{
  "data": {
    "similar": [
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/baseten.json",
        "name": "Baseten",
        "score": 66.5,
        "shared": [
          "compute.gpu",
          "compute.endpoints",
          "compute.serverless",
          "compute.containers"
        ],
        "slug": "baseten"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/modal.json",
        "name": "Modal",
        "score": 63.6,
        "shared": [
          "compute.gpu",
          "compute.serverless",
          "compute.endpoints",
          "compute.containers"
        ],
        "slug": "modal"
      },
      {
        "grade": "B",
        "json": "https://www.anchorterminal.com/tools/replicate-deploy.json",
        "name": "Replicate Deployments",
        "score": 63.6,
        "shared": [
          "compute.gpu",
          "compute.endpoints",
          "compute.serverless",
          "compute.containers"
        ],
        "slug": "replicate-deploy"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/beam.json",
        "name": "Beam",
        "score": 55.5,
        "shared": [
          "compute.gpu",
          "compute.serverless",
          "compute.endpoints",
          "compute.containers"
        ],
        "slug": "beam"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/cerebrium.json",
        "name": "Cerebrium",
        "score": 55.3,
        "shared": [
          "compute.gpu",
          "compute.serverless",
          "compute.endpoints",
          "compute.containers"
        ],
        "slug": "cerebrium"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/runpod.json",
        "name": "Runpod",
        "score": 53.5,
        "shared": [
          "compute.gpu",
          "compute.serverless",
          "compute.endpoints",
          "compute.containers"
        ],
        "slug": "runpod"
      }
    ],
    "tool": {
      "slug": "vast-ai",
      "name": "Vast.ai",
      "vendor": "Vast.ai Inc.",
      "vendorUrl": "https://vast.ai",
      "kind": "http-api",
      "category": "gpu-compute",
      "summary": "Vast.ai is a marketplace for renting GPUs by the second from independent hosts and data centres, as Docker instances, virtual machines or autoscaling serverless endpoints. Agents use the `vastai` CLI, a Python SDK or a REST API.",
      "url": "https://www.anchorterminal.com/tools/vast-ai",
      "markdownUrl": "https://www.anchorterminal.com/tools/vast-ai.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/vast-ai.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/vast-ai.json",
      "repo": "https://github.com/vast-ai/vast-cli",
      "license": "Proprietary service under Vast.ai's Terms of Use Agreement. The `vastai` CLI and Python SDK on GitHub are MIT",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://console.vast.ai/api/v0",
      "packages": [
        {
          "registry": "pypi",
          "name": "vastai"
        }
      ],
      "auth": "api-key",
      "authNotes": "API key from the console's Keys page, sent as `Authorization: Bearer` to https://console.vast.ai/api/v0, or stored once with `vastai set api-key`. Access is self-serve after a browser signup and email verification. A key has full account access by default. Scoped keys take any of 11 permission categories (`instance_read`, `instance_write`, `billing_write` and others) and constraints that narrow an endpoint to resource IDs. Keys are shown once, and can be reset or deleted with immediate effect. The rate-limit page names an `api_key` query parameter as part of a caller's identity, while the authentication page documents only the header.",
      "pricing": "usage",
      "pricingNotes": "Prepaid credit with a $5 minimum deposit and no free tier or trial found. Each host sets its own rate per listing, so there is no fixed price list. Live rates are public at vast.ai/pricing and through `vastai search offers`. GPU time bills per second while an instance runs, storage per second while it exists (stopped included) and bandwidth per byte. Interruptible rentals are bid-priced and reserved rentals are prepaid for 1, 3 or 6 months. Serverless adds no fee on top of instance rates. Spent credit is not refunded (https://docs.vast.ai/guides/reference/billing.md, https://docs.vast.ai/guides/instances/pricing.md, checked 2026-10-08).",
      "priceSummary": "Pay per use",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs index, llms.txt, the agent pricing page or the OpenAPI file (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 223,
        "npmWeekly": null,
        "pypiWeekly": 32699,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.vast.ai",
      "llmsTxt": "https://docs.vast.ai/llms.txt",
      "openapi": "https://docs.vast.ai/api-reference/openapi.json",
      "capabilities": [
        "compute.gpu",
        "compute.containers",
        "compute.serverless",
        "compute.endpoints"
      ],
      "tags": [
        "hosted",
        "marketplace",
        "usage-priced",
        "prepaid",
        "api-key",
        "scoped-keys",
        "openapi",
        "llms-txt",
        "python",
        "cli",
        "agent-skill",
        "serverless",
        "spot",
        "status-page",
        "soc2"
      ],
      "lastRelease": "2026-10-02",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 62.6,
        "grade": "B",
        "agentReady": false,
        "rank": 331,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 4,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 57,
          "maintenance": 81,
          "payments": 20,
          "reliability": 65,
          "schema": 78,
          "security": 72,
          "transparency": 62
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 65,
            "points": 13,
            "reason": "Graded as a hosted service. status.vast.ai is Vast.ai's own page with three components (vast, console, serverless) and 30-day bars built from roughly hourly checks, with no incident write-ups (20). The raw check logs run from 12 July to 8 October 2026. The console and serverless checks each failed 5 times of 2,000 (3, 4, 5, 7 and 29 August) and the website once, never twice in a row, so we read the record as minor incidents only. The page covers Vast.ai's control plane and not the independent hosts' machines (20). Rate limits are described as a minimum interval per endpoint and identity, but thresholds are unpublished apart from an `x-rateLimit` value on 2 of 89 operations in the OpenAPI file (5 of 15). 429 is documented with backoff advice and the CLI retries it three times, but there is no `Retry-After` header and no idempotency key for instance creation (10 of 15). No SLA found, and the terms say availability is not guaranteed (0). Instances, serverless and the REST API carry no beta label (10)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 78,
            "points": 12.68,
            "reason": "Public OpenAPI 3.1 file with 66 paths and 89 operations, plus the YAML source in the CLI repository (25). llms.txt on both vast.ai and docs.vast.ai, with every docs page served as Markdown (10). Operation descriptions give the matching CLI command and rules such as template precedence, and the SKILL.md files list quirks and common errors, though the API introduction steers most users to the CLI (15 of 20). Request bodies are typed, with 37 enums and required fields marked. Search filters are operator objects and several routes are not REST-shaped, such as PUT /asks/{id}/ to create an instance (10 of 15). Examples on most operations and 400, 401 and 429 responses on most, but the docs say the error body varies by endpoint (11 of 15). Routes are versioned v0 and v1 and the CLI has tagged releases. No API changelog was found in the docs index (7 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 57,
            "points": 9.26,
            "reason": "No MCP server for account actions. The CLI skill file is about 19 KB, `--raw` returns JSON on every command, and the v1 instances route supports column selection (18 of 25). Search takes filter operators, sort fields and a price cap, and v1 instances use keyset pagination with at most 25 a page (16 of 20). The usual error body has `success`, `error` and `msg`, but some endpoints omit fields and 429 is often plain text (10 of 20). No idempotency keys were found in the OpenAPI file. The CLI retries only 429, and `vastai destroy instance` asks for confirmation unless `-y` is passed (5 of 20). Templates supply launch defaults. The only official SDK is Python, and the docs send other languages to raw REST (8 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 72,
            "points": 12.6,
            "reason": "Keys can be scoped to 11 permission categories and narrowed by constraints to resource IDs, are shown once, and can be reset or deleted with immediate effect (30). The rate-limit page names an `api_key` query parameter as part of a caller's identity while the authentication page shows only the Bearer header. We took 5 of the checklist's 10 points for a key that can travel in a URL, a judgement call because the option is acknowledged but not taught (25 of 30). Read-only categories and per-instance constraints exist. The CLI confirms a destroy, and Vast.ai's auth.md asks agents to confirm paid or destructive actions, but nothing on the server enforces approval and default keys have full access (15 of 20). The service runs the customer's own containers and returns their logs (10). `vastai show audit-logs` returns account action history. Its retention and fields were not reviewed (10 of 15). A vulnerability disclosure policy dated 23 July 2025 has safe harbour, triage within 5 business days and a discretionary bounty. Vast.ai states SOC 2 Type 2 with the report under NDA. There is no security.txt and no public advisories were found, and the security FAQ says individual hosts may have less formal security (12 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 20,
            "points": 2.5,
            "reason": "No x402, MPP or L402 found (0). Live per-GPU rates are public without a login at vast.ai/pricing, and billing units (per second for GPU and storage, per byte for bandwidth) are documented. Rates are set per listing by hosts, so there is no fixed list (20). No free tier or trial found. Credit is prepaid with a $5 minimum deposit (0). Signup is a browser flow with email verification. Further keys can be created through the API once an account and key exist (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 81,
            "points": 7.09,
            "reason": "`vastai` 1.8.3 was published to PyPI on 2 October 2026 (30). Twelve tagged releases between 27 July and 2 October 2026 (20). The repository had 54 open issues and pull requests. Of the 30 most recently opened, 22 had no comments, among them issues from June, August and September 2026. Vast.ai lists 24/7 chat support and Discord, which we did not test (10 of 25). The CLI and Python SDK are current and ship together (15). Three CI workflows cover the installer, publishing and SDK tests. An open issue of 6 September 2026 reports hard-pinned dependencies, and we did not check whether CI passes (6 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 62,
            "points": 5.43,
            "note": "editorial 45, provenance 79",
            "reason": "A closed service with an MIT CLI and SDK. The Terms of Use Agreement of 1 September 2026 prohibits scripts and automated access to the services without a separate written agreement, which conflicts with the public API and agent tooling (17 of 30). The compliance page says data is destroyed when an instance is deleted, and the DPA allows return or deletion on written notice within 30 days of termination. The privacy policy of 18 June 2025 is written for website users, gives no retention periods, allows targeted advertising and contains an unfilled `[INSERT HYPERLINK]` placeholder (15 of 30). No deprecation policy was found, and the terms allow changes or discontinuation without notice. v0 and v1 routes coexist (3 of 20). The DPA names five sub-processors without locations and gives new ones only on request. Host location is shown per listing and can be filtered (10 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "No MCP server for account actions. The CLI skill file is about 19 KB, `--raw` returns JSON on every command, and the v1 instances route supports column selection (18 of 25). Search takes filter operators, sort fields and a price cap, and v1 instances use keyset pagination with at most 25 a page (16 of 20). The usual error body has `success`, `error` and `msg`, but some endpoints omit fields and 429 is often plain text (10 of 20). No idempotency keys were found in the OpenAPI file. The CLI retries only 429, and `vastai destroy instance` asks for confirmation unless `-y` is passed (5 of 20). Templates supply launch defaults. The only official SDK is Python, and the docs send other languages to raw REST (8 of 15).",
            "maintenance": "`vastai` 1.8.3 was published to PyPI on 2 October 2026 (30). Twelve tagged releases between 27 July and 2 October 2026 (20). The repository had 54 open issues and pull requests. Of the 30 most recently opened, 22 had no comments, among them issues from June, August and September 2026. Vast.ai lists 24/7 chat support and Discord, which we did not test (10 of 25). The CLI and Python SDK are current and ship together (15). Three CI workflows cover the installer, publishing and SDK tests. An open issue of 6 September 2026 reports hard-pinned dependencies, and we did not check whether CI passes (6 of 10).",
            "payments": "No x402, MPP or L402 found (0). Live per-GPU rates are public without a login at vast.ai/pricing, and billing units (per second for GPU and storage, per byte for bandwidth) are documented. Rates are set per listing by hosts, so there is no fixed list (20). No free tier or trial found. Credit is prepaid with a $5 minimum deposit (0). Signup is a browser flow with email verification. Further keys can be created through the API once an account and key exist (0).",
            "reliability": "Graded as a hosted service. status.vast.ai is Vast.ai's own page with three components (vast, console, serverless) and 30-day bars built from roughly hourly checks, with no incident write-ups (20). The raw check logs run from 12 July to 8 October 2026. The console and serverless checks each failed 5 times of 2,000 (3, 4, 5, 7 and 29 August) and the website once, never twice in a row, so we read the record as minor incidents only. The page covers Vast.ai's control plane and not the independent hosts' machines (20). Rate limits are described as a minimum interval per endpoint and identity, but thresholds are unpublished apart from an `x-rateLimit` value on 2 of 89 operations in the OpenAPI file (5 of 15). 429 is documented with backoff advice and the CLI retries it three times, but there is no `Retry-After` header and no idempotency key for instance creation (10 of 15). No SLA found, and the terms say availability is not guaranteed (0). Instances, serverless and the REST API carry no beta label (10).",
            "schema": "Public OpenAPI 3.1 file with 66 paths and 89 operations, plus the YAML source in the CLI repository (25). llms.txt on both vast.ai and docs.vast.ai, with every docs page served as Markdown (10). Operation descriptions give the matching CLI command and rules such as template precedence, and the SKILL.md files list quirks and common errors, though the API introduction steers most users to the CLI (15 of 20). Request bodies are typed, with 37 enums and required fields marked. Search filters are operator objects and several routes are not REST-shaped, such as PUT /asks/{id}/ to create an instance (10 of 15). Examples on most operations and 400, 401 and 429 responses on most, but the docs say the error body varies by endpoint (11 of 15). Routes are versioned v0 and v1 and the CLI has tagged releases. No API changelog was found in the docs index (7 of 15).",
            "security": "Keys can be scoped to 11 permission categories and narrowed by constraints to resource IDs, are shown once, and can be reset or deleted with immediate effect (30). The rate-limit page names an `api_key` query parameter as part of a caller's identity while the authentication page shows only the Bearer header. We took 5 of the checklist's 10 points for a key that can travel in a URL, a judgement call because the option is acknowledged but not taught (25 of 30). Read-only categories and per-instance constraints exist. The CLI confirms a destroy, and Vast.ai's auth.md asks agents to confirm paid or destructive actions, but nothing on the server enforces approval and default keys have full access (15 of 20). The service runs the customer's own containers and returns their logs (10). `vastai show audit-logs` returns account action history. Its retention and fields were not reviewed (10 of 15). A vulnerability disclosure policy dated 23 July 2025 has safe harbour, triage within 5 business days and a discretionary bounty. Vast.ai states SOC 2 Type 2 with the report under NDA. There is no security.txt and no public advisories were found, and the security FAQ says individual hosts may have less formal security (12 of 20).",
            "transparency": "A closed service with an MIT CLI and SDK. The Terms of Use Agreement of 1 September 2026 prohibits scripts and automated access to the services without a separate written agreement, which conflicts with the public API and agent tooling (17 of 30). The compliance page says data is destroyed when an instance is deleted, and the DPA allows return or deletion on written notice within 30 days of termination. The privacy policy of 18 June 2025 is written for website users, gives no retention periods, allows targeted advertising and contains an unfilled `[INSERT HYPERLINK]` placeholder (15 of 30). No deprecation policy was found, and the terms allow changes or discontinuation without notice. v0 and v1 routes coexist (3 of 20). The DPA names five sub-processors without locations and gives new ones only on request. Host location is shown per listing and can be filtered (10 of 20)."
          },
          "sources": [
            {
              "what": "docs index",
              "url": "https://docs.vast.ai/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "site llms.txt and agent files",
              "url": "https://vast.ai/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI file",
              "url": "https://docs.vast.ai/api-reference/openapi.json",
              "seen": "2026-10-08"
            },
            {
              "what": "API introduction",
              "url": "https://docs.vast.ai/api-reference/introduction.md",
              "seen": "2026-10-08"
            },
            {
              "what": "authentication",
              "url": "https://docs.vast.ai/api-reference/authentication.md",
              "seen": "2026-10-08"
            },
            {
              "what": "API key management",
              "url": "https://docs.vast.ai/guides/reference/api-keys.md",
              "seen": "2026-10-08"
            },
            {
              "what": "permissions",
              "url": "https://docs.vast.ai/api-reference/permissions-and-authorization.md",
              "seen": "2026-10-08"
            },
            {
              "what": "rate limits and errors",
              "url": "https://docs.vast.ai/api-reference/rate-limits-and-errors.md",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI rate limits and retries",
              "url": "https://docs.vast.ai/cli/rate-limits.md",
              "seen": "2026-10-08"
            },
            {
              "what": "agents guide",
              "url": "https://docs.vast.ai/guides/get-started/agents.md",
              "seen": "2026-10-08"
            },
            {
              "what": "billing",
              "url": "https://docs.vast.ai/guides/reference/billing.md",
              "seen": "2026-10-08"
            },
            {
              "what": "instance pricing",
              "url": "https://docs.vast.ai/guides/instances/pricing.md",
              "seen": "2026-10-08"
            },
            {
              "what": "serverless pricing",
              "url": "https://docs.vast.ai/guides/serverless/pricing.md",
              "seen": "2026-10-08"
            },
            {
              "what": "serverless quickstart",
              "url": "https://docs.vast.ai/guides/serverless/quickstart.md",
              "seen": "2026-10-08"
            },
            {
              "what": "serverless endpoint parameters",
              "url": "https://docs.vast.ai/guides/serverless/serverless-parameters.md",
              "seen": "2026-10-08"
            },
            {
              "what": "quickstart and minimum deposit",
              "url": "https://docs.vast.ai/guides/get-started/quickstart.md",
              "seen": "2026-10-08"
            },
            {
              "what": "security FAQ",
              "url": "https://docs.vast.ai/guides/reference/faq/security.md",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing page",
              "url": "https://vast.ai/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing for agents",
              "url": "https://vast.ai/pricing.md",
              "seen": "2026-10-08"
            },
            {
              "what": "auth for agents",
              "url": "https://vast.ai/auth.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server card",
              "url": "https://vast.ai/.well-known/mcp/server-card.json",
              "seen": "2026-10-08"
            },
            {
              "what": "status page",
              "url": "https://status.vast.ai",
              "seen": "2026-10-08"
            },
            {
              "what": "status check log, console",
              "url": "https://status.vast.ai/logs/console_report.log",
              "seen": "2026-10-08"
            },
            {
              "what": "terms",
              "url": "https://vast.ai/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://vast.ai/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "data processing agreement",
              "url": "https://vast.ai/data-processing-agreement",
              "seen": "2026-10-08"
            },
            {
              "what": "compliance",
              "url": "https://vast.ai/compliance",
              "seen": "2026-10-08"
            },
            {
              "what": "vulnerability disclosure policy",
              "url": "https://vast.ai/vulnerability-disclosure-policy",
              "seen": "2026-10-08"
            },
            {
              "what": "security.txt (404)",
              "url": "https://vast.ai/.well-known/security.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI and SDK repository, tags and skill file",
              "url": "https://github.com/vast-ai/vast-cli",
              "seen": "2026-10-08"
            },
            {
              "what": "open issues and pull requests",
              "url": "https://api.github.com/repos/vast-ai/vast-cli/issues?state=open\u0026per_page=30",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI package",
              "url": "https://pypi.org/pypi/vastai/json",
              "seen": "2026-10-08"
            },
            {
              "what": "PyPI downloads",
              "url": "https://pypistats.org/api/packages/vastai/recent",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.org/domain/vast.ai",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "unchecked: per-GPU prices. The pricing page loads rates with JavaScript, and the public JSON feed's terms ask for a data licence before use in any index or benchmark, so we did not read it and recorded no unit prices.",
            "unchecked: whether CI passes on the default branch, and the retention and fields of the account audit log.",
            "unchecked: response times on live chat and Discord.",
            "The terms of 1 September 2026 prohibit scripts and automated access to the services without a separate written agreement. We could not establish whether Vast.ai treats the published API, CLI and agent skills as that authorisation.",
            "Whether the REST API still accepts the key as an `api_key` query parameter is not stated on the authentication page; the rate-limit page implies it.",
            "The lead's interface (CLI, Python SDK, REST API, serverless endpoints) was correct. The MCP server Vast.ai lists is documentation only."
          ]
        },
        "negative": 0,
        "verdict": "API keys can be limited by permission category and by resource ID, the REST API has a public OpenAPI 3.1 file, and the CLI ships weekly with a skill file for coding agents. Machines belong to independent hosts, prices move with the market, rate-limit thresholds are unpublished, and there is no SLA or free tier.",
        "bestFor": "Cost-sensitive training, batch work and self-managed inference where the agent can search listings, set a price cap and tolerate host variance or interruption.",
        "strengths": [
          "API keys take 11 permission categories and per-endpoint constraints on resource IDs, and can be reset or deleted at once",
          "Public OpenAPI 3.1 file with 89 operations, llms.txt and Markdown docs pages",
          "MIT CLI and Python SDK, v1.8.3 on 2 October 2026, with 12 tagged releases since 27 July 2026",
          "Per-second billing, with serverless workers charged at the same rates as rented instances",
          "Vulnerability disclosure policy with safe harbour and triage within 5 business days, and an account audit log from the CLI"
        ],
        "weaknesses": [
          "No SLA. The terms say availability is not guaranteed and the service can change without notice",
          "Rate-limit thresholds are unpublished and 429 responses carry no `Retry-After` header",
          "No free tier. Credit is prepaid with a $5 minimum deposit after a browser signup and email verification",
          "Hosts are independent. The security FAQ says individual hosts may have less formal security than Secure Cloud data centres",
          "The terms of 1 September 2026 prohibit scripts and automated access to the services without a separate written agreement, which conflicts with the public API"
        ],
        "agentNotes": [
          "Create a scoped key with `vastai create api-key --permissions` for the agent. A default key has full account access, billing and key management included",
          "Pass `--raw` on every CLI command for JSON output, and `-y` on `vastai destroy instance`, which otherwise waits for a confirmation prompt",
          "Register an SSH key with `vastai create ssh-key` before creating an instance, or the host is unreachable",
          "Destroy instances when finished. A stopped instance still bills storage, and a zero balance without a saved card leads to deletion",
          "Back off on HTTP 429 yourself when calling REST directly. The CLI retries 429 three times from 0.15 seconds",
          "Filter searches with `verified=true` or the Secure Cloud option for sensitive data, and set a `dph_total` price cap"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "B",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 62.6
          }
        ],
        "editorialScores": {
          "ergonomics": 57,
          "maintenance": 81,
          "payments": 20,
          "reliability": 65,
          "schema": 78,
          "security": 72,
          "transparency": 45
        },
        "provenanceScore": 79
      },
      "connect": {
        "install": "pip install vastai",
        "http": "curl -s -H \"Authorization: Bearer $VAST_API_KEY\" \\\n  \"https://console.vast.ai/api/v0/users/current/\"",
        "claudeCode": "/plugin marketplace add vast-ai/vast-claude-plugin\n/plugin install vastai"
      },
      "letme": {
        "capability": "https://letme.dev/compute.gpu",
        "tool": "https://letme.dev/vast-ai"
      },
      "notable": [
        "Vast.ai publishes agent discovery files: llms.txt, an API catalogue (https://vast.ai/.well-known/api-catalog), auth.md and pricing.md for agents, and SKILL.md files for the CLI and SDK (https://vast.ai/llms.txt)",
        "Plugins for Claude Code, Codex and Cursor bundle a renter skill and a host skill, and every Vast image places an AGENTS.md and CLAUDE.md on the instance (https://docs.vast.ai/guides/get-started/agents.md)",
        "The only MCP server Vast.ai lists is a read-only documentation server hosted by Mintlify with no auth. Account actions go through the CLI, SDK or REST API (https://vast.ai/.well-known/mcp/server-card.json)",
        "Serverless bills GPU time only while a worker is Ready or Loading. Storage and bandwidth bill in every worker state until the endpoint is destroyed (https://docs.vast.ai/guides/serverless/pricing.md)",
        "The API returns 429 without a `Retry-After` header, and rate limits are a minimum interval per endpoint and identity with no thresholds published (https://docs.vast.ai/api-reference/rate-limits-and-errors.md)",
        "status.vast.ai tracks three components by roughly hourly checks. From 12 July to 8 October 2026 the console and serverless checks each failed 5 times of 2,000, none consecutive (https://status.vast.ai)",
        "The terms of 1 September 2026 list any script or automated method of accessing the website or services as prohibited unless a separate written agreement allows it (https://vast.ai/terms)",
        "The pricing feed's terms ask for a data licence before use in an index or benchmark, so no unit prices from it are recorded here (https://vast.ai/pricing.md)"
      ],
      "area": "models",
      "details": [
        {
          "label": "Interfaces",
          "value": "`vastai` CLI and Python SDK in one PyPI package (Python 3.10 or later), REST API at https://console.vast.ai/api/v0 with some v1 routes, serverless routing at run.vast.ai"
        },
        {
          "label": "Rental types",
          "value": "On-demand, interruptible (bid-priced, can be paused) and reserved (prepaid, 1, 3 or 6 month terms, up to 50 per cent off per Vast.ai)"
        },
        {
          "label": "Billing",
          "value": "Prepaid credit, $5 minimum deposit. GPU time per second while running, storage per second while the instance exists, bandwidth per byte. Rates are set per listing by the host"
        },
        {
          "label": "Free tier",
          "value": "None found. Cards through Stripe, crypto through BitPay and Crypto.com. Spent credit is not refunded"
        },
        {
          "label": "Serverless",
          "value": "Endpoints with worker groups recruited from the marketplace, scaled by load. Defaults are `max_workers` 16, `min_workers` 5, `min_load` 1 and `target_util` 0.9. No fee on top of instance rates"
        },
        {
          "label": "Cold start",
          "value": "The serverless quickstart says to expect 3 to 5 minutes before first workers are ready. Cold workers keep the model on disk and bill storage only"
        },
        {
          "label": "API keys",
          "value": "Full access by default. Scoped keys take 11 permission categories and constraints with `eq`, `lte` and `gte` on parameters such as an instance ID. Reset has no overlap window"
        },
        {
          "label": "Rate limits",
          "value": "Minimum interval per endpoint and identity, some per method or per burst. Thresholds unpublished. 429 has no `Retry-After`. The CLI retries 429 three times, 0.15 s then 1.5 times longer each attempt"
        },
        {
          "label": "Security tiers",
          "value": "Verified hosts with Docker isolation, or Secure Cloud data centres vetted by Vast.ai. Certification such as ISO 27001 is encouraged for partners but not strictly required, per the compliance page"
        },
        {
          "label": "Compliance",
          "value": "Vast.ai states SOC 2 Type 2 (report under NDA), SOC 3 on request and HIPAA support with BAAs on Secure Cloud"
        },
        {
          "label": "Status page",
          "value": "status.vast.ai, own page, three components (vast, console, serverless), 30-day bars from roughly hourly checks, no incident write-ups"
        },
        {
          "label": "Agent tooling",
          "value": "`npx skills add vast-ai/vast-cli --skill vastai`, plugins for Claude Code, Codex and Cursor, AGENTS.md on every Vast image"
        }
      ],
      "provenance": {
        "legalEntity": "Vast.ai Inc.",
        "domain": "vast.ai",
        "domainRegistered": "2017-12-16",
        "endpointOnVendorDomain": true,
        "terms": "https://vast.ai/terms",
        "privacy": "https://vast.ai/privacy",
        "statusPage": "https://status.vast.ai",
        "changelog": "https://github.com/vast-ai/vast-cli/releases",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The Terms of Use Agreement, version date 1 September 2026, names Vast.ai Inc. and its affiliates, covers the website and the rental service, and is governed by California law with JAMS arbitration in the Los Angeles area.",
          "The privacy policy, version date 18 June 2025, names Vast.ai Inc. and a Privacy Officer at contact@vast.ai. It is written for users of the website and contains an unfilled `[INSERT HYPERLINK]` placeholder.",
          "A Data Processing Agreement at vast.ai/data-processing-agreement forms part of the terms, with standard contractual clauses and five named sub-processors (Stripe, Google, Meta, Twitter, Microsoft).",
          "The REST API answers at console.vast.ai and serverless routing at run.vast.ai, both on the vendor's domain. Rented machines belong to independent hosts.",
          "vast.ai/.well-known/security.txt returns 404. A vulnerability disclosure policy dated 23 July 2025 at vast.ai/vulnerability-disclosure-policy sends reports to security@vast.ai.",
          "No API changelog was found in the docs index. The changelog link is the CLI and SDK repository's release list, which has no CHANGELOG file.",
          "RDAP for vast.ai gives a registration date of 2017-12-16."
        ],
        "score": 79,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Vast.ai Inc.",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "vast.ai, registered 2017-12-16 (8 years)",
            "points": 11,
            "max": 15,
            "state": "part"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "console.vast.ai",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points",
            "points": 3.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 8 of the 8 things a reader expects",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Status page",
            "value": "status.vast.ai",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "Changelog",
            "value": "published",
            "points": 10,
            "max": 10,
            "state": "ok"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://vast.ai/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-01",
            "words": 7940,
            "points": 3.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Version Date: September 1, 2026",
                "says": "Last updated 2026-09-01"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "With Company With respect to any dispute regarding the Website, Privacy Policy or these Terms, all rights and obligations and all actions concerning these Terms, shall be governed by the laws of California, as if these Terms were a contract wholly entered into and wholly performed within California.",
                "says": "The law of California"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "…LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE AMOUNT PAID, IF ANY, BY YOU TO COMPANY FOR THE APPLICABLE SERVICES DURING THE PERIOD OF THREE (3) MONTHS PRIOR TO ANY CAUSE OF ACTION ARISING.",
                "says": "Capped at the fees paid in the 3 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "Vast.ai may suspend or terminate the Services immediately upon notice if it reasonably believes a transaction violates Export Control Laws."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": true,
                "quote": "We will alert you regarding any changes by updating the “Last updated” date of this Agreement, and you waive any right to receive specific notice of each such change.",
                "says": "Says it gives notice of a change"
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "IF YOU DO NOT AGREE TO BE SO BOUND, YOU MAY NOT ACCESS OR USE THE WEBSITE OR ANY COMPANY SERVICES."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": false
              }
            ],
            "toKnow": [
              {
                "key": "terms.automated",
                "label": "Restricts automated access",
                "found": true,
                "quote": "Making any unauthorized use of the Company Services, including collecting usernames and/or email addresses of users by electronic or other means for the purpose of sending unsolicited email, or creating user accounts by automated means or under false pretenses.",
                "costsPoints": true
              },
              {
                "key": "terms.benchmark",
                "label": "Restricts benchmarking or competitive use",
                "found": true,
                "quote": "…maintain, or compile, directly or indirectly, a collection, compilation, database, dataset, index, benchmark, or directory without written permission from Company.",
                "costsPoints": true
              },
              {
                "key": "terms.nonotice",
                "label": "Says the terms or the service can change without notice",
                "found": true,
                "quote": "Company reserves the right at any time to change, revise, update, suspend, discontinue, or otherwise modify the Website or the offerings at any time or for any reason without notice to you.",
                "costsPoints": true
              },
              {
                "key": "terms.cutoff",
                "label": "Says access can be ended without notice or for any reason",
                "found": true,
                "quote": "COMPANY RESERVES THE RIGHT TO, IN COMPANY’S SOLE DISCRETION AND WITHOUT NOTICE OR LIABILITY, DENY ACCESS TO AND USE OF THE WEBSITE AND THE COMPANY SERVICES, TO ANY PERSON FOR ANY REASON OR FOR NO REASON AT ALL"
              },
              {
                "key": "terms.arbitration",
                "label": "Requires arbitration or waives class actions",
                "found": true,
                "quote": "YOU AGREE THAT ANY CLAIMS YOU MAY HAVE AGAINST US RELATING TO THE WEBSITE OR THE COMPANY SERVICES, THIS AGREEMENT OR ANY TERMS AND CONDITIONS CONTAINED HEREIN MUST BE ARBITRATED, AND YOU EXPRESSLY WAIVE THE RIGHT TO (1) ASSERT CLAIMS AGAINST US IN COURT;"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Liability for any cause is limited to the amount paid for the applicable services in the three months before the claim arose.",
                "quote": "COMPANY’S LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE AMOUNT PAID, IF ANY, BY YOU TO COMPANY FOR THE APPLICABLE SERVICES DURING THE PERIOD OF THREE (3) MONTHS PRIOR TO ANY CAUSE OF ACTION ARISING."
              },
              {
                "date": "2026-10-08",
                "text": "Vast.ai reserves the right to change credit pricing and to cause purchased credits to expire, and says payments for spent credits are final.",
                "quote": "We reserve the right to change credit pricing, run promotions and cause credits to expire."
              },
              {
                "date": "2026-10-08",
                "text": "Any claim arising from use of the website, the services or the agreement must be filed within one year or it is barred.",
                "quote": "ANY CLAIM OR CAUSE OF ACTION ARISING OUT OF OR RELATED TO USE OF THE WEBSITE, COMPANY SERVICES, OR THE AGREEMENT MUST BE FILED WITHIN ONE (1) YEAR AFTER SUCH CLAIM OR CAUSE OF ACTION ARISES OR IT WILL BE FOREVER BARRED."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://vast.ai/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2025-06-18",
            "words": 6057,
            "points": 10,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "Version Date: June 18, 2025",
                "says": "Last updated 2025-06-18"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "Aggregated and Non-Personally-Identifying Information We may share aggregated and Non-Personally Identifying Information we collect under any of the above circumstances."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "We will retain your Personal Data for as long as you have an account or profile with us.",
                "says": "For as long as needed, with no period named"
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "Although such information is not Personally-Identifying Information, it may be possible for Company to determine from an IP address a user’s Internet service provider and the"
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We may also share it with third parties and our affiliate companies to develop and deliver targeted advertising on the Website and on websites of third parties."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": true,
                "quote": "…Your Information You may have certain rights under applicable data protection laws, including the right to access and update your Personal Data, restrict how it is used, transfer certain Personal Data to another controller, withdraw your consent at any time, and the right to have us erase certain Personal Data about y…"
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "Data Controller, Data Protection Officer, and Representative Vast.ai is the data controller of the Personal Data you provide on or through our Site.",
                "says": "Names a data protection officer"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": true,
                "quote": "To ensure your Personal Data is treated in accordance with this Privacy Notice, we use Data Protection Agreements between us and other recipients of your data that include, where applicable, the Standard Contractual Clauses adopted by the European Commission (the “Standard Contractual Clauses”).",
                "says": "Relies on standard contractual clauses"
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Online data partners may use cookies to link a visit or login to other personal information they hold, including an email address, which Vast.ai may then use for marketing.",
                "quote": "When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including your email."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/vast-ai.json",
      "live": {
        "slug": "vast-ai",
        "probe": {
          "target": "https://console.vast.ai/api/v0",
          "method": "get",
          "lastAt": "2026-10-08T19:53:05.315409291Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 341,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 340,
          "p95ms24h": 407,
          "samples24h": 27,
          "samples30d": 27,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 27,
              "ok": 27
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.vast.ai",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T19:39:18.949416936Z"
        },
        "pages": [
          {
            "url": "https://docs.vast.ai/guides/instances/pricing.md",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:43.22968168Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "7cd305f9206a"
          },
          {
            "url": "https://vast.ai/privacy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:30.293684318Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "afe890f5aa20"
          },
          {
            "url": "https://vast.ai/terms",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:25:32.570996649Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "652ca94c3dd7"
          }
        ],
        "updatedAt": "2026-10-08T19:53:05.315409291Z"
      }
    },
    "verify": {
      "accepts": "a page on vast.ai or one of its subdomains, or the README of github.com/vast-ai/vast-cli",
      "badgeUrl": "https://www.anchorterminal.com/badges/vast-ai.svg",
      "body": {
        "slug": "vast-ai",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/vast-ai",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/vast-ai\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/vast-ai.svg\" alt=\"Vast.ai on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![Vast.ai on Anchor Terminal](https://www.anchorterminal.com/badges/vast-ai.svg)](https://www.anchorterminal.com/tools/vast-ai)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/vast-ai\"\u003eVast.ai on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/vast-ai",
    "json": "https://www.anchorterminal.com/tools/vast-ai.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/vast-ai.md",
    "slim": "https://www.anchorterminal.com/tools/vast-ai.min.md"
  },
  "markdown": "## Overview\n\n**Grade B · 62.6/100 · rank #331 of 722 · #4 in GPU \u0026 serverless compute · not agent-ready · confidence medium**\n\n\n## Assessment\n\nAPI keys can be limited by permission category and by resource ID, the REST API has a public OpenAPI 3.1 file, and the CLI ships weekly with a skill file for coding agents. Machines belong to independent hosts, prices move with the market, rate-limit thresholds are unpublished, and there is no SLA or free tier.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Vast.ai Inc. (https://vast.ai) |\n| Kind | HTTP API |\n| Category | GPU \u0026 serverless compute (https://www.anchorterminal.com/categories/gpu-compute) |\n| Transport | HTTP |\n| Endpoint | `https://console.vast.ai/api/v0` |\n| Auth | API key · API key from the console's Keys page, sent as `Authorization: Bearer` to https://console.vast.ai/api/v0, or stored once with `vastai set api-key`. Access is self-serve after a browser signup and email verification. A key has full account access by default. Scoped keys take any of 11 permission categories (`instance_read`, `instance_write`, `billing_write` and others) and constraints that narrow an endpoint to resource IDs. Keys are shown once, and can be reset or deleted with immediate effect. The rate-limit page names an `api_key` query parameter as part of a caller's identity, while the authentication page documents only the header. |\n| Pricing | Pay per use (Pay per use) · Prepaid credit with a $5 minimum deposit and no free tier or trial found. Each host sets its own rate per listing, so there is no fixed price list. Live rates are public at vast.ai/pricing and through `vastai search offers`. GPU time bills per second while an instance runs, storage per second while it exists (stopped included) and bandwidth per byte. Interruptible rentals are bid-priced and reserved rentals are prepaid for 1, 3 or 6 months. Serverless adds no fee on top of instance rates. Spent credit is not refunded (https://docs.vast.ai/guides/reference/billing.md, https://docs.vast.ai/guides/instances/pricing.md, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs index, llms.txt, the agent pricing page or the OpenAPI file (checked 2026-10-08). |\n| Licence | Proprietary service under Vast.ai's Terms of Use Agreement. The `vastai` CLI and Python SDK on GitHub are MIT |\n| Packages | pypi: `vastai` |\n| Source | https://github.com/vast-ai/vast-cli |\n| Docs | https://docs.vast.ai |\n| llms.txt | https://docs.vast.ai/llms.txt |\n| Last release | 2026-10-02 |\n| GitHub stars | 223 (as of 2026-10-08) |\n| PyPI downloads / week | 32,699 |\n| Interfaces | `vastai` CLI and Python SDK in one PyPI package (Python 3.10 or later), REST API at https://console.vast.ai/api/v0 with some v1 routes, serverless routing at run.vast.ai |\n| Rental types | On-demand, interruptible (bid-priced, can be paused) and reserved (prepaid, 1, 3 or 6 month terms, up to 50 per cent off per Vast.ai) |\n| Billing | Prepaid credit, $5 minimum deposit. GPU time per second while running, storage per second while the instance exists, bandwidth per byte. Rates are set per listing by the host |\n| Free tier | None found. Cards through Stripe, crypto through BitPay and Crypto.com. Spent credit is not refunded |\n| Serverless | Endpoints with worker groups recruited from the marketplace, scaled by load. Defaults are `max_workers` 16, `min_workers` 5, `min_load` 1 and `target_util` 0.9. No fee on top of instance rates |\n| Cold start | The serverless quickstart says to expect 3 to 5 minutes before first workers are ready. Cold workers keep the model on disk and bill storage only |\n| API keys | Full access by default. Scoped keys take 11 permission categories and constraints with `eq`, `lte` and `gte` on parameters such as an instance ID. Reset has no overlap window |\n| Rate limits | Minimum interval per endpoint and identity, some per method or per burst. Thresholds unpublished. 429 has no `Retry-After`. The CLI retries 429 three times, 0.15 s then 1.5 times longer each attempt |\n| Security tiers | Verified hosts with Docker isolation, or Secure Cloud data centres vetted by Vast.ai. Certification such as ISO 27001 is encouraged for partners but not strictly required, per the compliance page |\n| Compliance | Vast.ai states SOC 2 Type 2 (report under NDA), SOC 3 on request and HIPAA support with BAAs on Secure Cloud |\n| Status page | status.vast.ai, own page, three components (vast, console, serverless), 30-day bars from roughly hourly checks, no incident write-ups |\n| Agent tooling | `npx skills add vast-ai/vast-cli --skill vastai`, plugins for Claude Code, Codex and Cursor, AGENTS.md on every Vast image |\n| Capabilities | compute.gpu, compute.containers, compute.serverless, compute.endpoints |\n| Tags | hosted, marketplace, usage-priced, prepaid, api-key, scoped-keys, openapi, llms-txt, python, cli, agent-skill, serverless, spot, status-page, soc2 |\n| JSON | https://www.anchorterminal.com/api/v1/tools/vast-ai.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 65 | 13.0 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 78 | 12.7 |\n| Agent ergonomics | 13% | 16.2 | 57 | 9.3 |\n| Security \u0026 auth | 14% | 17.5 | 72 | 12.6 |\n| Payments \u0026 pricing | 10% | 12.5 | 20 | 2.5 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 81 | 7.1 |\n| Transparency \u0026 trust (editorial 45, provenance 79) | 7% | 8.8 | 62 | 5.4 |\n| Negative events | up to −15 | up to −15 | none recorded | 0 |\n| **Total** | | | | **62.6 → B** |\n\n### Why each score\n\n- Reliability 65: Graded as a hosted service. status.vast.ai is Vast.ai's own page with three components (vast, console, serverless) and 30-day bars built from roughly hourly checks, with no incident write-ups (20). The raw check logs run from 12 July to 8 October 2026. The console and serverless checks each failed 5 times of 2,000 (3, 4, 5, 7 and 29 August) and the website once, never twice in a row, so we read the record as minor incidents only. The page covers Vast.ai's control plane and not the independent hosts' machines (20). Rate limits are described as a minimum interval per endpoint and identity, but thresholds are unpublished apart from an `x-rateLimit` value on 2 of 89 operations in the OpenAPI file (5 of 15). 429 is documented with backoff advice and the CLI retries it three times, but there is no `Retry-After` header and no idempotency key for instance creation (10 of 15). No SLA found, and the terms say availability is not guaranteed (0). Instances, serverless and the REST API carry no beta label (10).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 78: Public OpenAPI 3.1 file with 66 paths and 89 operations, plus the YAML source in the CLI repository (25). llms.txt on both vast.ai and docs.vast.ai, with every docs page served as Markdown (10). Operation descriptions give the matching CLI command and rules such as template precedence, and the SKILL.md files list quirks and common errors, though the API introduction steers most users to the CLI (15 of 20). Request bodies are typed, with 37 enums and required fields marked. Search filters are operator objects and several routes are not REST-shaped, such as PUT /asks/{id}/ to create an instance (10 of 15). Examples on most operations and 400, 401 and 429 responses on most, but the docs say the error body varies by endpoint (11 of 15). Routes are versioned v0 and v1 and the CLI has tagged releases. No API changelog was found in the docs index (7 of 15).\n- Agent ergonomics 57: No MCP server for account actions. The CLI skill file is about 19 KB, `--raw` returns JSON on every command, and the v1 instances route supports column selection (18 of 25). Search takes filter operators, sort fields and a price cap, and v1 instances use keyset pagination with at most 25 a page (16 of 20). The usual error body has `success`, `error` and `msg`, but some endpoints omit fields and 429 is often plain text (10 of 20). No idempotency keys were found in the OpenAPI file. The CLI retries only 429, and `vastai destroy instance` asks for confirmation unless `-y` is passed (5 of 20). Templates supply launch defaults. The only official SDK is Python, and the docs send other languages to raw REST (8 of 15).\n- Security \u0026 auth 72: Keys can be scoped to 11 permission categories and narrowed by constraints to resource IDs, are shown once, and can be reset or deleted with immediate effect (30). The rate-limit page names an `api_key` query parameter as part of a caller's identity while the authentication page shows only the Bearer header. We took 5 of the checklist's 10 points for a key that can travel in a URL, a judgement call because the option is acknowledged but not taught (25 of 30). Read-only categories and per-instance constraints exist. The CLI confirms a destroy, and Vast.ai's auth.md asks agents to confirm paid or destructive actions, but nothing on the server enforces approval and default keys have full access (15 of 20). The service runs the customer's own containers and returns their logs (10). `vastai show audit-logs` returns account action history. Its retention and fields were not reviewed (10 of 15). A vulnerability disclosure policy dated 23 July 2025 has safe harbour, triage within 5 business days and a discretionary bounty. Vast.ai states SOC 2 Type 2 with the report under NDA. There is no security.txt and no public advisories were found, and the security FAQ says individual hosts may have less formal security (12 of 20).\n- Payments \u0026 pricing 20: No x402, MPP or L402 found (0). Live per-GPU rates are public without a login at vast.ai/pricing, and billing units (per second for GPU and storage, per byte for bandwidth) are documented. Rates are set per listing by hosts, so there is no fixed list (20). No free tier or trial found. Credit is prepaid with a $5 minimum deposit (0). Signup is a browser flow with email verification. Further keys can be created through the API once an account and key exist (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 81: `vastai` 1.8.3 was published to PyPI on 2 October 2026 (30). Twelve tagged releases between 27 July and 2 October 2026 (20). The repository had 54 open issues and pull requests. Of the 30 most recently opened, 22 had no comments, among them issues from June, August and September 2026. Vast.ai lists 24/7 chat support and Discord, which we did not test (10 of 25). The CLI and Python SDK are current and ship together (15). Three CI workflows cover the installer, publishing and SDK tests. An open issue of 6 September 2026 reports hard-pinned dependencies, and we did not check whether CI passes (6 of 10).\n- Transparency \u0026 trust 62: A closed service with an MIT CLI and SDK. The Terms of Use Agreement of 1 September 2026 prohibits scripts and automated access to the services without a separate written agreement, which conflicts with the public API and agent tooling (17 of 30). The compliance page says data is destroyed when an instance is deleted, and the DPA allows return or deletion on written notice within 30 days of termination. The privacy policy of 18 June 2025 is written for website users, gives no retention periods, allows targeted advertising and contains an unfilled `[INSERT HYPERLINK]` placeholder (15 of 30). No deprecation policy was found, and the terms allow changes or discontinuation without notice. v0 and v1 routes coexist (3 of 20). The DPA names five sub-processors without locations and gives new ones only on request. Host location is shown per listing and can be filtered (10 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/vast-ai.md (JSON https://www.anchorterminal.com/fixes/vast-ai.json)\n\n### What we couldn't check\n\n- unchecked: per-GPU prices. The pricing page loads rates with JavaScript, and the public JSON feed's terms ask for a data licence before use in any index or benchmark, so we did not read it and recorded no unit prices.\n- unchecked: whether CI passes on the default branch, and the retention and fields of the account audit log.\n- unchecked: response times on live chat and Discord.\n- The terms of 1 September 2026 prohibit scripts and automated access to the services without a separate written agreement. We could not establish whether Vast.ai treats the published API, CLI and agent skills as that authorisation.\n- Whether the REST API still accepts the key as an `api_key` query parameter is not stated on the authentication page; the rate-limit page implies it.\n- The lead's interface (CLI, Python SDK, REST API, serverless endpoints) was correct. The MCP server Vast.ai lists is documentation only.\n\n### Sources\n\n- docs index: \u003chttps://docs.vast.ai/llms.txt\u003e (seen 2026-10-08)\n- site llms.txt and agent files: \u003chttps://vast.ai/llms.txt\u003e (seen 2026-10-08)\n- OpenAPI file: \u003chttps://docs.vast.ai/api-reference/openapi.json\u003e (seen 2026-10-08)\n- API introduction: \u003chttps://docs.vast.ai/api-reference/introduction.md\u003e (seen 2026-10-08)\n- authentication: \u003chttps://docs.vast.ai/api-reference/authentication.md\u003e (seen 2026-10-08)\n- API key management: \u003chttps://docs.vast.ai/guides/reference/api-keys.md\u003e (seen 2026-10-08)\n- permissions: \u003chttps://docs.vast.ai/api-reference/permissions-and-authorization.md\u003e (seen 2026-10-08)\n- rate limits and errors: \u003chttps://docs.vast.ai/api-reference/rate-limits-and-errors.md\u003e (seen 2026-10-08)\n- CLI rate limits and retries: \u003chttps://docs.vast.ai/cli/rate-limits.md\u003e (seen 2026-10-08)\n- agents guide: \u003chttps://docs.vast.ai/guides/get-started/agents.md\u003e (seen 2026-10-08)\n- billing: \u003chttps://docs.vast.ai/guides/reference/billing.md\u003e (seen 2026-10-08)\n- instance pricing: \u003chttps://docs.vast.ai/guides/instances/pricing.md\u003e (seen 2026-10-08)\n- serverless pricing: \u003chttps://docs.vast.ai/guides/serverless/pricing.md\u003e (seen 2026-10-08)\n- serverless quickstart: \u003chttps://docs.vast.ai/guides/serverless/quickstart.md\u003e (seen 2026-10-08)\n- serverless endpoint parameters: \u003chttps://docs.vast.ai/guides/serverless/serverless-parameters.md\u003e (seen 2026-10-08)\n- quickstart and minimum deposit: \u003chttps://docs.vast.ai/guides/get-started/quickstart.md\u003e (seen 2026-10-08)\n- security FAQ: \u003chttps://docs.vast.ai/guides/reference/faq/security.md\u003e (seen 2026-10-08)\n- pricing page: \u003chttps://vast.ai/pricing\u003e (seen 2026-10-08)\n- pricing for agents: \u003chttps://vast.ai/pricing.md\u003e (seen 2026-10-08)\n- auth for agents: \u003chttps://vast.ai/auth.md\u003e (seen 2026-10-08)\n- MCP server card: \u003chttps://vast.ai/.well-known/mcp/server-card.json\u003e (seen 2026-10-08)\n- status page: \u003chttps://status.vast.ai\u003e (seen 2026-10-08)\n- status check log, console: \u003chttps://status.vast.ai/logs/console_report.log\u003e (seen 2026-10-08)\n- terms: \u003chttps://vast.ai/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://vast.ai/privacy\u003e (seen 2026-10-08)\n- data processing agreement: \u003chttps://vast.ai/data-processing-agreement\u003e (seen 2026-10-08)\n- compliance: \u003chttps://vast.ai/compliance\u003e (seen 2026-10-08)\n- vulnerability disclosure policy: \u003chttps://vast.ai/vulnerability-disclosure-policy\u003e (seen 2026-10-08)\n- security.txt (404): \u003chttps://vast.ai/.well-known/security.txt\u003e (seen 2026-10-08)\n- CLI and SDK repository, tags and skill file: \u003chttps://github.com/vast-ai/vast-cli\u003e (seen 2026-10-08)\n- open issues and pull requests: \u003chttps://api.github.com/repos/vast-ai/vast-cli/issues?state=open\u0026per_page=30\u003e (seen 2026-10-08)\n- PyPI package: \u003chttps://pypi.org/pypi/vastai/json\u003e (seen 2026-10-08)\n- PyPI downloads: \u003chttps://pypistats.org/api/packages/vastai/recent\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.org/domain/vast.ai\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 79/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Vast.ai Inc. | 20/20 |\n| Domain age | vast.ai, registered 2017-12-16 (8 years) | 11/15 |\n| Endpoint on the vendor's domain | console.vast.ai | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects, and has 3 clauses that cost points | 3.1/10 |\n| Privacy policy | read, states 8 of the 8 things a reader expects | 10/10 |\n| Status page | status.vast.ai | 10/10 |\n| Changelog | published | 10/10 |\n| security.txt | not found | 0/10 |\n\nThe Terms of Use Agreement, version date 1 September 2026, names Vast.ai Inc. and its affiliates, covers the website and the rental service, and is governed by California law with JAMS arbitration in the Los Angeles area.\n\nThe privacy policy, version date 18 June 2025, names Vast.ai Inc. and a Privacy Officer at contact@vast.ai. It is written for users of the website and contains an unfilled `[INSERT HYPERLINK]` placeholder.\n\nA Data Processing Agreement at vast.ai/data-processing-agreement forms part of the terms, with standard contractual clauses and five named sub-processors (Stripe, Google, Meta, Twitter, Microsoft).\n\nThe REST API answers at console.vast.ai and serverless routing at run.vast.ai, both on the vendor's domain. Rented machines belong to independent hosts.\n\nvast.ai/.well-known/security.txt returns 404. A vulnerability disclosure policy dated 23 July 2025 at vast.ai/vulnerability-disclosure-policy sends reports to security@vast.ai.\n\nNo API changelog was found in the docs index. The changelog link is the CLI and SDK repository's release list, which has no CHANGELOG file.\n\nRDAP for vast.ai gives a registration date of 2017-12-16.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://vast.ai/terms), read 2026-10-08, dated 2026-09-01, states 6 of the 7 things a reader expects.\n\n- To know. Restricts automated access (costs points). \"Making any unauthorized use of the Company Services, including collecting usernames and/or email addresses of users by electronic or other means for the purpose of sending unsolicited email, or creating user accounts by automated means or under false pretenses.\"\n- To know. Restricts benchmarking or competitive use (costs points). \"…maintain, or compile, directly or indirectly, a collection, compilation, database, dataset, index, benchmark, or directory without written permission from Company.\"\n- To know. Says the terms or the service can change without notice (costs points). \"Company reserves the right at any time to change, revise, update, suspend, discontinue, or otherwise modify the Website or the offerings at any time or for any reason without notice to you.\"\n- To know. Says access can be ended without notice or for any reason. \"COMPANY RESERVES THE RIGHT TO, IN COMPANY’S SOLE DISCRETION AND WITHOUT NOTICE OR LIABILITY, DENY ACCESS TO AND USE OF THE WEBSITE AND THE COMPANY SERVICES, TO ANY PERSON FOR ANY REASON OR FOR NO REASON AT ALL\"\n- To know. Requires arbitration or waives class actions. \"YOU AGREE THAT ANY CLAIMS YOU MAY HAVE AGAINST US RELATING TO THE WEBSITE OR THE COMPANY SERVICES, THIS AGREEMENT OR ANY TERMS AND CONDITIONS CONTAINED HEREIN MUST BE ARBITRATED, AND YOU EXPRESSLY WAIVE THE RIGHT TO (1) ASSERT CLAIMS AGAINST US IN COURT;\"\n- Gives the date it was last updated. Last updated 2026-09-01.\n- Names the governing law or courts. The law of California.\n- States a limit on its liability. Capped at the fees paid in the 3 months before the claim.\n- Says how changes to the terms are announced. Says it gives notice of a change.\n- Not found in the text. Refers to a service level or uptime commitment.\n- Also in the text (2026-10-08). Liability for any cause is limited to the amount paid for the applicable services in the three months before the claim arose. \"COMPANY’S LIABILITY TO YOU FOR ANY CAUSE WHATSOEVER AND REGARDLESS OF THE FORM OF THE ACTION, WILL AT ALL TIMES BE LIMITED TO THE AMOUNT PAID, IF ANY, BY YOU TO COMPANY FOR THE APPLICABLE SERVICES DURING THE PERIOD OF THREE (3) MONTHS PRIOR TO ANY CAUSE OF ACTION ARISING.\"\n- Also in the text (2026-10-08). Vast.ai reserves the right to change credit pricing and to cause purchased credits to expire, and says payments for spent credits are final. \"We reserve the right to change credit pricing, run promotions and cause credits to expire.\"\n- Also in the text (2026-10-08). Any claim arising from use of the website, the services or the agreement must be filed within one year or it is barred. \"ANY CLAIM OR CAUSE OF ACTION ARISING OUT OF OR RELATED TO USE OF THE WEBSITE, COMPANY SERVICES, OR THE AGREEMENT MUST BE FILED WITHIN ONE (1) YEAR AFTER SUCH CLAIM OR CAUSE OF ACTION ARISES OR IT WILL BE FOREVER BARRED.\"\n\n**Privacy policy** (https://vast.ai/privacy), read 2026-10-08, dated 2025-06-18, states 8 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2025-06-18.\n- Says how long data is kept. For as long as needed, with no period named.\n- Gives a privacy contact. Names a data protection officer.\n- Says where data is transferred or stored. Relies on standard contractual clauses.\n- Also in the text (2026-10-08). Online data partners may use cookies to link a visit or login to other personal information they hold, including an email address, which Vast.ai may then use for marketing. \"When you visit or log in to our website, cookies and similar technologies may be used by our online data partners or vendors to associate these activities with other personal information they or others have about you, including your email.\"\n\n## Live (updated 2026-10-08 19:53 UTC)\n\n- Right now: up, HTTP 404, 341 ms, checked 2026-10-08 19:53 UTC (get on `https://console.vast.ai/api/v0`)\n- Uptime 24h 100.0% (27 probes) · 30 days 100.0% (27 probes) · p50 340 ms · p95 407 ms\n- Vendor status page: unknown, no machine-readable status found\n- Watching pricing \u003chttps://docs.vast.ai/guides/instances/pricing.md\u003e\n- Watching privacy \u003chttps://vast.ai/privacy\u003e\n- Watching terms \u003chttps://vast.ai/terms\u003e\n- Always current: https://www.anchorterminal.com/api/v1/live/vast-ai.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Strengths\n\n- API keys take 11 permission categories and per-endpoint constraints on resource IDs, and can be reset or deleted at once\n- Public OpenAPI 3.1 file with 89 operations, llms.txt and Markdown docs pages\n- MIT CLI and Python SDK, v1.8.3 on 2 October 2026, with 12 tagged releases since 27 July 2026\n- Per-second billing, with serverless workers charged at the same rates as rented instances\n- Vulnerability disclosure policy with safe harbour and triage within 5 business days, and an account audit log from the CLI\n\n## Weaknesses\n\n- No SLA. The terms say availability is not guaranteed and the service can change without notice\n- Rate-limit thresholds are unpublished and 429 responses carry no `Retry-After` header\n- No free tier. Credit is prepaid with a $5 minimum deposit after a browser signup and email verification\n- Hosts are independent. The security FAQ says individual hosts may have less formal security than Secure Cloud data centres\n- The terms of 1 September 2026 prohibit scripts and automated access to the services without a separate written agreement, which conflicts with the public API\n\n## Before you call it (notes for agents)\n\n1. Create a scoped key with `vastai create api-key --permissions` for the agent. A default key has full account access, billing and key management included\n2. Pass `--raw` on every CLI command for JSON output, and `-y` on `vastai destroy instance`, which otherwise waits for a confirmation prompt\n3. Register an SSH key with `vastai create ssh-key` before creating an instance, or the host is unreachable\n4. Destroy instances when finished. A stopped instance still bills storage, and a zero balance without a saved card leads to deletion\n5. Back off on HTTP 429 yourself when calling REST directly. The CLI retries 429 three times from 0.15 seconds\n6. Filter searches with `verified=true` or the Secure Cloud option for sensitive data, and set a `dph_total` price cap\n\n## Connect\n\nInstall:\n\n```bash\npip install vastai\n```\n\nFirst request:\n\n```bash\ncurl -s -H \"Authorization: Bearer $VAST_API_KEY\" \\\n  \"https://console.vast.ai/api/v0/users/current/\"\n```\n\nClaude Code:\n\n```bash\n/plugin marketplace add vast-ai/vast-claude-plugin\n/plugin install vastai\n```\n\nThrough letme (picks today, calling later): https://letme.dev/vast-ai. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Baseten | B | 66.5 | 233 | compute.gpu, compute.endpoints, compute.serverless, compute.containers | no | https://www.anchorterminal.com/tools/baseten.md |\n| Modal | B | 63.6 | 302 | compute.gpu, compute.serverless, compute.endpoints, compute.containers | no | https://www.anchorterminal.com/tools/modal.md |\n| Replicate Deployments | B | 63.6 | 303 | compute.gpu, compute.endpoints, compute.serverless, compute.containers | no | https://www.anchorterminal.com/tools/replicate-deploy.md |\n| Beam | C | 55.5 | 507 | compute.gpu, compute.serverless, compute.endpoints, compute.containers | no | https://www.anchorterminal.com/tools/beam.md |\n| Cerebrium | C | 55.3 | 512 | compute.gpu, compute.serverless, compute.endpoints, compute.containers | no | https://www.anchorterminal.com/tools/cerebrium.md |\n| Runpod | D | 53.5 | 542 | compute.gpu, compute.serverless, compute.endpoints, compute.containers | no | https://www.anchorterminal.com/tools/runpod.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- Vast.ai publishes agent discovery files: llms.txt, an API catalogue (https://vast.ai/.well-known/api-catalog), auth.md and pricing.md for agents, and SKILL.md files for the CLI and SDK (source: \u003chttps://vast.ai/llms.txt\u003e)\n- Plugins for Claude Code, Codex and Cursor bundle a renter skill and a host skill, and every Vast image places an AGENTS.md and CLAUDE.md on the instance (source: \u003chttps://docs.vast.ai/guides/get-started/agents.md\u003e)\n- The only MCP server Vast.ai lists is a read-only documentation server hosted by Mintlify with no auth. Account actions go through the CLI, SDK or REST API (source: \u003chttps://vast.ai/.well-known/mcp/server-card.json\u003e)\n- Serverless bills GPU time only while a worker is Ready or Loading. Storage and bandwidth bill in every worker state until the endpoint is destroyed (source: \u003chttps://docs.vast.ai/guides/serverless/pricing.md\u003e)\n- The API returns 429 without a `Retry-After` header, and rate limits are a minimum interval per endpoint and identity with no thresholds published (source: \u003chttps://docs.vast.ai/api-reference/rate-limits-and-errors.md\u003e)\n- status.vast.ai tracks three components by roughly hourly checks. From 12 July to 8 October 2026 the console and serverless checks each failed 5 times of 2,000, none consecutive (source: \u003chttps://status.vast.ai\u003e)\n- The terms of 1 September 2026 list any script or automated method of accessing the website or services as prohibited unless a separate written agreement allows it (source: \u003chttps://vast.ai/terms\u003e)\n- The pricing feed's terms ask for a data licence before use in an index or benchmark, so no unit prices from it are recorded here (source: \u003chttps://vast.ai/pricing.md\u003e)\n\n## Compare\n\n- [Baseten vs Vast.ai](https://www.anchorterminal.com/compare/baseten-vs-vast-ai.md): B 66.5 vs B 62.6\n- [Beam vs Vast.ai](https://www.anchorterminal.com/compare/beam-vs-vast-ai.md): C 55.5 vs B 62.6\n- [Cerebrium vs Vast.ai](https://www.anchorterminal.com/compare/cerebrium-vs-vast-ai.md): C 55.3 vs B 62.6\n- [CoreWeave vs Vast.ai](https://www.anchorterminal.com/compare/coreweave-vs-vast-ai.md): C 61.5 vs B 62.6\n- [Koyeb vs Vast.ai](https://www.anchorterminal.com/compare/koyeb-vs-vast-ai.md): D 46.5 vs B 62.6\n- [Lambda Cloud vs Vast.ai](https://www.anchorterminal.com/compare/lambda-vs-vast-ai.md): D 50 vs B 62.6\n- [Modal vs Vast.ai](https://www.anchorterminal.com/compare/modal-vs-vast-ai.md): B 63.6 vs B 62.6\n- [Northflank vs Vast.ai](https://www.anchorterminal.com/compare/northflank-vs-vast-ai.md): C 61.3 vs B 62.6\n- [Replicate Deployments vs Vast.ai](https://www.anchorterminal.com/compare/replicate-deploy-vs-vast-ai.md): B 63.6 vs B 62.6\n- [Runpod vs Vast.ai](https://www.anchorterminal.com/compare/runpod-vs-vast-ai.md): D 53.5 vs B 62.6\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on vast.ai or one of its subdomains, or the README of github.com/vast-ai/vast-cli. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"vast-ai\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/vast-ai\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/vast-ai.svg\" alt=\"Vast.ai on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![Vast.ai on Anchor Terminal](https://www.anchorterminal.com/badges/vast-ai.svg)](https://www.anchorterminal.com/tools/vast-ai)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/vast-ai\"\u003eVast.ai on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Vast.ai is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/vast-ai-dark.png\n- Light: https://www.anchorterminal.com/assets/share/vast-ai-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "GPU \u0026 serverless compute",
        "url": "https://www.anchorterminal.com/categories/gpu-compute"
      },
      {
        "name": "Vast.ai",
        "url": ""
      }
    ],
    "description": "Vast.ai is a marketplace for renting GPUs by the second from independent hosts and data centres, as Docker instances, virtual machines or autoscaling serverless endpoints. Agents use the vastai CLI, a Python SDK or a REST API.",
    "facts": [
      "rank #331 of 722",
      "API key auth",
      "0 desk reviews"
    ],
    "h1": "Vast.ai",
    "image": "https://www.anchorterminal.com/assets/og/tools-vast-ai.png",
    "path": "/tools/vast-ai",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Vast.ai review for AI agents, grade B (62.6/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/vast-ai"
  },
  "tokens": {
    "markdown": 8050,
    "slim": 1730
  },
  "version": 1
}
