A real Linux computer
Ubuntu, root, systemd, Docker, package managers, runtimes, and the tools your agents already know.
Private beta access is open.
Launch a full Linux computer once. Let the agent work, pause it when idle, branch it when needed, and return to the same state when the next task starts.
Full VM
Ubuntu + root
Durable
Pause + resume
Any agent
API + SDK + CLI
Activity
Agent run
Active
Preview
:3000
Branch
main
Snapshot
Fresh
Terminal
user@checkout-fix:~/store$
pnpm test --filter checkout
Tests 42 passed · duration 11.8s
Flight recorder
Live
Not another disposable sandbox. Dock is the persistent, inspectable computer layer for agents that do real work.
Ready on the computer
Docks arrive with the runtimes, browsers, editors, and agent CLIs needed for real software work. Install more whenever the job demands it.
Docker
VS Code
Chrome
Ghostty
GitHub
Rust
Node.js
Bun
Codex
Claude Code
Oh My Pi
Pi
Hermes
OpenCode
The primitive
A dock has durable identity and state. Environments, runs, snapshots, branches, ports, policy, and audit events attach to it, so your team does not have to assemble the machine around every invocation.
Ubuntu, root, systemd, Docker, package managers, runtimes, and the tools your agents already know.
Files, repositories, browser profiles, and tool state persist through archive and resume.
Branch a snapshot into independent docks for parallel agents, evaluations, and experiments.
Open a live desktop or browser, inspect the work, take control, then hand it back to the agent.
Keep long-lived secrets outside the guest and authorize narrowly scoped actions through Vault Gateway.
Correlate runs, commands, files, snapshots, network decisions, and cost in Flight Recorder.
Lifecycle
Archive a dock without discarding its filesystem. Resume it under the same identity, or branch a snapshot into isolated descendants for parallel work.
Isolated Ubuntu
Tools + Docker
State preserved
Parallel copies
Same identity
Developer experience
Use the framework you already have. Dock exposes one lifecycle through REST, typed SDKs, and a CLI, with queryable operations and stable errors.
TypeScript SDK
Create a dock, run real work, preserve its state. The same lifecycle is available through REST, Python, TypeScript, and the Dock CLI.
Production boundary
MicroVM isolation is the start. Dock adds policy-bound credential use, network decisions, human approvals, and a replayable record around the guest.
Authorize a credential for an approved destination and action without placing the long-lived secret in the guest.
Define allowed destinations and record whether each connection was permitted or blocked.
Trace agent runs, shell commands, file changes, snapshots, network decisions, and cost together.
Apply ownership, budgets, roles, retention, and approvals across a fleet of agent docks.
Security capabilities and deployment options vary by release and plan. Dock publishes only verified isolation, retention, and compliance status.
Built for builders
Give every task a repository-aware workstation with Docker, previews, and cheap branches.
Keep Chrome profiles and session state, with live human takeover when the workflow needs judgment.
Connect agents to approved tools and private systems without handing the guest permanent credentials.
Build branches, run services, expose private URLs, preserve screenshots, logs, and artifacts.
Give the work somewhere to live
Tell us about your workload