Axtary
Axtary provides payload-bound content authorization for AI agents and automated systems, enforcing policy and human approvals before connectors or tools execute sensitive actions across code, infrastructure, data, messages, and MCP tools.
Axtary is ai agents software teams evaluate for ai agents. Use this page to review pricing, integration signals, and the best alternatives before you commit.
Used in These Packs
Quick Overview
Best for: AI Agents
What it does
AI Agents software for decision-makers comparing workflow fit and alternatives.
Best fit
AI Agents
Pricing snapshot
Contact for pricing
Next step
Compare Axtary with similar tools before you shortlist it.
Compare this tool before you shortlist it
Review alternatives, pricing posture, and workflow fit side by side.
Axtary
Axtary is a platform for content- and payload-bound authorization of actions executed by AI agents and automated workflows. It normalizes an action (actor, task, resource, constraints, and payload hash), evaluates deterministic policy locally, and issues a signed ActionPass that binds approval to the exact payload so that any post-approval tampering causes verification to fail. The product is aimed at teams that need to govern security-sensitive engineering and agent operations — code changes, infrastructure reads/changes, data access, messaging, tickets, and MCP tool calls — while keeping provider credentials and execution data local to their runtimes.
Enforcement is performed beside the agent via a local proxy and SDKs; a hosted control plane coordinates policies, human approvals, and audit exports without entering the action data path. Axtary includes a deterministic policy engine (Cedar/OPA-compatible), a verifiable append-only ledger for decisions, scoped connector adapters, and tooling (CLI, runtime packages) to integrate into existing developer workflows.
Axtary checks the exact tool call, payload, policy, and approval before an AI agent touches GitHub, Slack, MCP tools, or production APIs.
Own this listing?
Claim this page to add pricing, features, screenshots, and verified owner details.
Claim this listingKey Features
ActionPass (signed authorization artifact)
Signs the normalized action, payload hash, policy version, constraints, and expiry into a portable, payload-bound pass for execution authorization.
Payload-bound human approvals
Human approvals are bound to the exact payload hash; if the payload changes after approval, adapter-side verification rejects execution before the provider call.
Local enforcement proxy and SDKs
Runs policy evaluation, ActionPass issuance, execution checks, and ledger recording beside agents so provider credentials and action data remain local.
Deterministic policy engine (Cedar + OPA inputs)
Evaluates normalized actions locally and maps the same decision context to Cedar and OPA inputs for consistent policy decisions.
Verifiable action ledger
Maintains an append-only hash chain with signed attestations and verifiable inclusion/consistency proofs recording decisions, approvals, and execution traces.
Scoped connector adapters and MCP provenance controls
Applies provider-specific scope and evidence checks, records server identity, tool schema and definition hash, and approval state before execution.
Runtime & CLI tooling
Provides a global CLI, runtime packages, proxy, and npm packages (ActionPass, policy, proxy, ledger, approvals, adapters, mcp) to integrate into developer and agent runtimes.
Typed configuration and validation
Loads and validates axtary.yml with typed errors for unsupported or incomplete configuration.
Pricing
Claim this listing to add current pricing tiers.
Use Cases
Secure code changes and pull requests
Require exact-diff approvals and policy checks before creating pull requests or modifying infrastructure paths (example: require approval for infra/prod/** diffs).
Controlled messaging and notifications
Prevent agents from posting to unauthorized channels by binding approved channel and message payload to the ActionPass so modified messages are rejected.
Scoped cloud and data access
Limit AWS/GCP reads and other data access to specific project, bucket, region, or prefix constraints enforced before provider calls.
MCP tool calls and server-bound actions
Record MCP server identity, tool definition hash, and approval state so server-side or hosted tools execute only the approved action.
Document and search access governance
Enforce root/result/byte/traversal limits and blocked-paths for docs.search/read before executing agent queries.
Integrations
GitHub
Connector for pull requests and contents read/write actions with path and diff constraints.
Slack
Connector for chat.postMessage with channel and recipient scopes to enforce allowed channels.
Linear / Jira
Ticketing connectors (Linear, Jira) for controlled issue updates with project/assignee/field constraints.
Sentry
Integration point for error/ticket-related governance (listed among supported connectors).
PostgreSQL
Connector for scoped database reads with identity and non-destructive evidence checks.
AWS
Cloud connector for scoped reads and actions (project, bucket, region, prefix constraints).
Google Cloud
Cloud connector for scoped reads and actions (project/bucket constraints).
Google Drive
Connector for document access with root/result/byte/traversal limits.
Microsoft (coming soon)
Microsoft integrations listed as coming soon on the product page.
Okta (coming soon)
Identity provider connector marked as coming soon.
Auth0 (coming soon)
Identity provider connector marked as coming soon.
Anthropic (runtime)
Supported LLM runtime mentioned for agent execution.
OpenAI (runtime)
Supported LLM runtime mentioned for agent execution.
Cursor (runtime)
Supported runtime listed for agent execution.
Benefits
Limitations
Frequently Asked Questions
Claim this listing to publish FAQs.
Getting Started
- 1 Install the CLI and try the demo: npm i -g @axtary/cli && axtary init && axtary demo
- 2 Configure policies in axtary.yml and deploy the local proxy/SDK beside your agents (install relevant @axtary/* packages for proxy, policy, actionpass, ledger, and adapters)
- 3 Connect the hosted control plane to coordinate approvals, policy registry, and audit exports; use the approval inboxes and verifier guides to review and sign ActionPasses
Support
docs
Developer docs, spec, and verifier guide available on the site (referenced as 'read the spec and verifier guide').
sales/support
Request access, pricing inquiries, and sales support are handled via the website (Request access / Join the waitlist prompts).
packages/repos
Developer resources and packages available via listed npm packages (installation commands shown on the site).
API
Compare Axtary with similar tools
See how it stacks up against alternatives
Related Tools
View all 432 →
Oodle.ai
Oodle Agent Observability provides agent/LLM observability at scale with S3-backed columnar storage, fast search (<1s P99), out-of-the-box AI-powered insights, and flat ingestion-based pricing designed to retain 100% of traces affordably for debugging and optimizing production agents.
Sentinel
Sentinel is an open-source (MIT) autonomous QA agent that reads a codebase to derive end-to-end business flows and tests them across frontend and backend, combining deterministic repo recon, model-driven planning, Playwright browser automation, and backend assertions.
Nous
Nous is an open-source context graph for agentic GTM (go-to-market) teams that centralizes identity-resolved people and company data from multiple GTM tools so agents can read a single, source-traced account context in one call. It is available as a hosted service and as a self-hostable stack.
Scalix World
Scalix World is an AI-native neocloud that unifies database, AI, functions, storage, and compute into one platform operable by humans and AI agents via a single API key and credit pool.
X402vps
X402vps provides pay-per-hour Docker containers designed for autonomous AI agents — no signup or API key required; your wallet (USDC on Base mainnet) is your identity. It offers prebuilt images, internet-enabled node/core tiers for scraping and browser automation, and a JSON API for lifecycle and exec operations.
Superserve
Superserve is an open-source, self-hostable sandbox platform for long-running AI agents that provides durable Firecracker microVMs, pausing/resuming sessions, and programmatic control via an SDK and API.
Premium Alternatives
OTP Inspired actor supervisor based full stack templates
ShipStacks provides production-grade, OTP-inspired full-stack SaaS templates that include supervisors/actor patterns, auth, payments, uploads, AI chat and agent playbooks, and Docker-ready deployment in multiple languages and frameworks.
ClaudeThings
ClaudeThings provides a packaged, continuously-updating set of 89 specialized agents, 103 pre-built skills, and 181 slash commands that act as an AI engineering and marketing team for Claude Code — delivered as a private GitHub repo and installed with a single npx command. It adapts to any stack via a CLAUDE.md project manifest and is sold as a one-time purchase with lifetime updates.
Listingbott
ListingBott is a directory-submission SaaS that lists a website, product, newsletter, or blog on 100+ hand-picked directories to save time, boost Domain Rating (DR), and drive relevant traffic using a combination of AI agents and human review.