# Docker Agent (slim) > Docker's open-source runtime for building and running AI agents from YAML or HCL files, formerly cagent. It runs as a docker agent CLI plugin with a terminal UI, headless mode, HTTP, MCP and A2A servers, and a Go library. - Full: https://www.anchorterminal.com/tools/docker-agent.md (~7,650 tokens) · this version ~1,530 tokens · JSON https://www.anchorterminal.com/tools/docker-agent.json · canonical https://www.anchorterminal.com/tools/docker-agent - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **BB · 76.5/100 · rank #30 of 629 · #4 in Agent frameworks & SDKs · agent-ready · confidence medium** Assessment: An agent with an MCP server is eight lines of YAML, and the same file runs in a terminal, headless, or as an HTTP, MCP or A2A server. Usage telemetry is on by default and can carry prompts passed as command arguments, and two high-severity approval bypasses were fixed in August and September 2026. ## Facts - Kind: Agent framework · vendor: Docker · category: Agent frameworks & SDKs · legal entity: Docker, Inc. · provenance 84/100 - Packages: oci `docker/docker-agent`, go `github.com/docker/docker-agent` - Auth: None · pricing: Free · x402: no · licence: Apache-2.0 - Probe metrics: not measured yet (probes haven't run) - Interfaces: `docker agent` CLI plugin and `docker-agent` binary, terminal UI, headless `run --exec`, HTTP API server, OpenAI-compatible chat server, MCP server, A2A server, ACP, Go library - Agent definition: YAML or HCL, config schema version 16, with a JSON Schema in the repository (agent-schema.json). Older configs are migrated on load - Languages: Go library only. No code is needed for a YAML agent - Models: About 30 provider pages, including OpenAI, Anthropic, Google, Bedrock, Mistral, xAI and OpenRouter, plus local models through Docker Model Runner - MCP client: stdio, streamable HTTP and SSE, with OAuth and dynamic client registration. `ref: docker:` pulls from Docker's MCP catalogue - Multi-agent: Sub-agents, hand-offs, background agents and `transfer_task` - Durable state: Sessions in SQLite, resumable with `--session`, and an API event stream with sequence numbers and replay - Approvals: Safety modes strict, balanced, restricted and autonomous, plus allow, ask and deny rules. The default asks for anything that isn't read-only - Sandbox: `--sandbox` runs the agent in a Docker Sandboxes VM. Off by default - Tracing: OpenTelemetry over OTLP/HTTP with `--otel`. Message content capture is off by default - Telemetry: On by default, sent to api.docker.com. `TELEMETRY_ENABLED=false` turns it off - Distribution: Agents push and pull as OCI artefacts. Binaries for macOS, Linux and Windows on amd64 and arm64, Homebrew, Docker Desktop 4.63 and later - Releases in 90 days: 45 (v1.111.0 to v1.149.0) - Scores: Reliability 88, Performance pending, Schema & documentation 90, Agent ergonomics 81, Security & auth 70, Payments & pricing 60, Task success pending, Maintenance & community 96, Transparency & trust 80 · negative events -4 · total over the 7 assessed categories - Why: Reliability, Read with the local-software lines, because the owner runs it. · Schema & documentation, Framework reading. · Agent ergonomics, Framework reading, scored on what an agent with MCP needs. · Security & auth, Framework reading. · Payments & pricing, No payment protocol (0). · Maintenance & community, v1.149.0 published on 2026-10-07 (30). · Transparency & trust, Apache-2.0 (30). - Sources: 24, open questions: 8, both in the full twin - Capabilities: agent.framework, agent.multi-agent, agent.mcp-client, agent.durable - JSON: https://www.anchorterminal.com/api/v1/tools/docker-agent.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/docker-agent.svg` or a link to https://www.anchorterminal.com/tools/docker-agent from a page on docker.com or docker.github.io or one of their subdomains, or the README of github.com/docker/docker-agent, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Set `TELEMETRY_ENABLED=false` before `run` or `exec` with a prompt on the command line. Telemetry is on by default and sends positional arguments 2. For unattended runs pass `--safety restricted` with an allow-list, or `--sandbox`. Without a policy, `--exec` rejects every tool call that needs approval 3. Set `max_iterations` and a `budget` block in the config. Both are unlimited by default 4. Run 1.130.0 or later. Earlier versions ran shell commands embedded in local skills, and A2A sessions before 1.126.0 skipped tool approval 5. Review `runtime.safety` in any config pulled from a registry or URL. An author default of `autonomous` runs every tool call unprompted ## Connect ```bash brew install docker-agent # bundled with Docker Desktop 4.63 and later as `docker agent` ``` ```bash claude mcp add --transport stdio myagent --env OPENAI_API_KEY=$OPENAI_API_KEY --env ANTHROPIC_API_KEY=$ANTHROPIC_API_KEY -- docker agent serve mcp myorg/agent:tag --working-dir $(pwd) ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | OpenAI Agents SDK | AA | 86.2 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | https://www.anchorterminal.com/tools/openai-agents-sdk.min.md | | Pydantic AI | A | 83.7 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | https://www.anchorterminal.com/tools/pydantic-ai.min.md | | Microsoft Agent Framework | A | 82.2 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | https://www.anchorterminal.com/tools/microsoft-agent-framework.min.md | | Agent Development Kit (ADK) | BB | 74.7 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | https://www.anchorterminal.com/tools/google-adk.min.md | | Agno | BB | 72.8 | agent.framework, agent.multi-agent, agent.durable, agent.mcp-client | https://www.anchorterminal.com/tools/agno.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)