Pricing
Verification is always free.
Start by proving what your agents are authorized to do. Pay when your team deploys Keydris in production.
Developer Preview · pricing is early and will evolve
Free
$0
forever
Build and verify agent authority.
- Verification at the execution boundary
- 3,000 KIT issuances per month
- Unlimited verification
- Policy authoring and versioning
- ALLOW, REJECT, and APPROVAL REQUIRED decisions
- Session, device, and agent revocation
- Audit trail with review and export
- One human member
- The CLI, and docs with no forms
Pro
$99
per month
Operate authority across your team's production work.
- Everything in Free
- Team administration with roles
- Central revocation controls
- Extended audit history
- Higher limits on agents and active KITs
- Additional KIT issuance capacity
- Standard support
Enterprise
Custom
custom terms
Govern machine authority across the organization.
- Everything in Pro
- Organization-level governance
- Enterprise administration and roles
- Long-term audit and evidence retention
- Assurance support under diligence
- Priority onboarding and support
Verification is unlimited on every plan; policy limits follow plan entitlements. An invalid authority proof is invalid at $0 and at custom terms; what scales with price is organizational control. Every plan includes the full CLI, the broker you run in your own environment, and the audit trail.
Before you decide
Pricing FAQ
The questions that decide an evaluation. The full FAQ covers the architecture questions too.
What is available today?
Developer Preview, free to try. The CLI is public on npm, the documentation and the in-browser authority demonstration are open, and you can sign up and use the hosted application yourself without speaking to us. Production use is possible; there is no production SLA yet. The docs list the integrations currently supported.
What does the Free plan's KIT allowance cover?
Free includes 3,000 KIT issuances each month, counted per agentic session. The allowance resets monthly, and unused issuances do not roll over. When a month's allowance is used up, further KIT issuance stops; you can resume by purchasing additional usage or by upgrading your plan.
Why shouldn’t I build scoped checks myself?
You can build pieces of the model yourself. Keydris is for teams that want the policy, authority issuance, per-action verification, revocation, administration, and decision evidence to operate as one governed system across supported integrations. The public docs and CLI let you evaluate that tradeoff directly.
What does the decision record prove?
A decision record preserves the evaluated action, agent, scope, policy version, checks, outcome, and timestamp for review and export. It is evidence of what the system checked and decided, not a guarantee of universal safety or compliance, and not a copy of the underlying request payload.
Does Keydris proxy my traffic or see my payloads?
Keydris does not claim to be a universal proxy for your application traffic. On supported self-hosted paths, payload traffic stays inside your environment and authorization information crosses to Keydris. On third-party systems a Keydris integration may participate in the data path. Keydris does not claim it is never in any data path.
Where does verification happen? Can it complete locally?
The receiving boundary evaluates the governed action by requesting verification from the Keydris platform. That boundary can run in your environment, but it does not evaluate the policy by itself.
Developer Preview, free to try. No invite required.