# Fix list: Crusoe Cloud From Anchor Terminal's listing at https://www.anchorterminal.com/tools/crusoe-cloud, the October 2026 research run, assessed 9 October 2026. Grade B, 63.4 out of 100. This is everything the published grade says the listing lacks, the biggest possible gain to the total first. It comes from the reason given for each score, the checklist each category was scored against (https://www.anchorterminal.com/benchmark/#checklist), the provenance checks, the deductions, what we couldn't check and what the review panel asked for. A fix counts at the next check, once it's public. For a coding agent working on Crusoe Cloud: work through the items below in the product, its docs and its public pages. Each category gives the reason for its score, with the points each checklist item earned, and the checklist itself, so the gap is the items that earned less than their points. Change the product, not the wording, and keep a note of what you changed and where it's published. ## 1. Agent ergonomics, 45 out of 100, up to 8.9 more on the total Why it scored 45: Lists take `limit` or `page_size` on 16 of about 104 list calls, and VM lists filter by id, name, type, location and state; no field selection (12 of 25). Token pagination with next and previous tokens and a `sort` parameter where present; most lists return everything (12). Errors are an HTTP status with `code` and `message`, and long-running calls return an operation with `state` and `result` to poll; no documented list of error codes (10). No idempotency key or safe-retry guidance found; the preview MCP server has read tools only, and its annotations were not read (4). VM create needs a name, type, location and SSH key and installs a monitoring agent by default; the Go client is the only official SDK found, beside a CLI and a Terraform provider, and other languages must code the request signature (7). The checklist (https://www.anchorterminal.com/benchmark/#checklist-ergonomics): - 0 to 25, context cost. For MCP, the number and size of the tool definitions (25 for ten or fewer compact tools, 15 for 11 to 30, 5 for more than 30, plus up to 10 back for toolsets, dynamic loading or read-only subsets). For APIs, whether responses can be sized (field selection, limits, summaries). - 20, pagination, filtering and output-size controls. - 20, actionable, documented error responses, codes and messages an agent can recover from. - 20, idempotency or safe retries, and for MCP the `readOnlyHint` and `destructiveHint` annotations. - 15, sensible defaults, few required parameters, and official SDKs in at least two languages. Models are read for tool use, structured output, prompt caching, context length, batch and SDKs. Frameworks for how much code and how many defaults a tool-calling agent with MCP needs. ## 2. Payments & pricing, 30 out of 100, up to 8.8 more on the total Why it scored 30: No machine payment protocol (0). Per-GPU-hour, per-vCPU-hour, per-GiB and per-token prices published without a login, though spot prices and on-demand prices for GB200, B200 and MI355X are contact sales (20). $5 of introductory credits cover Serverless Inference and Serverless Fine-Tuning without a payment method; GPU machines, the product graded here, need a non-prepaid credit card (10 of 20). Signup is a browser flow with Google, GitHub or an emailed code, and the first key is made in the console (0). The checklist (https://www.anchorterminal.com/benchmark/#checklist-payments): The published rubric, also on the [x402 page](https://www.anchorterminal.com/x402/). - 40, a machine payment protocol (x402, MPP or L402) on the tool's own endpoints. 10 to 30 when it covers only some endpoints or only goes through a third party, and the note says which. - 20, per-call or per-unit pricing published without a login. 10 for public plan-only pricing, 0 for "contact sales" or prices behind a login. - 20, a free tier or trial that doesn't need a card. - 20, autonomous onboarding, meaning an agent can get access without a person signing up in a browser (keyless use, x402, a programmatic key API). Payment platforms and agent wallets rarely charge for their own API over a machine protocol, so the first line has steps for them, and the highest one that applies counts. 40 when x402, MPP or L402 runs on all their own endpoints, 30 when it runs on part of their own API, 25 when their merchants can accept one, 20 for running a facilitator, 15 for paying as a buyer, and 0 when the only protocol is their own. Merchant acceptance sits above a facilitator because the platform's own customers can charge agents through it, while a facilitator settles for sellers who wire up the protocol themselves. The counter-argument (a facilitator does more for the protocol as a whole) has a point. Each note says which step applied. Open-source software you run yourself is scored on its hosted or paid option if it has one. A free, self-hosted package with nothing to buy gets 20, 20 and 20 for the last three lines, and 0 to 40 for the first only if it ships a payment protocol. ## 3. Reliability, 66 out of 100, up to 6.8 more on the total Why it scored 66: Graded as a hosted service on the REST API. Statuspage at status.crusoecloud.com with components per region and service (20). The history page shows, since August 2026, one critical incident (shared disks, Object Storage and the container registry unreachable in eu-norway1 for about 3 hours 54 minutes on 29 September), one minor incident (VM and Kubernetes cluster creation in us-east2 for about 7.5 hours on 2 September) and two with no stated impact; July was not on the page read (10). Rate limits carry numbers only for Serverless Inference (500,000 tokens and 30 requests a minute per model without a payment method, 2,000,000 and 600 with one); none were found for the infrastructure API, whose MCP server throttles itself to 60 requests a minute (8 of 15). Serverless Inference documents 429 and 503 with exponential backoff and `x-ratelimit-*` headers; no Retry-After, no idempotency keys and no retry guidance for infrastructure writes were found (8 of 15). SLA of 99.5 per cent a month per GPU virtual machine and per persistent disk, with credits of 10, 25 or 100 per cent (10). The v1 API is labelled Latest and the services graded are generally available; the MCP server is in preview (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-reliability): Hosted APIs, MCP servers, models and platforms. - 20, a public status page with component history (Statuspage, Instatus, BetterStack or the vendor's own). - 0 to 30, the incident record for the last 90 days on that page. 30 for a clean record or trivial incidents only, 20 for minor incidents only, 10 for one major outage (an hour or more of a core API down, or errors across the board), 0 for several. 5 when there's no history we could read, and the note says so. - 15, rate limits documented with numbers. - 15, documented 429 or overload handling (Retry-After, backoff guidance), and idempotency keys or safe-retry guidance where writes are involved. - 10, an SLA published for any paid tier. - 10, the surface agents use is generally available, not beta or preview. Local packages, SDKs, frameworks and stdio MCP servers. - 20, installs from an official package with supported runtimes stated. - 25, a public CI and test suite, passing on the default branch. - 0 to 25, open crash or regression issues relative to activity (25 for few and handled, 0 for many, old and unanswered). - 15, semver discipline and breaking changes called out in a changelog. - 15, version 1.0 or later, or declared stable. Protocols are read from their reference implementations, the public facilitators or servers, spec stability and test vectors. ## 4. Security & auth, 74 out of 100, up to 4.6 more on the total Why it scored 74: Access key and secret key with optional expiry, deletable in the console or through `/users/tokens`. Requests are signed with HMAC-SHA256 and a timestamp, so no secret is sent and none travels in a URL. Keys inherit their creator's roles and cannot be narrowed further; service accounts with their own credentials appear in the API description and the Terraform provider 1.6.0 (24). `org-reader` and `project-reader` roles give read-only access and the MCP server exposes no write tools; no confirmation step for destructive API calls (14). Returns infrastructure metadata, and the MCP docs warn that it is sent to the assistant and that an agent with a shell can still run the CLI (10). Audit log of 90 days of control-plane actions with actor, IP, surface and result, readable through the API by admins; read events are not logged (13). security.txt valid until 1 March 2027 with no Policy field, ISO 27001, ISO 42001 and SOC 2 Type I and II claimed on the cloud page, customer-managed encryption keys; no bug bounty found, the trust centre was unreadable, and the apt install line sets `[trusted=yes]` (13). The checklist (https://www.anchorterminal.com/benchmark/#checklist-security): - 0 to 30, the credential model. 30 for OAuth 2.1 with scopes, or scoped and revocable keys with rotation. 20 for plain revocable API keys. 10 for one all-powerful key. 10 off when a secret can travel in a URL query string as a documented option. - 0 to 20, read-only or least-privilege modes, and confirmation or approval for destructive actions. - 0 to 15, prompt-injection posture where the tool returns untrusted content (documented mitigations or guidance). A tool that returns no untrusted content gets 10. - 0 to 15, audit logs or per-call visibility for the operator. - 0 to 20, a security programme. security.txt or a disclosure policy, a bug bounty, SOC 2 or ISO 27001, advisories handled in public. Models are read for retention, whether API data trains models (and whether that's off by default), zero-retention options and certifications. Frameworks for telemetry defaults, approval hooks, guardrails and sandboxing. ## 5. Schema & documentation, 79 out of 100, up to 3.4 more on the total Why it scored 79: A Swagger 2.0 description for `/v1` and `/v1alpha5`, linked from the reference page and kept in `crusoecloud/client-go`, and an OpenAPI description for the Intelligence Foundry API (25). `llms.txt` and a Markdown twin of each docs page (10). Every one of the 257 operations in the repository copy has a one-line summary, 74 have a longer description, and fields are described; few say when not to call (11). 64 enums and 208 required lists, though `limit` is typed as a string and instance types and locations are plain strings; the file declares no security scheme (10). 1,231 examples with request and response samples, and 400, 401, 403, 404 and 500 responses with a `code` and `message` body; no error catalogue and 429 appears on one operation (10). Versioned paths, dated Crusoe Updates entries with RSS and Atom feeds, and tagged Go client releases; the updates do not list API changes field by field (13). The checklist (https://www.anchorterminal.com/benchmark/#checklist-schema): APIs and MCP servers. - 25, a machine-readable contract (a public OpenAPI file or similar; for MCP, typed JSON Schema inputs on every tool). - 10, llms.txt or Markdown docs served for agents. - 0 to 20, descriptions that say what a tool is for, when to use it and when not to, read from the tool definitions in the source or the API reference. - 0 to 15, typed inputs with enums, constraints and required fields, and no free-form JSON blobs. - 0 to 15, examples and documented error responses. - 15, versioning and a public changelog. Models are read from the API reference, the OpenAPI file, llms.txt, the structured-output and tool-use docs and the model cards. Frameworks from docs a model can follow, typed interfaces, examples and the API reference. ## 6. Maintenance & community, 76 out of 100, up to 2.1 more on the total Why it scored 76: Crusoe Updates entries on 5, 7 and 8 October 2026 and a Terraform provider 1.6.0 changelog entry on 8 October (30). Go client tags v1.0.1 to v1.0.18 and seven Terraform provider tags since 11 July 2026, plus more than 20 dated updates (20). Closed service with a dated changelog and feeds, a support portal, email support and published support tiers; GitHub issue response times were not read (10 of 15). The Go client is current and generated from the API description, with the Terraform provider and CLI beside it; one language only, and the MCP package was not checked against the official registry (10 of 15). A lint workflow in the Terraform provider and GitLab CI configuration in the Go client; results were not read (6). The checklist (https://www.anchorterminal.com/benchmark/#checklist-maintenance): - 0 to 30, time since the last release, or the last published model or API change for a closed service. 30 within 30 days, 20 within 90, 10 within 180, 0 older. - 20, at least three releases or dated changelog entries in the last 90 days. - 0 to 25, responsiveness. Issues and pull requests answered on GitHub (the open issues and how recent the replies are). For closed services, a public changelog and a support or community channel that answers, 0 to 15. - 15, presence in the official MCP registry under a verified namespace (MCP servers), or current official SDKs (APIs and models). - 10, package health, current dependencies and CI. Models are read for deprecation notice periods and model churn rather than release counts. ## 7. Transparency & trust, 77 out of 100, up to 2 more on the total Made of editorial 64, provenance 90. Why it scored 77: Closed service under Terms of Service version 1.10, effective 10 August 2026, with ten earlier versions kept on the legal page; the Go client and MCP package are MIT (15). The Privacy Notice (version 1.3, 12 March 2026) covers Service Data and the Data Processing and Security Terms (version 1.3, 14 July 2026) cover Customer Data, with deletion on instruction and at the end of the term, and the Intelligence Foundry terms say inputs, outputs and training data are not used to train models without opt-in consent; no retention periods are given in numbers (22). The terms promise 90 days' notice before discontinuing a service or changing a customer-facing API incompatibly, and a deprecation page gives dates such as 8 November 2026 for old CSI drivers, announced 15 September; model deprecations are logged on the day they take effect (17). Seven data centre zones are published; the data processing terms point to a sub-processor list that was not found in the pages read (10). The checklist (https://www.anchorterminal.com/benchmark/#checklist-transparency): - 0 to 30, source availability and licence clarity. 30 for open source under an OSI licence, 15 for closed with clear terms, 0 for unclear terms. - 0 to 30, data handling and retention statements that agree with each other (privacy policy, DPA, retention periods, subprocessors). - 0 to 20, a deprecation policy or notices with dates. - 0 to 20, telemetry disclosed with an opt-out (local software), or subprocessors and data locations disclosed (hosted). The other half of Transparency and trust is the provenance score, computed from checked facts (below). The category score is the mean of the two. Provenance checks not met in full (half of this category, computed from checked facts): - Domain age: crusoe.ai, registered 2019-01-28 (7 years) (11 of 15) - Terms of service: published, but our reader couldn't read it (7 of 10) - Privacy policy: published, but our reader couldn't read it (7 of 10) ## What we couldn't check What we couldn't read counted as absent. Publishing it on a page a plain HTTP fetch can read (not only in a browser) lets the next check count it. - The lead named only the CLI and the Terraform provider. Crusoe also publishes a REST API with an API description, a Go client and a preview MCP server, and the API is the surface graded. - unchecked: the trust centre at trust.crusoe.ai is drawn by script, so certifications, the sub-processor list and any penetration test summary were not read. Certifications are taken from the product page as the vendor's claim. - unchecked: status history for July 2026. The history page read showed August to October only, and robots.txt closes the status API. - unchecked: the API description at `https://api.crusoecloud.com/v1/openapi.json` was not fetched. The copy in `crusoecloud/client-go` and the rendered reference page were read, and the two differ in operation count (257 and 164). - unchecked: GitHub issue response times, CI results, repository stars and CLI release dates. Tags in the CLI repository all carry one 2022 commit date. - unchecked: the tool definitions and annotations of `@crusoeai/cloud-mcp`. Its source is on a GitLab address that was not read, and the package was not downloaded or run. The count of 41 tools comes from the docs page. - No request rate limits or idempotency keys were found for the infrastructure API. They may exist in pages not read. - Whether a deprecated Serverless Inference model stops answering on the listed date, and how much notice customers had, was not established. The changelog entries are dated the day of deprecation. - Service accounts are in the API description and the Terraform provider 1.6.0, with no docs page found, so their scopes and token lifetimes are not established. - The create-an-account page says billing must be enabled to use managed inference, while the updates and rate-limit pages describe use on introductory credits with no payment method. - The Service Specific Terms require written consent before benchmark results are published and the Intelligence Foundry terms bar competitive analysis or benchmarking. The Acceptable Use Policy bars disruptive crawling or scraping and testing the services to find limitations. This matters before any Anchor Terminal probe runs. - `provenance.terms` and `provenance.privacy` are anchors on one 3.5 MB page that holds every legal document and its earlier versions, so the policy reader may need the section picked out by hand. - `compute.endpoints` rests on Self-Serve Deployments, which serve catalogue models and LoRA adapters, not a customer's own container. `compute.serverless` is left out. ## Weaknesses - No idempotency key or safe-retry guidance was found for create and delete calls, which return asynchronous operations to poll. - No request rate limits were found for the infrastructure API. Numbers are published only for Serverless Inference. - Spot prices and on-demand prices for GB200, B200 and MI355X are listed as contact sales, and provisioning compute needs a non-prepaid credit card. - The status page shows a critical storage incident in eu-norway1 on 29 September 2026 (about 3 hours 54 minutes) and a 7.5-hour VM and cluster creation fault in us-east2 on 2 September. - The Service Specific Terms let customers publish benchmark results only with Crusoe's written consent, and the Intelligence Foundry terms bar competitive analysis or benchmarking. Recorded as a fact, and it matters before any probe is run. ## What costs an agent a turn today The notes we give agents before they call it. Each one is a workaround an agent shouldn't need. - Sign every request. Build the payload from path, sorted query string, verb and `X-Crusoe-Timestamp`, HMAC-SHA256 it with the base64url-decoded secret, and send `Authorization: Bearer 1.0::`. - Use `https://api.cloud.crusoe.ai/v1`. Some docs pages and the MCP server still name `api.crusoecloud.com` and `/v1alpha5`. - Creates, updates and deletes return an operation. Poll the matching operations endpoint for `state`, and list existing resources by name before retrying a create, because no idempotency key was found. - Managed AI uses separate Intelligence API keys and hosts, `api.inference.crusoecloud.com` for OpenAI-compatible calls and `api.intelligence.crusoecloud.com` for files and fine-tuning jobs. - Delete a VM and its disks to stop charges. A stopped on-demand VM is not billed for compute, but its 128 GB OS disk still bills at $0.08 a GiB-month. ## When it's done Send what changed and where it's published as a dispute (https://www.anchorterminal.com/builders/#disputes, or `POST https://www.anchorterminal.com/api/v1/contact` with `"kind": "dispute"`). Disputes are answered in public, and the listing is checked again by the same checklist. Paying for an audit or a listing claim changes nothing here.