Pricing
Everything that makes it safe — deny by default, tools invisible until approved, credentials that never touch the agent, a full audit trail — is on every plan, including free. Plans differ in how much you govern, what you integrate, and how we support you.
▲ TRY BEFORE YOU COMMIT — SEE HOW A 4–6 WEEK PILOT WORKS ↓gatewayctl CLI + admin APICompare
The governance core never varies by plan. If a row reads "all plans," that's a guarantee, not marketing.
| Capability | Developer | Team | Business | Enterprise |
|---|---|---|---|---|
| MCP servers | 3 | 10 | 50 | Unlimited |
| API sources (OpenAPI → MCP) | 1 | 5 | 25 | Unlimited |
| Governed calls / month | 25k | 250k | 5M | Unlimited |
| Environments | 1 | 3 | Unlimited | Unlimited |
| Default-deny Cedar policy | ALL PLANS | ✓ | ✓ | ✓ |
| Policy-filtered discovery | ALL PLANS | ✓ | ✓ | ✓ |
| Emergency disable + revocation | ALL PLANS | ✓ | ✓ | ✓ |
| Credential modes | Service | All modes | All modes | All modes |
| Policy simulation | — | ✓ | ✓ | ✓ |
| SAML SSO (admin) | — | — | ✓ | ✓ |
| Private connectors | — | — | ✓ | ✓ |
| SIEM export | — | — | ✓ | ✓ |
| Audit retention | 7 days | 30 days | 90 days | Custom |
| Deployment | Self-hosted | Self-hosted | Self-hosted / HA | Hybrid · no-egress · multi-region |
| Support | Community | Priority | Named + SLA |
Over a call limit, new sessions are throttled — the gateway never fails open and never bypasses policy to keep traffic flowing.
How a pilot works
A pilot is a sign-off-driven plan with named owners and dates — 4–6 weeks, one governed boundary, proven end to end on your infrastructure. Not a roadmap tour: one real MCP server or API operation, one allowed call, one denied call, one revocation.
| Week | Milestone | You sign off when |
|---|---|---|
| W0 | Kickoff & scope | Charter and one concrete use case signed |
| W1 | Environment stand-up | Gateway running in your chosen mode — self-hosted or hybrid |
| W1–2 | Identity wired | Your IdP resolves real actor context |
| W2–3 | Capability + policy | One server or API operation approved; one allow and one deny rule simulated and accepted |
| W3–4 | Credentials + routing + revocation | Opaque-reference resolution verified; no secret in any log; revoke reaches live sessions |
| W4–5 | Audit + SIEM | Metadata-only events landing in your SIEM |
| W6 | Readout & decision | Go · extend · or no-go, with documented reasons |
FAQ
One tool invocation through the gateway — policy evaluation, credential resolution, routing, and the audit event included. Discovery requests and denied calls don't count against your quota; you are never billed for being protected.
Yes. The policy engine, hidden discovery, fail-closed behavior, and metadata-only audit are identical on every plan. We don't sell a less-safe version of a security product.
Soft limits, fail-safe semantics: new sessions throttle and you get an operator alert. The gateway never fails open — an over-quota deployment keeps enforcing policy on existing traffic.
All of them — the gateway is self-hosted by design (Helm into your cluster, your PostgreSQL/Valkey/IdP/secret manager). Enterprise adds the fully-no-egress profile, multi-region, and custom evidence contracts for regulated environments.
Yes — that's the pilot above: 4–6 weeks, one governed boundary on your infrastructure, with sign-off criteria your security and platform teams agree to up front. Early design partners also shape the roadmap.
Next step
Deploy the free plan from the docs, or bring your architecture to a 25-minute walkthrough.