# Dock > A persistent computer for every agent. Dock gives AI agents persistent, isolated Ubuntu computers with root, Docker, SSH, a browser, snapshots, and branches, plus credential brokering, network policy, and a replayable audit trail. Dock is the persistent, inspectable computer layer for agents that do real work. A dock is a complete, isolated Ubuntu machine with durable state, not a short-lived code runner. It can be paused, resumed under the same identity, branched into independent copies, and inspected afterward. Dock is framework neutral: bring Claude Code, Codex, OpenCode, or your own agent harness, and drive docks over REST, TypeScript and Python SDKs, the dock CLI, or SSH. Status: preview. Pricing is preview packaging until beta economics are validated; capabilities ship as each release gate is verified. ## About - Website: https://usedock.io - API base: https://api.usedock.io/v1 - Contact: hello@usedock.io - Category: developer infrastructure, cloud computers and sandboxes for AI agents ## Key pages - [Home](https://usedock.io): Overview of Dock persistent computers for agents - [Features](https://usedock.io/features): All Dock capabilities - [How it works](https://usedock.io/how-it-works): The dock lifecycle: create, work, archive, resume, branch, with API calls - [Developers](https://usedock.io/developers): REST API endpoints, SDKs, CLI commands, and response format - [Security](https://usedock.io/security): Isolation model, host-side guardrails, and data handling - [Blog](https://usedock.io/blog): Explainers on persistent computers, isolation, and parallel agents - [Use cases](https://usedock.io/use-cases): How teams use Dock - [Compare](https://usedock.io/vs): Dock compared with other agent sandboxes - [Pricing](https://usedock.io/pricing): Preview packaging and runtime tiers - [FAQ](https://usedock.io/faq): Answers about persistence, branching, security, and billing - [About](https://usedock.io/about): Company thesis and principles - [Contact](https://usedock.io/contact): Talk to the Dock team ## Features - [Persistent Linux computers](https://usedock.io/features/persistent-linux-computers): Dock gives every agent a full Ubuntu machine with root, systemd, Docker, and SSH. Files, packages, and caches survive archive and resume. - [Snapshots and branching](https://usedock.io/features/snapshots-and-branching): Snapshot a dock and branch it into independent, writable copies for parallel agents, evaluations, and experiments, each traceable to its parent. - [Live desktop and human takeover](https://usedock.io/features/human-takeover): Open a live desktop or browser session on any dock, inspect what the agent is doing, take control, and return it, with control locking. - [Vault Gateway](https://usedock.io/features/vault-gateway): Vault Gateway authorizes a credential for an approved destination and action without placing the long-lived secret inside the agent's machine. - [Flight Recorder](https://usedock.io/features/flight-recorder): Flight Recorder correlates agent runs, prompts, shell commands, file changes, snapshots, network decisions, and cost in one timeline. - [Network policy](https://usedock.io/features/network-policy): Define which destinations a dock may reach. Dock enforces egress policy outside the guest and records every permitted or blocked connection. - [Workspace controls](https://usedock.io/features/workspace-controls): Workspaces give agent docks ownership, roles, budgets, retention, and human approvals, with payment and account actions kept out of agent reach. ## Use cases - [Coding agents](https://usedock.io/use-cases/coding-agents): Run coding agents like Claude Code, Codex, and OpenCode in isolated, repository-aware Linux machines with Docker, previews, and cheap branches. - [Browser and computer use agents](https://usedock.io/use-cases/browser-agents): Keep Chrome profiles, logins, and session state on a persistent dock, with a live desktop for human takeover when the workflow needs judgment. - [QA and preview environments](https://usedock.io/use-cases/qa-and-previews): Build branches, run services, expose private preview URLs, and keep screenshots, logs, and artifacts on a persistent dock per change. - [Internal agent platforms](https://usedock.io/use-cases/internal-automation): Connect agents to internal tools and private systems with deny-by-default egress, brokered credentials, approvals, and a full audit trail. - [Agent evaluations](https://usedock.io/use-cases/agent-evaluations): Branch one snapshot into many identical docks to run agents, prompts, or models side by side and compare results fairly. ## Comparisons - [Dock vs E2B](https://usedock.io/vs/e2b): Dock vs E2B: both run agents in Firecracker microVMs. Dock adds deny-by-default egress, native SSH, and a replayable audit timeline. - [Dock vs Daytona](https://usedock.io/vs/daytona): Dock vs Daytona: Daytona defaults to containers with optional VMs. Every dock is a full VM with branching, deny-by-default egress, and a run timeline. - [Dock vs Modal Sandboxes](https://usedock.io/vs/modal): Dock vs Modal Sandboxes: Modal excels at huge numbers of short sandboxes. Dock gives agents long-lived machines with SSH, Docker, and a desktop. - [Dock vs boat](https://usedock.io/vs/boat): Dock vs boat (formerly Box by ASCII): both give agents persistent Ubuntu VMs with SSH, Docker, a desktop, and forks. Dock adds egress policy, brokered secrets, and audit. - [Dock vs Morph Cloud](https://usedock.io/vs/morph-cloud): Dock vs Morph Cloud: both offer persistent agent computers with branching. Dock documents egress policy, brokered credentials, and a run timeline. - [Dock vs Vercel Sandbox](https://usedock.io/vs/vercel-sandbox): Dock vs Vercel Sandbox: both use Firecracker microVMs. Dock keeps one machine identity across resume, denies egress by default, and adds a desktop and run timeline. ## Blog - [Why AI agents need persistent computers](https://usedock.io/blog/why-agents-need-persistent-computers): Agents that do real work build up state: repos, packages, caches, sessions. Throwing that away after every run is slow, expensive, and fragile. - [Containers vs microVMs for AI agents](https://usedock.io/blog/containers-vs-microvms-for-ai-agents): How containers, gVisor, and Firecracker microVMs isolate untrusted agent code, and how to choose between them. - [Running agents in parallel with branches](https://usedock.io/blog/parallel-agents-with-branches): Set up a machine once, snapshot it, and branch it into independent copies so several agents can attack the same task side by side. ## FAQ ### What is a dock? A dock is an isolated Ubuntu machine in the cloud that belongs to one agent. The agent can install software, run Docker, use files and a browser, and open a preview. When the work stops, you archive the dock and resume or branch it later. ### How is this different from a code sandbox? A code sandbox runs one short job and throws the machine away. A dock is a full Ubuntu computer that keeps its repositories, packages, caches, and browser sessions across many agent runs. ### Does anything survive when a dock stops? Yes. Archiving saves the dock's disk as a snapshot. Resume brings back the same dock with the same ID, and any snapshot can be branched into new docks. How long snapshots are kept depends on your plan. ### Can my agent run Docker and system services? Yes. You get root, systemd, package managers, and Docker inside the dock. Every dock is isolated from other customers and from the host. ### Can a person watch or take over? Yes. Open a full desktop or a browser-only session to watch the agent, take control, and hand it back. Only one side controls the input at a time, so the agent and the person never fight over it. ### How does Dock handle secrets? Environments decide what enters a dock. For keys an agent should use but never see, Vault Gateway attaches the credential to approved requests from outside the machine, so the secret never lands inside it. ### Which agents and frameworks work with Dock? Any agent that runs on Linux. Claude Code, Codex, and OpenCode come preinstalled. Drive docks from your own harness through the REST API, the TypeScript and Python SDKs, the dock CLI, or SSH. ### What happens when I branch a dock? Branching starts a new dock from a snapshot. The new dock gets its own ID and can be changed freely. Changes in the original, the branch, or any sibling never affect each other. ### How is usage billed? You pay for running time by machine size, billed by the second. Snapshot storage is listed separately. Archived docks have no compute charge. Prices are a preview until the beta confirms real costs. ### What are the Nano, Standard, and Premium tiers? Nano runs on shared container capacity at the lowest price with best-effort performance. Standard runs on dedicated KVM hardware and is the default. Premium uses lightly loaded hosts with priority placement. You pick the tier when you create a dock. ### Can I move a dock to a different tier? Not in place, because snapshots cannot resume across different backends. Branch the dock into the new tier instead. If a tier is full you get a tier_exhausted error and can choose another tier yourself; Dock never moves you to a pricier tier on its own. ### Is Dock available now? Dock is in private beta. We are giving access in stages and publish regions, features, and security details only once each one is verified.