Skip to main content
A per-backend comparison of sandbox capabilities, and the Gateway-side execution that stays outside the sandbox boundary.

Supported capability matrix

Sandbox backends isolate tool execution. They do not move the Gateway, native plugins, or control-plane RPC into the sandbox. Native plugins remain in-process with the Gateway and share its trust boundary. Sandboxed sessions can use plugin-owned and MCP tools only when normal tool policy and tools.sandbox.tools both allow them. See MCP and plugin tools inside sandbox tool policy and Plugin execution model.