BetaPrivate beta is open. Teams are onboarded in stages.

Dock vs E2B

Both give agents isolated Firecracker machines with pause and fork. E2B is session-first, open source, and mature. Dock is built around long-lived machines with guardrails and a full record of the work.

Side by side

E2B in its own words: “E2B is the AI agent cloud. It gives each agent session an isolated Linux machine that boots from a snapshot.”

CapabilityDockE2B
IsolationFirecracker microVMs on KVM bare metal (Standard, Premium); gVisor containers for the Nano tier.Firecracker microVMs.
PersistenceArchive snapshots the filesystem; resume keeps the same dock identity. Stopped docks incur no compute charge.Pause keeps filesystem and memory; paused sandboxes are kept with no expiry. Continuous runtime is capped per plan.
Snapshots and forksBranch any snapshot into independent, writable docks with recorded lineage.Live snapshots and fork from in-memory state.
Docker insideRoot, systemd, and Docker inside every dock.Supported through a Docker template.
SSHNative SSH and SCP, plus REST, TypeScript and Python SDKs, and the dock CLI.Not native; documented as a WebSocket tunnel workaround.
DesktopFull desktop or browser-only sessions with control locking for human takeover.Ubuntu XFCE desktop over VNC via the Desktop SDK.
Network egressDeny by default on every dock; allowed destinations set per Environment, enforced on the host.Outbound internet allowed by default; allow and deny rules available.
SecretsVault Gateway: the agent uses an approved credential without the secret entering the guest.Egress proxy can inject secrets so the sandbox never sees the value.
AuditFlight Recorder: runs, prompts, commands, file changes, network decisions, and cost in one timeline.Logs, metrics, lifecycle events, webhooks, and OpenTelemetry export.
Open source and self-hostHosted service.Apache-2.0 runtime, bring your own cloud, and self-hosting options.

Where Dock is different

Deny-by-default egress
Every dock starts with no outbound access until an Environment allows it. E2B sandboxes start with the internet open.
Native SSH to a long-lived machine
Docks are built to be returned to day after day, with SSH and SCP as first-class access.
Action-level audit
Flight Recorder ties commands, files, network decisions, and cost to each run, beyond lifecycle events and telemetry.

Where E2B is strong

Open source and self-hostable
You can run E2B in your own cloud or on your own KVM hosts.
Mature memory-preserving pause and fork
Running processes survive pause, and E2B is generally available with SOC 2 Type II.

Choose Dock if

your agents return to the same machine across many tasks and you want network policy, brokered credentials, and a replayable record built in.

Choose E2B if

you want an open source runtime you can self-host, or short sessions that preserve running processes in memory today.

Tell us what your agents need to run.

Private beta is open. Describe your workload and we will reply about access.