---
title: MicroVM Networking and Access (public)
description: MicroVM HTTPS endpoints, ports, public and VPC networking, and the API token scopes MicroVMs use.
product: Microvms
url: https://docs.digitalocean.com/products/microvms/concepts/networking-access/
last_updated: "2026-10-09"
---

> **For AI agents:** The documentation index is at [https://docs.digitalocean.com/llms.txt](https://docs.digitalocean.com/llms.txt). Markdown versions of pages use the same URL with `index.html.md` in place of the HTML page (for example, append `index.html.md` to the directory path instead of opening the HTML document).

# MicroVM Networking and Access (public)

DigitalOcean MicroVMs are lightweight virtual machines that run a container image in an isolated kernel, pause automatically when idle, and resume on the next request with memory, files, and processes intact.

Each DigitalOcean MicroVM serves its container over its own authenticated HTTPS endpoint. You choose public or VPC networking for outbound traffic when you create the MicroVM. The API, `doctl`, and requests to a MicroVM’s endpoint all authenticate with a DigitalOcean API token.

## Endpoints

Each MicroVM has an HTTPS endpoint for its HTTP port, in the following form:

```text
https://<your-microvm-id>.<region>.microvm.ondigitalocean.com
```

The endpoint serves HTTP or HTTP/2 on the MicroVM’s HTTP port, which you set at creation. The endpoint is empty until provisioning finishes. For how to find and use it, see [How to Send Requests to a MicroVM](https://docs.digitalocean.com/products/microvms/how-to/send-requests/index.html.md).

Every request to an endpoint needs a DigitalOcean API token with the `microvm:access` scope in the `Authorization` header. A token with `microvm:access` can reach every MicroVM on your team. You cannot scope a token to a single MicroVM.

## Ports

A MicroVM’s endpoint reaches only its HTTP port. The API and `doctl` accept up to five ports at creation, but ports other than the HTTP port are not reachable during the public preview.

## Public and VPC Networking

**Public** networking is the default. Outbound traffic from the MicroVM uses a shared NAT gateway.

**VPC** networking places the MicroVM in a [VPC network](https://docs.digitalocean.com/products/networking/vpc/index.html.md) in the same region. The VPC network must belong to your team. A MicroVM in a VPC network has no internet access unless the VPC network has a [NAT gateway](https://docs.digitalocean.com/products/networking/vpc/how-to/create-nat-gateway/index.html.md).

MicroVMs do not support IPv6, Cloud Firewalls, or a public IP address on the MicroVM.

## Access Tokens and Scopes

If you use a [custom-scoped token](https://docs.digitalocean.com/reference/api/scopes/index.html.md), grant it the `microvm` scopes you need:

| Scope | Allows |
|---|---|
| `microvm:create` | Create MicroVMs and checkpoints. |
| `microvm:read` | List and get MicroVMs, checkpoints, and create options. |
| `microvm:update` | Pause and resume MicroVMs, run commands, and open the console. |
| `microvm:delete` | Delete MicroVMs and checkpoints. |
| `microvm:access` | Send requests to a MicroVM’s endpoint. |