THE GOVERNED MCP GATEWAY EVERY PLAN: DEFAULT DENY · HIDDEN DISCOVERY · BROKERED CREDENTIALS · AUDIT BY DIGITALAPI.AI

Pricing

Pay for scale.
Not for security.

Everything that makes it safe — deny by default, tools invisible until approved, credentials that never touch the agent, a full audit trail — is on every plan, including free. Plans differ in how much you govern, what you integrate, and how we support you.

▲ TRY BEFORE YOU COMMIT — SEE HOW A 4–6 WEEK PILOT WORKS ↓
DEVELOPER
For one team proving the governed pattern.
$0
self-hosted · forever free
  • 3 MCP servers · 1 API source
  • 25k governed calls / month
  • 1 environment
  • Default-deny Cedar policy + explicit deny
  • Policy-filtered discovery
  • Credential broker — service accounts
  • Audit search · 7-day retention
  • gatewayctl CLI + admin API
  • Community support
Start free
TEAM
For a platform team going first.
$49 / mo
per gateway deployment
  • Everything in Developer
  • 10 MCP servers · 5 API sources
  • 250k governed calls / month
  • 3 environments (dev · stage · prod)
  • All credential modes — OAuth user-delegated, agent-scoped, workload
  • Policy simulation before rollout
  • OpenAPI → MCP conversion
  • Audit · 30-day retention
  • Email support
Book a walkthrough
ENTERPRISE
For regulated estates and strict data boundaries.
Custom
annual · talk to us
  • Everything in Business
  • Unlimited servers, sources & calls
  • Hybrid or fully self-hosted — no vendor egress
  • Multi-cluster / multi-region
  • Custom audit retention + export contracts
  • Dedicated security review & onboarding
  • Signed releases: Cosign + SBOM evidence packet
  • Air-gapped packaging (roadmap)
  • SLA + custom terms · named support
Talk to the team

Compare

Every limit, on the record.

The governance core never varies by plan. If a row reads "all plans," that's a guarantee, not marketing.

Capability Developer Team Business Enterprise
MCP servers31050Unlimited
API sources (OpenAPI → MCP)1525Unlimited
Governed calls / month25k250k5MUnlimited
Environments13UnlimitedUnlimited
Default-deny Cedar policyALL PLANS
Policy-filtered discoveryALL PLANS
Emergency disable + revocationALL PLANS
Credential modesServiceAll modesAll modesAll modes
Policy simulation
SAML SSO (admin)
Private connectors
SIEM export
Audit retention7 days30 days90 daysCustom
DeploymentSelf-hostedSelf-hostedSelf-hosted / HAHybrid · no-egress · multi-region
SupportCommunityEmailPriorityNamed + SLA

Over a call limit, new sessions are throttled — the gateway never fails open and never bypasses policy to keep traffic flowing.

How a pilot works

Prove one boundary. Then decide.

A pilot is a sign-off-driven plan with named owners and dates — 4–6 weeks, one governed boundary, proven end to end on your infrastructure. Not a roadmap tour: one real MCP server or API operation, one allowed call, one denied call, one revocation.

SCOPE one boundary W0 STAND UP your cluster · idp W1–2 POLICY allow ✓ · deny ✕ W2–3 PROVE revoke live · siem W3–5 DECIDE go · extend · no-go W6 EVIDENCE AT EVERY STEP — THE SIGN-OFF IS YOURS, ROW BY ROW
The pilot, drawnThe number you take to the board comes from week 6
WeekMilestoneYou sign off when
W0Kickoff & scopeCharter and one concrete use case signed
W1Environment stand-upGateway running in your chosen mode — self-hosted or hybrid
W1–2Identity wiredYour IdP resolves real actor context
W2–3Capability + policyOne server or API operation approved; one allow and one deny rule simulated and accepted
W3–4Credentials + routing + revocationOpaque-reference resolution verified; no secret in any log; revoke reaches live sessions
W4–5Audit + SIEMMetadata-only events landing in your SIEM
W6Readout & decisionGo · extend · or no-go, with documented reasons

What you bring

  • A security owner and a platform owner committed to the decision
  • One concrete use case, named up front
  • A non-production tool or API (or an accepted fixture)
  • Your deployment mode: self-hosted or hybrid

Who signs off

  • Security: denied tools hidden, every call attributable, no secrets in any record, revocation works
  • Platform: runs on your infra, your data stores, repeatable install, no vendor egress
  • Developers: one governed call succeeds end to end with validation enforced

How it ends

  • Go — expand to the next boundaries on a paid plan
  • Extend — one defined gap, one new exit criterion
  • No-go — documented reason; you keep everything you learned

FAQ

Fair questions.

What counts as a governed call?

One tool invocation through the gateway — policy evaluation, credential resolution, routing, and the audit event included. Discovery requests and denied calls don't count against your quota; you are never billed for being protected.

Is the free plan really default-deny?

Yes. The policy engine, hidden discovery, fail-closed behavior, and metadata-only audit are identical on every plan. We don't sell a less-safe version of a security product.

What happens when I hit a limit?

Soft limits, fail-safe semantics: new sessions throttle and you get an operator alert. The gateway never fails open — an over-quota deployment keeps enforcing policy on existing traffic.

Which plans can self-host?

All of them — the gateway is self-hosted by design (Helm into your cluster, your PostgreSQL/Valkey/IdP/secret manager). Enterprise adds the fully-no-egress profile, multi-region, and custom evidence contracts for regulated environments.

Can we try it before committing?

Yes — that's the pilot above: 4–6 weeks, one governed boundary on your infrastructure, with sign-off criteria your security and platform teams agree to up front. Early design partners also shape the roadmap.

Next step

Start with one boundary. Free.

Deploy the free plan from the docs, or bring your architecture to a 25-minute walkthrough.

Start free Book a walkthrough