DigitalOcean opened public preview access to Managed Agents in late September 2026 — a single runtime that bundles sandboxed execution, model inference, and governed tool access for AI agents, billed by active use instead of provisioned capacity. If you're currently stitching together three or four separate vendors to run an agent in production, this closes a real gap. If you're not running agents yet, nothing here changes your stack today.
What Is DigitalOcean Managed Agents, Exactly?#
It's three things DigitalOcean used to sell separately, now wired into one product, so an agent doesn't need five vendor accounts to do its job:
- A sandboxed runtime (Firecracker microVMs)
- Model inference (open-weight and frontier models)
- Governed tool access (the Action Gateway)
- Persistent, checkpointable session storage
The sandbox layer runs on Firecracker microVMs — the same isolation technology AWS Lambda uses — with sub-second startup and roughly 300ms resume times for a paused session. Sessions are durable: they survive disconnections and can be checkpointed, forked, or moved between devices, which is a harder problem than it sounds.
The part we found more interesting is the Action Gateway. It brokers credentials at execution time across more than 16,000 tools from over 500 providers through a managed MCP endpoint, and DigitalOcean's own framing is blunt about it: "the agent never sees the key." Sensitive actions sit behind human approval gates. Inference runs on open-weight models like Kimi K3 and GLM 5.3 co-located with the sandbox, with pay-as-you-go routing to frontier models when needed. Full detail is in DigitalOcean's own writeup on why they built Managed Agents and the Managed Agents documentation.
Pricing is the detail worth sitting with: $0.044 per vCPU-hour and $0.0095 per GB-hour of memory, charged only while the agent is doing something — not while it's waiting on a model or tool response. Snapshots run $0.05 per GiB-month. It's a public preview, so DigitalOcean isn't promising production-grade reliability yet.
Does This Affect You If You're Not Building AI Agents Yet?#
If you're a solo founder running a couple of n8n workflows or one WhatsApp chatbot, no. The integration pain this product removes isn't pain you have.
It starts to matter once you're running more than one agent in production and paying separately for sandboxing, inference, and tool access to keep them alive. That's three invoices, three sets of credentials, and three places something can quietly break at 2am. My read is the pricing model is built for agents that burst and idle — not agents holding a connection open all day. An idle agent costs you almost nothing here. One holding a persistent WebSocket open gets billed the whole time, tool call or not.
The Honest Trade-Offs#
The real upside is removing integration grunt work. Firecracker isolation plus a managed MCP endpoint plus credential brokering is, genuinely, three separate engineering projects most small teams never get around to building properly, and here they're one. Claude's connector marketplace solved a version of this for one assistant; Managed Agents is trying to solve it at the infrastructure layer for anything you build.
The downsides are just as real. It's a public preview on one provider's proprietary primitives — build on Action Gateway's conventions and you're coupled to DigitalOcean, same as any managed platform. Billing that rewards bursty agents punishes anything needing a long-held connection. And one endpoint brokering 16,000+ tools is a bigger blast radius if that layer ever has a bad day, credential brokering or not.
How We're Handling It at WebEpex#
At WebEpex we build and run client automation — chatbots, WhatsApp flows, and the backend systems behind them — on our own VPS infrastructure with PM2 and Nginx, not on managed agent platforms, and that's been true since before this launch. We ran the vCPU-hour math against GhostBoard's WebSocket relay, which holds open connections for hundreds of tickers at once, within a day of the preview going live. The active-use pricing would bill us for every second those connections sit open, whether a tool call is happening or not. That ruled it out for that specific workload fast.
I'll be straight about this: I didn't expect a hosting company to ship a working credential-brokering layer before most of the dedicated agent-tooling startups did. That part surprised me, and it's changed how I think about where the boundary between "self-host it" and "rent the primitive" actually sits.
Where it does make sense for us is short-lived, bursty jobs — a one-off scraping agent, a document-processing task that spins up and dies. We're testing one low-stakes internal workflow there before it goes anywhere near a client build. Agentic AI isn't replacing SaaS the way some headlines suggest, and infrastructure like this is part of why: it's plumbing, not a product decision, and we treat it that way.
What I'd Tell a Client This Week#
If you're a service business or SaaS founder across the GCC, Europe, the US, Canada, or India running one or two automations, do nothing. This is an infrastructure story, not a feature you're missing.
If you're already running multiple agents in production and juggling vendors for sandboxing, model access, and tool calls, test Managed Agents against one low-traffic workflow before putting anything client-facing on a product still in public preview. Check your connection pattern first: bursty and stateless fits this billing model, persistent connections don't. We covered the same self-hosted-versus-managed calculus in our breakdown of SaaS MVP development costs and in what to patch after n8n's last security fixes.
If you're trying to work out whether this actually changes anything for your setup, send me what you're running and I'll tell you straight — takes two minutes and you don't have to buy anything. cal.com/webepex/growth-review