OpenRouter has published a practical comparison of server-side code execution from OpenAI, Anthropic, Google and its own platform. These tools let a model run commands inside a provider-managed sandbox during the same API request, avoiding a separate tool handler in the developer’s application.
The products differ in language support, persistence and network controls. OpenAI documents a Debian 12 environment with several preinstalled languages and network access disabled unless an administrator configures an allowlist. Anthropic provides Python and Bash in a Linux container with one CPU, 5 GiB of memory and 5 GiB of storage; outbound connections are disabled. Google’s tool focuses on Python.
OpenRouter’s beta `openrouter:shell` works across models on its Responses and Messages APIs, while `openrouter:bash` is limited to the Messages API. Its containers disable outbound networking by default, impose command and output limits, and cost $0.0001 per second with a 30-second minimum for a new or sleeping sandbox.
Hosted execution reduces provisioning and patching work, but it does not replace every sandbox. OpenRouter recommends separately operated infrastructure when an agent needs a custom base image, GPU access or sessions lasting hours. Developers must still control uploaded data, tool-call limits and any network exceptions.