Skip to content

Pricing

Verification is always free.

Start by proving what your agents are authorized to do. Pay when your team deploys Keydris in production.

Developer Preview · pricing is early and will evolve

Free

$0

forever

Build and verify agent authority.

  • Verification at the execution boundary
  • 3,000 KIT issuances per month
  • Unlimited verification
  • Policy authoring and versioning
  • ALLOW, REJECT, and APPROVAL REQUIRED decisions
  • Session, device, and agent revocation
  • Audit trail with review and export
  • One human member
  • The CLI, and docs with no forms

Pro

$99

per month

Operate authority across your team's production work.

  • Everything in Free
  • Team administration with roles
  • Central revocation controls
  • Extended audit history
  • Higher limits on agents and active KITs
  • Additional KIT issuance capacity
  • Standard support

Enterprise

Custom

custom terms

Govern machine authority across the organization.

  • Everything in Pro
  • Organization-level governance
  • Enterprise administration and roles
  • Long-term audit and evidence retention
  • Assurance support under diligence
  • Priority onboarding and support

Verification is unlimited on every plan; policy limits follow plan entitlements. An invalid authority proof is invalid at $0 and at custom terms; what scales with price is organizational control. Every plan includes the full CLI, the broker you run in your own environment, and the audit trail.

Before you decide

Pricing FAQ

The questions that decide an evaluation. The full FAQ covers the architecture questions too.

What is available today?

Developer Preview, free to try. The CLI is public on npm, the documentation and the in-browser authority demonstration are open, and you can sign up and use the hosted application yourself without speaking to us. Production use is possible; there is no production SLA yet. The docs list the integrations currently supported.

What does the Free plan's KIT allowance cover?

Free includes 3,000 KIT issuances each month, counted per agentic session. The allowance resets monthly, and unused issuances do not roll over. When a month's allowance is used up, further KIT issuance stops; you can resume by purchasing additional usage or by upgrading your plan.

Why shouldn’t I build scoped checks myself?

You can build pieces of the model yourself. Keydris is for teams that want the policy, authority issuance, per-action verification, revocation, administration, and decision evidence to operate as one governed system across supported integrations. The public docs and CLI let you evaluate that tradeoff directly.

What does the decision record prove?

A decision record preserves the evaluated action, agent, scope, policy version, checks, outcome, and timestamp for review and export. It is evidence of what the system checked and decided, not a guarantee of universal safety or compliance, and not a copy of the underlying request payload.

What happens if Keydris is unavailable?

The current platform fails closed: an action whose authority decision cannot be obtained does not proceed. That platform-unavailable behavior is currently fixed, not configurable. It is separate from a policy's own default decision, which you author (for example, reject unmatched actions). Keydris does not claim governed work continues uninterrupted through a control-plane outage.

Does Keydris proxy my traffic or see my payloads?

Keydris does not claim to be a universal proxy for your application traffic. On supported self-hosted paths, payload traffic stays inside your environment and authorization information crosses to Keydris. On third-party systems a Keydris integration may participate in the data path. Keydris does not claim it is never in any data path.

Where does verification happen? Can it complete locally?

The receiving boundary evaluates the governed action by requesting verification from the Keydris platform. That boundary can run in your environment, but it does not evaluate the policy by itself.

Developer Preview, free to try. No invite required.

Quickstart