Pricing
Simple pricing for secure agents.
Every plan includes AES-256-GCM encryption, scoped tokens, approval workflows, and full audit trail. Pick the capacity that matches your fleet.
Starter
$192 billed annually (save 20%)
For early AI teams validating secure secret workflows.
Start free trial →- ✓50 secrets
- ✓5 agents
- ✓10,000 API calls/month
- ✓7-day audit retention
- ✓Email support
- ✓All core features
Pro
$470 billed annually (save 20%)
For production workloads with strict compliance requirements.
Start free trial →- ✓500 secrets
- ✓25 agents
- ✓100,000 API calls/month
- ✓90-day audit retention
- ✓Scheduled rotation
- ✓Priority email support (48 hr)
Enterprise
$950 billed annually (save 20%)
For large fleets and regulated environments requiring SSO and SLAs.
Start free trial →- ✓Unlimited secrets
- ✓Unlimited agents
- ✓Unlimited API calls
- ✓1-year audit retention
- ✓SSO/SAML
- ✓Dedicated CSM (4 hr SLA)
Full feature comparison
| Feature | Starter | Pro | Enterprise |
|---|---|---|---|
| Secrets stored | 50 | 500 | Unlimited |
| Registered agents | 5 | 25 | Unlimited |
| API calls / month | 10,000 | 100,000 | Unlimited |
| Scoped tokens | ✓ | ✓ | ✓ |
| Audit log retention | 7 days | 90 days | 1 year |
| Human-in-the-loop approval | Basic | Advanced | Custom workflows |
| Secret rotation | Manual | Scheduled | Automated + webhooks |
| Team members | 1 | 5 | Unlimited |
| SSO / SAML | — | — | ✓ |
| MoltbotDen integration | ✓ | ✓ | ✓ Priority sync |
| Support | Community | Email (48 hr) | Dedicated (4 hr SLA) |
Frequently asked questions
Is there a free trial?
Yes — every paid plan includes a 14-day trial. No credit card required to start. Cancel anytime before day 14 and you will not be charged.
Can AI agents pay autonomously?
Coming soon: Stripe M2M (Machine-to-Machine) USDC payments so agents can subscribe and pay for their own vault tier without human intervention. Get early access by emailing us.
How does the encryption work?
We use envelope encryption: each secret is encrypted with a unique Data Encryption Key (AES-256-GCM). That DEK is itself encrypted by a per-tenant Key Encryption Key (KEK) managed by GCP Cloud KMS with FIPS 140-2 Level 3 HSMs. The raw key never leaves the HSM.
What happens if I exceed my tier limit?
API calls beyond your monthly limit are billed at $0.001 per call (fractions of a cent). We will notify you at 80% and 100% of your limit. No sudden service cuts.
Is there a self-hosted option?
No. Agent Secret Store is hosted-only by design — managing your own KMS key hierarchy, HSMs, and audit pipeline defeats the purpose of a managed secret store. We handle the security infrastructure so you can focus on building agents.
How does MoltbotDen Trust Tier integration work?
If your agents are registered on MoltbotDen, their trust tier maps to automatic approval thresholds. High-trust agents can access standard secrets without human sign-off. All agents need approval for critical secrets regardless of trust tier.
Custom
Need something larger?
Running 100+ agents, need multi-region replication, Terraform provider, or a custom SLA? Let's talk about an Enterprise agreement.
Contact Enterprise Sales →