# AX Check: docker.com
Checked 2026-10-06.

Docker's agent quickstart and pricing are clear and ready to use
Quickstart gives runnable commands well within a reasonable reading length; pricing lists all tiers plainly. Main gap: no llms.txt index exists (404).

## Onboarding needs a login

## Coding sessions
All three independent sessions (DeepSeek V4.1 Flash, Kimi K3, Qwen 3.8 Max) completed and correctly reported Docker's pricing tiers from Personal $0 up to Business $24/user, each noting the per-user/month structure and flagging that current rates should be verified on the pricing page.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/266ead77-be33-4201-8937-99d8dc3adc9c) · [Read transcript](https://www.ax-check.com/docker.com/sessions/deepseek.json)
Final output lists per-plan prices (Personal $0, Pro $11/$9yr, Team $16/$15yr, Business $24/user) with the assumption named that figures are 'fetched from docker.com/pricing, verify current rates' and tied to specific plan/billing-cycle tiers.
#### End-to-end onboarding
- **End-to-end onboarding not demonstrated**: The agent never attempted to obtain or use product credentials. It explored the local sandbox, confirmed a local Docker CLI/daemon were present, and fetched the public Docker pricing page over HTTP, but took no action requiring authentication (no Docker Hub login, no API token, no SDK call). It self-terminated before any onboarding or authenticated operation could occur.
  Event 23:

  ```text
  command -v docker || echo "docker CLI: not installed"; docker info >/dev/null 2>&1 && echo "docker daemon: running" || echo "docker daemon: not running/unavailable"
  ```
  Event 51:

  ```text
  Per your instruction (“if the quickstart requires either, say so plainly and stop”), **I’m stopping and not starting anything.**
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **Docker's core workflow is local-only, conflicting with the hosted-only test constraint**: The agent determined that building and running a Docker example requires a local daemon and containers (docker build / docker run), which the session's instructions explicitly forbade (no local service stacks, hosted SDK/API only). This is a product-behavior fact about Docker rather than an agent error or missing credential: Docker Hub/Scout/Build Cloud are registry/analysis services, not a hosted container runtime. The agent correctly identified the conflict and stopped per instructions rather than attempting a workaround.
  Event 51:

  ```text
  Docker’s actual developer quickstart is **local-first**: you author a `Dockerfile`, then `docker build` and `docker run` against a **local daemon**, which runs containers (i.e., a local service stack, often long-running). There is **no Docker-hosted SDK/API path** to build and run an example
  ```
  Event 51:

  ```text
  So your two requirements conflict:
  - “build a simple example using Docker” → needs the local daemon + containers
  - “only use the hosted product via SDK/API, no local service stacks, no long-running commands” → forbids exactly that
  ```

#### Suggested Changes
- **Clarify on the Pricing page that per-minute Testcontainers/Build Cloud charges apply beyond the monthly seat price**: The scraped pricing text bundles 'Included usage' minutes (e.g. 100 Testcontainers Cloud runtime minutes) with per-seat pricing, and the agent had to dig through raw HTML to figure out overage billing (e.g. '$3 per 100 minutes'). Adding a clear overage-rate callout next to each tier on docker.com/pricing would save users from parsing minified page content to find metered costs.
  Event 32:

  ```text
  $3 per 100 minutes (Expired at the end of 
  $4 per 100 minutes
  ```
  Event 49:

  ```text
  100 Testcontainers Cloud runtime minutes** MOST POPULAR Docker Team $16 $15 per user/month
  ```

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/90ed4604-d487-47a9-99ba-b05357d4db52) · [Read transcript](https://www.ax-check.com/docker.com/sessions/kimi.json)
Final output (seq 28) lists per-plan pricing (Personal/Pro/Team/Business) with the plan-tier assumption named and a caveat to verify current numbers on docker.com/pricing.
#### End-to-end onboarding
- **End-to-end onboarding not demonstrated**: No product account or credentials were created during the session. The agent used Docker Hub's public, anonymous registry API (auth.docker.io token endpoint for anonymous pull scope) to fetch a public image manifest, which required no real credentials and no authenticated write/create operation. It also ran a local `docker run hello-world` against a pre-existing daemon it did not start and did not authenticate. Neither path demonstrates obtaining real product credentials and using them for an authenticated operation.
  Event 18:

  ```text
  Get an anonymous read token for the library (official images) repo.
  ```
  Event 22:

  ```text
  Image:          library/alpine:latest
  Content digest: None
  Media type:     application/vnd.oci.image.index.v1+json
  ```
  Event 26:

  ```text
  Unable to find image 'hello-world:latest' locally
  latest: Pulling from library/hello-world
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No hosted API exists for container execution**: The agent determined that Docker's product line has no managed hosted API for actually running containers — only for registry/image metadata (Docker Hub) and builds (Build Cloud). This is a product scope limitation, not an agent error: running containers inherently requires a local daemon (a local service stack), which the session's instructions explicitly said to avoid starting.
  Event 10:

  ```text
  Docker's core developer workflow (build/run containers) requires a **local Docker daemon**, which is a local service stack. I won't start one, per your constraint.
  ```
  Event 28:

  ```text
  container *execution* has no managed API in Docker's product line, so "run my containers in the cloud" would mean a different product (ECS, Cloud Run, etc.).
  ```

#### Suggested Changes
- **Clarify in docs that container execution has no hosted/managed API**: Developers evaluating Docker as a 'light, API-only' hosted workflow hit a wall when trying to actually run containers without a local daemon. Add a note near the Docker Hub Registry API reference clarifying that image pull/push/inspect is available via hosted API, but execution requires a local or third-party container runtime. Verify by having a new developer attempt an API-only 'run a container' workflow and confirming they are redirected to the correct expectation instead of discovering it through trial and error.
  Event 28:

  ```text
  container *execution* has no managed API in Docker's product line, so "run my containers in the cloud" would mean a different product (ECS, Cloud Run, etc.).
  ```

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/25ed110b-70bc-47ab-8db0-3ca108508422) · [Read transcript](https://www.ax-check.com/docker.com/sessions/qwen.json)
Final output gives a pricing table (Personal/Pro/Team/Business, annual vs monthly) plus named assumptions: per-user/month, cloud runtime minute add-ons, Hardened Images at ~$5k/repo, and the >250-employee/$10M revenue licensing rule, with a 'numbers move, treat as snapshot' caveat.
#### End-to-end onboarding
- **Onboarding needs a login**: The agent confirmed it had no Docker Hub credentials (no ~/.docker/config.json, no Docker auth env vars) and only reached anonymous, read-only public endpoints. It never obtained real product credentials, so no authenticated write operation against a hosted Docker product occurred.
  Event 13:

  ```text
  no docker config (not logged in)
  ```
  Event 18:

  ```text
  search:200
  tags:200
  auth-required-endpoint:400
  ```
  Event 25:

  ```text
  This sandbox is not logged in (`~/.docker/config.json` absent, no Docker credentials in env). Anonymous access only works for **read-only public metadata**
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No Docker Hub credentials available for any write operation**: The sandbox had no Docker login config and no credentials in environment variables, so only anonymous read-only Hub API calls succeeded (search, tags) while an account-scoped endpoint returned 400. This is a missing-credentials limitation of the test environment, not a product defect, since Docker Hub normally requires a login for account actions.
  Event 13:

  ```text
  no docker config (not logged in)
  ```
  Event 18:

  ```text
  auth-required-endpoint:400
  ```
- **Quickstart path requires a local service stack and long-running pulls/builds**: The agent determined Docker's real workflow (Dockerfile build, docker run/compose) needs pulling images over the network and running a live daemon-backed container, with an empty local image cache. This conflicts with the session's explicit instruction to avoid local stacks and long-running commands, so the agent self-stopped rather than hitting a product or credential failure.
  Event 25:

  ```text
  Docker's actual workflow is `Dockerfile → docker build → docker run/compose` — i.e. a running daemon, live containers, and base-image pulls.
  ```
  Event 25:

  ```text
  You said don't start local stacks and don't wait on long-running commands, so that rules out the only real build/run path.
  ```

#### Suggested Changes
- **Add a documented lightweight/anonymous API path for a hosted Docker action**: The agent found only read-only anonymous endpoints (search, tags) on hub.docker.com/v2; any write-style action (push, repo create) needed an account token. Verify by having an unauthenticated SDK/CLI flow complete one real hosted action without requiring a daemon or long build, and confirm by checking docker.com's quickstart docs reflect this path.
  Event 18:

  ```text
  auth-required-endpoint:400
  ```
  Event 25:

  ```text
  There is also no first-party "Docker SDK" for this; it's a CLI plus REST APIs.
  ```

### Task given to each agent
Help me build a simple example using Docker. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: B · 65/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Failed** — Homepage answers Markdown requests

  ```text
  Homepage returned text/html for a text/markdown request; no Markdown representation offered.
  ```

- **Failed** — llms.txt provides an actionable documentation index

  ```text
  https://docker.com/llms.txt returns HTTP 404, so no documentation index exists.
  ```

- **Skipped** — llms.txt provides navigation guidance

  ```text
  llms.txt is 404, so its navigation guidance cannot be evaluated.
  ```

- **Skipped** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt is 404, so its mention of API, MCP, and skills cannot be evaluated.
  ```

- **Pass** — A compact guide representation exists

  ```text
  Docker Agent quickstart is served as text/markdown, a compact standalone guide representation.
  ```

- **Pass** — A focused guide is directly retrievable

  ```text
  Docker Agent Quick Start is directly retrievable as Markdown with concrete first steps.
  ```

- **Pass** — Equivalent instructions fit a token budget

  ```text
  Quickstart Markdown is 1099 tokens, well under the 8000-token budget.
  ```

- **Skipped** — Product-docs links survive format changes

  ```text
  Homepage Markdown unsupported, so link preservation across formats cannot be measured.
  ```

- **Pass** — The compact guide is independently actionable

  ```text
  Docker Agent quickstart gives concrete first steps: docker agent run, new, and config examples.
  ```

- **Pass** — Install and next-step links resolve

  ```text
  Sampled install/next-step links (docs.docker.com, extensions quickstart, agent quickstart) fetched successfully.
  ```


### Onboarding
- **Pass** — Docs lead to a relevant quickstart

  ```text
  Docker Agent and Extensions SDK quickstarts give concrete first steps with commands.
  ```

- **Pass** — Installation commands are extractable

  ```text
  Quickstarts show extractable install commands like docker extension init and docker agent run.
  ```

- **Pass** — Code examples are available without interaction

  ```text
  Quickstarts include inline code blocks for commands and YAML configs without interaction.
  ```

- **Pass** — Prerequisites and auth boundaries are explicit

  ```text
  Prerequisites list Docker Desktop, NodeJS, Go; API key needs like ANTHROPIC_API_KEY are stated.
  ```


### Pricing
- **Pass** — Pricing is readable without interaction

  ```text
  Pricing page renders plan cards and a full comparison table directly in HTML, no interaction needed.
  ```

- **Pass** — Prices are stated, not gated

  ```text
  Prices stated openly: Personal $0, Pro $9-11, Team $15-16, Business $24 per user/month.
  ```

- **Pass** — Pricing units and limits are explicit

  ```text
  Units and limits explicit: per user/month, user caps, pull rates, build/runtime minutes.
  ```

- **Pass** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 0 fell short. DeepSeek V4.1 Flash: Final output lists per-plan prices (Personal $0, Pro $11/$9yr, Team $16/$15yr, Business $24/user) with the assumption named that figures are 'fetched from docker.com/pricing, verify current rates' and tied to specific plan/billing-cycle tiers. Kimi K3: Final output (seq 28) lists per-plan pricing (Personal/Pro/Team/Business) with the plan-tier assumption named and a caveat to verify current numbers on docker.com/pricing. Qwen 3.8 Max: Final output gives a pricing table (Personal/Pro/Team/Business, annual vs monthly) plus named assumptions: per-user/month, cloud runtime minute add-ons, Hardened Images at ~$5k/repo, and the >250-employee/$10M revenue licensing rule, with a 'numbers move, treat as snapshot' caveat. This behavioural item does not affect the fast grade.
  ```


### Activation
- **Pass** — An API reference or OpenAPI spec is reachable

  ```text
  Docker Sandboxes API reference and OpenAPI spec are reachable on docs.docker.com.
  ```

- **Pass** — An MCP server is documented and well-formed

  ```text
  MCP gateway documented with sbx mcp add/run commands, OAuth, and modes.
  ```

- **Pass** — A CLI install path is documented

  ```text
  CLI install paths documented: brew, winget, apt for sbx; docker CLI reference.
  ```

- **Skipped** — SDK packages resolve on their registries

  ```text
  No registry lookup result for a Docker SDK/CLI package was supplied.
  ```

- **Pass** — Agent skills are published

  ```text
  Agent skills published: sbx skills add/import and Docker Agent SKILL.md docs.
  ```



[Full report data](https://www.ax-check.com/docker.com/report.json)
