Fly for AI agents

Fly.io runs applications as micro-VMs across global regions, giving developers infrastructure close to their users without managing traditional servers themselves. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Developer toolsAPI keyMCP + RESTfly.io
AUDIT LOG · FLYPOLICY: acme-support
09:41:07 · claude · u_8f2read
fly.list_apps
List Apps✓ allowed · 212ms
09:41:08 · claude · u_8f2read
fly.get_node
Get Node by ID✓ allowed · 164ms
09:41:09 · claude · u_8f2write
fly.create_check_job
Create Health Check Job✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
fly.delete_organization
Delete Organization✕ blocked · policy: deny
EVERY FLY CALL, ON THE RECORD
01 · USE CASES

What agents do in Fly.

01

Check an app's deployment details

Get an app's details to confirm which regions and machines are currently running.

02

Check certificate status

Get a certificate's status to confirm a custom domain is properly configured.

03

Confirm before deleting an organization

Require approval before deleting an organization, since it removes every app and resource under it.

02 · ACTIONS

45 Fly actions, graded by risk.

Every Fly action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

30

Look things up. Allowed by default.

  • fly.get_node
    Get Node by ID
  • fly.list_apps
    List Apps
  • fly.get_add_on
    Get Add-On
  • fly.get_machine
    Get Machine
  • fly.get_regions
    Get Regions
  • fly.get_products
    Get Products and Pricing
  • fly.list_add_ons
    List Add-Ons
  • fly.list_machines
    List Machines
  • fly.get_placements
    Get Placements
  • fly.get_app_details
    Get app details
  • fly.get_certificate
    Get Certificate
  • fly.get_viewer_info
    Get Viewer Info
  • fly.get_organization
    Get Organization
  • fly.get_platform_info
    Get Platform Information
  • fly.list_add_on_plans
    List Add-On Plans
  • fly.list_apps_graphql
    List Apps via GraphQL
+ 14 MORE

write

9

Create and change things. Allow, or ask the user first.

  • fly.create_check_job
    Create Health Check Job
  • fly.add_wire_guard_peer
    Add WireGuard Peer
  • fly.create_check_job_run
    Create Check Job Run
  • fly.create_third_party_configuration
    Create Third-Party Configuration
  • fly.update_third_party_configuration
    Update Third-Party Configuration
  • fly.create_delegated_wire_guard_token
    Create Delegated WireGuard Token
  • fly.establish_ssh_key
    Establish SSH Key
  • fly.issue_certificate
    Issue Certificate
  • fly.set_apps_v2_default_on
    Set Apps V2 Default

destructive

6

Delete, cancel or archive. Ask first, or deny outright.

  • fly.delete_organization
    Delete Organization
  • fly.delete_remote_builder
    Delete Remote Builder
  • fly.remove_wire_guard_peer
    Remove WireGuard Peer
  • fly.delete_third_party_configuration
    Delete Third Party Configuration
  • fly.delete_delegated_wire_guard_token
    Delete Delegated WireGuard Token
  • fly.detach_postgres_cluster
    Detach Postgres Cluster
03 · HOW IT WORKS

Fly in three steps.

  1. 01Your users connect FlyThey add their Fly api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Health Check Job” can wait for the user, and “delete Organization” can be denied outright.
  3. 03Any agent can actYour agent calls Fly through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('fly', {
  read: 'allow',
  write: 'ask',        // create_check_job
  destructive: 'deny',  // delete_organization
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Fly connects.

Users add their Fly api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Fly connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Fly from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Fly and Arc0, answered.

Q01

Can I use Fly with Claude, ChatGPT or Cursor?

Yes. Connect Fly to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Fly actions you allow.

Q02

How do users connect Fly?

Users add their Fly api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Fly actions can my agent take?

45 in total: 30 read, 9 write and 6 destructive, such as “create Health Check Job”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Fly?

Yes. Actions like “delete Organization” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Fly too?

Yes. The same Fly connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Fly into your agent.

Your users connect Fly once, under your brand. Your agent gets 45 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan