Where credentials live
Doing it by hand: API keys pasted into each agent's config.
With Spinrun: Connected once through OAuth and kept in an encrypted vault.
Spinrun for enterprise
Put every agent and model behind one endpoint, with read, write and destructive rules enforced on each call and a log your security team can read. Volume, terms and onboarding are agreed with you.
How it works
Every tool is sorted into read, write or destructive, and each app gets its own rule. A blocked call never reaches the app; the agent gets an error naming the rule, and the attempt is logged.
Each workspace key is scoped to one team and the apps it's allowed, with limits of its own. Revoking it stops that team's agents and nothing else.
The log records the user, the tool, the action and the outcome of every call, blocked ones included. Your plan sets how long it and the call payloads are kept, and a nightly job enforces it.
What agents take on
Each one is already a template or a department page, running on the same gateway.
Ask a question and get the answer from your docs and wikis, with the source cited.
TemplateDeal data from Salesforce, broken down by stage and owner, in one weekly report.
TemplateAccount details, open tickets and recent activity for a customer, pulled together before a call.
TemplateAlert triage, access requests, incident notes and audit prep across PagerDuty, Datadog, Auth0 and Cloudflare.
DepartmentA person connects each app once; every agent reaches it through the gateway, under that app's rules.
177 more apps connect the same way
Side by side
Each department still picks its own agent. Identity, rules and logging are decided once, for all of them.
Doing it by hand: API keys pasted into each agent's config.
With Spinrun: Connected once through OAuth and kept in an encrypted vault.
Doing it by hand: A line in the prompt asking the model to be careful.
With Spinrun: Read, write and destructive rules per app on Pro and up, enforced at the gateway on every call.
Doing it by hand: Rotating every key that team ever used.
With Spinrun: Revoking one workspace key, while every other team keeps running.
Doing it by hand: Each tool's own logs, in each tool's own format.
With Spinrun: One log of every call, blocked ones included, kept as long as your plan sets.
Doing it by hand: API keys pasted into each agent's config.
With Spinrun: Connected once through OAuth and kept in an encrypted vault.
Doing it by hand: A line in the prompt asking the model to be careful.
With Spinrun: Read, write and destructive rules per app on Pro and up, enforced at the gateway on every call.
Doing it by hand: Rotating every key that team ever used.
With Spinrun: Revoking one workspace key, while every other team keeps running.
Doing it by hand: Each tool's own logs, in each tool's own format.
With Spinrun: One log of every call, blocked ones included, kept as long as your plan sets.
Who it's for
Sales picks one agent, support another, engineering a third. Spinrun puts them all behind one governed endpoint, so identity, rules and logging are decided once instead of tool by tool.
Enterprise plan
All of Pro, and: volume, terms and onboarding agreed with you, a dedicated SLA and an account team. Pricing is quoted.
Your volume, your auditors, your terms.
Use cases
All of Pro, and: custom volume, terms and onboarding, a dedicated SLA and an account team. Enhanced Control, the Brain, artifacts, the code sandbox and the agent database come with it from Pro, and members, connections and API keys are uncapped.
Tell us about your volume and how your security review works, and a person from the team will reply with the next steps.
We would like to switch on analytics, so we can see which pages are worth keeping. Nothing has loaded yet and nothing will until you choose. The cookies that keep you signed in and remember your language are not part of this.
Read the Cookie Policy