Pricing
Everything that makes it safe — deny by default, tools invisible until approved, credentials that never touch the agent, a full audit trail — is on every plan, including free. Plans differ in how much you govern, what you integrate, and how we support you.
▲ TRY BEFORE YOU COMMIT — SEE HOW A 4–6 WEEK PILOT WORKS ↓gatewayctl CLI + admin APICompare
The governance core never varies by plan. If a row reads "all plans," that's a guarantee, not marketing.
| Capability | Free | Team | Business | Enterprise |
|---|---|---|---|---|
| MCP servers | 5 | 25 | 100 | Unlimited |
| API sources (OpenAPI → MCP) | 2 | 10 | 50 | Unlimited |
| Governed calls / month | 250k | 1M | 10M | Unlimited |
| Environments | 1 | 3 | Unlimited | Unlimited |
| Default-deny Cedar policy | ALL PLANS | ✓ | ✓ | ✓ |
| Policy-filtered discovery | ALL PLANS | ✓ | ✓ | ✓ |
| Emergency disable + revocation | ALL PLANS | ✓ | ✓ | ✓ |
| Credential modes | Service + user OAuth | All modes | All modes | All modes |
| Policy simulation | — | ✓ | ✓ | ✓ |
| SAML SSO (admin) | — | — | ✓ | ✓ |
| Private connectors | — | — | ✓ | ✓ |
| SIEM export | — | — | ✓ | ✓ |
| Audit retention | 7 days | 30 days | 90 days | Custom |
| Deployment | Hosted | Hosted | Hosted · HA profile | Dedicated · your cloud · or self-hosted |
| Availability | Best effort | Status commitments | HA profile | Contractual SLA |
| Support | Community | Priority | Named + SLA |
Over a call limit, new sessions are throttled — the gateway never fails open and never bypasses policy to keep traffic flowing.
How a pilot works
A pilot is a sign-off-driven plan with named owners and dates — 4–6 weeks, one governed boundary, proven end to end on your infrastructure. Not a roadmap tour: one real MCP server or API operation, one allowed call, one denied call, one revocation.
| Week | Milestone | You sign off when |
|---|---|---|
| W0 | Kickoff & scope | Charter and one concrete use case signed |
| W1 | Environment stand-up | Gateway running in your chosen mode: hosted, dedicated, or self-hosted |
| W1–2 | Identity wired | Your IdP resolves real actor context |
| W2–3 | Capability + policy | One server or API operation approved; one allow and one deny rule simulated and accepted |
| W3–4 | Credentials + routing + revocation | Opaque-reference resolution verified; no secret in any log; revoke reaches live sessions |
| W4–5 | Audit + SIEM | Metadata-only events landing in your SIEM |
| W6 | Readout & decision | Go · extend · or no-go, with documented reasons |
FAQ
One tool invocation through the gateway — policy evaluation, credential resolution, routing, and the audit event included. Discovery requests and denied calls don't count against your quota; you are never billed for being protected.
Yes. The policy engine, hidden discovery, fail-closed behavior, and metadata-only audit are identical on every plan. We don't sell a less-safe version of a security product.
Soft limits, fail-safe semantics: new sessions throttle and you get an operator alert. The gateway never fails open, so an over-quota deployment keeps enforcing policy on existing traffic. There is no card on file for free plans, so you are never surprised by a bill. Per-minute rate limits apply on every plan to keep one workload from starving another.
Yes, and we mean it. 250k governed calls a month is roughly 8,000 a day, which covers a solo builder's real automation load, not just a demo. What free doesn't buy is a promise: availability is best effort with no SLA, and the fences that matter as your stakes rise are separate environments, longer audit retention, and SSO.
Enterprise. Team and Business run on our hosted plane so you get the governed path in minutes with nothing to operate. For regulated estates, Enterprise deploys dedicated single-tenant, into your own cloud account, or fully self-hosted with no vendor egress (Helm into your cluster, your PostgreSQL/Valkey/IdP/secret manager), verifiable at your firewall.
Yes — that's the pilot above: 4–6 weeks, one governed boundary on your infrastructure, with sign-off criteria your security and platform teams agree to up front. Early design partners also shape the roadmap.
Next step
Start the free plan in minutes with nothing to run, or bring your architecture to a 25-minute walkthrough.