hyperlight-sandbox
Python API for running code in isolated Hyperlight sandboxes with swappable backends
Decision gist · record as of 2026-08-14
Yes, if you need isolated code execution with a clean Python API and don't mind the Alpha maturity level. The low install friction, active maintenance, permissive license, and zero known vulnerabilities make it a reasonable choice. However, verify that snapshot/restore semantics and backend stability meet your production requirements before relying on it for critical workloads.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later; backend and guest package extras must be installed based on your chosen backend (e.g., [wasm,python_guest] for WASM with Python guest).
- Low install friction with a pure-Python wheel distribution.
- Active maintenance with recent commits and steady releases since March 2026.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 permissive license allows commercial and private use with minimal restrictions, making it suitable for most production deployments.
last release 2026-06-24 (51 days) · last repo commit 2026-07-13 · 722 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 197,533 downloads/mo, #9,757 on PyPI
Alternatives
Verify before relying
pip install hyperlight-sandbox[wasm,python_guest]
from hyperlight_sandbox import Sandbox
sandbox = Sandbox(backend="wasm", module="python_guest.path")
sandbox.register_tool("add", lambda a=0, b=0: a + b)
result = sandbox.run("result = call_tool('add', a=3, b=4)\nprint(result)")
print(result.stdout)- Whether snapshot/restore semantics work correctly across all supported backends and guest runtimes.
- Performance characteristics and overhead of sandbox initialization and code execution.
- Compatibility and stability of the HyperlightJS backend relative to WASM.
- Whether the package is production-ready or remains in active development (Alpha status).
What it is and what it does
Hyperlight-sandbox is a Python API for running untrusted or isolated code inside sandboxes with multiple backend options (WASM, HyperlightJS) and guest language support (Python, JavaScript). It lets you register tools that guest code can call, capture output, and manage sandbox state through snapshots and restores. The package ships with separately installable backend and guest packages, so you only pull in what you need—for example, installing with [wasm,python_guest] gives you WASM execution with a Python runtime.
The core workflow is straightforward: create a Sandbox with your chosen backend and guest module, register any tools the guest code should access, then run code and inspect stdout or other outputs. Output files under /output are ephemeral per run. This design is useful for scenarios where you need to execute code safely without giving it full system access, or where you want to isolate execution contexts from one another.
Use it for
- Run untrusted user-submitted code safely without exposing the host system.
- Execute code in isolated contexts with controlled tool access for multi-tenant applications.
- Snapshot and restore sandbox state for testing, debugging, or resuming long-running computations.
- Combine Python and JavaScript code execution in the same application via different guest packages.
- Build code execution services (e.g., online judges, notebook environments) with pluggable backends.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need isolated code execution with a clean Python API and don't mind the Alpha maturity level.
The low install friction, active maintenance, permissive license, and zero known vulnerabilities make it a reasonable choice. However, verify that snapshot/restore semantics and backend stability meet your production requirements before relying on it for critical workloads.
Install
hyperlight-sandbox on PyPI
Before you install
Low install friction with a pure-Python wheel distribution. Active maintenance with recent commits and steady releases since March 2026. Requires Python 3.10 or later and optional backend/guest package extras depending on your use case.
Requires Python 3.10 or later; backend and guest package extras must be installed based on your chosen backend (e.g., [wasm,python_guest] for WASM with Python guest).
License in practice
Apache-2.0 permissive license allows commercial and private use with minimal restrictions, making it suitable for most production deployments.
Quickstart
pip install hyperlight-sandbox[wasm,python_guest]
from hyperlight_sandbox import Sandbox
sandbox = Sandbox(backend="wasm", module="python_guest.path")
sandbox.register_tool("add", lambda a=0, b=0: a + b)
result = sandbox.run("result = call_tool('add', a=3, b=4)\nprint(result)")
print(result.stdout)
Verify before relying
- Whether snapshot/restore semantics work correctly across all supported backends and guest runtimes.
- Performance characteristics and overhead of sandbox initialization and code execution.
- Compatibility and stability of the HyperlightJS backend relative to WASM.
- Whether the package is production-ready or remains in active development (Alpha status).
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Low. Pure-Python wheel |
| Runtime dependencies | None |
| Maintenance | Actively maintained 51 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 197,533 / month, #9,757 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 3 - AlphaIntended Audience :: DevelopersOperating System :: Microsoft :: WindowsOperating System :: POSIX :: LinuxProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Rust |
Evidence: hyperlight_sandbox-0.5.0-py3-none-any.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
An agent finds packages by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language. Give your agent the search over MCP.
More Security packages
Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.
MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.
joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.
Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.
Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.
ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.
Install only if maintaining existing code that already depends on it, and plan a migration.
See also agent-framework-hyperlight · hyperlight-sandbox-backend-wasm · hyperlight-sandbox-python-guest · llm-sandbox · e2b-code-interpreter · e2b · quickjs-rs · daytona · bashkit · pydantic-monty-runtime