Pricing

Open protocol. Paid managed infrastructure.

Run the entire stack yourself — protocol, SDKs, verifier, signing — for $0. Or use our managed infrastructure with API keys, rate limits, SLA, and a single bill. The free tier is generous; paid tiers exist because real production deployments need uptime guarantees and operational support.

Product 1

Verifier API

Hosted verification at verify.agentpki.dev. Mint, verify, intent_check, replay cache, audit log.

USD · per month · launch pricing, may change

Free

$0

forever

10,000 verifies / month

  • All v0.3 + Provenance v0.1 features
  • No API key required
  • Shared rate limit by IP
  • Community support
  • No SLA
  • No retention guarantee
Start playing →

Pro

$499

/ month

10,000,000 verifies / month

  • Everything in Team
  • Mode B replay-cache priority
  • Intent audit log 1-year retention
  • 99.9% uptime SLA
  • Webhook notifications included
  • $0.00002 per call over quota

Enterprise

Custom

per-vendor terms

Unlimited verifies

  • Dedicated verifier endpoint
  • EU / US / APAC data residency
  • 99.99% uptime SLA
  • SSO + SAML, audit reports
  • On-prem licensing available
  • SOC 2 attestation roadmap

Product 2

Signing-as-a-Service

You publish content. We hold your Ed25519 keys (encrypted at rest), you POST content, we return signed manifests. Hosted at signing.agentpki.dev.

Hobby

$0

forever

100 signatures / month

  • One issuer keypair, we manage
  • Content-Provenance header output
  • Sidecar manifest output
  • Community support
  • No key rotation API
  • No SLA
Sign up →

Newsroom

$499

/ month

100,000 signatures / month

  • Everything in Publisher
  • Multiple writer keypairs (~50)
  • Audit log + compliance report PDF
  • 99.9% signing SLA
  • Webhook on each signature
  • $0.004 per signature over quota

Enterprise

Custom

per-publisher terms

Unlimited signatures

  • HSM / KMS key custody
  • EU data residency
  • SOC 2 attestation roadmap
  • 99.99% signing SLA
  • SSO + SAML
  • Custom integration support

What happens when you click Subscribe →

Stripe Checkout → webhook → automatic key provisioning → email with your API key. Eight-step walkthrough — same call sequence the live system runs.

💳
Scenario: A customer subscribes to the Team plan from /pricing. Stripe handles payment; the webhook fires to AgentPKI; the verifier provisions an api_key; Resend emails it to the customer. End-to-end in seconds.
👤 Customer on /pricing 💳 Stripe Checkout hosted 📨 Webhook /v1/webhooks/stripe 🔐 Verifier provisionApiKey() 💾 KV storage apikey:apk_… ✉️ Resend email api_key delivered 📊 /account usage + billing portal Subscribe payment subscription.created write key send email link key → /account
Step 0 of 6
Ready to start.
Click Play to watch a Team subscription land an api_key in the customer's inbox.

Bot-defense + AI infrastructure vendors

Different model for partnership channels.

Cloudflare, Akamai, HUMAN, DataDome, Arkose, Kasada, and adjacent vendors integrate AgentPKI as a signal inside their existing products. We don't charge per-verify in those deployments. Pricing is OEM licensing or revenue share, negotiated per-vendor. Reach out for terms.

FAQ

Can I self-host instead?
Yes. Entire protocol is Apache 2.0; reference implementation runs on any Cloudflare Workers account for ~$5/month + usage. Trade-off is operational lift; managed pricing buys you that lift back.
What happens at the rate limit?
Free tier: shared 10K/month per IP, HTTP 429 after. Paid tiers: per-API-key quota with overage pricing. Usage surfaced via X-RateLimit headers and Retry-After.
Is there a free trial of paid tiers?
The Free tier IS the trial. It supports real prototyping (10K verifies = ~250K test runs of the demo flows). If prototyping needs more, you're in revenue territory.
Where do you store our signing keys?
Hobby / Publisher / Newsroom: AES-256-GCM encrypted at rest in Cloudflare KV, keyed with a KEK held in Workers Secrets. Enterprise: HSM custody available with your KMS provider (AWS KMS, GCP KMS, Azure Key Vault).
What if EU AI Act enforcement starts and I'm still on Hobby?
You'll want Newsroom or Enterprise for the audit log + compliance report. Migration is one API call; your keys, signatures, and audit history all carry over.
Annual billing?
2 months free on annual for Team / Pro / Publisher / Newsroom. Enterprise is annual by default.

Most teams start on Free. Talk to me before you commit on Enterprise.

I'm the founder. If you're considering AgentPKI for production, I want to make sure the protocol fits your problem before money changes hands. Honest 30 minutes.

Talk to Founder

Personal reply from Founder within 48 hours. Tell us a bit about you — what you're building, what you'd want from AgentPKI, anything you want to push back on.

By submitting, you agree we can email you back. We don't share leads, ever.