider.

What a cloud sandbox does #

You call an API, and a sandbox starts on the provider's machines. You upload files, run commands and read the output through that API, from your own program or from an agent framework. The sandbox has a filesystem, a network and a lifetime that the plan sets.

E2B runs each sandbox in a Firecracker microVM, with its own kernel. Its network rules allow by address, range and hostname, and deny by address and range. A hostname rule applies on ports 80 and 443. Its egress proxy swaps stored secrets into outbound requests, in private beta. Its hobby plan is a one-time credit plus usage, and the next plan is a monthly fee plus usage.

Daytona runs a container by default and offers VM classes. Its documentation describes the default class as "an isolated container with dedicated namespaces", and does not name the container runtime. Its proxy swaps a placeholder for a stored secret, so the plaintext is not inside the sandbox. Its core development is private since June 2026, its main repository was archived in October 2026, and its SDKs and CLI stay open. It bills by the second, with a free credit.

When a cloud sandbox fits #

  • Many sandboxes for many users. A product that runs untrusted code for its users needs sandboxes that scale and that are not on anyone's laptop.
  • No hardware requirement. The sandbox runs on the provider's machines. E2B also has an embed package for a Linux host of your own. Brig needs Apple silicon and macOS 15, or a Linux host with KVM.
  • A sandbox your program drives. The SDKs are built for that. Brig has a daemon and a --json flag, and it is a command line tool first.
  • Credentials the agent never holds, today. E2B and Daytona swap a placeholder for the stored secret at a proxy, after the request leaves the sandbox. Brig hands the agent the credential as a file on a memory-backed mount until v0.5.0 adds secret brokerage.

Run Claude Code under each #

Under Brig:

brig run claude ~/code/demo

With E2B, you write a program against the SDK that creates a sandbox, uploads the project, installs Claude Code and runs it with an API key. With Daytona, the same, against its SDK.

Sources #

Read on 2026-10-06.

Type a command, a flag or an error message.