Keydris
Keydris is an authorization infrastructure that enforces per-action authority for AI agents by evaluating agent-presented authority against versioned policies before actions run, returning ALLOW, APPROVAL REQUIRED, or REJECT decisions and recording decision evidence.
Keydris is security software teams evaluate for security. Use this page to review pricing, integration signals, and the best alternatives before you commit.
Profile facts come from the vendor source. AiMatch labels unknown pricing or API details instead of estimating them.
Review official source →Used in These Packs
Quick Overview
Best for: Security
What it does
Security software for decision-makers comparing workflow fit and alternatives.
Best fit
Security
Pricing snapshot
Freemium from $0
Next step
Compare Keydris with similar tools before you shortlist it.
Compare this tool before you shortlist it
Review alternatives, pricing posture, and workflow fit side by side.
Keydris
Keydris provides an authorization layer specifically for AI agents that evaluates whether a given agent action is permitted under a centrally authored, versioned policy at the moment the action is attempted. Integrators present the agent's authority at the execution boundary; Keydris returns a decision (ALLOW, APPROVAL REQUIRED, or REJECT) which the receiving boundary enforces. Keydris supplies the decision and records a decision record that preserves the evaluated action, agent, policy version, checks, outcome, and timestamp for audit and export. Keydris does not itself execute actions or serve as an identity provider; it operates alongside IAM and existing identity systems to add action-time authority verification and revocation.
Keydris lets developers and builders control what AI agents can do before they do it. You define the authority; Keydris checks it before a governed action runs.
Own this listing?
Claim this page for a one-time $29 to add pricing, features, screenshots, verified owner details, and a clearly labeled 30-day category position after the profile is live.
Claim this listing for $29Key Features
Per-action authority checks
Each governed action is checked against the policy assigned to an agent at the moment it is attempted; Keydris returns ALLOW, APPROVAL REQUIRED, or REJECT before execution.
Policy model and versioning
Policies are authored and versioned centrally so each decision is attributable to the policy version in force when the action was evaluated.
Decision records and audit logs
Every decision leaves a record that includes the evaluated action, agent, policy version, outcome, and timestamp for review and export.
Revocation of authority
Authorities can be revoked; revoked authority fails its next verification while the agent process may continue running.
CLI and developer quickstart
An installable CLI (@keydris/cli) and quickstart walkthrough enable registering agents, assigning policies, initializing a harness, and running governed sessions (Developer Preview).
Deployment/integration flexibility
You integrate Keydris at the execution boundary that will enforce the decision; payloads can stay on your execution path and Keydris is not required to proxy all traffic.
Fail-closed platform behavior
When Keydris cannot obtain a decision, the current platform behavior is to fail closed: the action does not proceed.
Pricing
Free plan: $0 — includes 1 agent, 1 policy, and 1,500 KIT issuances/month.
Free
$0- 1 agent
- 1 policy
- 1,500 KIT issuances/month
- Developer Preview access
Builder
$20/month- 3 agents
- 3 policies
- 5,000 KIT issuances/month
Pro
$99/month- For teams operating Keydris
- Verification stays unlimited on every plan
Enterprise
Custom (contact sales)- Enterprise governance is a conversation
- Scale and enterprise integrations via discussion
Use Cases
Govern repository operations
Allow agents to read repositories but require human approval before merging pull requests by enforcing policy checks at merge time.
Agent actions across MCP / API platforms
Provide per-action authorization for agents acting through MCP servers or APIs so platform teams can enforce scoped agent authority and audit decisions.
Enterprise governance and compliance
Centralize policy management, decision evidence, and revocation to support enterprise security reviews and governance of agent capabilities.
Integrations
@keydris/cli (npm)
Official CLI published on npm for initializing harnesses, starting the proxy, and interacting with Keydris.
MCP & API platforms
Integration points described for MCP and API platform teams so receiving boundaries can request verification from Keydris before executing actions.
Example harnesses (Claude Code)
Example harness and usage shown for governed sessions with Claude Code in documentation and quickstart.
Benefits
Limitations
Frequently Asked Questions
What is Keydris?
Why isn’t OAuth or IAM enough?
Is Keydris an identity provider or proxy?
Where does verification happen?
Does Keydris see my payloads?
What happens if Keydris is unavailable?
What is available today?
Getting Started
- 1 Register the agent in the Keydris console and assign a policy to obtain an Agent ID.
- 2 Install the CLI (Node.js 20+): npm install -g @keydris/cli.
- 3 Initialize the harness with the Agent ID and configure harness settings (keydris init ...).
- 4 Start the background proxy (keydris proxy up) and verify status (keydris status).
- 5 Run the governed agent session; Keydris issues a short-lived KIT and checks each governed action against the policy before execution.
Support
docs
Documentation and quickstart available via the 'Docs' link on the site for configuration, policy model, and integrations.
contact
Contact page linked from the site for sales and enterprise conversations (Contact).
developer tools
Public CLI on npm (@keydris/cli) and in-browser demos to try the Developer Preview without a sales call or credit card.
API
Documentation and API/integration information are available via the site's Docs and developer quickstart; the platform references MCP & API platform integrations.
Not stated
Compare Keydris with similar tools
See how it stacks up against alternatives
Related Tools
View all 27 →
backmesh
Backmesh is an open-source backend that protects LLM API keys and acts as an API Gatekeeper, providing JWT-based authentication, per-user rate limits, resource access controls, and instrumentation for LLM usage analytics to help apps safely call LLM APIs and reduce costs.
adversa-ai
Adversa AI provides a coding-agent security platform — a runtime control layer that observes and blocks dangerous actions by AI coding agents, performs continuous adversarial testing, and delivers audit-ready evidence and remediation for enterprises running mission-critical AI.
loginllama
LoginLlama is a login-risk scoring API and SDK suite that evaluates each login with a 0–10 risk score (credential stuffing, account takeover, bot traffic) and actionable risk codes so apps can allow, step up to MFA, or block in real time.
idwise-identity-verification-ekyc-aml
IDWise is an enterprise-grade, AI-based identity verification and e-KYC/AML platform that provides document recognition, biometric facial verification, proof-of-address capture, and global AML/PEP/sanctions screening to onboard customers quickly and prevent fraud.