Ponyc: the actor-model language where data races are a compile error
Pony is an open-source, actor-model, capabilities-secure, high performance programming language.
At a glance
- What is it?
- Pony is a pre-1.0, BSD-2-Clause language built around actors and reference capabilities. It removes data races at compile time, but the same type system is the main thing you have to learn.
- Who is it for?
- Adopt Pony when you want data-race freedom enforced by the compiler and you can absorb a pre-1.0 language that introduces breaking changes semi-regularly. Do not adopt it if you need a frozen API surface, or if you target Windows 10 or a Linux kernel older than 5.3, because binaries will not run there.
- Can I use it commercially?
- Yes. BSD-2-Clause is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 4 days ago.
- What is it written in?
- Mainly Pony, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 25, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Ponyc actually solves, and who should care
Pony is described in its README as an object-oriented, actor-model, capabilities-secure, high-performance programming language. The compiler in this repository, ponyc, is what turns that description into a running binary. The problem it attacks is shared mutable state. In most languages, two threads touching the same object is a runtime question: you find out with a mutex, a sanitizer, or a production incident. Pony moves that question into the type system. Reference capabilities annotate how a reference may be used (read-only, mutable, isolated, and so on), and the compiler rejects programs that would let two actors mutate the same data at once. That is the whole pitch, and it is a narrower pitch than "a faster language". If your program is a single-threaded script, the capability machinery buys you nothing and costs you type annotations.
The audience is therefore specific. It fits people building concurrent network services, message-passing systems, and anything where a data race would be a correctness bug rather than a performance annoyance. The repository ships examples/networking/ and examples/actors/ alongside examples/language-features/, which is a fair signal of where the maintainers expect newcomers to look first. It does not fit teams that want a stable, frozen language surface. The README states plainly that Pony is still pre-1.0 and "semi-regularly introduces breaking changes", while noting that applications written in Pony are currently used in production environments. Both of those sentences are true at once, and you should read them together rather than picking the one you prefer.
Reference capabilities and actors: the mechanism under the syntax
An actor in Pony is a unit of isolation with its own mailbox. You send it a message, it processes messages one at a time, and it never shares mutable state with another actor. That much is Erlang-shaped. What is different is that the compiler also tracks the references you hold. A mutable reference that is not reachable from anywhere else can be moved between actors; a readable reference can be shared; a mutable reference that is also aliased cannot cross an actor boundary. The checker enforces this before code generation, so a program that compiles has no data races by construction.
The cost lands on the programmer. You will spend your first hours fighting the compiler about capabilities rather than about logic, and error messages are about aliasing, not about the feature you were trying to write. This is the honest trade: the language takes on a hard verification problem and hands you a stricter type discipline in return. It is not a small annotation layer you can ignore, the way you can ignore lifetimes in a garbage-collected language. It is the core of the design, and the examples/language-features/ directory exists precisely because the rules need demonstrating.
Pony is also compiled, not interpreted, and the repository carries benchmark/ and examples/benchmarks/ directories, so performance is clearly a first-class concern for the maintainers. The README calls the language high-performance, but it publishes no numbers, and nothing in the repository would let anyone quote a figure responsibly.
Installing ponyc and compiling your first actor
The README points to INSTALL.md for installation, BUILD.md for building from source, and INSTALL_DOCKER.md for Docker images. Prebuilt binaries are published for Linux, macOS and Windows on amd64 and arm64; the platform matrix marks arm32 on Linux as best-effort, riscv64 as tested in CI only, and the BSDs as tested in CI with no prebuilt binary, meaning you build from source there. The homepage at ponylang.io is where the project directs readers for learning material, and there is an online playground at playground.ponylang.io if you want to try the language before installing anything.
The README lists INSTALL.md as the installation entry point and INSTALL_DOCKER.md for Docker images; the exact commands for each platform live in those files, so follow them there rather than copying a package name from a summary. Once ponyc is on your PATH, running it in a directory that contains Pony source builds the program and produces an executable named after that directory.
The repository's examples/getting-started/ directory is the documented starting point, and examples/actors/ shows how messages move between actors, which is the part a hello-world does not teach you. The README also links a playground at playground.ponylang.io for trying the language without installing the compiler locally, and the learn section at ponylang.io for tutorials.
Where Pony refuses to run, and where it is the wrong tool
The platform floor is unusually high and it is stated without hedging. On Windows the minimum supported version is Windows 11 or Windows Server 2022, build 20348. The README explains why: Pony's networking uses an OS readiness API introduced in that build, and a Pony binary will not run on earlier versions, Windows 10 included. That is not a soft recommendation. It is a hard cut, and it rules out a large installed base for desktop or on-premise deployment.
Linux has a similar floor at kernel 5.3. Pony's process support detects a child's exit with `pidfd_open`, a system call added in that release, and on an older kernel starting a process returns an error. Older kernels are unsupported. If you deploy onto long-term-support distributions with older kernels, check the kernel version before you write any code, because the failure appears at process spawn, not at compile time.
There are also cases where Pony is simply the wrong choice rather than a constrained one. If your work is data analysis, scripting, or anything where the ecosystem of libraries matters more than the concurrency model, the capability discipline is overhead with no payoff. If you need to interoperate heavily with an existing runtime, examples/c-ffi/ shows that C interop exists, but every boundary you cross is a place where the compiler's guarantees stop being able to help you. And if your team cannot absorb breaking changes on a semi-regular cadence, the pre-1.0 status is disqualifying on its own, regardless of how good the type system is.
Pony compared with Rust on concurrency
The comparison people reach for is Rust, and the difference is structural rather than a matter of degree. Rust gives you threads and shared memory, then uses ownership and borrowing to prove that your use of that shared memory is safe. You can still write a mutex-protected counter, and the compiler checks that you locked it. Pony removes the shared mutable memory from the model instead. Actors communicate by message, and the capability system proves that no message carries a mutable reference that is still reachable elsewhere. There is no lock to forget because there is no shared state to lock.
That changes what your programs look like. Rust code is often organized around data structures that threads borrow; Pony code is organized around actors that own their state and exchange messages. Rust has a much larger ecosystem and a stable release channel, and Pony is pre-1.0 with breaking changes. What Pony offers in exchange is a smaller set of concurrency mistakes to make: the class of bug where two actors race on the same object cannot be expressed. If your concurrency problem is genuinely message-passing shaped, that is a real simplification. If it is shared-memory shaped and you want threads over a large array, Pony's model will feel like it is fighting you, and Rust's will not.
Licence, release cadence and the cost of staying current
Pony is distributed under the 2-Clause BSD License, with the full text in LICENSE. That is a permissive licence: it permits use in closed-source products and requires preservation of the copyright notice and disclaimer. It is not a copyleft licence, so it does not oblige you to publish modifications. This is a description of the licence text, not legal advice; if the distinction matters to your organization, read LICENSE and get your own counsel.
The upgrade cost is the part to weigh honestly. The README says breaking changes arrive semi-regularly and are "usually fairly easy to adapt to". The release history in this repository shows three releases in the space of a month: 0.68.0 on 2026-08-01, then 0.69.0 and 0.69.1 on 2026-08-21. That is a fast cadence for a language with a type system this strict, and it means the CHANGELOG.md and the .release-notes/ directory are not optional reading if you track the compiler. The last push to the default branch was on 2026-08-21. Pin a compiler version in CI and move deliberately, because a minor version bump is where a breaking change will land. There is also a RELEASE_PROCESS.md in the repository if you want to understand how those bumps are decided.
Editorial conclusion
Adopt Pony when you want data-race freedom enforced by the compiler and you can absorb a pre-1.0 language that introduces breaking changes semi-regularly. Do not adopt it if you need a frozen API surface, or if you target Windows 10 or a Linux kernel older than 5.3, because binaries will not run there. Before committing, verify the reference capability rules against your own concurrency design and check the release notes for the breaking changes between 0.68.0 and 0.69.1.
Frequently asked questions
What is the Pony programming language?
Pony is an open-source, object-oriented, actor-model, capabilities-secure, high-performance programming language. Its defining feature is a type system that uses reference capabilities to prevent data races at compile time, and it is currently pre-1.0.
How do I install ponyc?
The README points to INSTALL.md for installation, BUILD.md for building from source, and INSTALL_DOCKER.md for Docker images. Prebuilt binaries are published for Linux, macOS and Windows on amd64 and arm64.
Which operating systems and versions does ponyc support?
Linux, macOS and Windows are released for amd64 and arm64, with arm32 on Linux as best-effort and riscv64 tested in CI. Windows requires 11 or Windows Server 2022 build 20348 and later, and Linux requires kernel 5.3 or newer, because older versions lack the OS APIs Pony depends on.
Is Pony stable enough for production?
The README states that Pony is still pre-1.0 and semi-regularly introduces breaking changes, while also noting that applications written in Pony are currently used in production environments. Both apply, so plan for adapting to breaking changes rather than assuming a frozen language surface.
What licence does ponyc use?
Pony is distributed under the terms of the 2-Clause BSD License, with the full text in the LICENSE file. That is a permissive licence rather than a copyleft one.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/ponylang-ponyc)