Wasmer: WebAssembly Sandboxes for Apps and AI Agents Across Every Platform
🚀 Fast and lightweight sandboxes for your apps and AI agents
At a glance
- What is it?
- Wasmer is a WebAssembly runtime that runs programs in secure, lightweight sandboxes on macOS, Linux, Windows, and in the browser. A CLI installs with one command; an SDK for JavaScript, Python, Rust, and Swift lets you embed the same sandboxes inside your own application.
- Who is it for?
- Wasmer suits developers who need to run untrusted or platform-specific code in a controlled sandbox, whether from a shell script, a Node.js service, or an iOS app. The CLI installs in one command on macOS and Linux; the JavaScript SDK requires Node.js 20 or newer; the Swift SDK targets macOS 12 and iOS 27.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 1 day ago.
- What is it written in?
- Mainly Rust, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Wasmer Does and Who It Is For
Wasmer runs programs compiled to WebAssembly inside sandboxes that are isolated by default. The README describes the model in four points: secure by default, with you controlling file, network, and environment access; lightweight, with fast startup and a small memory footprint; ready to run, because Python, JavaScript, Bash, and other packages are available from the Wasmer registry; and embeddable, through the Wasmer SDK which exposes sandboxes as an API your application can call.
The primary use cases are running untrusted code safely, executing platform-specific tools in a portable way, and embedding sandboxed execution inside AI agents or application backends. The README specifically calls out AI agents as a target workload alongside general application sandboxing. The project is written in Rust, released under the MIT licence, and hosted under the wasmerio GitHub organization. Current version is v7.4.2, with the full set of library crates pinned to that version in the Cargo.toml workspace.
Running Your First Sandbox with the CLI
On macOS or Linux, install the CLI in a single command:
curl https://get.wasmer.io -sSfL | shOn Windows PowerShell:
iwr https://win.wasmer.io -useb | iexOr via Homebrew:
brew install wasmerOnce installed, run Python inside a sandbox without needing Python on your host:
wasmer run python/python -- -c "print('Hello from Wasmer')"Wasmer downloads the package from the registry and caches it for future runs. The README documents how to grant file access with --volume and enable host networking with --net. The -- separator distinguishes Wasmer's own flags from the arguments passed to the sandboxed program. To try the CLI without installing anything locally, the README points to wasmer.sh, a browser-based interface.
Embedding Sandboxes with the Wasmer SDK
The Wasmer SDK lets you create and run sandboxes programmatically from your own application. For JavaScript and TypeScript on Node.js 20 or newer, install the SDK:
npm install @wasmer/sdkThen create a sandbox and run a command inside it:
import { Wasmer } from "@wasmer/sdk/node";
const wasmer = new Wasmer();
const sandbox = await wasmer.sandboxes.create({
packages: ["python/python@=3.13.20"],
});
const output = await sandbox
.command("python", ["-c", "print('Hello from Wasmer')"])
.run();
console.log(output.text());Python executes inside the sandbox; the host machine does not need Python installed. The README notes to run the script with node sandbox.mjs. The README provides equivalent examples for Python, Rust, and Swift. The Python SDK wheels support macOS and Linux on Intel and ARM64; install with python -m pip install wasmer-sdk. For Rust, the SDK currently uses a source dependency pointing to the wasmerio/wasmer-sdk repository, with Crates.io publishing noted as disabled in the README. Rust embedders must clone that repository and point to its rust directory in Cargo.toml.
Swift SDK for iOS and macOS
The Wasmer SDK supports Swift 6 on macOS 12 and iOS 27. Add the package to your Swift package dependencies:
.package(
url: "https://github.com/wasmerio/wasmer-sdk.git",
revision: "wasmer-sdk-swift-v0.4.0"
)On iOS, the SDK manages a hidden WKWebView internally; the application does not need to display one. iOS apps must declare local networking in Info.plist with NSAllowsLocalNetworking set to true. The Swift API shares the same sandboxes.create and sandbox.command structure as the JavaScript SDK. The requirement for iOS 27 is a hard constraint, not a soft recommendation.
Compiler Backends and the Build Matrix
Wasmer exposes three compiler backends: Cranelift, LLVM, and Singlepass. The Makefile documents the supported matrix across compiler, platform, and architecture columns. Linux supports amd64, aarch64, riscv64gc, and loongarch64. Darwin (macOS) and Windows cover amd64 and aarch64. FreeBSD is also listed in the platform column. The Cargo.toml workspace includes a library crate for each backend: wasmer-compiler-cranelift, wasmer-compiler-llvm, and wasmer-compiler-singlepass.
The examples directory at the top of the Rust crate contains low-level integration files such as compiler_cranelift.rs, compiler_llvm.rs, compiler_singlepass.rs, exports_function.rs, imports_function.rs, memory.rs, and others. These demonstrate embedding Wasmer at the Rust API level. They are distinct from the higher-level Wasmer SDK, which abstracts the sandbox lifecycle and is the recommended path for application developers who do not need direct control over the WebAssembly instance.
The rust-toolchain.toml file pins the Rust toolchain version for reproducible builds, which is relevant for contributors and for teams that build Wasmer from source rather than using the pre-built CLI distribution.
When Wasmer Is the Wrong Choice
Wasmer does not sandbox arbitrary native binaries; it runs WebAssembly modules. Code that has not been compiled to WebAssembly cannot run in Wasmer without a recompilation step, which is a real constraint for teams that need to sandbox existing native software without modifying the build pipeline.
The browser SDK requires the page to set cross-origin isolation headers (Cross-Origin-Opener-Policy: same-origin and Cross-Origin-Embedder-Policy: require-corp) for worker-backed execution. Environments that cannot set those headers, such as some shared hosting configurations or older CDN setups, cannot use Wasmer in the browser. The README links to a browser setup guide and to wasmer.sh as a reference implementation.
Wasmtime is an alternative WebAssembly runtime maintained by the Bytecode Alliance, built in Rust and focused on standards compliance and a strict security model. Wasmtime is a lower-level runtime library primarily targeted at server-side embedding, with no bundled package registry or multi-language SDK comparable to what Wasmer ships. Teams that need a package registry and a higher-level SDK with JavaScript, Python, Rust, and Swift bindings will find Wasmer's offering more complete, while teams that want a minimal WASM host with direct control over the component model may prefer Wasmtime.
Maintenance, Versioning, and the MIT Licence
The current release is v7.4.2, released on 2026-09-16. v7.4.0 arrived on 2026-08-31 and v7.4.1 on 2026-09-08, showing a weekly cadence over that period. The last push to the repository was on 2026-09-28, confirming active development at the time of this writing.
The Cargo.toml workspace pins all internal library crates to version 7.4.2, including wasmer, wasmer-cache, wasmer-compiler, wasmer-compiler-cranelift, wasmer-compiler-llvm, wasmer-compiler-singlepass, wasmer-middlewares, wasmer-types, and wasmer-wasix. The repository uses Rust as the primary language, with the edition and rust-version centralized in the workspace configuration.
Wasmer is released under the MIT licence. The SDK repository at wasmerio/wasmer-sdk is a separate codebase that backs the JavaScript, Python, Rust, and Swift bindings; the Rust SDK notes that Crates.io publishing is currently disabled, so Rust embedders must use the source dependency path documented in the README rather than a published crate version. The CHANGELOG.md in the main repository tracks runtime changes, while the wasmer-sdk repository maintains its own history.
Editorial conclusion
Wasmer suits developers who need to run untrusted or platform-specific code in a controlled sandbox, whether from a shell script, a Node.js service, or an iOS app. The CLI installs in one command on macOS and Linux; the JavaScript SDK requires Node.js 20 or newer; the Swift SDK targets macOS 12 and iOS 27. Projects that need LLVM-based compilation or loongarch64 support should check the backend matrix in the Makefile before committing to the runtime.
Frequently asked questions
What is Wasmer?
Wasmer is a WebAssembly runtime that runs programs inside fast, secure sandboxes on macOS, Linux, Windows, and in the browser. A CLI gives shell access to sandboxed packages from the Wasmer registry, and a multi-language SDK embeds sandboxes into applications.
Is Wasmer free to use?
The Wasmer runtime and CLI are released under the MIT licence, which permits free use, modification, and redistribution. The README does not document any usage tier or subscription requirement for the open-source runtime.
How do I use Wasmer?
Install the CLI with the curl command from get.wasmer.io on macOS or Linux, then run a package with wasmer run, using -- to separate Wasmer flags from the program's arguments. For embedding in an application, install the @wasmer/sdk npm package or the wasmer-sdk Python package and use the sandboxes.create API.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/wasmerio-wasmer)