included baselineGit, tmux, editors, Claude, Codex, logs, repo storage, workspace metadata, and signed-link state stay ready before service CPU starts.
Pricing + security story
Spinnery keeps collaboration available without pretending every workspace is always running: the included shell baseline stays ready, the runtime meter wakes only for service work, and access controls stay scoped to the organization, workspace, service, and session.
Boundary ledger
The marketing story should make the product contract obvious before a buyer asks for architecture detail: what stays ready, what bills, what a reviewer can open, where the VM boundary sits, and how secrets reach runtime services.
included baselineGit, tmux, editors, Claude, Codex, logs, repo storage, workspace metadata, and signed-link state stay ready before service CPU starts.
Small / Medium / LargeDev URL traffic, tests, workers, and agent jobs wake the selected runtime size; idle sleep stops CPU and memory billing without deleting the workspace.
service / workspace / org / expirationA signed dev.spinnery.dev link creates one browser session for the app surface and blocks SSH, secrets, logs, private consoles, and runtime admin.
one organization per VMCustomer organizations never share shell or runtime VMs. Root is disabled, approved break-glass, or workspace elevation as an explicit organization policy.
/spinnery/{org}/{workspace}/SSM SecureString/KMS references are injected only into declared runtime inputs, while platform secrets remain in the control plane.
First workspace receipt
The first-release explanation should fit on one receipt: CLI entry, always-ready shell, awake runtime billing, signed dev links, organization-exclusive hosts, Auth0, SecureString secrets, and optional Tailscale private access.
Auth0 + spin upAuth0 starts the user session, Spinnery checks the organization role, and spin up opens the always-ready shell before runtime minutes begin.
signed dev link / tests / jobsWeb, same-origin /api, workers, tests, and agent jobs wake Small, Medium, or Large capacity only when service work needs the runtime VM.
signed dev.spinnery.devReviewer links are signed browser sessions for one service, workspace, organization, and expiration; SSH, logs, secrets, root, and runtime admin remain closed.
org-exclusive VMsShell and runtime hosts belong to one customer organization, with optional Tailscale for private shell or runtime routes that should not use the public dev gateway.
SSM SecureString/KMSWorkspace secrets stay as SSM SecureString references and are injected only into declared runtime inputs, never into signed dev links or public route metadata.
cost stops, policy staysIdle sleep or spinnery sleep stops metered service CPU and memory while Auth0, Spinnery roles, signed-link revocation, root policy, and workspace event history stay active.
Rollout checks
This page keeps the pricing and security claims close together so docs, demos, and product review can reuse the same language without widening the promise into infrastructure detail.