For anyone building AI agents
Safe tool access for AI agents
One MCP endpoint per tenant and actor, in front of vendor MCP servers, our own provider records and built-in tools. The same guardrails apply to every call, whichever route it takes.
How it works
Your app gets a server key
Register once. Keys are shown once, stored only as a hash, and can be rotated without downtime.
Tenants connect their tools
Each of your tenants signs in to Slack, Notion, GitHub and more on our hosted page. Credentials stay encrypted here.
Agents call one MCP endpoint
A short-lived token per actor opens /mcp/<tenant>/<actor>: only granted tools, capped per day, approval before risky calls.
Guardrails on every call
Programmable Dev never calls a model. It owns everything between “an agent wants to act in another app” and “the call happened, safely, and was logged”.
- Grants per actor, read live on every call
- Daily caps and approvals bound to what the approver saw
- Every call logged with its cost
- Results marked as untrusted outside text
- Tenant isolation proven by tests
- Licence-clean provider records