A serverless cloud platform for running Python code, including GPU-accelerated AI workloads, sandboxed code execution, and scheduled jobs, with usage-based billing.
Software capabilities Compute & Execution Autoscaling Automatically scales a Function's container pool up and down based on load, configurable via min/max/buffer container counts and scaledown window, including dynamic runtime updates. Cold-start optimization Reduces container startup latency through configurable warm pools and memory snapshots that restore initialized CPU and GPU state. CPU, memory, and disk configuration Lets Functions and Sandboxes request specific CPU core counts, memory, and ephemeral disk sizes, with configurable soft and hard resource limits. Dynamic request batching Accumulates individually invoked inputs into a single batched execution once a maximum batch size or wait time is reached. Failure handling & retries Automatically retries failed executions, gracefully handles GPU preemption, reschedules crashed containers, and monitors GPU hosts for hardware errors. GPU acceleration Runs Functions and Sandboxes on a selectable range of NVIDIA GPU types from T4 through B300, with multi-GPU-per-container and ordered GPU-fallback-list support. Input concurrency Lets a single container process multiple inputs concurrently via threads or async tasks instead of handling one input per container. Multi-node GPU clusters Gang-schedules multiple containers as a single job with direct high-bandwidth networking for distributed training across nodes. Region selection & routing Pins containers to a specific cloud region — including a ca-central (Montreal) region — or routes requests through a regional gateway to reduce latency or meet data-residency needs, with routing and compute regions now selectable independently via --compute-region.
Sandboxes Restricted Functions Runs untrusted code inside a Function with Modal resource access disabled so it cannot call other Functions or use internal Modal APIs. Sandbox connectivity & file access Exposes ports of a running Sandbox to the internet via tunnels or authenticated connect tokens, and reads, writes, and copies files inside it from the client, with large writes in copy_from_local/write_bytes/write_text ≈2.5x faster. Sandbox network access controls Restricts a Sandbox's inbound and outbound network traffic through CIDR or domain allowlists that can be updated at runtime. Sandbox outbound policy Replaces headers in outbound HTTPS requests from Sandboxes via an OutboundPolicy whose secret-backed values are resolved outside the container and updatable at runtime. Sandbox Sidecars Runs additional containers alongside a Sandbox on the same host, joined by an internal bridge network and addressable by name, with an experimental `proxy_traffic_via_sidecar` option routing a main container's outbound HTTPS traffic through a named Sidecar, whose filesystem (but not memory) can be snapshotted into a reusable Image. Sandbox snapshots Saves a Sandbox's filesystem, a specific directory, or its full memory state to restore later or to branch new Sandboxes from, raising a dedicated SnapshotCreationError if an exit snapshot fails to create. Sandboxes Creates secure, isolated containers at runtime for running arbitrary or untrusted commands through a process-style exec, stdin, and stdout interface. VM Sandboxes Runs a Sandbox on a full virtual machine with a real Linux kernel instead of gVisor, enabling Docker-in-Docker, systemd, and eBPF workloads.
Security & Identity Audit logs Maintains an append-only, filterable record of sensitive workspace actions for compliance and incident review, including Proxy Auth token creation, deletion and environment-scope changes. OIDC identity federation Issues short-lived signed tokens so Functions can authenticate to external cloud providers or services without long-lived secrets, injected automatically into Function containers and, on request, into Sandboxes as MODAL_IDENTITY_TOKEN. Secrets management Stores and injects encrypted credentials into Function and Sandbox containers as environment variables, manageable via dashboard, CLI, or code. Security & compliance certifications Encrypts customer data at rest and in transit, enforces TLS 1.3, and maintains SOC 2 Type 2, HIPAA, and PCI DSS compliance postures. SSO (Okta & SAML) Supports identity-provider- and service-provider-initiated single sign-on through a published Okta app or configurable SAML 2.0 for any identity provider, with an enforcement mode that immediately terminates non-Okta sessions once enabled. User groups Manages access for multiple workspace members at once through custom groups created in Modal and SCIM-provisioned groups managed in the customer's identity provider, each assignable an Environment Role in Restricted Environments.
Web Serving & Endpoints Custom domains, tunnels & static IPs Attaches custom domains to endpoints with automatic TLS, exposes container ports through public tunnels, and routes outbound traffic through static allowlistable IPs on a Proxy whose region is chosen at creation. Endpoint authentication Protects Web Function, Server, and Endpoint URLs by default with Modal-issued proxy tokens that can be scoped per environment, presentable as separate Modal-Key/Modal-Secret headers or joined into a single Authorization: Bearer header compatible with OpenAI API clients. Managed LLM endpoints Deploys a production LLM inference endpoint from a Hugging Face model ID or custom weights with a single command, as either a Shared Endpoint (fully managed, per-token billing) or a Dedicated Endpoint (isolated capacity, configurable autoscaling), called via OpenAI- and Anthropic-compatible APIs with a Proxy Token. Modal Servers Runs long-lived HTTP server processes with concurrency-based autoscaling, sticky request routing, health checks, and an optional explicit `name` distinct from the class name. Session affinity Routes requests sharing a Modal-Session-Id header to the same container so cached prompt prefixes stay warm on Shared and Dedicated Endpoints. Web endpoints Turns a Python function or an ASGI/WSGI app into a public HTTP endpoint with a decorator, including streaming and WebSocket support.
Workspaces, Governance & Billing Environment managed/unmanaged toggle Toggles an environment between managed and unmanaged access, removing every per-environment role for that environment when managed access is disabled. GitHub org auto-join Lets members of a linked GitHub organization join the workspace without an invite, controlled by a workspace-level setting. Role-based access control Grants workspace-wide roles for members and, via the Environment.roles interface, per-Environment Roles — No Access, Viewer, or Contributor — for members and service users, replacing the deprecated Environment.members interface. Unauthenticated URL blocking Lets Workspace Managers block deployments in an Environment from exposing unauthenticated URLs, with workspace defaults and per-Environment inherit/block/allow overrides. Usage-based billing & budgets Bills by the second for actual compute used, with configurable spend budgets, cost-attribution tags, exportable billing reports, and a billing.summary() API/CLI returning per-cycle metered cost, adjustments, and billed cost at the workspace and Environment level. Workspaces & environments Organizes deployments into workspaces and sub-divided environments such as dev and prod, each with independent secrets, namespaces, and token-authenticated service user accounts.
Container Images Container image builder Defines container images via chainable methods for installing Python and system packages, adding local files or code, running build commands or functions, and attaching GPUs during setup. CUDA stack support Provides a pre-installed NVIDIA driver and CUDA driver API on GPU containers and documents how to layer the full CUDA Toolkit for libraries that need it. External & private registry images Imports existing container images from public or private registries (Docker Hub, ECR, Google Artifact Registry, ACR) or from a Dockerfile as the base for Functions and Sandboxes. Named images Publishes a built image under a durable, versionable name that Functions and Sandboxes can reference later without triggering an implicit rebuild.
Developer Tooling Deployment management Deploys, rolls out, rolls back, and rolls over Apps with configurable traffic-shift strategies and reverts to prior versions from the CLI or dashboard. Interactive debugging & shells Drops into a debugger, IPython session, or interactive shell inside a running container, and can exec one-off commands or stream logs from live containers. JavaScript & Go SDKs Provides official client libraries for calling Modal Functions and managing Sandboxes, Volumes, and Secrets from JavaScript/TypeScript and Go. Modal Skills (agent skills CLI) Installs and updates packaged coding-agent skills and offline documentation resources for use with Claude Code and similar tools.
Observability & Integrations App observability dashboard Streams per-App logs, resource metrics, and call success/failure history, including GPU utilization and endpoint latency metrics. Datadog & OpenTelemetry export Exports Modal logs, metrics, and audit events to Datadog or any OTLP-compatible observability provider. Programmatic log retrieval Streams, fetches by UTC time range, or tails the most recent logs programmatically from Function, Server, and FunctionCall objects via stream(), fetch(), and tail() methods. Slack notifications Sends alerts to a linked Slack channel for failed scheduled runs, crash-looping containers, idle warm containers, workspace and environment budget thresholds, GPU limits and credit grants.
Function Orchestration Async job spawning Lets callers submit work asynchronously via spawn or spawn_map and poll or fetch results later through a FunctionCall handle. Cross-app Function invocation Looks up and invokes Functions and Classes from other deployed Apps by name, including from JavaScript and Go clients, as if calling a remote service, and reports a looked-up Function's resources, regions, schedule, volumes, cloud bucket mounts, secrets and web-endpoint settings through Function.info(). Scheduled functions Runs deployed Functions automatically on a recurring cron-style expression or fixed interval schedule.
Storage & Data Primitives Cloud bucket mounts Mounts AWS S3, Cloudflare R2, or Google Cloud Storage buckets as a read/write filesystem inside Functions and Sandboxes. Dicts & Queues Provides a distributed key-value store and a FIFO queue primitive shared across Functions for passing state and messages between Apps. Volumes Provides a distributed, cached filesystem for sharing data across containers, with read-only mounts, sub-path mounts, and background auto-commits.
Notebooks Modal Notebooks Hosts serverless Jupyter notebooks with GPU access, real-time multi-user collaborative editing, and AI code completion.