Back to vendors
U

Unikraft

Also known as: Unikraft Cloud

Visit site
Entry priceHobby free · Team from $39/mo · Pro $199/moFull pricing detail

Cloud platform that runs any Dockerfile as a hardware-isolated microVM with millisecond cold starts and scale to zero, used for agent sandboxes, headless browsers and MCP servers.

Unikraft Cloud runs any Dockerfile-based workload as a minimal Linux-based microVM with hardware-level isolation. It is a commercial cloud platform from Unikraft Inc., not the open source unikernel project at unikraft.org, and not a unikernel product. Instances cold start in under ten milliseconds, scale to zero when idle and wake in milliseconds on the next connection, and more than 100,000 isolated instances can run on one server.

For agents, Unikraft hosts sandboxes for untrusted AI-generated code, headless and headful browsers with GPU rendering, remote desktops, and MCP servers that wake when an agent calls them. Snapshots pre-initialize a workload so new instances boot warm from a template, a live VM and its children can be forked in about ten milliseconds, and managed volumes keep data. The customer brings its own browser, tools and agent logic; Unikraft provides the isolated machines and the lifecycle around them.

Unikraft Cloud runs in named metros in the US, Germany and Singapore, and can also be deployed dedicated, on premises or as BYOC on bare metal or AWS, GCP and Azure VMs, or added as a node to an existing Kubernetes cluster. It states SOC 2 Type II and HIPAA compliance with BAAs, and a May 2026 independent penetration test.

Plans run from a free Hobby tier to Team at thirty nine dollars a month and Pro at one hundred ninety nine, with Enterprise custom.

Vendor details

Canonical URL

https://unikraft.com

Category

Agent infrastructure

Funding status

Independent. Unikraft Inc. was founded in 2022 by Felipe Huici (CEO), Simon Kuenzer (CTO) and Alexander Jung (CPO).

Company status

independent

Use cases & customers

Primary use cases

agent sandboxesheadless browser infrastructurecode execution isolationephemeral compute at scalecheckpoint and fork of running VMs

Target customers

developersAI platformsenterpriseinfrastructure teams

Deployment options

SaaSon-premBYOCdedicated hostsbare metalAWSGCPAzureKubernetes node

Integrations

Any Dockerfile workload, the Unikraft Cloud REST API and unikraft CLI, Kubernetes (as a node in EKS, GKE, AKS or your own cluster) and Karpenter, Prometheus metrics, and deployment on bare metal or AWS EC2, GCP Compute Engine and Azure VMs.

In practice

Your agent calls a dozen MCP tools, most of them idle most of the time. You run each as a Unikraft microVM that wakes in milliseconds when called and costs nothing between calls.

Your browser agents need a fresh, isolated browser per session without waiting for Chrome to start. You snapshot a warmed browser into a Unikraft template and boot every session from it in milliseconds.

Your security team will not let AI-generated code run in shared containers. You run each execution in its own hardware-isolated Unikraft microVM, on premises if the data cannot leave your network.

Agentic Index coverage score

6.0 / 14 capabilities · 43%

Integrations & Tool Calling Partial

Agents' tools run on Unikraft rather than coming from it. The docs cover hosting MCP servers as microVMs that wake when an agent calls them, webhook receivers and API gateways, and connecting workloads to hyperscaler services such as S3, and a customer story describes keeping credentials outside the VM. No catalog of connectors, OAuth actions or credential brokering of Unikraft's own is documented, so the read and write integrations are the customer's code.

Sourceunikraft.com/docs/use-cases/mcp-serversread 2026-09-22

Workflow Orchestration Not documented

Unikraft schedules and scales microVMs (autoscale, load balancing, forking a live VM for parallel sub-agents) but does not sequence, branch, retry or route an agent's steps. That logic lives in the customer's code. No workflow logic mixing deterministic nodes with agent steps is documented as a Unikraft mechanism. Scheduling infrastructure across metros is compute placement rather than workflow orchestration.

Sourceunikraft.com/llms-full.txtread 2026-09-22

Knowledge Grounding & RAG Not documented

Unikraft runs the customer's workloads, including databases and MCP servers, but does not maintain a retrieval structure over the customer's content that an agent queries. Volumes and databases hosted on it are the customer's storage, not a Unikraft index a query returns. No sources the product indexes, refreshes or permissions are documented.

Sourceunikraft.com/llms-full.txtread 2026-09-22

Human Oversight & Guardrails Not documented

No approval step, consent checkpoint or escalation to a person is documented for work running on Unikraft. The closest features are the network shield and relay, an Enterprise feature that routes an instance's traffic through a relay VM, and delete locks that stop instances being removed. Both are isolation and protection the developer configures, not a point where a person reviews an agent's action. Nothing documented shows where approvals can be inserted.

Sourceunikraft.com/docs/features/network-shieldread 2026-09-22

Security, Identity & Governance Full

The company states SOC 2 Type II (Security criteria, audit period July 2024 to July 2025), HIPAA compliance with BAAs available, and an independent penetration test by DEFION Security in May 2026 that found no exploitable cross-VM, hypervisor, filesystem or host-agent issues. Controls customers use sit beside it. Every workload is its own Firecracker-based microVM with per-tenant filesystem boundaries, delete locks protect instances from removal, and on Enterprise a network shield and relay route an instance's traffic through a relay VM.

No SSO, roles or identity provider support is documented, and the stated audit period ended in July 2025.

Sourceunikraft.com/llms-full.txtread 2026-09-22

Observability & Auditability Partial

Logs and metrics follow the instance rather than the agent. Every user gets full stdout and stderr logs, paying customers get Prometheus metrics, and a metrics API reports CPU time, memory, network I/O, connection counts and scale-to-zero wake latency per instance. That covers export to monitoring systems. Inspecting prompts, tool calls, retrieved knowledge and outputs step by step is left to the customer's own code, and no audit log separate from runtime or retention by plan is documented.

Sourceunikraft.com/docs/platform/metricsread 2026-09-22

Memory & State Persistence Partial

A workload's state carries across sessions. Instances snapshot and resume in milliseconds with their state intact, a live VM and its children fork in about ten milliseconds, managed volumes persist data, and paid plans add snapshot history and rollback. The agent's code reads that restored state to carry on.

A volume is storage the code reads, and restored process state belongs to the machine: the buyer can resume, roll back or delete it but cannot review or edit it as memory. No memory layer with a stated scope and lifetime is documented. A browser session ROM carrying its own cookies and profile is a saved login, not agent memory.

Sourceunikraft.com/docs/features/snapshotsread 2026-09-22

Deployment & Data Residency Full

Unikraft Cloud runs in named metros the customer selects (Dallas, Frankfurt, San Francisco, Singapore and Washington DC by default, listed per account). Its fact sheet documents hosted, dedicated hosted, on-premises and BYOC deployment on bare metal or on AWS EC2, GCP Compute Engine or Azure VMs, plus a Kubernetes integration that adds Unikraft Cloud as a node in EKS, GKE, AKS or the customer's own cluster.

Sourceunikraft.com/docs/platform/metrosread 2026-09-22

Prebuilt Agents / Templates / Packs Not documented

Templates here are snapshots of the customer's own warmed up workload that new instances boot from, not ready made starting points from the vendor. The vendor's use case pages (sandboxes, headless browsers, MCP servers, remote desktops) describe patterns rather than shipping working agents or templates a buyer adopts. No production-ready templates or role-specific agents are documented.

Sourceunikraft.com/docs/features/on-demand-templatesread 2026-09-22

Triggers & Channel Coverage Full

Incoming connections wake work without the customer's code starting it. An instance scaled to zero consumes nothing until the next connection arrives, when the platform boots or resumes it in milliseconds and answers, so an MCP server wakes when an agent calls it and a webhook receiver wakes on the incoming event. A tutorial covers scale-to-zero triggers. No scheduler is documented.

Sourceunikraft.com/docs/features/scale-to-zeroread 2026-09-22

Model Flexibility & Routing Not documented

Any Dockerfile workload runs here, and nothing about language models is documented. No model selection, routing, provider keys or guidance for connecting the customer's own models is documented, and the one GPU mention is rendering for headful browsers. Nor does the platform impose a model of its own.

Sourceunikraft.com/llms-full.txtread 2026-09-22

APIs / SDKs / MCP Extensibility Full

From outside, a documented platform REST API (instances, templates, volumes, services, metrics) drives Unikraft Cloud, alongside the unikraft CLI with a raw API passthrough, a Kraftfile specification, and Kubernetes and Karpenter integrations. No SDK or MCP server of Unikraft's own is documented, and some newer features (plugins, network shield) are API only for now.

Sourceunikraft.com/docs/llms.txtread 2026-09-22

Testing, Debugging & Optimization Not documented

Tests get somewhere to run, but agents are not tested. The build and test environments use case and forking give the customer disposable, parallel VMs, but no fixtures, scoring, quality gates or comparison of agent runs are documented as Unikraft features.

Sourceunikraft.com/docs/llms.txtread 2026-09-22

Browser / Computer-use Partial

Browser and desktop agents get their machines here. Every browser session can run in its own disposable headless or headful microVM with GPU rendering, booted from a snapshotted template, and whole desktop sessions snapshot after login and resume on connect. Browser-agent companies run on it. The platform is browser-agnostic, so the customer brings the browser and drives it with its own tooling, and no Unikraft API for screenshots, clicks or typing is documented. What Unikraft supplies is the environment for operating web interfaces and desktops, not the control.

Sourceunikraft.com/docs/use-cases/headless-browsersread 2026-09-22

The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded

Recent platform changes

2026-08-04·Deployment / data residencyVerified

Unikraft launched Release 12, codenamed Thebe, which introduces NVIDIA GPU support for running GPU-accelerated inference and headful browser agents. The release also adds cluster-wide instance templates and advanced image control features like image pinning, strict authorization for shared private registries, and pull timeouts.

Bears on: Deployment / data residency

View source
2026-07-27·Agent capabilityVerified

Unikraft detailed its agent infrastructure platform architecture, optimized for running AI sandboxes at scale. The platform leverages hardware-isolated microVMs to deliver 10-millisecond cold starts and stateful scale-to-zero capabilities, allowing agents to pause and resume exactly where they left off. It also features a dedicated network shield that enforces outbound traffic policies and isolates credentials from the agent environment.

Bears on: Agent capability

View source
2026-07-06·Agent capabilityPartially Verified

Unikraft introduced Sandboxes on Unikraft Cloud, providing on-demand, hardware-isolated microVMs for executing short-lived tasks and AI agent tool calls. The environments boot in milliseconds, feature automatic scale-to-zero, and charge users solely for active execution time.

Bears on: Security / enterprise

View source
View all 3 changes for Unikraft →Tracked since Jul 2026 · Verified from public vendor sources

Pricing

Hobby free · Team from $39/mo · Pro $199/mo

compute usage (instances, VM runtime, resources)

Free tierTrial available

What is public

Unikraft publishes four tiers (Hobby free, Team $39, Pro $199, Enterprise custom) with instance limits and features per tier.

Billing mechanics

A flat monthly plan that sets how many instances can run and stand by, with scale to zero so idle instances cost nothing; Enterprise is contracted.

Cost watchouts

Plans cap running and standby instances by tier, so fleet size can force an upgrade; Enterprise dedicated, on prem and BYOC are quoted.

Variable cost rationale

Compute infrastructure billed on usage, so total cost scales with the number of instances, VM runtime, and resource consumption rather than a fixed plan fee. Scale to zero reduces idle cost.

Additional watchouts

Check the running and standby instance limits for your fleet size before choosing a tier.

Sales call required

Mixed (some tiers require a call)

Free / trial

Hobby plan free forever, no credit card required

Lowest paid plan

Team $39/month

Key ambiguities

Plan prices are public, but whether compute beyond each plan's limits is billed by usage, and at what rates, is not stated.

Missing data

Usage rates beyond plan limits and the full Team plan limits.

Agentic Index verified 2026-09-22

Alternatives to Unikraft

The closest documented capability profiles to Unikraft among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.

  • Modal8.0 / 14Adds documented Workflow Orchestration and Prebuilt Agents, Templates & Packs, among others
  • E2B8.5 / 14Adds documented Prebuilt Agents, Templates & Packs and Model Flexibility & RoutingUnikraft vs E2B →
  • Exa6.5 / 14Adds documented Prebuilt Agents, Templates & Packs and Model Flexibility & Routing
  • Rime3.5 / 14A lighter documented profile than Unikraft
  • Speechmatics3.5 / 14A lighter documented profile than Unikraft
  • Daytona8.0 / 14Adds documented Prebuilt Agents, Templates & Packs and Model Flexibility & RoutingUnikraft vs Daytona →

Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded

Contact us

Found a vendor we missed? Have feedback on the index? We'd love to hear from you.