{
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-09",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "tool": {
    "slug": "sprites",
    "name": "Sprites",
    "vendor": "Fly.io",
    "vendorUrl": "https://fly.io",
    "kind": "http-api",
    "category": "code-sandboxes",
    "summary": "Sprites are hosted Linux microVMs from Fly.io that keep their disk between runs, pause when idle and wake on request. They are driven through a REST API, a CLI, four SDKs or a hosted MCP server.",
    "url": "https://www.anchorterminal.com/tools/sprites",
    "markdownUrl": "https://www.anchorterminal.com/tools/sprites.md",
    "slimMarkdownUrl": "https://www.anchorterminal.com/tools/sprites.min.md",
    "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/sprites.json",
    "repo": "https://github.com/superfly/sprites-js",
    "license": "Proprietary service under the Fly.io Terms of Service. The JavaScript, Go, Python and Elixir SDKs are MIT",
    "transports": [
      "http"
    ],
    "packages": [
      {
        "registry": "npm",
        "name": "@fly/sprites"
      },
      {
        "registry": "pypi",
        "name": "sprites-py"
      }
    ],
    "auth": "api-key",
    "authNotes": "A bearer token created at sprites.dev/account after signing in with a Fly.io account, sent as `Authorization: Bearer \u003ctoken\u003e` to `https://api.sprites.dev`. Tokens belong to an organisation, and no scopes or expiry were found in the reviewed docs. The CLI signs in through a browser with `sprite org auth` or takes a token with `sprite auth setup --token`. The hosted MCP server uses OAuth with a token restricted by default to a name prefix and a capped number of Sprites.",
    "pricing": "usage",
    "pricingNotes": "$0.0385 a CPU-hour and $0.021875 a GB-hour of memory while a Sprite is active, hot storage at $0.000683 a GB-hour while awake and cold storage at $0.000027 a GB-hour while data is kept. Nothing is charged per Sprite or for bandwidth. New organisations get a $30 trial credit, and whether it needs a card was not established. The product page also describes monthly plans with allowances, of which Hero ($100) and Mythic ($2,000) are priced (https://fly.io/sprites/, https://fly.io/pricing/, checked 2026-10-08).",
    "priceSummary": "$0.0385 / vCPU-hr",
    "where": "local",
    "x402": {
      "level": "no",
      "evidence": "No x402, MPP or L402 in the Sprites docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
      "endpoints": []
    },
    "toolCount": null,
    "popularity": {
      "githubStars": null,
      "npmWeekly": 157565,
      "pypiWeekly": 58695,
      "asOf": "2026-10-08"
    },
    "docsUrl": "https://docs.fly.io/sprites",
    "llmsTxt": "https://docs.fly.io/llms.txt",
    "openapi": "https://docs.fly.io/sprites/api/openapi.json",
    "capabilities": [
      "sandbox.code",
      "sandbox.fs",
      "sandbox.persist"
    ],
    "tags": [
      "hosted",
      "usage-priced",
      "microvm",
      "persistent",
      "checkpoints",
      "openapi",
      "cli",
      "typescript",
      "python",
      "go",
      "elixir",
      "mcp",
      "llms-txt",
      "status-page"
    ],
    "lastRelease": "2026-10-06",
    "graded": true,
    "anchor": {
      "graded": true,
      "score": 58.3,
      "grade": "C",
      "agentReady": false,
      "rank": 528,
      "ranked": true,
      "rankOf": 842,
      "categoryRank": 11,
      "methodology": "0.4",
      "run": "2026-10-01",
      "scores": {
        "ergonomics": 68,
        "maintenance": 80,
        "payments": 30,
        "reliability": 55,
        "schema": 74,
        "security": 59,
        "transparency": 59
      },
      "pending": [
        "performance",
        "tasks"
      ],
      "breakdown": [
        {
          "key": "reliability",
          "name": "Reliability",
          "weight": 16,
          "effectiveWeight": 20,
          "score": 55,
          "points": 11,
          "reason": "Hosted lines. status.flyio.net runs on incident.io with history and a Sprites component (20). Four Sprites incidents in the last 90 days. Deletion jobs failed for 47 minutes on 30 August 2026, a partial API outage ran 1 hour 38 minutes on 2 September, a partial outage ran 7 hours 28 minutes from 23 September, and creates failed in all regions outside Europe for 28 minutes on 8 October (5). The product page gives creation limits of 10 a minute on pay-as-you-go and 60 to 240 on plans, and 100 running Sprites on the Hero plan. No general request limits were found in the docs (10). The Go SDK reads `Retry-After` and `X-RateLimit` headers on a 429 and names a `sprite_creation_rate_limited` code, but the docs and the OpenAPI document list no 429 response and no idempotency keys (7). A 99.9 per cent uptime SLA is listed with Enterprise support, from $2,500 a month, without saying whether it covers Sprites (5). No beta label was found on Sprites, though the API document is version 0.1.12 and the SDKs are 0.x (8)."
        },
        {
          "key": "performance",
          "name": "Performance",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
        },
        {
          "key": "schema",
          "name": "Schema \u0026 documentation",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 74,
          "points": 12.03,
          "reason": "A public OpenAPI 3.1 document with 44 operations and 59 schemas, plus an AsyncAPI file for the WebSocket calls (25). llms.txt and a Markdown copy of every docs page (10). Concept pages say when to use Services, Tasks and checkpoints and when not to, while operation descriptions are one line each (15). Request bodies have required fields and examples, but the document has 6 enums and no schema for error bodies (10). 116 examples in the OpenAPI document. Error responses are a status code and a short phrase, and the product page's create and exec examples disagree with the OpenAPI document (8). Paths are versioned under `/v1`. No API changelog was found, and only the Python SDK keeps a changelog file (6)."
        },
        {
          "key": "ergonomics",
          "name": "Agent ergonomics",
          "weight": 13,
          "effectiveWeight": 16.25,
          "score": 68,
          "points": 11.05,
          "reason": "List calls take `max_results`, and service logs take `lines` and `duration`. Exec returns command output directly, with a WebSocket route for streaming (17). Sprite lists page with `continuation_token` and filter by `prefix` (16). Status codes are listed per operation and the SDKs raise typed errors with a machine code, but no code list is published (10). No idempotency keys. Service creation is a PUT by name and Sprite names are unique per organisation, and the hosted MCP server marks tools as read-only or destructive (10). Creating a Sprite needs only a name, and there are official SDKs in four languages and a CLI (15)."
        },
        {
          "key": "security",
          "name": "Security \u0026 auth",
          "weight": 14,
          "effectiveWeight": 17.5,
          "score": 59,
          "points": 10.33,
          "reason": "Bearer tokens are created and removed at sprites.dev/account per organisation, with no scopes found. The MCP connector uses OAuth, and its default token can only create a capped number of Sprites under a name prefix (22). Sprite URLs are private by default, Connectors deny by default and can limit provider paths, and a privileges policy can drop capabilities. The network allowlist is opt-in, so egress is open by default (15). Connectors keep provider credentials out of the Sprite and the MCP page describes what its tools can destroy. No prompt-injection guidance was found (9). No audit log of API calls was found in the reviewed documentation (0). SOC 2 Type 2, named third-party penetration testers, published remediation times and security@fly.io. fly.io has no security.txt and no bug bounty was found (13)."
        },
        {
          "key": "payments",
          "name": "Payments \u0026 pricing",
          "weight": 10,
          "effectiveWeight": 12.5,
          "score": 30,
          "points": 3.75,
          "reason": "No x402, MPP or L402 (0). Unit prices are public without a login, $0.0385 a CPU-hour, $0.021875 a GB-hour of memory, $0.000683 a GB-hour of hot storage and $0.000027 a GB-hour of cold storage (20). New organisations get a $30 trial credit. Whether a card is needed to receive it was not established, so half credit (10). A person signs up with a Fly.io account in a browser and creates the token (0)."
        },
        {
          "key": "tasks",
          "name": "Task success",
          "weight": 10,
          "effectiveWeight": 0,
          "pending": true,
          "points": 0,
          "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
        },
        {
          "key": "maintenance",
          "name": "Maintenance \u0026 community",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 80,
          "points": 7,
          "reason": "`sprites-py` 0.7.2 on 6 October 2026, 2 days ago, and `@fly/sprites` 0.2.3 on 17 September (30). Six `sprites-py` releases and five `@fly/sprites` releases since 22 July 2026 (20). No product changelog was found. Support is the community forum below the Hero plan and email above it. Issue response on GitHub was not read (7). Current official SDKs for JavaScript, Go, Python and Elixir (15). All four SDK repositories run a checks workflow in CI. The JavaScript SDK requires Node.js 24 or later (8)."
        },
        {
          "key": "transparency",
          "name": "Transparency \u0026 trust",
          "weight": 7,
          "effectiveWeight": 8.75,
          "score": 59,
          "points": 5.16,
          "note": "editorial 54, provenance 64",
          "reason": "The SDKs are MIT and the platform is closed under terms of service effective 29 April 2026 (18). The privacy statement, effective 24 September 2026, keeps account data while the account is active and analytics data for at most 12 months. A pre-signed DPA is available on request. The terms grant Fly.io a licence to use customer data to run and improve the services. No retention period for Sprite data after deletion was found beyond the docs calling destruction permanent (18). No deprecation policy was found. The maintenance page says Sprites on Ubuntu 25.04 must upgrade, without a date (3). A sub-processor list of 34 vendors with countries and a dated change log, last updated 24 September 2026, names Tigris for Sprites object storage. The docs do not say which region a Sprite runs in (15)."
        }
      ],
      "assessment": {
        "date": "2026-10-08",
        "basis": "public evidence",
        "confidence": "medium",
        "notes": {
          "ergonomics": "List calls take `max_results`, and service logs take `lines` and `duration`. Exec returns command output directly, with a WebSocket route for streaming (17). Sprite lists page with `continuation_token` and filter by `prefix` (16). Status codes are listed per operation and the SDKs raise typed errors with a machine code, but no code list is published (10). No idempotency keys. Service creation is a PUT by name and Sprite names are unique per organisation, and the hosted MCP server marks tools as read-only or destructive (10). Creating a Sprite needs only a name, and there are official SDKs in four languages and a CLI (15).",
          "maintenance": "`sprites-py` 0.7.2 on 6 October 2026, 2 days ago, and `@fly/sprites` 0.2.3 on 17 September (30). Six `sprites-py` releases and five `@fly/sprites` releases since 22 July 2026 (20). No product changelog was found. Support is the community forum below the Hero plan and email above it. Issue response on GitHub was not read (7). Current official SDKs for JavaScript, Go, Python and Elixir (15). All four SDK repositories run a checks workflow in CI. The JavaScript SDK requires Node.js 24 or later (8).",
          "payments": "No x402, MPP or L402 (0). Unit prices are public without a login, $0.0385 a CPU-hour, $0.021875 a GB-hour of memory, $0.000683 a GB-hour of hot storage and $0.000027 a GB-hour of cold storage (20). New organisations get a $30 trial credit. Whether a card is needed to receive it was not established, so half credit (10). A person signs up with a Fly.io account in a browser and creates the token (0).",
          "reliability": "Hosted lines. status.flyio.net runs on incident.io with history and a Sprites component (20). Four Sprites incidents in the last 90 days. Deletion jobs failed for 47 minutes on 30 August 2026, a partial API outage ran 1 hour 38 minutes on 2 September, a partial outage ran 7 hours 28 minutes from 23 September, and creates failed in all regions outside Europe for 28 minutes on 8 October (5). The product page gives creation limits of 10 a minute on pay-as-you-go and 60 to 240 on plans, and 100 running Sprites on the Hero plan. No general request limits were found in the docs (10). The Go SDK reads `Retry-After` and `X-RateLimit` headers on a 429 and names a `sprite_creation_rate_limited` code, but the docs and the OpenAPI document list no 429 response and no idempotency keys (7). A 99.9 per cent uptime SLA is listed with Enterprise support, from $2,500 a month, without saying whether it covers Sprites (5). No beta label was found on Sprites, though the API document is version 0.1.12 and the SDKs are 0.x (8).",
          "schema": "A public OpenAPI 3.1 document with 44 operations and 59 schemas, plus an AsyncAPI file for the WebSocket calls (25). llms.txt and a Markdown copy of every docs page (10). Concept pages say when to use Services, Tasks and checkpoints and when not to, while operation descriptions are one line each (15). Request bodies have required fields and examples, but the document has 6 enums and no schema for error bodies (10). 116 examples in the OpenAPI document. Error responses are a status code and a short phrase, and the product page's create and exec examples disagree with the OpenAPI document (8). Paths are versioned under `/v1`. No API changelog was found, and only the Python SDK keeps a changelog file (6).",
          "security": "Bearer tokens are created and removed at sprites.dev/account per organisation, with no scopes found. The MCP connector uses OAuth, and its default token can only create a capped number of Sprites under a name prefix (22). Sprite URLs are private by default, Connectors deny by default and can limit provider paths, and a privileges policy can drop capabilities. The network allowlist is opt-in, so egress is open by default (15). Connectors keep provider credentials out of the Sprite and the MCP page describes what its tools can destroy. No prompt-injection guidance was found (9). No audit log of API calls was found in the reviewed documentation (0). SOC 2 Type 2, named third-party penetration testers, published remediation times and security@fly.io. fly.io has no security.txt and no bug bounty was found (13).",
          "transparency": "The SDKs are MIT and the platform is closed under terms of service effective 29 April 2026 (18). The privacy statement, effective 24 September 2026, keeps account data while the account is active and analytics data for at most 12 months. A pre-signed DPA is available on request. The terms grant Fly.io a licence to use customer data to run and improve the services. No retention period for Sprite data after deletion was found beyond the docs calling destruction permanent (18). No deprecation policy was found. The maintenance page says Sprites on Ubuntu 25.04 must upgrade, without a date (3). A sub-processor list of 34 vendors with countries and a dated change log, last updated 24 September 2026, names Tigris for Sprites object storage. The docs do not say which region a Sprite runs in (15)."
        },
        "sources": [
          {
            "what": "Sprites product page, prices, FAQ on plans, limits and trial credit",
            "url": "https://fly.io/sprites/",
            "seen": "2026-10-08"
          },
          {
            "what": "Markdown copy of the product page",
            "url": "https://fly.io/sprites.md",
            "seen": "2026-10-08"
          },
          {
            "what": "Sprites docs overview",
            "url": "https://docs.fly.io/sprites",
            "seen": "2026-10-08"
          },
          {
            "what": "Quickstart",
            "url": "https://docs.fly.io/sprites/quickstart",
            "seen": "2026-10-08"
          },
          {
            "what": "Working with Sprites, environment, URLs and storage",
            "url": "https://docs.fly.io/sprites/working-with-sprites",
            "seen": "2026-10-08"
          },
          {
            "what": "Lifecycle and persistence, resources",
            "url": "https://docs.fly.io/sprites/concepts/lifecycle",
            "seen": "2026-10-08"
          },
          {
            "what": "Networking, URL authentication and network policy",
            "url": "https://docs.fly.io/sprites/concepts/networking",
            "seen": "2026-10-08"
          },
          {
            "what": "Checkpoints",
            "url": "https://docs.fly.io/sprites/concepts/checkpoints",
            "seen": "2026-10-08"
          },
          {
            "what": "Connectors",
            "url": "https://docs.fly.io/sprites/concepts/connectors",
            "seen": "2026-10-08"
          },
          {
            "what": "Keeping a Sprite running, Tasks API",
            "url": "https://docs.fly.io/sprites/keeping-sprites-running",
            "seen": "2026-10-08"
          },
          {
            "what": "Sprite maintenance, Ubuntu versions",
            "url": "https://docs.fly.io/sprites/sprite-maintenance",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI authentication and tokens",
            "url": "https://docs.fly.io/sprites/cli/authentication",
            "seen": "2026-10-08"
          },
          {
            "what": "CLI commands reference",
            "url": "https://docs.fly.io/sprites/cli/commands",
            "seen": "2026-10-08"
          },
          {
            "what": "Remote MCP server",
            "url": "https://docs.fly.io/sprites/integrations/remote-mcp",
            "seen": "2026-10-08"
          },
          {
            "what": "SDKs and frameworks",
            "url": "https://docs.fly.io/sprites/integrations/agent-sdks",
            "seen": "2026-10-08"
          },
          {
            "what": "Sprites API reference overview",
            "url": "https://sprites.dev/api",
            "seen": "2026-10-08"
          },
          {
            "what": "Sprites OpenAPI document",
            "url": "https://docs.fly.io/sprites/api/openapi.json",
            "seen": "2026-10-08"
          },
          {
            "what": "Docs llms.txt",
            "url": "https://docs.fly.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "fly.io llms.txt",
            "url": "https://fly.io/llms.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "Fly.io pricing page, Sprites rates, support plans and SLA",
            "url": "https://fly.io/pricing/",
            "seen": "2026-10-08"
          },
          {
            "what": "Status page",
            "url": "https://status.flyio.net/",
            "seen": "2026-10-08"
          },
          {
            "what": "Status feed",
            "url": "https://status.flyio.net/feed.rss",
            "seen": "2026-10-08"
          },
          {
            "what": "Incident, Sprite creates failing, 8 October 2026",
            "url": "https://status.flyio.net/incidents/01M4EPC94XF097RBMJ5S35XMMN",
            "seen": "2026-10-08"
          },
          {
            "what": "Incident, partial Sprites outage, 23 September 2026",
            "url": "https://status.flyio.net/incidents/01M37TXDN856S591W41YPEB22M",
            "seen": "2026-10-08"
          },
          {
            "what": "Incident, Sprites API partial outage, 2 September 2026",
            "url": "https://status.flyio.net/incidents/01M1J5TSVGA1QX4GJGW9QA85J7",
            "seen": "2026-10-08"
          },
          {
            "what": "Terms of service",
            "url": "https://fly.io/legal/terms-of-service/",
            "seen": "2026-10-08"
          },
          {
            "what": "Privacy statement",
            "url": "https://fly.io/legal/privacy-policy/",
            "seen": "2026-10-08"
          },
          {
            "what": "Sub-processors",
            "url": "https://fly.io/legal/sub-processors/",
            "seen": "2026-10-08"
          },
          {
            "what": "Security page",
            "url": "https://fly.io/security/",
            "seen": "2026-10-08"
          },
          {
            "what": "Compliance page",
            "url": "https://fly.io/compliance/",
            "seen": "2026-10-08"
          },
          {
            "what": "Security practices and compliance",
            "url": "https://docs.fly.io/security/security-at-fly-io",
            "seen": "2026-10-08"
          },
          {
            "what": "security.txt, 404",
            "url": "https://fly.io/.well-known/security.txt",
            "seen": "2026-10-08"
          },
          {
            "what": "JavaScript SDK repository, cloned",
            "url": "https://github.com/superfly/sprites-js",
            "seen": "2026-10-08"
          },
          {
            "what": "Go SDK repository, cloned",
            "url": "https://github.com/superfly/sprites-go",
            "seen": "2026-10-08"
          },
          {
            "what": "Python SDK repository, cloned",
            "url": "https://github.com/superfly/sprites-py",
            "seen": "2026-10-08"
          },
          {
            "what": "Elixir SDK repository, cloned",
            "url": "https://github.com/superfly/sprites-ex",
            "seen": "2026-10-08"
          },
          {
            "what": "npm registry, @fly/sprites",
            "url": "https://registry.npmjs.org/@fly%2fsprites",
            "seen": "2026-10-08"
          },
          {
            "what": "PyPI, sprites-py",
            "url": "https://pypi.org/pypi/sprites-py/json",
            "seen": "2026-10-08"
          },
          {
            "what": "Sprites blog feed",
            "url": "https://fly.io/sprites-blog/feed.xml",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record for fly.io",
            "url": "https://rdap.identitydigital.services/rdap/domain/fly.io",
            "seen": "2026-10-08"
          },
          {
            "what": "RDAP record for sprites.dev",
            "url": "https://rdap.org/domain/sprites.dev",
            "seen": "2026-10-08"
          }
        ],
        "openQuestions": [
          "The lead listed a CLI and SDKs for JavaScript, Go and Elixir. It left out the REST API at api.sprites.dev, the Python SDK (`sprites-py`) and the hosted MCP server at sprites.dev/mcp. The listing grades the REST API.",
          "Which create and exec shape the API accepts. The product page uses `PUT /v1/sprites/{name}` and a JSON `command` body, and the OpenAPI document uses `POST /v1/sprites` and `cmd` query parameters. We made no API calls.",
          "Whether the $30 trial credit needs a card. The product page says start free, and the general Fly.io trial page describes Machines only.",
          "Prices and allowances for the Adventurer, Veteran, Champion, Legend and Epic plans. Only Hero ($100) and Mythic ($2,000) are priced on the product page, and the pricing page says there are no plans.",
          "Whether the Enterprise 99.9 per cent uptime SLA covers Sprites.",
          "Whether Sprites run on Firecracker. Fly.io's security docs say compute jobs use Firecracker, and the Sprites docs say only hardware-isolated microVM.",
          "Which regions Sprites run in and whether a region can be chosen. Not found in the reviewed documentation.",
          "unchecked: GitHub stars, open issues and issue response times for the SDK repositories. The GitHub API refused our requests for a rate limit.",
          "unchecked: whether tokens created at sprites.dev/account can be scoped or given an expiry, and whether the dashboard has an audit log. Both need a login.",
          "unchecked: the number and definitions of the MCP server's tools, which need an OAuth sign-in to list.",
          "unchecked: the DPA text. The compliance page says it is pre-signed and available, and no public copy was found.",
          "No changelog for the API or the Sprite environment was found, so `provenance.changelog` is left empty.",
          "fly.io/llms.txt asks AI agents to send an `AI-Agent` request header, and the product page tells AI agents to refetch it as Markdown. Both are recorded as facts. We did not act on them."
        ]
      },
      "negative": -2,
      "negativeNotes": [
        "2026-10-08: the Fly.io pricing page says of Sprites \"No plans and no tiers\", while the Sprites product page read the same day describes paid plans (Hero at $100 a month, Mythic at $2,000) that carry usage allowances and set concurrency and creation-rate limits. Prices for the other named plans were not found. 2 points. https://fly.io/pricing/ and https://fly.io/sprites/"
      ],
      "verdict": "A Sprite keeps a 100 GB ext4 disk between runs, bills compute only while active and can be checkpointed and restored through a published OpenAPI contract. The status page records four Sprites incidents in the last 90 days, one lasting over seven hours, and outbound network access is unrestricted until a policy is set.",
      "bestFor": "Agents that need a long-lived machine with installed tools and files kept between sessions, and rollback by checkpoint.",
      "strengths": [
        "The filesystem persists across pauses, and compute billing stops about 30 seconds after activity ends, per the lifecycle docs",
        "A public OpenAPI 3.1 document covers 44 operations on sprites, exec, files, checkpoints, services and policies, with an AsyncAPI file for the WebSocket calls",
        "Connectors hold third-party credentials outside the Sprite, deny access by default and can limit which provider paths a Sprite may call",
        "Checkpoints are copy-on-write snapshots of the writable filesystem, and the last five are mounted read-only inside the Sprite",
        "Unit prices are public, $0.0385 a CPU-hour, $0.021875 a GB-hour of memory and about $0.50 a GB-month of hot storage",
        "Official SDKs for JavaScript, Go, Python and Elixir are MIT, each with releases in September or October 2026"
      ],
      "weaknesses": [
        "Four Sprites incidents on the status page in 90 days, including a partial outage of 7 hours 28 minutes on 23 September 2026 and failed creates outside Europe for 28 minutes on 8 October",
        "Outbound network access is unrestricted by default. The DNS allowlist is opt-in and set from outside the Sprite",
        "The product page creates a Sprite with `PUT /v1/sprites/my-sprite` and a JSON `command` body, while the OpenAPI document creates with `POST /v1/sprites` and passes `cmd` as a query parameter",
        "No API changelog, deprecation policy or error-code reference was found in the reviewed documentation",
        "The pricing page says Sprites have no plans and no tiers, while the product page describes paid plans that set concurrency and creation-rate limits",
        "No scopes were found for API tokens created at sprites.dev/account. Only the MCP connector's OAuth token is restricted by default"
      ],
      "agentNotes": [
        "Create a token at sprites.dev/account after a browser signup, and send it as `Authorization: Bearer \u003ctoken\u003e` to `https://api.sprites.dev`",
        "Follow the OpenAPI document, not the product page example. Create with `POST /v1/sprites` and a JSON `name`, and run commands with `POST /v1/sprites/{name}/exec` using `cmd` query parameters",
        "Set a network policy with `POST /v1/sprites/{name}/policy/network` before running untrusted code. Egress is open until one is set",
        "Processes started by exec stop on a cold wake. Define a Service for anything that must answer the request that wakes the Sprite",
        "Create a checkpoint before a restore. Restoring replaces the filesystem, ends active sessions and keeps no copy of the replaced state",
        "Sprite creation is limited to 10 a minute on pay-as-you-go. The Go SDK reads `Retry-After` and the error code `sprite_creation_rate_limited` on a 429",
        "Delete Sprites you no longer need. An idle Sprite still bills cold storage for the bytes it holds"
      ],
      "metrics": {
        "kind": "remote",
        "measured": false
      },
      "reviewCount": 0,
      "avgRating": 0,
      "history": [
        {
          "basis": "public evidence",
          "confidence": "medium",
          "grade": "C",
          "methodology": "0.4",
          "pending": [
            "performance",
            "tasks"
          ],
          "run": "2026-10-01",
          "runLabel": "October 2026 research run",
          "score": 58.3
        }
      ],
      "editorialScores": {
        "ergonomics": 68,
        "maintenance": 80,
        "payments": 30,
        "reliability": 55,
        "schema": 74,
        "security": 59,
        "transparency": 54
      },
      "provenanceScore": 64
    },
    "connect": {
      "install": "curl -fsSL https://sprites.dev/install.sh | sh  # CLI. SDKs: npm install @fly/sprites, pip install sprites-py",
      "http": "curl -X POST https://api.sprites.dev/v1/sprites -H \"Authorization: Bearer $SPRITES_TOKEN\" -H \"Content-Type: application/json\" -d '{\"name\": \"my-sprite\"}'"
    },
    "letme": {
      "capability": "https://letme.dev/sandbox.code",
      "tool": "https://letme.dev/sprites"
    },
    "notable": [
      "Each Sprite has 8 vCPUs, 100 GB of storage and memory the platform sizes and scales, none of which the user sets (https://docs.fly.io/sprites/concepts/lifecycle)",
      "A Sprite pauses about 30 seconds after activity stops. A warm wake takes 100 to 500 ms and keeps processes, and a cold wake takes 1 to 2 seconds and starts them fresh, per the docs (https://docs.fly.io/sprites/concepts/lifecycle)",
      "The hosted MCP server at sprites.dev/mcp uses OAuth, and its default token can only create a capped number of Sprites whose names start with `mcp-` (https://docs.fly.io/sprites/integrations/remote-mcp)",
      "The status page lists four Sprites incidents between 30 August and 8 October 2026, the longest a partial outage of 7 hours 28 minutes (https://status.flyio.net/feed.rss)",
      "The product page's API example creates with `PUT /v1/sprites/my-sprite`, and the OpenAPI document creates with `POST /v1/sprites` and uses PUT to update (https://fly.io/sprites/, https://docs.fly.io/sprites/api/openapi.json)",
      "The pricing page says Sprites have no plans and no tiers, and the product page describes plans from Adventurer to Mythic (https://fly.io/pricing/, https://fly.io/sprites/)",
      "The sub-processor list names Tigris for Sprites object storage, and says Anthropic and OpenAI are used only by Fly.io's internal tooling (https://fly.io/legal/sub-processors/)",
      "fly.io/llms.txt asks AI agents to identify themselves with an `AI-Agent` request header, and the product page tells AI agents to refetch it as Markdown (https://fly.io/llms.txt)"
    ],
    "area": "agent-runtime",
    "details": [
      {
        "label": "Interfaces",
        "value": "REST API at `https://api.sprites.dev` (OpenAPI 3.1, 44 operations) with WebSocket routes, the `sprite` CLI, SDKs `@fly/sprites` 0.2.3, `sprites-py` 0.7.2, `sprites-go` 0.2.1 and `sprites-ex` 0.2.4, and a hosted MCP server at `https://sprites.dev/mcp`"
      },
      {
        "label": "Isolation",
        "value": "A dedicated, hardware-isolated microVM per Sprite, per the docs"
      },
      {
        "label": "Resources",
        "value": "8 vCPUs, 100 GB of storage, and memory sized and scaled by the platform. None is configurable"
      },
      {
        "label": "Environment",
        "value": "Ubuntu 25.10 with Node.js, Python, Go, Ruby, Rust, Elixir, Java, Bun, Deno and several coding agent CLIs preinstalled"
      },
      {
        "label": "Lifetime",
        "value": "No stated maximum. Pauses about 30 seconds after activity stops and wakes on an API call or a request to its URL. A task holds it active for up to 1 hour, renewable"
      },
      {
        "label": "Persistence",
        "value": "ext4 filesystem on local NVMe synced to object storage. Memory and processes survive a warm pause and not a cold one. Services restart on wake"
      },
      {
        "label": "Checkpoints",
        "value": "Copy-on-write snapshots of the writable filesystem, manual and automatic, restorable by id. The last five are mounted read-only at `/.sprite/checkpoints/`"
      },
      {
        "label": "Network",
        "value": "Outbound unrestricted by default. An opt-in DNS allowlist, set through the API, blocks raw IP and private ranges once in force"
      },
      {
        "label": "Access from outside",
        "value": "One HTTPS URL per Sprite at `\u003cname\u003e-\u003corg-id\u003e.sprites.app`, routed to port 8080 and needing an organisation token unless set public. `sprite proxy` forwards any TCP port"
      },
      {
        "label": "Connectors",
        "value": "Third-party credentials held at a gateway, with deny-by-default access by Sprite name prefix or label and optional path allow and block lists"
      },
      {
        "label": "Limits",
        "value": "Sprite creation 10 a minute on pay-as-you-go and 60 to 240 on plans. Hero allows 100 running and 100 warm Sprites, per the product page"
      },
      {
        "label": "Status",
        "value": "status.flyio.net on incident.io, with a Sprites component since 11 February 2026"
      },
      {
        "label": "SLA and compliance",
        "value": "99.9 per cent uptime SLA with Enterprise support, from $2,500 a month. SOC 2 Type 2, with a pre-signed DPA and BAA available"
      }
    ],
    "unitPrices": [
      {
        "item": "CPU time while active",
        "unit": "vcpu-hour",
        "usd": 0.0385,
        "note": "Memory extra at $0.021875 a GB-hour"
      },
      {
        "item": "Hot storage while the Sprite is awake",
        "unit": "gb-month",
        "usd": 0.5,
        "note": "Billed at $0.000683 a GB-hour, on bytes written"
      },
      {
        "item": "Cold storage while data is kept",
        "unit": "gb-month",
        "usd": 0.02,
        "note": "Billed at $0.000027 a GB-hour"
      }
    ],
    "provenance": {
      "legalEntity": "Fly.io, Inc.",
      "domain": "fly.io",
      "domainRegistered": "2004-07-15",
      "endpointOnVendorDomain": false,
      "terms": "https://fly.io/legal/terms-of-service/",
      "privacy": "https://fly.io/legal/privacy-policy/",
      "statusPage": "https://status.flyio.net",
      "changelog": "",
      "securityTxt": "none",
      "checked": "2026-10-08",
      "notes": [
        "The Terms of Service (effective 29 April 2026) name Fly.io, Inc. and cover the website and all products and services reached through it. No separate Sprites terms were found.",
        "The Privacy Statement is effective 24 September 2026. The sub-processor list was last updated the same day.",
        "The API is at api.sprites.dev and Sprite URLs are on sprites.app, second domains of the vendor's. sprites.dev redirects to fly.io/sprites, and RDAP gives its registration date as 2025-06-03.",
        "RDAP for fly.io gives a registration date of 2004-07-15.",
        "fly.io/.well-known/security.txt returned 404. The security docs give security@fly.io for reports.",
        "No changelog for the Sprites API or environment was found. The Python SDK repository keeps a CHANGELOG.md."
      ],
      "score": 64,
      "checks": [
        {
          "check": "Legal entity named",
          "value": "Fly.io, Inc.",
          "points": 20,
          "max": 20,
          "state": "ok"
        },
        {
          "check": "Domain age",
          "value": "fly.io, registered 2004-07-15 (22 years)",
          "points": 15,
          "max": 15,
          "state": "ok"
        },
        {
          "check": "Endpoint on the vendor's domain",
          "value": " is not on fly.io",
          "points": 0,
          "max": 15,
          "state": "no"
        },
        {
          "check": "Terms of service",
          "value": "read, states 6 of the 7 things a reader expects",
          "points": 9.1,
          "max": 10,
          "state": "part"
        },
        {
          "check": "Privacy policy",
          "value": "read, states 8 of the 8 things a reader expects",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Status page",
          "value": "status.flyio.net",
          "points": 10,
          "max": 10,
          "state": "ok"
        },
        {
          "check": "Changelog",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        },
        {
          "check": "security.txt",
          "value": "not found",
          "points": 0,
          "max": 10,
          "state": "no"
        }
      ],
      "policies": [
        {
          "kind": "terms",
          "url": "https://fly.io/legal/terms-of-service/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-04-29",
          "words": 3730,
          "points": 9.1,
          "max": 10,
          "expected": [
            {
              "key": "terms.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective date: April 29th, 2026",
              "says": "Last updated 2026-04-29"
            },
            {
              "key": "terms.law",
              "label": "Names the governing law or courts",
              "found": true,
              "quote": "**Governing Law and Venue.** This Agreement and any action related thereto will be governed and interpreted by and under the laws of the State of California, without giving effect to any conflicts of laws principles that require the application of the law of a different jurisdiction.",
              "says": "The law of the State of California"
            },
            {
              "key": "terms.liability",
              "label": "States a limit on its liability",
              "found": true,
              "quote": "IN NO EVENT WILL FLY.IO OR ITS AFFILIATES, SUPPLIERS, CONTRACTORS, OR LICENSORS BE LIABLE FOR ANY SPECIAL, CONSEQUENTIAL, EXEMPLARY, INCIDENTAL, OR INDIRECT DAMAGES, INCLUDING LOST PROFITS, IN CONNECTION WITH THIS AGREEMENT OR THE FLY.IO SERVICES, EVEN IF PREVIOUSLY ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.",
              "says": "Rules out indirect and consequential losses, with no cap named in this sentence"
            },
            {
              "key": "terms.termination",
              "label": "Says how the agreement or account can be ended",
              "found": true,
              "quote": "**Term.** This Agreement commences on the Effective Date and will remain in effect until terminated by either party as set forth below."
            },
            {
              "key": "terms.changes",
              "label": "Says how changes to the terms are announced",
              "found": true,
              "quote": "Unless otherwise stated in such update, any changes to this Agreement will be effective immediately for new customers and thirty (30) days after posting for existing customers.",
              "says": "Gives thirty days of notice before a change"
            },
            {
              "key": "terms.use",
              "label": "Lists what users may not do",
              "found": true,
              "quote": "Customer may not access or use the specific Fly.io Services if it does not agree with these Supplemental Terms."
            },
            {
              "key": "terms.sla",
              "label": "Refers to a service level or uptime commitment",
              "found": false
            }
          ],
          "toKnow": [
            {
              "key": "terms.cutoff",
              "label": "Says access can be ended without notice or for any reason",
              "found": true,
              "quote": "Either party may terminate this Agreement for no reason or any reason upon written notice to the other party, effective immediately at the end of the then current Subscription Term."
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "The licence the customer grants over Customer Data covers improving the Fly.io Services as well as supplying them to the customer.",
              "quote": "Customer hereby grants to Fly.io a non-exclusive, worldwide, royalty-free and fully paid license (a) to use the Customer Data as necessary for purposes of providing the Fly.io Services to Customer and improving the Fly.io Services"
            },
            {
              "date": "2026-10-08",
              "text": "Fly.io may use the customer's name and logo in its marketing materials to show the customer as a user of the services.",
              "quote": "Customer agrees that Fly.io may use Customer’s name and logo in Fly.io’s marketing materials or communications (including, but not limited to, Fly.io’s website and in Fly.io’s marketing presentations) for the sole purpose of indicating Customer as a user of the Fly.io Services."
            },
            {
              "date": "2026-10-08",
              "text": "Fly.io has no obligation to back up Customer Data, and backups are the customer's responsibility and cost.",
              "quote": "Fly.io is not obligated to back up any Customer Data; the Customer is solely responsible for creating backup copies of any Customer Data at Customer’s sole cost and expense."
            }
          ]
        },
        {
          "kind": "privacy",
          "url": "https://fly.io/legal/privacy-policy/",
          "state": "read",
          "readAt": "2026-10-08",
          "statedDate": "2026-09-24",
          "words": 3198,
          "points": 10,
          "max": 10,
          "expected": [
            {
              "key": "privacy.date",
              "label": "Gives the date it was last updated",
              "found": true,
              "quote": "Effective date: September 24, 2026",
              "says": "Last updated 2026-09-24"
            },
            {
              "key": "privacy.collected",
              "label": "Says what personal data is collected",
              "found": true,
              "quote": "If you’re **just browsing the website** , we collect the same basic information that most websites collect."
            },
            {
              "key": "privacy.retention",
              "label": "Says how long data is kept",
              "found": true,
              "quote": "Analytics data described in the cookies and tracking section is retained for no more than 12 months.",
              "says": "Names a period of 12 months"
            },
            {
              "key": "privacy.processors",
              "label": "Says who else receives the data",
              "found": true,
              "quote": "For the data in your applications, fly.io acts as a processor (or service provider) on your instructions, and you are the controller."
            },
            {
              "key": "privacy.sale",
              "label": "Says whether personal data is sold or shared for advertising",
              "found": true,
              "quote": "We may share User Personal Information if we are involved in a merger, sale, or acquisition."
            },
            {
              "key": "privacy.rights",
              "label": "Says what rights people have over their data",
              "found": true,
              "quote": "For changes to this Privacy Statement that do not affect your rights, we encourage visitors to check this page frequently."
            },
            {
              "key": "privacy.contact",
              "label": "Gives a privacy contact",
              "found": true,
              "quote": "You may email us directly at [compliance@fly.io](mailto:compliance@fly.io) with the subject line “Privacy Concerns.” We will respond within 45 days at the latest.",
              "says": "compliance@fly.io"
            },
            {
              "key": "privacy.transfers",
              "label": "Says where data is transferred or stored",
              "found": true,
              "quote": "Data Privacy Framework, the UK Extension to the EU-U.S.",
              "says": "Relies on the Data Privacy Framework"
            }
          ],
          "notes": [
            {
              "date": "2026-10-08",
              "text": "At account creation and sign-in, third-party fraud-prevention services collect device and browser signals to detect automated abuse, with no opt-out.",
              "quote": "When you create an account or sign in, we use third-party fraud-prevention services that may collect device and browser signals (and set cookies strictly necessary for that purpose) to detect automated abuse and repeat offenders."
            },
            {
              "date": "2026-10-08",
              "text": "Fly.io staff do not access customer applications except for security or maintenance, or for support with the application owner's consent.",
              "quote": "fly.io employees do not access applications unless required to for security or maintenance, or for support reasons, with the consent of the application owner."
            }
          ]
        }
      ]
    },
    "pageJsonUrl": "https://www.anchorterminal.com/tools/sprites.json",
    "live": {
      "slug": "sprites",
      "vendorStatus": {
        "page": "https://status.flyio.net",
        "indicator": "none",
        "summary": "All Systems Operational",
        "checkedAt": "2026-10-09T10:11:20.135416857Z"
      },
      "updatedAt": "2026-10-09T10:11:20.135416857Z"
    }
  }
}
