Rift vs Vercel Sandbox

Vercel Sandbox runs agent code inside your Vercel project. Rift syncs an agent's files to your own machines.

Vercel Sandbox

Youlaptop
work
api
billing
runs
.env
Vercel
It stores your files and can read them.
work
api
billing
runs
.env
a team token
OpenClawOpenClawanother company's agent
uses a team and project token
work
api
billing
runs
.env

Rift

Youlaptop
work
api
billing
runs
.env
Rift Cloud
It cannot read your files. It holds only ciphertext.
Fv+a8LdicjU6ce
efFPD/W3GEGTbB
FFu91EY6OfuOIc
j3iz+iV3W5kvab
1hZDb7nJAxjHmy
one folder, read
OpenClawOpenClawanother company's agent
holds its own key
apiread

What Vercel Sandbox is

Vercel Sandbox runs agent-written code in isolated virtual machines. CPU is billed only while it is active, the filesystem is saved automatically when a sandbox stops, and several agents can share one sandbox as separate Linux users. It has been generally available since January 2026.

How they differ

A Vercel sandbox belongs to one Vercel project. Inside one sandbox, agents can run as separate Linux users. Rift keeps a folder in sync across every machine it runs on, and its grants reach across accounts.

Vercel SandboxRift
IdentityVercel SandboxThe agent has none outside the sandbox. Access uses a token tied to a Vercel team and project.RiftA key that each machine and agent makes for itself. No account.
Smallest shareVercel SandboxInside a sandbox, one Linux user's directory. For anyone outside the team, the documentation describes nothing smaller than a team token.RiftA folder, a subfolder or one file, as read or write.
Who checks accessVercel SandboxVercel, and the Linux kernel inside the sandbox.RiftEach machine that receives a file checks the grant itself.
Who can read your filesVercel SandboxNot established. Vercel's security page says data at rest is encrypted with AES-256. The Sandbox pages we read do not say who holds the keys.RiftOnly the machines you shared with. Rift Cloud holds ciphertext.
When your machines are offVercel SandboxA stopped sandbox is a snapshot that the next call resumes.RiftFiles stored in Rift Cloud stay available.
When a run endsVercel SandboxSandboxes are persistent by default, and the filesystem is saved when one stops. Files in a sandbox created as non-persistent are discarded. Drives, in public beta, outlive any sandbox.RiftFiles the run wrote to a Rift folder are already on your other machines.

Which to choose

Choose Vercel Sandbox when

  • Your application already runs on Vercel.
  • You want to pay for CPU only while it is active.
  • Several agents should share one machine as separate users.

Choose Rift when

  • The files should also be on your own machines.
  • A person or agent outside your Vercel team needs one folder.

Using them together

Vercel Sandbox runs the code and Rift keeps the files. Rift runs on Linux, which is what the sandbox runs.

Based on Vercel's documentation, read in October 2026. Sources: Sandbox, authentication, multiple agents, drives, general availability, security.