# Kern Sandbox

> Updated 2026-09-28 · type: tool · category: ai-infrastructure · status: active · rev 1

Kern Sandbox runs LLM-generated code and agent tool calls rootless and daemonless, in kernel-enforced isolation, from a CLI or Python/Node SDKs.

- Open source: yes (Apache-2.0)
- Self-hostable: yes
- Pricing model: free
- Best for: An engineer running untrusted, LLM-generated code or agent tool calls who wants a fast, rootless, daemonless sandbox — no Docker daemon to run or privilege to grant — driven from a CLI or embedded via Python/Node SDKs, with MCP support to hand it to an agent directly.
- Not for: Teams that need a managed, hosted execution service with an SLA rather than a self-run binary, or workloads that require full VM-level isolation beyond kernel-enforced containment.
- Last verified: 2026-09-28

- **Canonical:** https://gtmstacker.com/registry/tool/kern-sandbox/
- **Source:** [getkern · GitHub](https://github.com/getkern/kern)
- **Tags:** ai-infrastructure, agent-sandbox, code-execution, isolation, mcp-agents, self-hostable
- **Repository:** https://github.com/getkern/kern

## Is Kern Sandbox open source?

Yes, Kern Sandbox is open source under the Apache-2.0 license.

## How much does Kern Sandbox cost?

Kern Sandbox is free to use.

## Can I self-host Kern Sandbox?

Yes, Kern Sandbox can be self-hosted (the source is available under the Apache-2.0 license).

## Alternatives & related

- [OpenSandbox](https://gtmstacker.com/registry/tool/opensandbox/)
- [BoxHaven](https://gtmstacker.com/registry/tool/boxhaven/)
- [Docker Sandbox Kit Spec](https://gtmstacker.com/registry/news/docker-sandbox-kit-spec/)


---

Kern Sandbox is a rootless, daemonless container runtime that runs LLM-generated code and agent tool calls in kernel-enforced isolation, callable from a CLI or Python/Node SDKs with MCP support. Open source: yes (Apache-2.0); self-hostable; pricing free. It ships as a single static binary and has 427 stars.

## What it does

Kern Sandbox gives an agent somewhere safe and fast to run code. It executes LLM-generated code and tool calls inside a container isolated by the kernel, but without a root requirement and without a background daemon — the whole thing is a single static binary you drop in and call. You reach it from a CLI, embed it through the Python or Node SDK, or expose it to an agent over MCP. The design target is throughput at agent scale: a prewarm pool keeps ready sandboxes on hand so a tool call does not pay full container-startup cost each time. Open source: yes (Apache-2.0); self-hostable; pricing free.

## Provenance

- Apache-2.0 per repo; 427 stars; single static binary, no daemon; Python + Node SDKs; CLI; MCP support; rootless, kernel-enforced isolation (github.com/getkern/kern + getkern.dev/guide/sandbox.html, verified 2026-09-28).
- Vendor-reported benchmarks: ~1/20th the cost of `docker run` per tool call, 21x faster via the prewarm pool, and 7x faster than Docker on library imports — stated here as the vendor's own numbers (vendor-claim), not independently reproduced.
- Curated from the GTM Stacker signal registry (2026-09-28 pass); license/facts independently verified 2026-09-28.

## Why it matters for a GTM stack

The moment a GTM agent starts running code — parsing a scraped page, transforming an enrichment payload, executing a generated SQL or Python snippet — you need that code contained, and you need it cheap enough to do thousands of times a day. Kern Sandbox targets exactly that: rootless, daemonless isolation you can self-host, addressable over MCP so an agent can call it as a tool, with a prewarm pool aimed at keeping per-call cost low. Open source: yes (Apache-2.0); self-hostable; pricing free. The honest read: the isolation is a container boundary rather than a VM, and the eye-catching cost and speed multiples are the vendor's own benchmarks — pilot it against your real tool-call mix and confirm both the containment guarantees and the numbers before it fronts untrusted execution at scale.
