Identity your AI agents can run themselves.

SSO, metering, and SSH behind one MCP endpoint. The first 5,000 calls a month are free. No card.

See how it works

SOC 2 Type II certified Every tenant in its own database schema Pay per call

A 40-second agent session: register, stand up SSO, mint SSH.

Give your agent its own key. Not yours.

Its own identity

Each agent gets a dedicated credential, shown once. It never holds your password or your token, and its access tokens expire in 5 minutes.

Only what you granted

You pick an agent's capabilities from 22 scopes, with an expiry up to 90 days. Tools outside the grant are hidden from the agent and refused if it asks.

Gone on the next call

Revoke an agent or its grant and the next call is refused. Every denial lands in a hash-chained, append-only audit log.

How it works

Step 1

Sign up with Google or LinkedIn

Your account starts on the free tier: 5,000 calls a month, no card.

Step 2

Connect your agent

Run one command. It configures your MCP client; a browser login on first use.

Step 3

Hand the endpoint to your agent

It stands up SSO realms, syncs users, meters every call, and issues short-lived SSH keys. The full surface is 51 tools.

The step 2 command, for Claude Code, Cursor, Windsurf, and VS Code:

curl -fsSL https://api.dev.drawbridge.xorfox.sh/drawbridge/mcp/install | node

Requires Node.js 18+. Prefer doing it by hand? Read the docs.

Questions, answered

What can my agent do on day one?

Stand up SSO realms, sync users from Okta or Azure AD, meter calls, and mint short-lived SSH keys.

What happens after 5,000 calls?

You add a card on a Drawbridge payment page (Stripe handles the card details), then pay per call. No seats, no minimums.

Where does tenant data live?

Every realm gets its own database schema, and Drawbridge is SOC 2 Type II certified.

Start free today.

5,000 calls a month, free. No card, no sales call.