Pricing

You pay for the seconds a sandbox exists.

One meter, billed by the second, from a balance you top up in advance. No subscription, no seats, no invoice at the end of a month you cannot remember.

no card to start · about 50 hours of a small sandbox

Rates

Three sizes. One price each.

A sandbox is a fixed slice of a machine, reserved for you from the moment it is ready until the moment it is gone. Twice the box costs twice as much — there is no curve to model and no tier that changes the arithmetic.

default

small

$0.10/ hour

cpu
0.5 vCPU
memory
1 GiB
disk
2 GiB

The default. Enough for a shell, a package install and most agent work.

medium

$0.20/ hour

cpu
1 vCPU
memory
2 GiB
disk
4 GiB

A build that compiles something, or a server with real traffic on it.

large

$0.40/ hour

cpu
2 vCPU
memory
4 GiB
disk
8 GiB

Test suites, data frames that do not fit anywhere smaller.

Billed per second, displayed per hour. A sandbox that lived ninety seconds costs ninety seconds — there is no minimum charge and nothing rounds up to an hour.

bandwidth

$0.15/ GB served

What your sandboxes serve on their public URLs, measured at the gateway and spent from the same balance as everything else. Traffic into a sandbox is free — package installs, uploads, git clones — and so is anything that never leaves through a public URL.

template builds

$0.02/ build minute

Only when a template builds an image from your Dockerfile, on an 8-vCPU machine, capped at fifteen minutes. A build that fails costs the same as one that works, because the machine ran either way. Rebuilding files you have not changed costs nothing at all.

How you pay

A balance, not a bill.

You add credit; sandboxes spend it by the second; when it reaches zero everything stops. That is the entire billing system, and it is the one property we were not willing to give up: you cannot run up a bill on Sandy, because there is no bill to run up.

It is also the honest shape for a service that hands out root on a real machine. Post-paid billing for untrusted compute means someone else's stolen card decides how much of our cluster to use and we find out four weeks later. Prepaid means the only person who can spend your money is you.

credit never expires · top up any amount · no monthly minimum

sandy — usage
$sandy usage
SANDBOX SIZE SECONDS COST
sb-a1b2c3d4e5f60718 small 4 324 $0.120
sb-9f8e7d6c5b4a3021 medium 1 307 $0.073
sb-1122334455667788 small 216 $0.006
 
this month 5 847s $0.199
credit remaining $4.80
sandy — sb-a1b2c3d4e5f60718
$sandy new --size=medium --timeout=30m
sb-9f8e7d6c5b4a3021
 
# thirty minutes with no command, no terminal
# attached and no traffic on its URLs, and the
# sandbox is destroyed
 
# the meter stops at the same instant

Idle timeout

Sandboxes you forget about stop costing money.

Every sandbox has an idle timeout, fifteen minutes by default. No command, no attached terminal and no traffic on its public URLs for that long, and it is destroyed. Set it per sandbox, from one minute to twenty-four hours.

Destroyed, not paused — Sandy has no pause. A stopped machine that kept its filesystem would still be occupying a disk somewhere, and we would have to charge you for it while calling it free. The sandbox goes away, and so does the meter.

Included

Six things we decided not to charge for.

Every one of these is a line item somewhere else in this market. They are absent here because a second meter buys us a little revenue and costs you the ability to predict a number.

Per-seat anything

Invite your whole team. Seats are not a meter, they are a way of charging twice for the same compute.

API requests

Creating, listing, destroying, exec, file transfer, terminal attach. Calls are free; the box is what costs.

Traffic into a sandbox

Package installs, uploads, git clones, every byte you send us. Inbound costs us nothing, so it costs you nothing. What a sandbox serves back out on a public URL is on the rate card above.

Storage

A sandbox disk is part of its size. There is no second line item, because a sandbox does not outlive itself.

Cold starts

The meter starts when your sandbox is ready to take a command, not when you asked for one.

Support

There is no tier that buys you a reply. Everyone gets the same one, from the person who wrote the thing.

The meter

What we count, and how you check it.

Billing is the one part of a platform a customer cannot verify from the outside, so here is the inside. These are commitments, not implementation notes.

01

We count from the cluster, never from your sandbox

You are root inside your own sandbox, which means anything running in there is yours to change. It would be absurd to bill from a number you could edit — and worse to pretend we could stop you. The meter reads sandbox state from Kubernetes, outside your reach and outside ours.

02

A heartbeat, not a stopwatch

Every sixty seconds we record which sandboxes are alive, rather than starting a clock on create and stopping it on delete. A missed event in the second scheme bills forever; in this one it costs a single interval. Our worst case is bounded, so yours is too.

03

At most sixty seconds of error, always in your favour

A sandbox starts costing money at the first heartbeat that finds it ready, and stops at the last heartbeat that found it alive. Both edges round the same way — towards not charging you. If a sandbox dies in a way nobody observed, the final minute of it is on us.

04

The ledger stores seconds, not dollars

We keep the raw quantity of every interval, append-only, and apply prices at the moment we show you a number. A pricing change applies forward and cannot rewrite what you already used. It also means every second on your invoice can be traced back to a sandbox id and a wall-clock interval.

Limits

What the account can do.

Caps exist so that a loop in an agent is a small mistake rather than a large one. Every number here moves if you ask — email marcel@sandy.computer and say what you are building.

LimitFree creditPaid balance
Concurrent sandboxes225
Idle timeout15 min default15 min default, up to 24h
Sizessmallsmall, medium, large

Questions

The awkward ones first.

What happens when I run out of credit?

Running sandboxes are destroyed and new ones are refused. We email you when you cross 20% remaining and again at zero. Nothing keeps running quietly and nothing arrives as a surprise later, because there is no later — you have already paid for everything you have used.

Do credits expire?

No. Money you have given us stays yours until you spend it on compute.

Why am I charged for a sandbox that is sitting idle?

Because an idle sandbox is holding a reserved slice of a real machine — its CPU and memory are committed to you whether or not you are using them, and nobody else can be given them. That is the honest cost, so it is the one we charge. The answer to paying for idle time is not a discount, it is the idle timeout above: sandboxes you have stopped using should stop existing.

Can I be invoiced instead of prepaying?

Not as a separate billing mode — one meter and one balance is the whole design, and a second path that accrues debt would need collections, dunning and credit checks behind it. If you need a purchase order and an invoice, email marcel@sandy.computer and we will raise one against a single large prepayment. It lands in the same balance and is spent the same way.

What if a sandbox dies on its own?

The meter stops when the sandbox stops, whether that was your call, the idle timeout, or a node failing underneath it. If we lose sight of a sandbox mid-flight, the interval closes at the last moment we could confirm it was alive — so the most that can go wrong is that we fail to bill you for a minute.

Is there a free tier?

There is a free start: $5 of credit on signup, no card. It is a grant, not a monthly allowance — when it is gone you decide whether Sandy is worth paying for, which is the only question a free tier should be asking.

Fifty hours, on us.

Create an account and the credit is already there. No card, no trial that ends, no call with anyone.