---
title: box
slug: box
url: "https://toolweight.com/options/box"
homepage: "https://box.ascii.dev"
categories: sandbox-providers
last_verified: 2026-07-23
license: CC-BY-4.0
---

# box

> Persistent Linux VMs with SSH, per-VM IPv4 and disk-level forking, priced flat.

box sells persistent Linux VMs you SSH into, with Docker running inside the guest, a dedicated IPv4 per VM, disk-level forking and a flat price. It is also the author of the capability table this row is transcribed from, published at box.ascii.dev/compare. toolweight has not independently verified any of it, so every cell here is either the vendor's own claim or explicitly unknown, there are no toolweight measurements on this row.

## Identity

|  |  |
| --- | --- |
| Name | box |
| Company | ASCII |
| One-liner | Persistent Linux VMs with SSH, per-VM IPv4 and disk-level forking, priced flat. |
| Site | https://box.ascii.dev |
| Docs | https://docs.ascii.dev |
| Compared in | 1 |

## Where it is compared

### [Sandbox providers](https://toolweight.com/compare/sandbox-providers)
Ranked **#14 of 20** on default weights.
| Field | Value | Confidence | Verified | Source | Note |
| --- | --- | --- | --- | --- | --- |
| Cold start | - | Unknown | - | - | toolweight has not measured box, and the vendor's comparison table publishes no boot figure. |
| Cold start (claimed) | - | Unknown | - | - | box is absent from its own table's "<500ms time to VM-ready" row, which lists only Daytona, E2B and Blaxel, so box does not claim sub-500 ms. No alternative figure is published, so there is nothing to record. |
| Isolation | - | Unknown | - | - | The table calls these VMs and claims Docker runs inside them, but names no hypervisor or isolation technology. Not inferred here. |
| Root in guest | ● | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from the "Docker inside the VM" row: a Docker daemon in the guest implies root. The table claims Docker, not root, so this is an inference from a vendor claim rather than the claim itself. Transcribed from box's own comparison table, a source with an obvious interest in the outcome; not verified by toolweight. |
| Egress control | - | Unknown | - | - | The table covers what the network can reach, not what the platform can restrict. |
| Max runtime | - | Unknown | - | - | The table's "No session cap / runs 24/7" row is a marketing statement about intent, not a published runtime ceiling, and this page's 24 h ceiling is reserved for platforms whose documented limit is genuinely absent. Awarding the maximum off that row handed box full marks on a weight-5 field with no evidence behind it. Left unknown until box publishes a limit or the absence of one. |
| Persistent FS | - | Unknown | - | - | Not a row in the table. Disk snapshots imply a disk, but not that files survive the VM. |
| Snapshot & fork | ◐ | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Listed under "Fast disk snapshots / branching" but deliberately not under "Process fork (memory + running processes)", disk-only cloning without live memory forking, which is exactly this field's partial. The value is derived from a presence and an absence rather than stated, so it is inferred; the absence itself is a concession about box's own product and is credited as such. Transcribed from box's own table; unverified. |
| Custom images | ◐ | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from "BYO repos + arbitrary setup script", a base you extend with a setup script, this field's partial. The table does not say whether an arbitrary OCI image can be supplied, so the mapping is ours. Vendor-published, unverified. |
| GPU | - | Unknown | - | - | Not a row in the table. |
| Runtimes | - | Unknown | - | - | Not a row in the table. |
| Preview URLs | ◐ | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from two rows that are not about preview URLs, "Dedicated IPv4 per VM" and "Full TCP/UDP + BYO domain". Ports are reachable, but on a domain you own rather than a first-party HTTPS URL returned by the API, which is this field's partial. The mapping is ours, not the table's. Vendor-published, unverified. |
| Browser inside | - | Unknown | - | - | Not a row in the table. |
| File up/download | ◐ | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from the "SSH access" row: scp and sftp follow from SSH. The table describes no first-party file API, and CLI-only access is this field's partial. Vendor-published, unverified. |
| Sydney region | - | Unknown | - | - | The table says nothing about regions. |
| Concurrent limit | - | Unknown | - | - | The table's "1000+ concurrent VMs ergonomically" row is the vendor scoring its own product against rivals, with "ergonomically" doing considerable work, and it is not a published quota. Recording it as 1000 handed box this page's concurrency ceiling, the same value the self-hosted-Firecracker baseline earns from hardware limits, off a marketing line. Left unknown until a documented limit exists. |
| MCP server | - | Unknown | - | - | Not a row in the table. |
| SDKs | - | Unknown | - | - | Not a row in the table. |
| Streaming output | - | Unknown | - | - | Not a row in the table. |
| Price / hour | - | Unknown | - | - | The comparison page quotes $20 for roughly 2M VM-seconds, which works out near $0.036 per VM-hour. It does not say what CPU and memory shape those VM-seconds buy, so there is no way to know whether it is comparable to the 2 vCPU / 4 GB hour this column prices, and toolweight has not checked the rate. Left unknown rather than converted against an assumed shape. |
| Meter | subscription | Inferred | 2026-07-23 | https://box.ascii.dev/compare | Derived from the "Flat pricing" row and mapped to subscription because that is this field's option for a flat fee rather than a meter. The table gives no metering detail and never uses the word, so the mapping is ours. Vendor-published, unverified. |
| Idle cost | - | Unknown | - | - | Not a row in the table; flat pricing says nothing about what an idle VM costs. |
| GitHub stars | - | Unknown | - | - | - |
| Funding | - | Unknown | - | - | - |
| Shipped | - | Unknown | - | - | - |
| Positioning | A persistent Linux VM with SSH, disk-level forking, a dedicated IPv4 and Docker inside. | Vendor-claimed | 2026-07-23 | https://box.ascii.dev | Paraphrased from box's own site. |

**Verdict.** Read this row as a vendor's self-assessment, because that is what it is: every cell comes from the comparison table box publishes on its own site, and toolweight has measured nothing. Taken on its own terms the shape is coherent and unusual here, a long-lived VM with SSH, Docker, a routable IPv4 and a flat bill, rather than an ephemeral per-second sandbox, and the table is notably candid about what box lacks, conceding process fork and sub-500 ms boots to E2B, Modal, Daytona and Blaxel. Two of its louder claims earn nothing here, though: "runs 24/7" is not a published runtime ceiling and "1000+ concurrent VMs ergonomically" is not a published quota, so both cells are unknown rather than scored at this page's maximum. What is missing is everything a buyer would check it against: no isolation technology, no measured boot time, no comparable hourly rate.

## Alternatives

- [ascii](https://toolweight.com/options/ascii), Agent orchestration over Telegram, running on box's VM infrastructure.
- [Blaxel](https://toolweight.com/options/blaxel), Agent-first cloud claiming ~25 ms microVM boots from snapshots.
- [Cloudflare Sandbox](https://toolweight.com/options/cloudflare-sandbox), Container sandboxes driven from a Worker, addressed through Durable Objects.
- [CodeSandbox SDK](https://toolweight.com/options/codesandbox-sdk), Firecracker VMs with memory snapshots, from the online IDE, now owned by Together AI.
- [Daytona](https://toolweight.com/options/daytona), Sub-second container sandboxes for agent workloads, from a team that built a dev-env manager.
- [Self-hosted Firecracker](https://toolweight.com/options/diy-firecracker), The baseline: Firecracker on your own metal, plus every hard part you now own.
- [E2B](https://toolweight.com/options/e2b), Open-source Firecracker sandboxes with Python and TypeScript SDKs for AI agents.
- [exe.dev](https://toolweight.com/options/exe-dev), Persistent VMs you SSH into, with root, apt and systemd, on a flat monthly plan.
- [Fly.io Machines](https://toolweight.com/options/fly-machines), Raw Firecracker microVMs with a REST API, durable volumes and 35+ regions.
- [Freestyle](https://toolweight.com/options/freestyle), Run untrusted JavaScript and full dev servers, with git hosting and domains built in.
- [GitHub Codespaces](https://toolweight.com/options/github-codespaces), Devcontainer-backed cloud VMs built for humans, occasionally repurposed for agents.
- [Islo](https://toolweight.com/options/islo), Per-agent isolated cloud sandboxes with enterprise policy controls, from Incredibuild.

## Licence and attribution

Data from toolweight (https://toolweight.com), licensed CC-BY-4.0.

- Licence: [CC-BY-4.0](https://creativecommons.org/licenses/by/4.0/)
- Canonical HTML: https://toolweight.com/options/box
- Machine-readable: https://toolweight.com/options/box.md · https://toolweight.com/api/v1 · https://toolweight.com/mcp
- toolweight takes no affiliate revenue and sells no placements. Corrections: https://toolweight.com/suggest
