Start on Free, upgrade the moment you need more. Talk to us if you're bigger.
Permisyn puts a pre-execution authorization layer in front of your model providers — for teams running shared company model access, internal copilots, or agent traffic who need control before requests hit OpenAI or Anthropic, not observability after the fact.
For evaluation
Free
$0forever
Real limits from the first request, no card required, no countdown. Upgrade any time from your dashboard the moment you need more.
2
Agents
2
Team seats
20
Req / min
Includes:
Pre-execution authorization on every agent call
MCP Gateway — wrap any MCP server, signed receipt either way
Basic agent passports (models, providers, budget)
Signed receipts + kill switch & freeze safety controls
Team & user-level freeze granularity, not just org-wide
Full transparency log + offline receipt verifier
Append-only proof — pin a tree head and check nothing was rewritten
Proof carried on the response, checkable in your own process
When someone else starts asking how you control your agents — signed attestations you can hand to a customer, and authority you can extend past your own org.
15
Agents
10
Team seats
300
Req / min
Everything in Starter, plus:
SOC 2 & EU AI Act attestations — signed, verifiable by your customer
Portable agent credentials — scoped authority that leaves your org
Cross-org agent visas — let a partner's agent act under your terms
One video support call a month — a real slot on the calendar
Everything auditors, security, and regulators ask for — the full attestation set, an auditor portal, and enforced secrets, in one bundle. Talk to us and we'll size it to your traffic.
Every account starts on Free, no card required — pick a plan any time from your dashboard whenever you need more. Each plan also has a short per-minute burst limit, separate from the monthly request count above — see how it works in the developer guide.
Pre-execution authorization
Every call is checked against model, budget, and passport before it reaches OpenAI, Anthropic, or any other provider — not logged after the fact.
Org-side controls
Model restrictions, per-agent cost caps, and an org-wide freeze switch — enforced at the boundary, no redeploy required to change them.
Signed evidence
Every governed decision — allowed or denied — is Ed25519-signed into a receipt your security or compliance team can independently verify.
Agent identity
Each AI worker gets a signed passport: who owns it, what it's allowed to call, and what it's allowed to spend.
Compare plans
Everything in every plan, side by side.
Including the rows where every plan is the same. A table that only listed what you don't get would read as a paywall map, and some of the things we'd have left out — the signed receipts, the transparency log, the kill switch — are the point of the product.
Free
$0
Starter
$19/mo
Pro
$40/mo
Business
Contact us
Limits
Authorized requests / month
Paid plans keep being served 20% past this before anything is refused. Free stops at its number.
2,000
25,000
100,000
500,000
Sandbox requests / month
A separate test partition on every plan, with its own agents, receipts and quota. Spending it never touches your live allowance, and no grace band applies.
500
5,000
20,000
50,000
Request rate
Sustained rate plus the burst that can arrive at once, so one runaway loop cannot spend the month in an afternoon. The allowance refills continuously — idle for a moment and you can spend the burst immediately, then you settle back to the sustained rate. Business is sized in the sales conversation rather than published as a self-serve number: its higher ceiling hasn't had the same real multi-tenant load test the self-serve tiers' numbers have.
20/min · burst 10
60/min · burst 10
300/min · burst 50
Custom
Governed agents
2
5
15
75
Team seats
2
3
10
25
Encrypted provider keys
1
3
Unlimited
Unlimited
Shareable header profiles
1
3
Unlimited
Unlimited
Audit history
7 days
30 days
90 days
1 year
Control before the call
Pre-execution authorization on every call
Checked before the request reaches the provider — not logged after it.
One allowed_actions allow-list, checked the same way whether the call is a declared LLM tool or an MCP server's tools/call.
Agent passports — models, providers, budget
Kill switch, org freeze, team & user halts
Never plan-gated. A safety control stays available even on a lapsed trial.
Passport role templates & autopilot baselines
Proof you can hand to someone else
Ed25519-signed receipt for every decision
Transparency log + offline verifier
Anyone can re-check a proof without trusting us, on every plan. The verifier is a published package — permisyn-verify on PyPI, @permisyn/verify on npm — not a snippet to copy.
Append-only proof against a head you pinned
Inclusion proofs cannot see a log rebuilt overnight; a consistency proof against a head you recorded earlier can. Public endpoints with no plan gate, plus a monitor cron that alarms only on a real contradiction.
Proof carried on the response itself
Opt in per call and the response carries a signed token, so the code holding the answer verifies the decision in-process instead of asking us and believing the reply.
Waste ledger figures
Signed waste statement
The figures are on every plan; this is the artifact an auditor can verify.
Compliance attestations
SOC 2, EU AI Act
All six
Auditor / regulator portal
AI Bill of Materials
Working with other agents
Chain of custody across your own agents
Outbound webhooks
Trace export to your own observability stack
OpenTelemetry spans carrying the decision, our overhead, and a link to the receipt — in the Datadog or Honeycomb you already watch.
Portable agent credentials
A scoped, short-lived credential the holder can present elsewhere.
Cross-org agent visas
Another company's agent acting under terms you set.
Enforced Secrets — zero-knowledge redaction
Support
Async support
Video support calls
A real slot on a real calendar, which is its own limit.
1 / month
Uncounted
Enterprise sets every limit above by agreement, and adds private, edge, or self-hosted deployment. The monthly count is what your plan includes, not a shutter: on any paid plan we keep serving past it — 20% over — and tell you where you stand, so a launch or a retry storm can't take your agents down while you sort out a plan. Free stops at its number. Neither counts blocked or failed calls: only calls we actually authorized through to your provider. Sandbox is metered on its own, with no grace band — a load test spends the sandbox number and leaves your live one untouched.
Book a free demo
Tell me what you'd put behind Permisyn.
Fill this out and I'll follow up personally — usually within a day — to walk you through Permisyn and understand your traffic before we talk infrastructure. Not ready to talk to anyone? The first two cards beside it are the ways past me.
Start free — no card, no form, and the stop button works on every plan. Or read the docs first and decide from the API rather than from a call.
What happens after you hit send
Every step of it, so none of it is a surprise.
1
Straight to my inbox
A confirmation lands in yours immediately; the details land in mine, with your address as the reply-to. Nothing is routed to a sales team, because there isn't one.
2
A reply from me, usually within a day
If you asked a question, you get the answer. If you want to talk, you get times — and if the honest answer is that Permisyn isn't a fit for what you described, you get that instead.
3
25 minutes, your traffic first
Which agents, which providers, what you need to stop before it happens. Your setup on screen if you want it, not a deck.
And if you go quiet, nothing chases you: there is no drip and no nurture track to be added to.