Kastra
Authorization layer for AI systems — checks every AI action (prompts, tool calls, shell commands) against policy before it runs, in under a millisecond.
| What is it | Authorization layer for AI systems — checks every AI action (prompts, tool calls, shell commands) against policy before it runs, in under a millisecond. |
|---|---|
| Pricing | Freemium — from $19.99/mo |
| Free tier | Yes |
| Platform | Web Application |
| API | Yes |
| Best for | preventing AI agents from deleting production databases or reading secrets, enforcing policy on developer laptops for Claude Code, Cursor, and Codex CLI |
| Domain registered | 2025 |
Data updated Aug. 1, 2026
What does Kastra do?
Kastra is an authorization layer designed specifically for AI systems. It sits between your AI agents (like Claude Code, Cursor, or custom agents) and the tools, databases, and APIs they interact with. Before any action executes — whether it's a shell command, a file write, a database query, or an API call — Kastra checks it against your policy and either allows or denies it. The whole decision takes less than a millisecond. This isn't monitoring or logging after the fact; it's real-time enforcement that stops risky actions before they happen.
Kastra works through a four-step pipeline: identity verification, scope evaluation, guardrail matching, and signed audit logging. You write policies using a typed DSL that feels like code — version-controlled and reviewable. The tool runs in multiple deployment models: cloud, self-hosted, or air-gapped. It also offers Kastra Edge, a local daemon that governs coding agents on developer laptops, and Kastra Recon, which scans your AI's history to surface past risky actions and draft policies for them. Every decision is signed and replayable, making audits straightforward.
This tool is built for engineering and security teams that need to govern autonomous AI agents without slowing down development. It's especially useful in regulated industries like finance and healthcare, where you need to prove that AI actions are controlled and auditable. If you're running AI coding agents, browser automation, or any autonomous workflow, Kastra gives you a way to say "no" before something bad happens — not after.
Key features
What makes it stand outWho is Kastra for?
Who benefits most from this toolPricing
Free tier available — start without a credit cardFree
- 1 developer · 1 machine
- 50K authorization decisions / month
- 7-day audit retention
- Claude Code + Codex CLI support
- Prebuilt safety packs
- Shadow mode + destructive-action blocking
- Local machine governance
- Kastra Recon scan
- Kastra Edge local enforcement
- Community support
Pro
- 1 developer · 1 machine
- 1M authorization decisions / month
- 90-day audit retention
- Custom policies + versioning
- Plain-English AI rule generation
- YAML + UI-based policy management
- Kastra Recon with auto-drafted policies
- Kastra Edge on every machine
- Slack + webhook alerts
- CSV / JSON audit exports
- Priority support
Team
- Pooled authorization infrastructure
- 10M authorization decisions / month
- Shared audit infrastructure
- 1-year+ audit retention
- Centralized policy management
- Admin-enforced policies
- Mandatory runtime enforcement
- Cross-machine policy synchronization
- Fleet-wide audit visibility
- Team-wide Kastra Recon
- Fleet-wide Kastra Edge enforcement
- Usage analytics
- Team onboarding + fast support
Enterprise
- Unlimited authorization scale
- Multi-region deployments
- Self-hosted + private cloud
- Advanced RBAC, SSO / SAML
- Dedicated VPC infrastructure
- Compliance + extended retention
- Enterprise SLAs + incident response
- Dedicated runtime governance architecture reviews
- Custom Kastra Recon deployments
- Custom Kastra Edge fleet rollouts
- Custom integrations + regulatory support
Trust & presence
Gallery
Click any image to enlargeAlternatives in Developer Tools
Drop-in security layer for AI agents — blocks prompt injections, redacts secrets, and cuts token costs automatically.
Real-time AI code review that catches bugs and security risks as you type, directly in your IDE.
AI output verification layer — checks, fixes, and blocks unsafe AI responses before they reach users or systems.
A desktop IDE for running multiple AI coding agents (like Claude Code) in parallel with integrated terminals and worktrees.
TypeScript framework for building AI agents with tools for workflows, RAG, memory, and deployment
Blocks AI coding agents from reading secrets, running risky commands, or making dangerous config changes before they execute
Managed control plane for AI agents — policy enforcement, audit trails, and human-in-the-loop approvals.
Security control plane for AI agents — enforce least-privilege access, block PII leaks, and get readable audit logs.