Keycard provides a security platform that controls AI agents’ access to tools, APIs, and data by building a composite identity from the execution context and enforcing policies at the request gate. It offers real‑time policy evaluation with observe‑only testing, detailed audit trails, and instant rollback of policy changes, ensuring that only authorized actions are permitted.
Funding
$30M raised to dateRaised to date based on public sources. This may differ from the amount the company actually raised and is based only on what is publicly available on the internet.
1OFounders
Product
Problem
AI agents and autonomous workloads often operate without granular identity, policy enforcement, or audit trails, leading to over‑privileged access, credential leakage, and difficulty tracking actions across tools, APIs, and data stores.
Solution
Keycard provides a control plane that assigns a composite identity to every agent based on its execution context and enforces fine‑grained access policies at the edge of each request. Policies are authored visually, can be tested in observe‑only mode against live traffic, and rolled back instantly. The platform issues short‑lived, scoped credentials only when policy permits, and logs each authorization decision for full auditability. Integrated SDKs and CLI enable developers to embed identity, token exchange, and policy checks directly into agents, services, and multi‑agent systems without managing static secrets. Real‑time telemetry and export capabilities give teams visibility into agent activity and compliance across any cloud or on‑prem environment.
Target Audience
Keycard is aimed at developers and security teams building autonomous agents, multi‑agent applications, or any workload that needs programmatic, policy‑driven access to APIs, tools, and data across cloud and on‑prem environments.
Features
- Composite identity graph that resolves agent, workload, device, and user attributes from the full execution context
- Edge‑based policy evaluation with visual authoring, observe‑only testing, and instant rollback of policy changes
- Support for RBAC, ABAC, and ReBAC models, including app binding, zone, organization, and device‑based policies
- Automatic issuance of short‑lived, scoped credentials per request; no static API keys required
- Full audit log of every authorization decision with real‑time telemetry and configurable export to SIEM or data warehouses
- SDKs and CLI for Python, TypeScript, OAuth primitives, MCP, and agent‑to‑agent protocols to integrate Keycard into any codebase
- Multi‑tenant SaaS, dedicated, BYOC, or on‑prem deployment options with customer‑managed KMS and private networking