Waynode
Waynode / Guides

By Francesco Frapporti · Updated 2026-07-12 · Markdown version

"Self-hosted vs cloud coding agents: how to choose" Cover Image

Self-hosted vs cloud coding agents: how to choose

Choose a cloud coding agent when you want someone else operating the infrastructure and a shorter adoption path; choose a self-hosted agent when your code, credentials, and LLM spend must stay under your control, and you can accept the operational work that comes with running it. The decision is rarely about agent quality (most self-hostable agents call the same frontier models via API) and mostly about where your repository is cloned, who holds the keys, and how you pay for tokens.

TL;DR

What is the actual difference?

A cloud coding agent is a managed service: the vendor clones your repository into a sandbox on their infrastructure, runs the agent there, and returns a pull request. You grant it access to your GitHub or GitLab account, and the vendor operates everything: compute, secrets, model routing, updates.

A self-hosted coding agent runs the same loop on machines you control: a workstation, an on-prem server, or your own cloud account. The repository is cloned to your disk, the agent process runs under your OS, and model calls go directly from your network to the LLM provider (or to a local model). Nothing about your code or credentials passes through the agent vendor.

Terminal-based agents like Claude Code blur the line: the agent process runs locally on your machine, but code context is sent to Anthropic's API for inference, and its subscription plans (Pro $20/mo, Max $100-$200/mo, per claude.com/pricing) bill through Anthropic. "Self-hosted" in the strict sense means the whole workspace (repo storage, session state, execution sandbox) lives on your infrastructure, with only inference (optionally) leaving it.

Comparison: self-hosted vs cloud coding agents

Dimension Cloud agent Self-hosted agent
Where your repo is cloned Vendor-operated sandbox/VM Your own disk or server
Git credentials OAuth grant held by vendor Stay in your deployment
LLM keys and billing Vendor's keys; you buy credits/subscription Your keys; you pay API list price
Setup effort Minutes (sign in, connect repo) Hours (Docker/compose, env config, OAuth apps)
Maintenance None (vendor updates) Yours: updates, backups, TLS, secrets
Model choice Vendor's menu, sometimes locked Any provider or local models
Cost structure Subscription + metered credits Infra cost + raw token spend
Compliance/data residency Vendor's certifications and DPA Whatever you enforce; data never leaves
Failure mode Vendor outage/policy change Your ops mistake

Who sees your code with a cloud coding agent?

With any cloud agent, at minimum two parties process your source: the agent vendor (whose sandbox clones the repo) and the model provider (who receives code context in prompts). Sometimes they are the same company, sometimes not. Cursor's cloud agents run on Cursor infrastructure but call third-party frontier models; its privacy mode commits that "we will not train on your data" with contractual controls on model providers (cursor.com/security). OpenAI states there is no training on business data by default for ChatGPT Business/Enterprise plans that include Codex (Codex pricing docs).

Training opt-outs are not the whole story. The practical exposure surface also includes:

Self-hosting collapses this surface to one party: the model provider you choose to send prompts to. If you run local models, it collapses to zero. This is the core answer to "should I self-host a coding agent": self-host when reducing that surface is a requirement, not a preference.

How do the cost structures compare?

Cloud agents are subscription-first with metered usage on top. Current published pricing (July 2026):

Product Entry price Metering
OpenAI Codex (via ChatGPT) Free tier; Plus $20/mo; Pro from $100/mo; Business $20/user/mo annual Token-based credits since April 2026 (source)
Devin (Cognition) Free tier; Pro $20/mo; Max $200/mo; Teams $80/mo + $40/seat Consumption-based on model and task; Enterprise adds VPC deployment (source)
Cursor Individual from $20/mo; Teams $40/user/mo Cloud agents bill usage-based on top of plans (source)
GitHub Copilot coding agent Pro $10/mo ($15 credits); Pro+ $39/mo ($70); Max $100/mo ($200) AI Credits, 1 credit = $0.01; agent on paid plans (source)
Claude Code Pro $20/mo; Max $100-$200/mo Plan rate limits; API pay-as-you-go alternative (source)

Self-hosting inverts the structure: the software is often free (open source), and you pay two real costs: infrastructure (a VPS or spare machine running Docker is typically $5-$40/mo, or effectively zero on hardware you own) and model API usage at list price with no intermediary margin. For heavy agent use, BYO keys is usually cheaper per token than vendor credits; for light use, a flat subscription can be cheaper than the discipline of managing keys. There is also an unpriced cost: your time operating the deployment.

What maintenance does self-hosting actually require?

Be honest about the burden before choosing it:

If your team has no one willing to own this, a managed offering is the more truthful choice even if self-hosting looks free on paper.

When should you choose each?

Choose a cloud agent when:

Choose self-hosted when:

Consider a hybrid when different repos have different sensitivity: cloud agents for open-source and low-risk work, self-hosted for the crown jewels. Devin's enterprise VPC option (devin.ai/pricing) is one vendor-managed version of this.

Where does Waynode fit?

Waynode is one example of a tool built to offer both modes with the same open-source (MIT) stack. Self-hosted, it uses a guided Docker Compose installer that collects the OAuth and model-provider configuration, generates server secrets, validates Compose, and starts on loopback; each workspace is a real cloned Git repository on disk, while your database and LLM keys stay with you. Waynode Cloud operates the server, updates, encrypted secrets, and Stripe billing, from $39/mo (Starter: 3 seats, 3M agent tokens/mo, 10 GB) up to $249/mo (Team: 25 seats, 20M tokens, 200 GB), with a 15-day free trial for new organizations. Interactive terminal access is currently self-hosted only. Because both modes run the same open-source stack, teams can start managed and move to self-hosting (or the reverse) without changing tools. It does not currently offer SSO or compliance certifications, so enterprises with those requirements should evaluate accordingly. Feature-level comparisons against specific cloud agents are collected at /learn.

FAQ

Is a self-hosted coding agent more private than a cloud one?

Structurally yes: self-hosting removes the agent vendor from the data path, leaving only the model provider you send prompts to (or no one, with local models). A cloud agent's privacy depends on its retention, training, and access policies, which vary by vendor and plan.

Is self-hosting a coding agent cheaper?

For heavy usage, usually: you pay raw API token prices plus modest infrastructure costs instead of subscription credits with margin. For light or occasional use, a $10-$20/mo cloud subscription is often cheaper than the time spent operating your own deployment.

Can I use frontier models like GPT or Claude with a self-hosted agent?

Yes. Self-hosted agents typically use bring-your-own API keys, so you can point them at OpenAI, Anthropic, or any provider; code execution and repository storage stay local while only inference requests leave your network.

Do cloud coding agents train on my code?

Major vendors default to no training for business plans: OpenAI states no training on ChatGPT Business/Enterprise data by default, and Cursor's privacy mode commits to no training with contractual controls on model providers. Check the specific plan's policy; consumer tiers can differ.

What is the minimum setup to self-host a coding agent workspace?

For Waynode: install Docker Compose v2, create a GitHub or GitLab OAuth app, get a supported model-provider key, clone the repo, and run ./scripts/self-host.sh setup. The installer writes and validates the deployment configuration and starts on loopback; remote access still needs a domain, HTTPS reverse proxy, and matching OAuth callbacks. Comparable open-source tools have similar Docker-based setups; allow time for OAuth and production network configuration rather than treating self-hosting as zero setup.