Start free.
Scale when you need to.
The open source server is the complete product — AGPL-3.0, every protocol feature included. Add AuthPlane EE for enterprise support, or let us run it for you with AuthPlane Cloud.
Self-hosted
Run AuthPlane on your own infrastructure. The OSS server is fully featured; EE adds enterprise support and licensing.
Open Source
The complete auth server. Every protocol feature included — no gates.
- OAuth 2.1 + S256 PKCE
- Token Vault — encrypted upstream credentials
- DPoP proof-of-possession
- Token Exchange + agent delegation
- XAA + OIDC federation (Okta, Entra, Google, Auth0)
- Admin UI, audit log, Prometheus + OTel
- PostgreSQL + SQLite · Helm chart
AuthPlane EE
For enterprises that self-host but need more than community support.
- Everything in Open Source
- Commercial license — no AGPL obligations
- Support SLA with private channel
- Security advisories + long-term support
- Enterprise features as they land
- Deployment & architecture review
AuthPlane Cloud
Coming soonThe managed SaaS — same server, zero infrastructure. Standard tiers at launch.
A hosted instance to try AuthPlane without running anything.
For small teams shipping their first authenticated MCP servers.
Production workloads with higher limits and priority support.
SSO, custom SLAs, and dedicated infrastructure.
Feature comparison
| Feature | Open Source | AuthPlane EE | AuthPlane Cloud |
|---|---|---|---|
| Protocol & auth — never gated | |||
| OAuth 2.1 + S256 PKCE | ✓ | ✓ | ✓ |
| Token Vault (encrypted upstream credentials) | ✓ | ✓ | ✓ |
| DPoP proof-of-possession | ✓ | ✓ | ✓ |
| Token Exchange + agent delegation | ✓ | ✓ | ✓ |
| OIDC federation + XAA (ID-JAG) | ✓ | ✓ | ✓ |
| Admin UI, audit log, Prometheus + OTel | ✓ | ✓ | ✓ |
| License & hosting | |||
| License | AGPL-3.0 | Commercial | Hosted service |
| Runs on | Your infra | Your infra | Our infra |
| Air-gap + offline deployment | ✓ | ✓ | — |
| Updates | Self-managed | LTS guidance | Automatic |
| Support | |||
| Community (GitHub Issues) | ✓ | ✓ | ✓ |
| Support SLA + private channel | — | ✓ | Paid tiers |
| Security advisories + LTS | — | ✓ | Included |
| Deployment & architecture review | — | ✓ | Enterprise |
Why AuthPlane wins.
| Feature | AuthPlane | Others |
|---|---|---|
| Self-Hosted | ✓ | ✗ Cloud-only or bloated |
| MCP-Native Auth | ✓ | ✗ Gateway or generic OAuth |
| Built-in Auth Server | ✓ | ✗ Requires external IdP |
| Token Vault | ✓ Encrypted at rest, RFC 8693 vending | ✗ BYO secrets manager |
| DPoP (RFC 9449) | ✓ | ✗ Rare or add-on |
| Single-binary deploy | ✓ One Go binary | ✗ SaaS or multi-service stacks |
| Agent Identity (delegation chains) | ✓ | ✗ |
Not sure which plan?
We'll help you figure out the right setup for your team and infrastructure.
Talk to us →