PRICING simple, per account

Start free. Pay when your agents scale.

Every plan includes zero-access custody, default-deny policy, workload identity, break-glass and the full audit log. You only pay for more agents and more operations.

Free
$0 forever

For trying PastKeys and for small projects.

Start free
  • 3 agents
  • 10,000 operations a month
  • All providers: AWS, GitHub, Postgres, Cloudflare, any HTTP API
  • Zero-access, post-quantum custody
  • Policies, approvals, guardrails
  • Workload identity (GitHub, GitLab, Google, Kubernetes, SPIFFE)
  • Break-glass lockdown and emergency grants
  • Tamper-evident audit log
Team most popular
$49 / month

For teams running agents in CI and production.

Get Team
  • 25 agents
  • 1,000,000 operations a month
  • Everything in Free
  • Email support
  • Priority on new provider requests
Enterprise
Custom

For organizations with compliance and scale needs.

Contact us
  • Custom agent and operation limits
  • Everything in Team
  • Dedicated support and SLA
  • Deployment and security review help
  • Self-hosted license for air-gapped setups
  • Managed broker with your own KMS keyroadmap
  • SSOroadmap
Security is never paywalled. Zero-access custody, default-deny policy, short-lived credentials, workload identity, break-glass and audit are in every plan, including Free.

Compare plans

FeatureFreeTeamEnterprise
Usage
Agents325Custom
Operations per month10,0001,000,000Custom
BrokersUnlimitedUnlimitedUnlimited
Security
Zero-access custody (hybrid post-quantum)✓✓✓
Default-deny policies, constraints, rate limits✓✓✓
Human approvals and guardrails✓✓✓
Short-lived, scoped credentials✓✓✓
Workload identity (OIDC, SPIFFE JWT-SVID)✓✓✓
Break-glass lockdown and emergency grants✓✓✓
Tamper-evident, signed audit log✓✓✓
Integrations
AWS, GitHub, Postgres, Cloudflare, HTTP✓✓✓
MCP server (Claude Code and other agents)✓✓✓
Published REST endpoints✓✓✓
Support and deployment
Documentation✓✓✓
Email support·✓✓
SLA and dedicated support··✓
Managed broker with your own KMS key··roadmap
SSO··roadmap

Questions

What counts as an operation?

Each request your broker performs for an agent after it is authorized. Denied requests do not count.

What counts as an agent?

Each distinct agent identity that performs an operation in a calendar month, whether it uses an agent token or workload identity.

What happens at the limit?

Further operations are refused with HTTP 429 and a clear reason until the next month or until you upgrade. Nothing is billed by surprise.

Can you see my credentials on any plan?

No. On every plan your credentials are sealed to a broker you run; we store only ciphertext and hold no key that opens it. How that works.

Where does the broker run?

In your environment: a server, VM, container or laptop. It connects to your PastKeys account to receive policies and send audit records.

How do I upgrade?

Email us from the address on your account and we switch your plan, usually the same day. Self-serve billing is coming.

Your first brokered call in minutes.Free for 3 agents. No card required.

Start freeRead the quickstart