Pricing
You pay for the seconds a sandbox exists.
One meter, billed by the second, from a balance you top up in advance. No subscription, no seats, no invoice at the end of a month you cannot remember.
no card to start · about 50 hours of a small sandbox
Rates
Three sizes. One price each.
A sandbox is a fixed slice of a machine, reserved for you from the moment it is ready until the moment it is gone. Twice the box costs twice as much — there is no curve to model and no tier that changes the arithmetic.
small
$0.10/ hour
- cpu
- 0.5 vCPU
- memory
- 1 GiB
- disk
- 2 GiB
The default. Enough for a shell, a package install and most agent work.
medium
$0.20/ hour
- cpu
- 1 vCPU
- memory
- 2 GiB
- disk
- 4 GiB
A build that compiles something, or a server with real traffic on it.
large
$0.40/ hour
- cpu
- 2 vCPU
- memory
- 4 GiB
- disk
- 8 GiB
Test suites, data frames that do not fit anywhere smaller.
Billed per second, displayed per hour. A sandbox that lived ninety seconds costs ninety seconds — there is no minimum charge and nothing rounds up to an hour.
bandwidth
$0.15/ GB served
What your sandboxes serve on their public URLs, measured at the gateway and spent from the same balance as everything else. Traffic into a sandbox is free — package installs, uploads, git clones — and so is anything that never leaves through a public URL.
template builds
$0.02/ build minute
Only when a template builds an image from your Dockerfile, on an 8-vCPU machine, capped at fifteen minutes. A build that fails costs the same as one that works, because the machine ran either way. Rebuilding files you have not changed costs nothing at all.
How you pay
A balance, not a bill.
You add credit; sandboxes spend it by the second; when it reaches zero everything stops. That is the entire billing system, and it is the one property we were not willing to give up: you cannot run up a bill on Sandy, because there is no bill to run up.
It is also the honest shape for a service that hands out root on a real machine. Post-paid billing for untrusted compute means someone else's stolen card decides how much of our cluster to use and we find out four weeks later. Prepaid means the only person who can spend your money is you.
credit never expires · top up any amount · no monthly minimum
$sandy usageSANDBOX SIZE SECONDS COSTsb-a1b2c3d4e5f60718 small 4 324 $0.120sb-9f8e7d6c5b4a3021 medium 1 307 $0.073sb-1122334455667788 small 216 $0.006 this month 5 847s $0.199credit remaining $4.80$sandy new --size=medium --timeout=30msb-9f8e7d6c5b4a3021 # thirty minutes with no command, no terminal# attached and no traffic on its URLs, and the# sandbox is destroyed # the meter stops at the same instantIdle timeout
Sandboxes you forget about stop costing money.
Every sandbox has an idle timeout, fifteen minutes by default. No command, no attached terminal and no traffic on its public URLs for that long, and it is destroyed. Set it per sandbox, from one minute to twenty-four hours.
Destroyed, not paused — Sandy has no pause. A stopped machine that kept its filesystem would still be occupying a disk somewhere, and we would have to charge you for it while calling it free. The sandbox goes away, and so does the meter.
Included
Six things we decided not to charge for.
Every one of these is a line item somewhere else in this market. They are absent here because a second meter buys us a little revenue and costs you the ability to predict a number.
Per-seat anything
Invite your whole team. Seats are not a meter, they are a way of charging twice for the same compute.
API requests
Creating, listing, destroying, exec, file transfer, terminal attach. Calls are free; the box is what costs.
Traffic into a sandbox
Package installs, uploads, git clones, every byte you send us. Inbound costs us nothing, so it costs you nothing. What a sandbox serves back out on a public URL is on the rate card above.
Storage
A sandbox disk is part of its size. There is no second line item, because a sandbox does not outlive itself.
Cold starts
The meter starts when your sandbox is ready to take a command, not when you asked for one.
Support
There is no tier that buys you a reply. Everyone gets the same one, from the person who wrote the thing.
The meter
What we count, and how you check it.
Billing is the one part of a platform a customer cannot verify from the outside, so here is the inside. These are commitments, not implementation notes.
01
We count from the cluster, never from your sandbox
You are root inside your own sandbox, which means anything running in there is yours to change. It would be absurd to bill from a number you could edit — and worse to pretend we could stop you. The meter reads sandbox state from Kubernetes, outside your reach and outside ours.
02
A heartbeat, not a stopwatch
Every sixty seconds we record which sandboxes are alive, rather than starting a clock on create and stopping it on delete. A missed event in the second scheme bills forever; in this one it costs a single interval. Our worst case is bounded, so yours is too.
03
At most sixty seconds of error, always in your favour
A sandbox starts costing money at the first heartbeat that finds it ready, and stops at the last heartbeat that found it alive. Both edges round the same way — towards not charging you. If a sandbox dies in a way nobody observed, the final minute of it is on us.
04
The ledger stores seconds, not dollars
We keep the raw quantity of every interval, append-only, and apply prices at the moment we show you a number. A pricing change applies forward and cannot rewrite what you already used. It also means every second on your invoice can be traced back to a sandbox id and a wall-clock interval.
Limits
What the account can do.
Caps exist so that a loop in an agent is a small mistake rather than a large one. Every number here moves if you ask — email marcel@sandy.computer and say what you are building.
| Limit | Free credit | Paid balance |
|---|---|---|
| Concurrent sandboxes | 2 | 25 |
| Idle timeout | 15 min default | 15 min default, up to 24h |
| Sizes | small | small, medium, large |
Questions
The awkward ones first.
What happens when I run out of credit?
Running sandboxes are destroyed and new ones are refused. We email you when you cross 20% remaining and again at zero. Nothing keeps running quietly and nothing arrives as a surprise later, because there is no later — you have already paid for everything you have used.
Do credits expire?
No. Money you have given us stays yours until you spend it on compute.
Why am I charged for a sandbox that is sitting idle?
Because an idle sandbox is holding a reserved slice of a real machine — its CPU and memory are committed to you whether or not you are using them, and nobody else can be given them. That is the honest cost, so it is the one we charge. The answer to paying for idle time is not a discount, it is the idle timeout above: sandboxes you have stopped using should stop existing.
Can I be invoiced instead of prepaying?
Not as a separate billing mode — one meter and one balance is the whole design, and a second path that accrues debt would need collections, dunning and credit checks behind it. If you need a purchase order and an invoice, email marcel@sandy.computer and we will raise one against a single large prepayment. It lands in the same balance and is spent the same way.
What if a sandbox dies on its own?
The meter stops when the sandbox stops, whether that was your call, the idle timeout, or a node failing underneath it. If we lose sight of a sandbox mid-flight, the interval closes at the last moment we could confirm it was alive — so the most that can go wrong is that we fail to bill you for a minute.
Is there a free tier?
There is a free start: $5 of credit on signup, no card. It is a grant, not a monthly allowance — when it is gone you decide whether Sandy is worth paying for, which is the only question a free tier should be asking.
Fifty hours, on us.
Create an account and the credit is already there. No card, no trial that ends, no call with anyone.