Programmable
For anyone building AI agents

Safe tool access for AI agents

One MCP endpoint per tenant and actor, in front of vendor MCP servers, our own provider records and built-in tools. The same guardrails apply to every call, whichever route it takes.

How it works

Your app gets a server key

Register once. Keys are shown once, stored only as a hash, and can be rotated without downtime.

Tenants connect their tools

Each of your tenants signs in to Slack, Notion, GitHub and more on our hosted page. Credentials stay encrypted here.

Agents call one MCP endpoint

A short-lived token per actor opens /mcp/<tenant>/<actor>: only granted tools, capped per day, approval before risky calls.

Guardrails on every call

Programmable Dev never calls a model. It owns everything between “an agent wants to act in another app” and “the call happened, safely, and was logged”.

  • Grants per actor, read live on every call
  • Daily caps and approvals bound to what the approver saw
  • Every call logged with its cost
  • Results marked as untrusted outside text
  • Tenant isolation proven by tests
  • Licence-clean provider records