Start free. Pay when your agents scale.
Every plan includes zero-access custody, default-deny policy, workload identity, break-glass and the full audit log. You only pay for more agents and more operations.
For trying PastKeys and for small projects.
Start free- 3 agents
- 10,000 operations a month
- All providers: AWS, GitHub, Postgres, Cloudflare, any HTTP API
- Zero-access, post-quantum custody
- Policies, approvals, guardrails
- Workload identity (GitHub, GitLab, Google, Kubernetes, SPIFFE)
- Break-glass lockdown and emergency grants
- Tamper-evident audit log
For teams running agents in CI and production.
Get Team- 25 agents
- 1,000,000 operations a month
- Everything in Free
- Email support
- Priority on new provider requests
For organizations with compliance and scale needs.
Contact us- Custom agent and operation limits
- Everything in Team
- Dedicated support and SLA
- Deployment and security review help
- Self-hosted license for air-gapped setups
- Managed broker with your own KMS keyroadmap
- SSOroadmap
Compare plans
| Feature | Free | Team | Enterprise |
|---|---|---|---|
| Usage | |||
| Agents | 3 | 25 | Custom |
| Operations per month | 10,000 | 1,000,000 | Custom |
| Brokers | Unlimited | Unlimited | Unlimited |
| Security | |||
| Zero-access custody (hybrid post-quantum) | ✓ | ✓ | ✓ |
| Default-deny policies, constraints, rate limits | ✓ | ✓ | ✓ |
| Human approvals and guardrails | ✓ | ✓ | ✓ |
| Short-lived, scoped credentials | ✓ | ✓ | ✓ |
| Workload identity (OIDC, SPIFFE JWT-SVID) | ✓ | ✓ | ✓ |
| Break-glass lockdown and emergency grants | ✓ | ✓ | ✓ |
| Tamper-evident, signed audit log | ✓ | ✓ | ✓ |
| Integrations | |||
| AWS, GitHub, Postgres, Cloudflare, HTTP | ✓ | ✓ | ✓ |
| MCP server (Claude Code and other agents) | ✓ | ✓ | ✓ |
| Published REST endpoints | ✓ | ✓ | ✓ |
| Support and deployment | |||
| Documentation | ✓ | ✓ | ✓ |
| Email support | · | ✓ | ✓ |
| SLA and dedicated support | · | · | ✓ |
| Managed broker with your own KMS key | · | · | roadmap |
| SSO | · | · | roadmap |
Questions
What counts as an operation?
Each request your broker performs for an agent after it is authorized. Denied requests do not count.
What counts as an agent?
Each distinct agent identity that performs an operation in a calendar month, whether it uses an agent token or workload identity.
What happens at the limit?
Further operations are refused with HTTP 429 and a clear reason until the next month or until you upgrade. Nothing is billed by surprise.
Can you see my credentials on any plan?
No. On every plan your credentials are sealed to a broker you run; we store only ciphertext and hold no key that opens it. How that works.
Where does the broker run?
In your environment: a server, VM, container or laptop. It connects to your PastKeys account to receive policies and send audit records.
How do I upgrade?
Email us from the address on your account and we switch your plan, usually the same day. Self-serve billing is coming.
Your first brokered call in minutes.Free for 3 agents. No card required.
Start freeRead the quickstart