Dock vs Vercel Sandbox
Vercel Sandbox is a mature, generally available microVM product with a strong firewall. Dock is built around one persistent machine per agent, with people able to see and take over the work.
Side by side
Vercel Sandbox in its own words: “Run untrusted or agent-generated code in isolated Linux microVMs.”
| Capability | Dock | Vercel Sandbox |
|---|---|---|
| Isolation | Firecracker microVMs on KVM bare metal (Standard, Premium); gVisor containers for the Nano tier. | Firecracker microVMs running Ubuntu with root. |
| Persistence | Archive snapshots the filesystem; resume keeps the same dock identity. Stopped docks incur no compute charge. | Stop snapshots the filesystem; resume boots a new session. Sessions are capped per plan. |
| Snapshots and forks | Branch any snapshot into independent, writable docks with recorded lineage. | Snapshots retained 30 days after last use by default, with rollback by ID. |
| Docker inside | Root, systemd, and Docker inside every dock. | Supported through system-privileged processes. |
| SSH | Native SSH and SCP, plus REST, TypeScript and Python SDKs, and the dock CLI. | sandbox connect from the CLI. |
| Desktop | Full desktop or browser-only sessions with control locking for human takeover. | Not stated. |
| Network egress | Deny by default on every dock; allowed destinations set per Environment, enforced on the host. | Allow-all by default; deny-all and allowlist modes, changeable while running. |
| Secrets | Vault Gateway: the agent uses an approved credential without the secret entering the guest. | Firewall injects credentials so secrets never enter the sandbox. |
| Audit | Flight Recorder: runs, prompts, commands, file changes, network decisions, and cost in one timeline. | Activity log of lifecycle events and session listing. |
| Status | Preview. Pricing is preview packaging. | Generally available across many regions. |
Where Dock is different
- Deny by default
- Docks start closed. Vercel sandboxes start open unless you set a policy.
- Same machine on resume
- A resumed dock keeps its identity and SSH endpoint rather than starting a new session from a snapshot.
- Takeover and timeline
- Desktop and browser takeover plus an action-level record of each run.
Where Vercel Sandbox is strong
- Mature firewall and brokering
- Generally available with detailed matchers, live policy updates, and large scale.
- Active CPU billing
- Time spent waiting on model inference is not billed as CPU, a real saving for agents.
Choose Dock if
your agent needs one persistent machine with a desktop that people can watch and take over, closed to the network by default.
Choose Vercel Sandbox if
you are already on Vercel and want a generally available sandbox with per-session isolation and active CPU pricing.
Tell us what your agents need to run.
Private beta is open. Describe your workload and we will reply about access.