# Sprites (slim) > Sprites are hosted Linux microVMs from Fly.io that keep their disk between runs, pause when idle and wake on request. They are driven through a REST API, a CLI, four SDKs or a hosted MCP server. - Full: https://www.anchorterminal.com/tools/sprites.md (~8,350 tokens) · this version ~1,830 tokens · JSON https://www.anchorterminal.com/tools/sprites.json · canonical https://www.anchorterminal.com/tools/sprites - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-09 **C · 58.3/100 · rank #528 of 842 · #11 in Code execution sandboxes · not agent-ready · confidence medium** Assessment: A Sprite keeps a 100 GB ext4 disk between runs, bills compute only while active and can be checkpointed and restored through a published OpenAPI contract. The status page records four Sprites incidents in the last 90 days, one lasting over seven hours, and outbound network access is unrestricted until a policy is set. ## Facts - Kind: HTTP API · vendor: Fly.io · category: Code execution sandboxes · legal entity: Fly.io, Inc. · provenance 64/100 - Local only (HTTP): npm `@fly/sprites`, pypi `sprites-py` - Auth: API key · pricing: Pay per use · x402: no · licence: Proprietary service under the Fly.io Terms of Service. The JavaScript, Go, Python and Elixir SDKs are MIT - Probe metrics: not measured yet (probes haven't run) - Interfaces: REST API at `https://api.sprites.dev` (OpenAPI 3.1, 44 operations) with WebSocket routes, the `sprite` CLI, SDKs `@fly/sprites` 0.2.3, `sprites-py` 0.7.2, `sprites-go` 0.2.1 and `sprites-ex` 0.2.4, and a hosted MCP server at `https://sprites.dev/mcp` - Isolation: A dedicated, hardware-isolated microVM per Sprite, per the docs - Resources: 8 vCPUs, 100 GB of storage, and memory sized and scaled by the platform. None is configurable - Environment: Ubuntu 25.10 with Node.js, Python, Go, Ruby, Rust, Elixir, Java, Bun, Deno and several coding agent CLIs preinstalled - Lifetime: No stated maximum. Pauses about 30 seconds after activity stops and wakes on an API call or a request to its URL. A task holds it active for up to 1 hour, renewable - Persistence: ext4 filesystem on local NVMe synced to object storage. Memory and processes survive a warm pause and not a cold one. Services restart on wake - Checkpoints: Copy-on-write snapshots of the writable filesystem, manual and automatic, restorable by id. The last five are mounted read-only at `/.sprite/checkpoints/` - Network: Outbound unrestricted by default. An opt-in DNS allowlist, set through the API, blocks raw IP and private ranges once in force - Access from outside: One HTTPS URL per Sprite at `-.sprites.app`, routed to port 8080 and needing an organisation token unless set public. `sprite proxy` forwards any TCP port - Connectors: Third-party credentials held at a gateway, with deny-by-default access by Sprite name prefix or label and optional path allow and block lists - Limits: Sprite creation 10 a minute on pay-as-you-go and 60 to 240 on plans. Hero allows 100 running and 100 warm Sprites, per the product page - Status: status.flyio.net on incident.io, with a Sprites component since 11 February 2026 - SLA and compliance: 99.9 per cent uptime SLA with Enterprise support, from $2,500 a month. SOC 2 Type 2, with a pre-signed DPA and BAA available - Prices: CPU time while active $0.0385 per vCPU-hour; Hot storage while the Sprite is awake $0.50 per GB per month; Cold storage while data is kept $0.02 per GB per month - Scores: Reliability 55, Performance pending, Schema & documentation 74, Agent ergonomics 68, Security & auth 59, Payments & pricing 30, Task success pending, Maintenance & community 80, Transparency & trust 59 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Hosted lines. · Schema & documentation, A public OpenAPI 3.1 document with 44 operations and 59 schemas, plus an AsyncAPI file for the WebSocket calls (25). · Agent ergonomics, List calls take `max_results`, and service logs take `lines` and `duration`. · Security & auth, Bearer tokens are created and removed at sprites.dev/account per organisation, with no scopes found. · Payments & pricing, No x402, MPP or L402 (0). · Maintenance & community, `sprites-py` 0.7.2 on 6 October 2026, 2 days ago, and `@fly/sprites` 0.2.3 on 17 September (30). · Transparency & trust, The SDKs are MIT and the platform is closed under terms of service effective 29 April 2026 (18). - Sources: 41, open questions: 13, both in the full twin - Capabilities: sandbox.code, sandbox.fs, sandbox.persist - JSON: https://www.anchorterminal.com/api/v1/tools/sprites.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/sprites.svg` or a link to https://www.anchorterminal.com/tools/sprites from a page on fly.io or one of its subdomains, or the README of github.com/superfly/sprites-js, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Create a token at sprites.dev/account after a browser signup, and send it as `Authorization: Bearer ` to `https://api.sprites.dev` 2. Follow the OpenAPI document, not the product page example. Create with `POST /v1/sprites` and a JSON `name`, and run commands with `POST /v1/sprites/{name}/exec` using `cmd` query parameters 3. Set a network policy with `POST /v1/sprites/{name}/policy/network` before running untrusted code. Egress is open until one is set 4. Processes started by exec stop on a cold wake. Define a Service for anything that must answer the request that wakes the Sprite 5. Create a checkpoint before a restore. Restoring replaces the filesystem, ends active sessions and keeps no copy of the replaced state 6. Sprite creation is limited to 10 a minute on pay-as-you-go. The Go SDK reads `Retry-After` and the error code `sprite_creation_rate_limited` on a 429 7. Delete Sprites you no longer need. An idle Sprite still bills cold storage for the bytes it holds ## Connect ```bash curl -fsSL https://sprites.dev/install.sh | sh # CLI. SDKs: npm install @fly/sprites, pip install sprites-py ``` ```bash curl -X POST https://api.sprites.dev/v1/sprites -H "Authorization: Bearer $SPRITES_TOKEN" -H "Content-Type: application/json" -d '{"name": "my-sprite"}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/sprites ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Microsoft Execution Containers | BB | 76.3 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/microsoft-execution-containers.min.md | | Modal Sandboxes | BB | 75.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/modal-sandboxes.min.md | | Vercel Sandbox | B | 69.6 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/vercel-sandbox.min.md | | E2B | B | 68.3 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/e2b.min.md | | Cloudflare Sandbox SDK | B | 67.5 | sandbox.code, sandbox.fs, sandbox.persist | https://www.anchorterminal.com/tools/cloudflare-sandbox-sdk.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)