MicroVM Networking and Accesspublic
Last verified 9 Oct 2026
DigitalOcean MicroVMs are lightweight virtual machines that run a container image in an isolated kernel, pause automatically when idle, and resume on the next request with memory, files, and processes intact.
Each DigitalOcean MicroVM serves its container over its own authenticated HTTPS endpoint. You choose public or VPC networking for outbound traffic when you create the MicroVM. The API, doctl, and requests to a MicroVM’s endpoint all authenticate with a DigitalOcean API token.
Endpoints
Each MicroVM has an HTTPS endpoint for its HTTP port, in the following form:
https://<your-microvm-id>.<region>.microvm.ondigitalocean.comThe endpoint serves HTTP or HTTP/2 on the MicroVM’s HTTP port, which you set at creation. The endpoint is empty until provisioning finishes. For how to find and use it, see How to Send Requests to a MicroVM.
Every request to an endpoint needs a DigitalOcean API token with the microvm:access scope in the Authorization header. A token with microvm:access can reach every MicroVM on your team. You cannot scope a token to a single MicroVM.
Ports
A MicroVM’s endpoint reaches only its HTTP port. The API and doctl accept up to five ports at creation, but ports other than the HTTP port are not reachable during the public preview.
Public and VPC Networking
Public networking is the default. Outbound traffic from the MicroVM uses a shared NAT gateway.
VPC networking places the MicroVM in a VPC network in the same region. The VPC network must belong to your team. A MicroVM in a VPC network has no internet access unless the VPC network has a NAT gateway.
MicroVMs do not support IPv6, Cloud Firewalls, or a public IP address on the MicroVM.
Access Tokens and Scopes
If you use a custom-scoped token, grant it the microvm scopes you need:
| Scope | Allows |
|---|---|
microvm:create |
Create MicroVMs and checkpoints. |
microvm:read |
List and get MicroVMs, checkpoints, and create options. |
microvm:update |
Pause and resume MicroVMs, run commands, and open the console. |
microvm:delete |
Delete MicroVMs and checkpoints. |
microvm:access |
Send requests to a MicroVM’s endpoint. |