Ryan Dahl isn't worried about AI writing bad code. He's worried about what happens when that code runs with access to your company's crown jewels.
The problem goes like this: You're using an AI coding assistant that generates functions on the fly. Those functions need to talk to real services—OpenAI's API, maybe Stripe, perhaps your internal systems. Which means they need real credentials. And if the AI writes something malicious, or just careless, those API keys can leak. Fast.
Dahl's company, Deno, thinks it has an answer. On February 3, it launched Deno Sandbox, a beta SDK and API that spins up isolated Linux microVMs designed specifically to run code you don't quite trust. The pitch? Let AI agents do their thing without giving them the keys to everything.
It's a crowded moment to enter this market. Vercel just shipped its own sandbox to general availability days earlier, on January 30. E2B has been in the space for a while. Cloudflare offers a completely different model with its Workers platform. Everyone, it seems, is racing to solve the same thorny question: how do you let intelligent systems execute code safely?
Secrets That Never Touch the Ground
What Deno is calling "secrets on the wire" isn't quite like other sandboxing approaches. The idea: API keys and credentials never actually exist inside the virtual machine. Not even for a millisecond.
Instead, developers configure placeholder values. When the sandbox makes HTTPS requests to pre-approved hosts—api.openai.com, say, or anything matching *.anthropic.com—an outbound proxy swaps in the real credentials during transit. Only then. Only to those specific destinations.
If AI-generated code tries logging those secrets or posting them somewhere sketchy, it gets nothing but useless dummy text. The real values materialize only when the request is already on its way to a legitimate endpoint you've explicitly allow-listed. "Safest, simplest way to run untrusted code," Deno's landing page promises. It's a bold claim, though the architecture does seem to address something standard compute sandboxing misses: you can isolate all you want, but if your agent needs internet access, you need control over where it can actually send things.
It's the kind of paranoid-but-practical thinking that makes sense when you remember Dahl co-created Node.js before starting Deno. He's been around long enough to know what can go wrong.
Fast Boots, Familiar Tech Stack
Each sandbox is a Firecracker microVM—the same virtualization layer Amazon uses for Lambda. Boot times come in under a second, with Deno claiming sub-200-millisecond starts in some materials (though your mileage may vary in practice).
Default resources: 2 vCPUs, about 1.2 GiB of RAM, 10 GB ephemeral disk. Sessions max out at 30 minutes, which is notably shorter than E2B's 24-hour windows. That time cap could complicate certain use cases—long-running autonomous agents come to mind—but Deno does allow reconnecting within a session's lifetime.
The pricing model splits from Deno Deploy's application hosting: $0.05 per CPU-hour, $0.016 per GiB-hour of memory, $0.20 per GiB-month for persistent volumes. The Pro tier bundles 40 CPU-hours and 1,000 GiB-hours of memory, which should cover moderate AI agent workloads without triggering sticker shock.
For developers who need tools to stick around between sessions, persistent volumes are in private beta. Think pre-installed dependencies or data that shouldn't evaporate every time.
Network Controls That Can't Be Gamed

The network egress controls work at the infrastructure level, not inside the VM. Administrators define which hosts, IP ranges, or wildcard patterns are allowed. Everything else hits a wall at the proxy layer. This isn't a firewall you configure; it's a chokepoint the sandbox can't route around no matter how clever the code inside gets.
There's flexibility for development workflows. Sandboxes can expose HTTP endpoints for live previews, generating random TLS-secured URLs under *.sandbox.deno.net. SSH access works. You can even pop open a VS Code session with one click. The documentation does note—perhaps obviously—that exposing HTTP makes things publicly accessible. Use accordingly.
One feature stands out: sandbox.deploy() lets you push code directly from a sandbox into production on Deno Deploy. It collapses some of the typical handoffs between prototyping and shipping.
Launch Logistics
SDKs ship for JavaScript/TypeScript via JSR (Deno's package registry) and npm, plus Python via PyPI. The @deno/sandbox package sits at version 0.9.0 as of launch. Node.js 24+ is recommended if you want the "await using" pattern for automatic cleanup.
Command-line tooling covers the basics: creating sandboxes, moving files around, managing SSH, handling volumes and snapshots.
Geographic availability is thin at launch. Amsterdam and Chicago. That's it. Asia regions are "planned," which in tech-speak means sometime later this year, maybe. Default organizational concurrency sits at 5 sandboxes during this pre-release phase. Higher limits require talking to sales, which suggests Deno is ramping capacity carefully rather than flipping the switch for everyone at once.
The Competitive Scramble
Timing matters here. Vercel's sandbox went live just days before Deno's, complete with open-sourced CLI tools and tight integration into Vercel's AI Gateway. E2B has been offering Firecracker-based microVMs with longer session windows and options to deploy on your own infrastructure. Cloudflare's Workers for Platforms uses V8 isolates instead of full VMs—lighter, but with different security boundaries.
InfoWorld's coverage on February 5 framed Deno's entry as a direct play for the AI execution space, calling out the secrets-on-wire mechanism as the standout differentiator. Discussions on Reddit's r/Deno community confirmed the timing coincided with Deno Deploy graduating to general availability after years in preview. Everything's moving fast.
Built for the AI Moment (But Not Only That)

The target use cases are laid out explicitly: AI agents, coding assistants, plugin systems, ephemeral CI environments, anywhere you're running code you didn't write yourself. The product page leans hard into "built for AI agents" messaging, though the tech works just as well for user-generated code in a SaaS app or disposable test environments.
Compliance credentials include SOC2 and ISO27001, inherited from Deno Deploy. HIPAA Business Associate Agreements are available if you're handling healthcare data and have an enterprise contract. Logs and traces flow into Deploy's existing observability setup.
The 30-minute cap will force some architectural decisions. Long-running tasks need workarounds—persistent volumes, reconnection patterns, or splitting work into smaller chunks. The limited regional presence means higher latency if your users are elsewhere, at least for now.
Where This Goes
For developers building with LLMs—which is to say, increasingly, most developers—the credential exfiltration problem is real. Deno Sandbox offers a genuinely different answer than the competition. Whether network-level controls and credential substitution beat out competitors' approaches isn't clear yet. The market's still figuring out what the right primitives even are.
But Dahl's made a career out of spotting where infrastructure needs to evolve before everyone else catches on. Node.js reshaped server-side JavaScript. Deno itself was a rethinking of that entire model. Whether this latest bet pays off the same way depends on factors beyond the tech itself: adoption, pricing, how fast they can expand regions, how well the developer experience holds up under real-world pressure.
What's certain is that AI code execution isn't a problem that's going away. If anything, it's just getting started. Deno's early to stake a position. The next few months will show whether being early means being right.
