Monty
A secure Python sandbox, written in Rust, for code written by AI.
Monty avoids the latency, complexity and cost of a container based sandbox for running LLM generated code. It comes in two forms: OSS Monty, the MIT licensed Python 3.14 sandbox you install as a package, and Full Monty, the commercial server that runs the same sandbox behind a WebSocket as a service.
A new OSS Monty sandbox takes under 1ms from a running pool (Full Monty: about 2ms) compared to around 1500ms for a sandbox service.
Filesystem, environment variables and network do not exist inside the sandbox: it reaches the host only through the functions and mounts you pass in.
Documentation: pydantic.dev/docs/monty
Install
uv add pydantic-monty # Python
npm install @pydantic/monty # JavaScript / TypeScript
cargo add monty # RustThe commercial Full Monty runs the same workers as a container image.
Example
The code string is what a model writes when asked how long a bar of chocolate could power a lightbulb:
from pydantic_monty import Monty
code = """
kcal = nutrition('chocolate bar')['kcal']
hours = kcal * 4184 / (bulb_watts * 3600)
print(f'a chocolate bar powers a {bulb_watts} W bulb for {hours:.1f} hours')
"""
with Monty() as pool:
with pool.checkout() as session:
session.feed_run(
code,
inputs={'bulb_watts': 10},
external_lookup={'nutrition': lambda food: {'kcal': 230}},
)
#> a chocolate bar powers a 10 W bulb for 26.7 hoursnutrition ran on the host and the sandbox saw only its return value.
Documentation
- Introduction with the latency measurements
- Comparison to alternatives: Docker, Pyodide, WASI, sandboxing services
- Getting started with Python, JavaScript or Rust
- Security model, resource limits, snapshots, the Python subset
docs/: the source of the documentation site
Monty runs Code Mode in Pydantic AI. Community bindings: gomonty (Go) and dart_monty (Dart / Flutter).
Part of the Pydantic Stack
The Pydantic Stack is everything you need to ship production-grade AI agents:
- Pydantic AI - Type-safe agent framework
- Pydantic Logfire - AI-first, full-stack observability
- Logfire AI Gateway - Unified LLM proxy