Every action has an identity
Connect Entra ID, Okta, OIDC, or SAML. Archestra records who initiated each tool call and resolves user credentials at runtime.
Explore identity and accessOpen-source infrastructure for enterprise AI
Built for platform teams rolling out AI across the company.
2. Platform architecture
AI becomes useful when it can tap into your data, call your tools, and take action—not just generate text. Archestra gives every agent and AI client one controlled gateway to your systems.
Claude · Codex · Cursor · n8n · Internal agents
LLM proxy · MCP gateway · Identity · Policy · Execution · Audit · Cost Control
Models · MCP servers · Knowledge · Business systems

“We were looking for an infrastructure layer to scale and secure our internal agents. Archestra stood out for its security-first mindset, open-source nature, and a deployment experience that just works.”
3. Production controls
Safe AI is not AI that never makes a mistake, but the one whose access and actions are bounded, enforced, and visible.
Connect Entra ID, Okta, OIDC, or SAML. Archestra records who initiated each tool call and resolves user credentials at runtime.
Explore identity and accessControl tool access, approvals, isolation, and network egress. Block unauthorized actions and unsafe data flows before they reach your systems.
Explore AI security and guardrailsTrace model requests, tool calls, policy decisions, and cost. Export telemetry through OpenTelemetry and Prometheus.
Explore observability4. Quickstart
Run locally, develop from source, or deploy to Kubernetes.
Explore deployment options5. Works with your stack
Engineers keep Claude Code, Codex, Cursor, Copilot CLI, n8n, and their preferred frameworks. Other teams can work directly in Archestra using Chat, Apps, RAG, and shared Projects.
Archestra gives your AI tools a shared control layer, integrated with your existing models, identity providers, and observability stack.
OpenAI · Anthropic · Azure OpenAI · Vertex AI · Bedrock · Self-hosted
Kubernetes · Helm · Postgres
OpenTelemetry · Prometheus · Grafana · Splunk
6. Entry points
Give MCP servers one registry, gateway, identity layer, and audit trail.
Explore MCPGive teams one endpoint for approved models. Route requests across providers, keep API keys server-side, set spend limits, and trace every request.
Explore the LLM proxyMove agents off laptops and run them as managed, sandboxed workloads.
Explore AgentsBring us the agent, MCP deployment, or access problem that is blocking your rollout.
Book a technical demoArchestra is licensed under AGPL-3.0 and free to self-host. Chat, agents, the MCP gateway, LLM proxy, orchestrator, and observability are included. SSO and OIDC, RBAC, white-labeling, and advanced knowledge bases with access control require an enterprise license. Teams under 30 users get that license free.
Yes - AGPL-3.0, the whole platform, not an SDK. The repo is on GitHub, and the quickstart runs in about three minutes.
No. Under 30 users, everything is free, including the enterprise features. Deploy and go. If you grow past that, email us - you’ll know when.
LiteLLM is an LLM proxy - very good at routing model traffic. Archestra includes its own LLM proxy and covers the layers around it: MCP infrastructure, agents, chat for non-technical teams, guardrails. Already run LiteLLM? It plugs in too; Archestra is a modular platform.
A gateway routes MCP traffic. Archestra includes one, plus the registry of 900+ evaluated MCP servers, agent runtime, chat, knowledge bases, and cost tracking that turn it into a platform your whole company can use.
You could - and several of our customers started that way. The gateway and proxy are the easy part; the policy engine, credential isolation, and auth flows are where the real time goes.
No, they can keep their tools. Connect in one click and keep working as before. Behind the scenes, every call now goes through Archestra: one registry, one policy set, full visibility.
Yes, set budgets per person, team, or agent. Virtual keys, so no shared API keys and no mystery spend. Everything lands in your Grafana. Cheaper model does the job? The proxy routes to it.