E2B runs agent code in isolated cloud sandboxes. Rift keeps the files those runs produce on machines you own.
E2B
Youlaptop
work
api
billing
runs
.env
E2B
It stores your files and can read them.
work
api
billing
runs
.env
the whole project, or a link to one file
OpenClawanother company's agent
uses a project API key
work
api
billing
runs
.env
Rift
Youlaptop
work
api
billing
runs
.env
Rift Cloud
It cannot read your files. It holds only ciphertext.
Fv+a8LdicjU6ce
efFPD/W3GEGTbB
FFu91EY6OfuOIc
j3iz+iV3W5kvab
1hZDb7nJAxjHmy
one folder, read
OpenClawanother company's agent
holds its own key
apiread
What E2B is
E2B starts a Linux virtual machine for each agent run, isolated with its own kernel. A sandbox can be paused with its disk and memory saved, kept indefinitely, and resumed in about a second.
How they differ
E2B runs code, and files live inside a sandbox. Access is by project, and every member of a project has the same permissions. Rift keeps a folder in sync across every machine it runs on and grants one folder at a time.
E2BRift
IdentityE2BThe agent has none by default. The developer's API key covers one project.RiftA key that each machine and agent makes for itself. No account.
Smallest shareE2BA whole project for API access. An access token covers one sandbox's control API. A signed link can give out one file from a sandbox.RiftA folder, a subfolder or one file, as read or write.
Who checks accessE2BE2B.RiftEach machine that receives a file checks the grant itself.
Who can read your filesE2BE2B runs the sandbox, and its disk sits under its cloud provider's default encryption. Its security FAQ says E2B adds no encryption layer of its own and describes no customer-held keys. With the bring-your-own-cloud option, storage sits in your cloud account.RiftOnly the machines you shared with. Rift Cloud holds ciphertext.
When your machines are offE2BA paused sandbox has to be resumed before its files can be read. Volumes, in private beta, can be read through the SDK with no sandbox running.RiftFiles stored in Rift Cloud stay available.
When a run endsE2BA sandbox that times out is deleted by default. It is kept if it is set to pause.RiftFiles the run wrote to a Rift folder are already on your other machines.
Which to choose
Choose E2B when
You need to run untrusted or agent-written code in isolation.
You want to pause a run and resume it in about a second with its memory intact.
Choose Rift when
Output should be on your own machines after the sandbox is gone.
The same files should be in the sandbox and on your laptop.
A person or agent outside your project should receive one folder and nothing else.
Using them together
E2B runs the code and Rift keeps the files. Rift runs on Linux, which is what an E2B sandbox runs.