Keycard
Keycard Labs operates a control plane for autonomous AI agents, resolving composite identity, enforcing runtime policy, issuing short-lived task-scoped credentials, and streaming audit telemetry. It serves enterprise security teams and developers deploying AI agents across engineering, sales, marketing, and finance functions.
- Company typePrivate
- Founded-
- Headquarters—
- Headcount—
- GTM typeB2B
- OfferingSoftware
What Keycard does
Keycard Labs, Inc. is a Delaware-incorporated company building a control plane for autonomous AI agents. The platform resolves composite identity from execution context — combining user, device, agent workload, and task — and enforces runtime policy at the moment credentials are issued. Short-lived, task-scoped credentials are issued via a Security Token Service (STS) exchange, and tamper-resistant audit telemetry is streamed to downstream SIEM systems. Keycard serves enterprise security and IT teams deploying AI agents across Engineering, Sales, Marketing, and Finance functions, as well as developers building agent applications through its TypeScript/JavaScript SDK, keycard run CLI, and Model Context Protocol (MCP) server integrations.
The product surface spans the Keycard Platform (core control plane), SDK, CLI, STS Exchange, Dashboard, Agent Tool Catalog, and The Loop (adaptive policy learning). Underlying technology includes SPIFFE-based workload attestation, OAuth 2.1 + PKCE, and mTLS certificates, with pre-built integrations against Okta SSO, Datadog, Linear, GitHub, Slack, Salesforce, AWS S3, PostgreSQL, Google Workspace, and HubSpot. Pricing is not publicly disclosed and the product is currently in early access, with developer-led adoption (SDK self-service) supplemented by an enterprise field sales motion for larger deployments. Keycard has achieved SOC 2 Type II certification and maintains category thought leadership through its Insecure Agents podcast and event presence at AI Engineer World's Fair.
The business model is enterprise SaaS subscription, with revenue mechanics not yet visible at the early access stage. No funding rounds, headcount, or named customer references are disclosed; operational telemetry reports approximately 127 developers on the platform and ~2,847 agent requests per day.
Keycard firmographics
Firmographics- Name
- Keycard
- Legal name
- Keycard Labs, Inc.
- Website
- https://keycard.sh
- Company type
- Private
- Operating status
- Operating
- Short description
- Keycard Labs operates a control plane for autonomous AI agents, resolving composite identity, enforcing runtime policy, issuing short-lived task-scoped credentials, and streaming audit telemetry. It serves enterprise security teams and developers deploying AI agents across engineering, sales, marketing, and finance functions.
- Ownership category
- akta.pro rank
Keycard industry classification
Industry- Product category
- AI Agent Identity Governance
- NAICS
- Software Publishers (513210)
- SIC
- Services-Computer Programming, Data Processing, Etc. (7370)
- akta.pro primary industry
- Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies) (HDAEANAE)
- akta.pro secondary industries
- Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII) (HDAEANAG), Identity, Access & Secrets Management for AI Systems (IAM for agents/models) (HDAAAKAJ), Audit, Explainability & Accountability Tooling (traceability, reporting) (HDAAAKAL)
Keywords
Keycard business model
Business model- GTM type
- B2B
- Offering type
- Software
- Cost components
- Personnel, Technology or R&D, Marketing or Sales, Infrastructure, Operations
Revenue model
- SaaS Subscription: Enterprise security and governance platform sold via subscription. Pricing likely tiered by agent volume or enterprise seat count. Currently in early access phase.
Go-to-market motion2 records
Distribution channels4 records
Marketing channels8 records
Keycard product offering
Product offeringCore offering
Keycard provides a control plane for autonomous AI agents that resolves composite identity (user + device + agent + task), enforces runtime policy at credential issuance, issues short-lived task-scoped credentials, and streams tamper-resistant audit telemetry to SIEM. The platform includes an SDK for embedding auth into MCP, CLI, or API surfaces and a CLI tool for governing coding agents in development workflows.
Product overview
Keycard is a unified control plane for autonomous agents, consisting of a core platform and several integrated sub-products: the Keycard SDK (TypeScript/JavaScript) for embedding auth into any agent surface, the keycard run CLI for governing coding agents, the STS Exchange for token-scoped downstream access, a real-time Dashboard for governance and compliance monitoring, an Agent Tool Catalog for department-scoped tool management, and The Loop for adaptive policy learning. The platform operates across MCP servers, CLI tools, and API surfaces, binding identity, policy, access, and audit into a single governed system.
Differentiator
Problem solved
Functional benefit
Products and services
- Keycard Platform The primary control plane for autonomous agents. Keycard resolves composite identity (user + device + agent + task), enforces runtime policy at credential issuance, issues short-lived task-scoped credentials, and streams tamper-resistant audit telemetry to SIEM. All four core functions (Identity, Policy, Access, Audit) operate as an integrated system for enterprise IT and security teams.
- Keycard SDK TypeScript/JavaScript SDK for integrating KeycardAuth into any agent surface (MCP, CLI, or API). One import provides full auth context: user, agent, task, device, and environment. SDK handles OAuth 2.1 + PKCE, credential caching, task-scoped tokens, and automatic refresh. Designed for developers and companies building autonomous AI agents.
- keycard run CLI command for governing coding agents such as Claude Code and Cursor. Virtualizes .env and mcp.json so credentials never touch disk. Every execution path (shell, MCP tools, agent-written code) is audited in real time. Disallowed tools are purged automatically.
- STS (Secure Token Service) Exchange Token exchange service: one Keycard JWT in exchange for scoped, short-lived credentials to downstream services (Google Calendar, GitHub, AWS S3, etc.). Keycard issues the credential but never proxies the data; the token goes straight to the API.
- Keycard Dashboard Real-time governance dashboard showing agent requests, success rate, auto-approved vs. user-approved vs. stopped actions, session playback with tool call timelines, and per-department event feeds with compliance metrics.
- Agent Tool Catalog Department-scoped catalog of agent tools. Admins discover, install, block, or approve tools per department (Marketing, Sales, Engineering, Finance). Every install, block, and denial is logged in real time.
- The Loop Adaptive policy learning cycle. Agent requests feed into telemetry, which updates the context graph and redefines policy rules, enabling progressively higher auto-approval rates over time (from 72% in week 1 to 94%+ by week 12).
- Keycard for Multi-Agent Apps Extension of the Keycard control plane designed for multi-agent applications. Governs access, identity, and policy for applications where multiple agents work together.
Companies that use Keycard
Customer profileSegments5 records
Ideal customer profiles2 records
Keycard technology and API
TechnologyTechnology focussed Yes
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
Integration13 records
AI capability4 records
Feature7 records
Keycard partnerships and signals
Strategic signalScale indicators8 records
Recent moves5 records
Expansion highlights5 records
Keycard competitors and assessment
Company assessmentBroad incumbents
- CyberArk: Privileged access management incumbent with deep enterprise penetration and machine-identity offerings. Comparable to Keycard because CyberArk is extending PAM concepts (least privilege, session isolation, audit) into machine and AI-agent identities.
- Okta: Leading identity provider with SSO, lifecycle management, and a growing portfolio of identity-governance products. Comparable to Keycard because Okta is the federated identity provider Keycard relies on, and Okta's roadmap into AI-agent identity is a direct competitive vector.
- HashiCorp Vault: Industry-standard secrets management and dynamic credential broker with token issuance, lease/TTL, and policy controls. Comparable to Keycard because Vault's short-lived dynamic secrets, policies, and audit logs are the closest incumbent analog to Keycard's STS + policy engine approach.
Direct peers
- Aembit: Workload identity and access management for non-human identities (services, APIs, automation). Comparable to Keycard because both treat machine/non-human identity as a first-class IAM problem and issue scoped, short-lived credentials at runtime.
- Scytale: Workload identity platform built on SPIFFE for service-to-service authentication and mTLS. Comparable to Keycard because both lean on SPIFFE-style workload attestation as a primitive of composite identity and use it to issue short-lived credentials to non-human actors.
- Styra: Creator of Open Policy Agent (OPA) and a policy-as-code platform for authorization across services, Kubernetes, and APIs. Comparable to Keycard because both center on runtime policy evaluation as the gating mechanism for access, with audit trails attached to every decision.
- Cerbos: Authorization-as-a-service that evaluates fine-grained policies at request time. Comparable to Keycard because both decouple policy decision from application logic and emphasize policy authoring, testing, and rollback — directly analogous to Keycard's 'observe-only mode' and instant rollback.
Emerging players
- Beyond Identity: Passwordless and device-bound identity platform using device attestation. Comparable to Keycard because Beyond Identity is pushing device-attestation-style identity (a key input in Keycard's composite identity graph) into enterprise workforce and machine-identity workflows.
- Doppler: Developer-focused secrets and configuration management platform. Comparable to Keycard because Doppler is an emerging player in the secrets/credentials-for-modern-workflows category and overlaps in the developer-tooling GTM motion.
- Scalekit: Authentication and user management infrastructure aimed at modern SaaS and AI applications. Comparable to Keycard because Scalekit addresses the developer-first authentication-and-credentials layer for AI-driven products, overlapping on token issuance and B2B SSO.
Market position
Strengths4 records
Weaknesses4 records
Competitive moat5 records
Key risks5 records
Key highlights6 records
Customer concentration
Keycard social profiles
Digital presenceKeycard compliance and trust
Trust signalCompliance1 record
Keycard financial estimates
Financial estimateRevenue estimate
Valuation estimate
Keycard leadership team
Management profileNumber of profiles
Keycard funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Keycard M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Keycard
What does Keycard do?
Keycard provides a control plane for autonomous AI agents that resolves composite identity (user + device + agent + task), enforces runtime policy at credential issuance, issues short-lived task-scoped credentials, and streams tamper-resistant audit telemetry to SIEM. The platform includes an SDK for embedding auth into MCP, CLI, or API surfaces and a CLI tool for governing coding agents in development workflows.
Is Keycard a public or private company?
Keycard is a private company. It is classified as venture growth investor backed and is currently operating.
When was Keycard founded?
Keycard was founded in -1.
How does Keycard make money?
One revenue line is on record: saaS Subscription.
Who are Keycard's main competitors?
Broad incumbents on record are CyberArk, Okta and HashiCorp Vault. Direct peers are Aembit, Scytale, Styra and Cerbos. Emerging players are Beyond Identity, Doppler and Scalekit.
Does Keycard have an API?
Yes. Keycard provides an SDK-based API for agent authentication and authorization. The SDK handles OAuth 2.1 + PKCE, agent identity binding, credential caching, task-scoped tokens, and automatic refresh. A Secure Token Service (STS) client enables token exchange — one Keycard token in exchange for scoped access to downstream services (e.g., Google Calendar, GitHub, AWS S3). Documentation is available at docs.keycard.ai. Developer documentation is at docs.keycard.ai.
What industry is Keycard in?
Keycard's product category is AI Agent Identity Governance. Its primary akta.pro industry code is HDAEANAE, Enterprise AI Governance, Risk & Compliance Platforms (Model Risk, Audit, Policies), with a secondary code of HDAEANAG, Responsible AI, Security & Privacy Platforms (Safety, Guardrails, PII). Its NAICS code is 513210 and its SIC code is 7370.