Dock vs E2B
Both give agents isolated Firecracker machines with pause and fork. E2B is session-first, open source, and mature. Dock is built around long-lived machines with guardrails and a full record of the work.
Side by side
E2B in its own words: “E2B is the AI agent cloud. It gives each agent session an isolated Linux machine that boots from a snapshot.”
| Capability | Dock | E2B |
|---|---|---|
| Isolation | Firecracker microVMs on KVM bare metal (Standard, Premium); gVisor containers for the Nano tier. | Firecracker microVMs. |
| Persistence | Archive snapshots the filesystem; resume keeps the same dock identity. Stopped docks incur no compute charge. | Pause keeps filesystem and memory; paused sandboxes are kept with no expiry. Continuous runtime is capped per plan. |
| Snapshots and forks | Branch any snapshot into independent, writable docks with recorded lineage. | Live snapshots and fork from in-memory state. |
| Docker inside | Root, systemd, and Docker inside every dock. | Supported through a Docker template. |
| SSH | Native SSH and SCP, plus REST, TypeScript and Python SDKs, and the dock CLI. | Not native; documented as a WebSocket tunnel workaround. |
| Desktop | Full desktop or browser-only sessions with control locking for human takeover. | Ubuntu XFCE desktop over VNC via the Desktop SDK. |
| Network egress | Deny by default on every dock; allowed destinations set per Environment, enforced on the host. | Outbound internet allowed by default; allow and deny rules available. |
| Secrets | Vault Gateway: the agent uses an approved credential without the secret entering the guest. | Egress proxy can inject secrets so the sandbox never sees the value. |
| Audit | Flight Recorder: runs, prompts, commands, file changes, network decisions, and cost in one timeline. | Logs, metrics, lifecycle events, webhooks, and OpenTelemetry export. |
| Open source and self-host | Hosted service. | Apache-2.0 runtime, bring your own cloud, and self-hosting options. |
Where Dock is different
- Deny-by-default egress
- Every dock starts with no outbound access until an Environment allows it. E2B sandboxes start with the internet open.
- Native SSH to a long-lived machine
- Docks are built to be returned to day after day, with SSH and SCP as first-class access.
- Action-level audit
- Flight Recorder ties commands, files, network decisions, and cost to each run, beyond lifecycle events and telemetry.
Where E2B is strong
- Open source and self-hostable
- You can run E2B in your own cloud or on your own KVM hosts.
- Mature memory-preserving pause and fork
- Running processes survive pause, and E2B is generally available with SOC 2 Type II.
Choose Dock if
your agents return to the same machine across many tasks and you want network policy, brokered credentials, and a replayable record built in.
Choose E2B if
you want an open source runtime you can self-host, or short sessions that preserve running processes in memory today.
Tell us what your agents need to run.
Private beta is open. Describe your workload and we will reply about access.