A single agent run at one early-access customer required six vendors — OpenCode for the harness, Fly.io for compute, AWS for storage, Fireworks for inference, Anthropic for the model, and Parallel for orchestration. Nobody on the team could say what that run actually cost. DigitalOcean’s October 2026 launch of Managed Agents and Agent Droplets is a direct answer to that fragmentation problem: one platform, one bill, and a governed tool layer that handles 16,000+ integrations through a single MCP endpoint.
- What Are DigitalOcean Managed Agents?
- Harness Runtime: Architecture and How It Works
- Action Gateway: The Tool Access Layer That Changes the Game
- How It Works
- Credential Brokering and Security
- Human-in-the-Loop Approval
- Pricing: $0.10 Per 1,000 Tool Invocations
- Agent Droplets: The Unified Pricing Model
- Architecture Deep Dive: How All the Pieces Fit Together
- Practical Use Cases for RPA and Automation Teams
- 1. Agentic Process Automation
- 2. Multi-Agent Orchestration
- 3. Long-Running Agent Sessions
- 4. Governed Tool Access for Regulated Industries
- Getting Started: From Zero to Running Agent
- Limitations and Considerations
- Who Should — and Shouldn’t — Use This
- What This Means for the Agentic AI Market
- FAQs
- How does DigitalOcean Managed Agents differ from AWS Bedrock AgentCore?
- Can I run my existing RPA workflows on DigitalOcean Managed Agents?
- What happens to my agent’s state when a session is paused?
- Is the Action Gateway limited to the pre-built 16,000 tools?
- What models can I use with Agent Droplets?
- Key Takeaways
- References
For agentic AI architects and RPA professionals already running production agent workloads — or planning to — this is the first time a mid-market cloud provider has shipped a fully integrated agent hosting stack that bundles compute, inference, tool access, and session management into a coherent product. This guide breaks down the architecture, pricing, security model, and practical deployment considerations so you can decide whether DigitalOcean’s approach fits your production pipeline.
What Are DigitalOcean Managed Agents?
Managed Agents is a platform service that entered public preview on September 22, 2026, combining two integrated components designed to eliminate the infrastructure management overhead of running AI agents at scale:
- Harness Runtime — managed, hardware-isolated Firecracker microVM sandboxes that execute agent code with persistent session state
- Action Gateway — a governed tool access layer exposing 16,000+ tools through a single MCP (Model Context Protocol) endpoint with credential brokering, rate limiting, and human-in-the-loop approval
The key architectural decision is that the agent harness and the tool layer are separate managed services that communicate through standardized protocols. This means you can run Claude Code, Codex CLI, OpenCode, Hermes, LangGraph, or any custom agent packaged as an OCI container — and all of them get the same governed access to the same 16,000+ tool catalog without custom integration work.

Harness Runtime: Architecture and How It Works
The Harness Runtime is where your agent code actually executes. Rather than spinning up full virtual machines or sharing container runtimes, DigitalOcean uses Firecracker microVMs — the same lightweight virtualization technology that powers AWS Lambda — to provide hardware-level isolation with near-instant startup.
Performance Benchmarks
DigitalOcean published specific performance numbers from their public preview:
| Metric | Measurement |
|---|---|
| Harness Runtime readiness | 886 milliseconds |
| First agent response (session creation → model reply) | 3.3 seconds |
| Resume to readiness | 305 milliseconds |
| Resumed session response time | 2.43 seconds |
| Command round-trip (including auth/audit overhead) | 189 milliseconds |
The 305ms resume time is the number that matters most for production workloads. Agent sessions that pause during idle periods — and most agents are idle far more than they’re active — can resume without the cold-start penalty that plagues serverless architectures. This is especially relevant for persistent enterprise agents that need to maintain conversational context across hours or days.
Session Lifecycle Management
The Harness Runtime exposes lifecycle APIs that go beyond simple start/stop:
- Pause — suspends the microVM, preserving all working state (files, environment variables, in-memory data) while eliminating CPU and memory charges
- Resume — restores the session from its paused state in ~300ms with full context preservation
- Fork — creates a checkpoint of the current session state that can be branched into parallel exploration paths
- Auto-pause — automatically suspends sessions when no LLM calls or tool invocations are detected, preventing runaway billing
Forking is particularly interesting for agentic AI architects designing multi-path decision workflows. Instead of running sequential A/B tests, you can fork a session at a decision point and let two agent branches explore different approaches simultaneously — then compare results and merge the winning path.
Supported Agent Harnesses
The platform ships with first-class support for six agent frameworks, plus a bring-your-own-template option:
| Harness | Type | Best For |
|---|---|---|
| Claude Code | Coding agent | Code generation, debugging, refactoring with Anthropic models |
| Codex CLI | Coding agent | OpenAI-backed coding tasks with CLI interface |
| OpenCode | Coding agent | Open-source coding agent supporting multiple LLM providers |
| Hermes | General-purpose agent | Multi-step reasoning and task orchestration |
| LangGraph | Orchestration framework | Complex agent workflows with state machines and cycles |
| CrewAI | Multi-agent framework | Role-based multi-agent collaboration |
| Custom OCI Image | Bring-your-own | Any agent packaged as a container |
The custom OCI image support is what makes this viable for enterprise RPA teams. If you’ve built an agent on top of MCP-compatible frameworks or have a proprietary orchestration layer, you can package it as a container and deploy it on the same infrastructure — no vendor lock-in to a specific agent framework.
Action Gateway: The Tool Access Layer That Changes the Game
The Action Gateway is, architecturally, the more significant component. Most agent hosting platforms solve the compute problem reasonably well. Very few solve the tool access problem — how agents securely authenticate to external services, handle rate limits, manage credentials, and provide audit trails — without forcing teams to build custom middleware.
How It Works
The Action Gateway provides a single managed MCP endpoint that your agent connects to. Behind that endpoint sits a curated catalog of 16,000+ tools spanning:
- DigitalOcean-maintained tools — web search, web fetch, browser automation (Chromium), code execution sandbox, and DigitalOcean infrastructure APIs
- Third-party integrations — GitHub, HubSpot, Stripe, Snowflake, PagerDuty, Box, Supabase, Exa, and hundreds more
- Custom MCP servers — teams can register their own proprietary tool providers for internal systems
The critical design decision is tool discovery via search, not context loading. Rather than dumping 16,000 tool schemas into your agent’s context window (which would obliterate your token budget), the Action Gateway provides a tool-search function that “discovers relevant catalog tools and their schemas without loading the entire catalog into an agent’s context.” DigitalOcean reports 99.3% accuracy on tool matching in internal testing.
Credential Brokering and Security
This is where the Action Gateway solves a genuinely hard problem for production agent deployments. When an agent needs to call the Stripe API or push to a GitHub repository, the credentials are:
- Brokered at execution time — the credential is injected into the API call by the gateway, never passed to the model or exposed in the sandbox
- Scoped by policy — tool policies can allow, require human approval for, or deny specific tool calls within a session
- Audited — every tool invocation is logged with the full request/response chain for compliance
For RPA professionals coming from platforms like UiPath or Automation Anywhere, this is analogous to the credential vault pattern — but applied natively to agentic AI workflows rather than bolted on as an afterthought.
Human-in-the-Loop Approval
The gateway supports configurable approval workflows for sensitive operations. Teams can define which tool categories require human sign-off before execution — a critical requirement for finance, healthcare, and any regulated industry where an autonomous agent writing to a production database needs a human checkpoint.
Approval can be handled through MCP elicitation (the agent pauses and requests approval through the protocol) or through a separate approval request workflow, depending on the integration pattern.
Pricing: $0.10 Per 1,000 Tool Invocations
The Action Gateway charges $0.10 per 1,000 tool invocations, with tool search queries included at no extra cost and separate charges for code execution and paid third-party tools. For context, an agent that makes 50 tool calls per task run across 100 daily runs would cost roughly $0.50/day — $15/month — for the tool layer alone. That’s competitive with building and maintaining your own tool middleware.
Agent Droplets: The Unified Pricing Model
Launched on October 1, 2026, Agent Droplets layer a subscription pricing model on top of Managed Agents. The name deliberately echoes DigitalOcean’s original “Droplet” product — the $5/month virtual server that made cloud computing accessible to individual developers and small teams. Agent Droplets aim to do the same for agent hosting.
Pricing Tiers
| Plan | Monthly Cost | Discount on Usage | Approximate Included Capacity |
|---|---|---|---|
| Free Trial | $5 credit (no card required) | 15% | Enough for initial testing |
| Pro | $50/month | 15% | ~53M inference tokens, ~235 agent hours, ~24 GB-months storage |
| Team | $200/month | 20% | Scaled for multi-agent production workloads |
Key features across all tiers:
- Unlimited agents and seats — no per-user charges, which is a stark contrast to per-seat models from Microsoft Copilot Studio or Salesforce Agentforce
- No idle charges — paused agents incur zero CPU/memory costs; you pay only for active compute
- Enterprise security included — SSO, MFA, RBAC, audit logs, cloud firewalls, and DDoS protection at every tier
- Spending caps — set a monthly limit; when reached, usage can optionally continue at standard (non-discounted) rates
Cost Comparison: DigitalOcean vs. the Alternatives
To put these numbers in context, here’s how Agent Droplets compare to the primary alternatives for hosting production agents:
| Platform | Compute Model | Tool Access | Billing | Starting Price |
|---|---|---|---|---|
| DigitalOcean Agent Droplets | Managed microVMs with pause/resume | 16,000+ via Action Gateway (MCP) | One subscription + usage discounts | $50/month (Pro) |
| AWS Bedrock AgentCore | EC2-backed sessions (up to 14-day sessions) | AWS service integrations + custom | Per-component metering | Pay-as-you-go (complex) |
| Azure AI Foundry | Managed compute with Azure integrations | Azure ecosystem + Semantic Kernel | Per-component metering | Pay-as-you-go (complex) |
| Google Vertex AI Agent Builder | Serverless with auto-scaling | Google Cloud integrations + A2A | Per-invocation + model costs | Pay-as-you-go |
| Modal | Serverless with GPU access | Custom integration required | Per-second billing | $30/month credits |
| Fly.io | Container-based with global distribution | No integrated tool layer | Usage-based | Pay-as-you-go |
The fundamental value proposition is billing simplicity. As DigitalOcean’s Chief Product and Technology Officer Vinay Kumar stated: “An Agent Droplet is one subscription for everything an agent needs.” AWS and Azure offer more raw power and deeper ecosystem integrations, but their billing for agent workloads requires reconciling compute, model invocation, storage, and tool-call charges across multiple service dashboards.
Architecture Deep Dive: How All the Pieces Fit Together
Understanding the full architecture is essential for agentic AI architects evaluating this platform. Here’s how the components interact:
The Request Flow
When an agent session runs on DigitalOcean Managed Agents, the following chain executes:
- Session initialization — the Harness Runtime provisions a Firecracker microVM with the selected agent harness (Claude Code, LangGraph, custom OCI image, etc.) in ~886ms
- User prompt arrives — the agent receives the task through the session’s conversational API
- Inference call — the agent calls the DigitalOcean Inference Engine (for hosted open models like Kimi K3 and GLM 5.3) or an external model provider (Claude, GPT) at standard rates
- Tool discovery — the agent queries the Action Gateway’s tool-search endpoint to find relevant tools for the current task step
- Tool execution — the agent invokes tools through the Action Gateway; credentials are brokered at execution time, never reaching the model context
- State persistence — session artifacts, conversation history, and working state are persisted in DigitalOcean storage
- Idle detection — when no LLM or tool calls are active, auto-pause suspends the microVM; resume takes ~305ms
Security Isolation Model
Each agent session runs in its own Firecracker microVM, providing:
- Hardware-level isolation — memory, CPU, and filesystem are fully isolated between sessions (unlike shared-container models)
- Dedicated compute and filesystem — no noisy-neighbor effects from other tenants’ workloads
- Security-hardened port forwarding — for previewing applications without exposing the full sandbox network stack
- Credential isolation — tool credentials brokered through the Action Gateway never enter the microVM environment
This isolation model is significantly stronger than container-based hosting (Docker, Fly.io) and comparable to what AWS provides with Bedrock AgentCore’s EC2-backed sessions — but without the EC2 instance management overhead.
Practical Use Cases for RPA and Automation Teams
While DigitalOcean’s marketing emphasizes coding agents, the platform’s architecture is directly applicable to enterprise automation scenarios that agentic AI architects and RPA teams encounter daily.
1. Agentic Process Automation
An agent running on Managed Agents can use the Action Gateway’s 16,000+ tools to orchestrate multi-step business processes — the same kind of work that traditional RPA bots handle, but with natural language understanding and dynamic decision-making. The Qencode case study from DigitalOcean’s early access program demonstrates this: a support-triage agent reviews incoming requests, assesses urgency and sentiment, and creates or updates Jira tickets — saving the team an estimated 4 to 8 hours per week with near-instant response times replacing hours of manual triage.
2. Multi-Agent Orchestration
The session forking and parallel execution capabilities map directly to multi-agent patterns where a supervisor agent distributes subtasks to specialized worker agents. Combined with the A2A protocol and MCP standards that the Action Gateway natively supports, this creates a foundation for building the kind of multi-agent systems that frameworks like CrewAI and LangGraph are designed for — but with managed infrastructure underneath.
3. Long-Running Agent Sessions
The pause/resume model is purpose-built for agents that need to maintain context over extended periods. Consider an Agentforce-style “job-ready agent” that monitors a procurement pipeline: it needs to wake up when a new purchase order arrives, review the PO against vendor contracts, flag exceptions, and pause again — potentially running across days or weeks. With Agent Droplets’ per-second active CPU billing, that agent costs almost nothing while paused.
4. Governed Tool Access for Regulated Industries
The Action Gateway’s policy-based tool access and human-in-the-loop approval system addresses a persistent problem in enterprise automation: how do you let an agent act autonomously on routine tasks while requiring human sign-off for high-risk operations? In a healthcare claims processing scenario, the agent might auto-classify and route standard claims (approved tool policy) but require a human reviewer’s approval before adjusting a claim above a certain dollar threshold (approval-required tool policy).
Getting Started: From Zero to Running Agent
DigitalOcean provides both a web control panel and CLI path. The CLI approach is more relevant for agentic AI architects who’ll be scripting deployments:
# Authenticate with DigitalOcean
doctl auth init
# Launch a Claude Code agent session
doctl harness-runtime launch \
--harness claude-code \
--name my-first-agent
# Launch a LangGraph agent from a custom image
doctl harness-runtime launch \
--harness custom \
--image my-registry/my-agent:latest \
--name production-orchestrator
Sessions persist across devices and can be resumed from any location — start a debugging session on your laptop, close it, and resume from your phone or another machine with full state preservation.
Connecting to the Action Gateway
Once your agent session is running, connecting to the Action Gateway’s tool catalog requires minimal configuration:
- Authorize providers — connect your GitHub, Stripe, HubSpot, or other accounts through the DigitalOcean control panel
- Configure tool policies — set which tools are allowed, which require approval, and which are denied for each agent or session
- Register custom tools — add your own MCP servers for internal APIs and proprietary systems
The tool-search function handles discovery automatically — your agent doesn’t need to know which tools are available in advance. It describes what it needs, and the gateway returns the relevant tool schemas.
Limitations and Considerations
No platform review is complete without honest limitations. Here’s what you should know before committing:
- Public preview, not GA — Managed Agents and Agent Droplets are in public preview as of October 2026. Expect rough edges, potential breaking changes, and limited SLA guarantees. Production-critical workloads should have a fallback plan.
- Frontier model access is pass-through — the discounted pricing applies to DigitalOcean-hosted open models (Kimi K3, GLM 5.3, and similar). Claude, GPT, and other frontier models are available but billed at standard provider rates with no discount. If your agent workload depends heavily on Claude Sonnet or GPT-4, the “one bill” advantage partially dissolves.
- GPU access is indirect — the Harness Runtime doesn’t provide GPU-attached microVMs. If your agent needs to run local inference or GPU-accelerated processing, you’ll need to pair Managed Agents with DigitalOcean’s GPU Droplets separately.
- Ecosystem maturity — AWS Bedrock and Azure AI Foundry have deeper native integrations with their respective cloud ecosystems (S3, DynamoDB, Azure Cosmos DB, etc.). DigitalOcean’s third-party integrations go through the Action Gateway, which adds a layer of abstraction that may or may not fit your existing architecture.
- No built-in observability yet — DigitalOcean Insights (their agent observability tool) is in private preview. Until it reaches public preview, monitoring agent behavior requires external tooling or custom logging.
Who Should — and Shouldn’t — Use This
Strong Fit
- Mid-market teams running 5-50 agents that don’t need the full weight of AWS or Azure but have outgrown local development
- Startups and agencies building agentic products for clients who need governed, auditable tool access without building their own middleware
- RPA-to-AI migration projects where you need a managed runtime for the new agentic workflows alongside existing UiPath or Automation Anywhere deployments
- Teams with multi-framework requirements — the framework-agnostic harness model means you can run Claude Code and LangGraph side by side without infrastructure duplication
Weaker Fit
- Large enterprises with deep AWS/Azure commitments — the switching cost and ecosystem integration gap may outweigh the billing simplicity
- GPU-intensive agent workloads — local inference, fine-tuning, or vision-heavy processing is better served by Modal, RunPod, or DigitalOcean’s own GPU Droplets (separate product)
- Teams needing GA-level SLAs — wait for general availability before betting production-critical workflows on a public preview product
What This Means for the Agentic AI Market
DigitalOcean’s entry into managed agent hosting signals a market inflection point. When the mid-market cloud provider — historically focused on developers and small teams — ships a dedicated agent hosting product, it confirms that agent workloads are moving from experimental to operational across the industry.
The Action Gateway’s MCP-native tool access layer is particularly significant. As the A2A and MCP protocols become the standardized plumbing for agent-to-agent and agent-to-tool communication, platforms that natively speak these protocols — rather than wrapping them in proprietary abstractions — will have a structural advantage.
For RPA professionals, this reinforces a pattern we’ve been tracking on this site: the infrastructure layer for agentic automation is commoditizing fast. The competitive differentiation is moving up the stack — to agent governance and safety, to domain-specific orchestration logic, and to the process intelligence that decides what to automate, not how to run it.
FAQs
How does DigitalOcean Managed Agents differ from AWS Bedrock AgentCore?
Managed Agents bundles compute, tool access, and session management into a single managed service with simplified pricing through Agent Droplets. AWS Bedrock AgentCore offers deeper AWS ecosystem integration and EC2-backed sessions supporting up to 14-day runs, but bills each component separately. DigitalOcean targets mid-market teams who want one platform and one bill; AWS targets enterprises who need fine-grained control over each infrastructure component.
Can I run my existing RPA workflows on DigitalOcean Managed Agents?
Not directly — Managed Agents is designed for agentic AI workloads, not traditional RPA bot execution. However, the custom OCI image support means you can containerize an agentic wrapper that coordinates with your existing UiPath or Automation Anywhere deployment. The Action Gateway’s custom MCP server support also lets you expose your RPA orchestrator as a tool that agents can invoke.
What happens to my agent’s state when a session is paused?
All working state — files, environment variables, in-memory data, and conversational history — is preserved on persistent storage. When the session resumes (~305ms), it restores to exactly where it left off. You’re not charged for CPU or memory while paused; only storage costs continue.
Is the Action Gateway limited to the pre-built 16,000 tools?
No. Teams can register custom MCP servers to expose internal APIs, proprietary databases, and legacy systems through the same governed access layer. The custom tools get the same credential brokering, rate limiting, and audit logging as the built-in catalog tools.
What models can I use with Agent Droplets?
Agent Droplets include discounted access to DigitalOcean-hosted open models (Kimi K3, GLM 5.3, and others). Frontier models like Claude and GPT are available at standard provider rates without the Agent Droplets discount. You can mix models within the same agent workflow — use a cheaper open model for routine classification and a frontier model for complex reasoning steps.
Key Takeaways
- DigitalOcean Managed Agents combines Firecracker microVM-based Harness Runtime with an MCP-native Action Gateway providing governed access to 16,000+ tools — all in public preview as of October 2026.
- Agent Droplets layer subscription pricing ($50/month Pro, $200/month Team) on top, bundling compute, inference, tools, and storage into one bill with 15-20% usage discounts.
- The Action Gateway’s credential brokering means tool credentials never reach the model context — a genuine security improvement over most DIY agent infrastructure setups.
- Sub-second resume times (305ms) and per-second active CPU billing make this cost-effective for long-running agents that spend most of their time waiting for events.
- Best suited for mid-market teams running 5-50 agents who need governed tool access and simplified billing without the complexity of AWS or Azure.
- Still in public preview — evaluate thoroughly, but the architecture is production-ready in design even if the product isn’t GA yet.
References
- DigitalOcean, “Managed Agents Public Preview,” DigitalOcean Blog, September 2026. https://digitalocean.com/blog/managed-agents-public-preview
- DigitalOcean, “Introducing Agent Droplets,” DigitalOcean Blog, October 2026. https://digitalocean.com/blog/introducing-agent-droplets
- DigitalOcean Documentation, “Managed Agents Overview,” 2026. https://docs.digitalocean.com/products/managed-agents/
- DigitalOcean Documentation, “Action Gateway,” 2026. https://docs.digitalocean.com/products/managed-agents/action-gateway/
- DigitalOcean Documentation, “Agent Harness Runtime,” 2026. https://docs.digitalocean.com/products/managed-agents/agent-harness-runtime/
- DigitalOcean, “Agent Droplets Pricing,” 2026. https://www.digitalocean.com/pricing/agent-droplets
- InfoQ, “DigitalOcean Managed Agents,” October 2026. https://infoq.com/news/2026/10/digitalocean-managed-agents
- Pulse2, “DigitalOcean Launches Agent Droplets With AI Agent Plans Starting At $50 Per Month,” October 2026. https://pulse2.com/digitalocean-launches-agent-droplets-with-ai-agent-plans-starting-at-50-per-month/





