Statiostatio
PricingBlogStart free
Governed MCP access. Live in five minutes.

One click connects your whole team to an MCP server. One click decides which tools their agents can touch. No EDR, no MDM, no sales call.

Start freeSee pricing
Works without an EDR·Set up in minutes·Encrypted at rest
Access Control
Per-tool accessEXECUTE
addALLOWED
echoALLOWED
getTinyImageALLOWED
printEnvDENIED
sampleLLMDENIED
Works with the AI clients your team already uses
Claude CodeClaude DesktopCursorWindsurfVS CodeClineContinueZedAmazon Q
One token. Zero exposed keys.

Stop scattering API keys across agent configs. Credentials stay in the vault. Agents only see a single token.

Keys stored in vault, never exposed
Instant credential rotation
Every API call logged with identity
Without Statio
{ "mcpServers": { "stripe": { "env": { "STRIPE_KEY": "sk_live_..." } }, "github": { "env": { "GITHUB_TOKEN": "ghp_..." } }, "slack": { "env": { "SLACK_TOKEN": "xoxb-..." } } } }
With Statio
{ "mcpServers": { "statio": { "env": { "STATIO_TOKEN": "eyJ..." } } } }
What it doesGive your team access. Keep control of it.

Connect every developer in minutes. See what agents actually do. Decide what they can touch.

One-Click ProvisioningConnect your whole team to an MCP server in one click — Claude Code, Claude Desktop, Cursor, Windsurf, VS Code and more. No hand-edited JSON, and new hires get the approved set on day one.
Shadow MCP DiscoverySee every MCP server your team has installed, including the ones nobody approved. No EDR or MDM required — most tools can't see this without one.
Access PoliciesGrant or revoke a tool in one click. Permissions are per tool, not per server, and enforced on every request at the gateway.
Pre-built CatalogOfficial MCP servers, hosted and kept working — Stripe, GitHub, Notion and more.
Credential VaultingKeys encrypted at rest and fetched at call time. Agents never see raw credentials.
Audit TrailsEvery tool call logged with identity, timestamp, and outcome. Stream it to your SIEM.
Fleet — dans-mbp2 UNAPPROVED
stripeClaude Desktop
MANAGED
githubClaude Code
MANAGED
internal-hr-apiCursor
EXTERNAL
notion-personalClaude Desktop
EXTERNAL
jiraClaude Code
MANAGED
Desktop app + CLIShadow AI discovery, without CrowdStrike.

Most tools discover unapproved MCP servers by reading your EDR or MDM. If you don't have one — and most teams under a few hundred people don't — they see nothing. Statio ships its own lightweight agent, so discovery works on day one.

How it works

Your agents talk to Statio. Statio fetches credentials from the vault, then routes to the MCP server. Keys never leave our infrastructure.

AI AgentClaude, GPT, etc.StatioGatewayValidate + RouteVaultCredentialsMCP ServerStripe, GitHub, etc.ExternalAPIJWTfetch creds+ credentialsAPI callYour configOur infrastructureExternal service
Gateway validates JWT, routes request
Vault provides credentials securely
MCP server calls external API with creds
Who it's forBuilt for both sides of the API.

Whether you consume APIs or provide them. Same checkpoint, same security.

For AI Agent Developers

Connect agents to APIs without scattering keys across every config file.

-One token replaces dozens of API keys
-Instant credential rotation without redeploying
-Works with Claude, GPT, any MCP client
Learn more
For API Providers
Expose your API to the AI ecosystem with zero infrastructure to build.
Learn more
For Enterprise Security
Govern your agents' API access with policies and complete audit trails.
Learn more
Shipped recentlyStatio is under active development. Here's what landed most recently.
August 2026
Self-serve capacityBuy additional hosted MCP servers and turn on usage overage from the billing page, with a spend cap you set.
August 2026
Per-tool access policiesGrant access to individual tools rather than whole servers, enforced at the gateway on every request.
July 2026
Fleet MCP discoveryFind every MCP server installed across your team, including the ones nobody approved — without an EDR or MDM.
July 2026
SIEM exportStream signed audit events of every tool call to your existing security tooling.
Full changelog
Simple pricing. Scale when you need to.

Start free. Upgrade when your usage demands it.

Free
$0
Evaluate Statio. Hard limits, never a surprise bill.
3 MCP servers
5,000 API calls/month
1 member
Catalog + external URLs
Credential vaulting
Developer
$19/mo
For a solo developer running agents in production.
10 MCP servers
3 hosted from your own spec
25,000 API calls/month
1 member
Full catalog
90-day audit logs
Most Popular
Team
$99/mo
For teams sharing one governed endpoint.
25 MCP servers
10 hosted from your own spec
250,000 API calls/month
Up to 25 members
Per-tool access policies
Fleet MCP discovery
Business
$349/mo
For organizations that have to answer to a security review.
Unlimited MCP servers
50 hosted from your own spec
1,000,000 API calls/month
Unlimited members
SSO / SAML
Full RBAC
1-year logs + SIEM export
EnterpriseUnlimited servers and members, custom call volume, 99.9% SLA, SOC 2 reports, bring-your-own proxy, and a named contact.
Talk to us
Pay annually and get 2 months free. Additional hosted MCP servers are $5/month each. Need more calls? Turn on overage billing for $9 per additional 100,000 — off by default, with a spend cap you set.
Common questions
Why not just run an MCP gateway myself?
How is this different from an enterprise AI governance platform?
What happens when I hit my call limit?
What counts as a hosted MCP server?
Are members billed per seat?
Can I switch plans or cancel anytime?
How long are audit logs retained?
Ready to connect your team?Free to start. No card required.Start free
Statiostatio
Security-first MCP governance for AI agents. Credential vaulting, access policies, audit trails.Open source on GitHub
ProductFeaturesPricingGetting StartedSecurityChangelogmcp-gen
LegalPrivacy PolicyTerms of Service
© 2026 Statio. A product of SID Technologies.