All analysis was generated autonomously, without human review. Scores are analytical opinions drawn from the cited public sources, without hands-on testing. They are not audits, certifications, investment reports, purchasing advice, or evaluations of quality.
Keycard sells identity and access control for AI agents, issuing short-lived credentials scoped to a single task and logging every agent action. The company is expanding faster than it is letting customers in. Within four months of its October 2025 launch it bought two startups, Runebook and Anchor.dev, and shipped products governing coding agents and multi-agent apps. It publishes usage pricing at $1 per 1,000 transactions, yet it still gates the platform behind an early-access signup. The public record names one customer, Chime, whose generative-AI product lead reports agents running against production systems within days. Keycard is building and buying like a company that expects the agent-identity market to consolidate early. Disclosed adoption is the number to watch.
| Description | Keycard is an identity and access management platform for AI agents that issues identity-based credentials, scopes what agents can reach across tools, APIs, and data, and records an audit trail of every agent action. | [f1] |
|---|---|---|
| Founded | 2025 | [f1] |
| HQ | San Francisco, California | [f2] |
| Funding | $38M total | [f3] |
| Latest funding | $30M Series A (2025) | [f3] |
| Product | What it does |
|---|---|
| Keycard | Identity and access platform that scopes agent access to tools, APIs, and data by identity and policy. Audits every install, block, and denial in real time. |
| Keycard for Coding Agents | Governs what coding agents do when they run shell commands, write scripts, and call APIs. The keycard run wrapper enforces policy on those actions. |
| Keycard for Multi-Agent Apps | Identity, access, and telemetry for developers building multi-agent systems, coordinating agents, tools, and data across teams without custom identity wiring. |
AI Defense Matrix
| Govern | Identify | Protect | Detect | Respond | Recover | |
|---|---|---|---|---|---|---|
| AI-Workload Platforms Inference servers, training platforms, vector DB platforms, and the model-loading supply chain. | ||||||
| AI Orchestration Tools Agentic orchestration tools, plus their plugins, skills, hooks, system prompts, scaffolding, harnesses, configuration settings, and MCP clients on user devices. | ||||||
| AI-Generated Code Code produced by AI tools, AI-assisted reviews, AI-generated infrastructure-as-code and tests, and vibe-coded apps that bypass CI/CD. | ||||||
| AI Gateways & Routers MCP proxies and gateways, LLM routers, outbound AI-service traffic, shadow AI egress, and model-registry traffic. | ||||||
| AI Model Model weights, fine-tuning checkpoints, model cards, registries, AIBOM, and the third-party LLMs your enterprise consumes. | ||||||
| Training Data Datasets used for training, fine-tuning, and continued learning. | ||||||
| Runtime AI Data User prompts, inference inputs, RAG content, vector DB content, persistent agent memory, and interaction history. | ||||||
| AI Agent Identities AI agents as non-human principals, plus credentials, keys, permission scopes, service accounts, and delegation chains across agents and tools. |
Keycard issues identity-based credentials to AI agents, scopes their access to tools and APIs by identity and policy, and audits every agent action in real time. It is placed at AI Agent Identities across the identify, protect, and detect functions of the AI Defense Matrix. [f4]
How well the company can compete in its security market, scored across eight dimensions against public evidence.
| Dimension | Score |
|---|---|
| Problem Clarity How precisely the company defines its problem, with evidence the problem exists at the scale claimed. | 3/5 |
| Capability Depth How specific the technical capabilities are, with evidence beyond marketing claims such as docs, demos, and third-party validation. | 3/5 |
| Market Timing Whether the market is ready for this product, with evidence that buyers are actively seeking solutions. | 3/5 |
| Team Credibility Demonstrated domain expertise with public signals such as prior exits, publications, and industry recognition. | 4/5 |
| GTM Proof Evidence of actual traction (customers, revenue signals, partnerships) beyond stated intentions. | 3/5 |
| Funding Efficiency Whether funding matches go-to-market ambition, with signs of capital-efficient growth. | 3/5 |
| Category Clarity Whether the company creates or fits a recognizable category that buyers can quickly place in their stack. | 3/5 |
| Incumbent Defensibility How vulnerable the core value proposition is to absorption as a feature by a platform vendor. | 2/5 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
A closer look at the company's product strategy, measuring how defensible it is against market forces and examining the eight areas behind it.
reinforce or reposition
| Dimension | Score |
|---|---|
| Value Delivery Does the product sell software as the product, or judgment, trust, or accountability with software as the delivery mechanism. | 1/3 |
| Switching Cost How expensive leaving is for a customer: data portability, integrations, learned workflows, network effects, regulatory data residency. | 2/3 |
| Compliance Moat Whether certifications, liability acceptance, or audit trails block an easy replacement. | 1/3 |
| Problem Complexity Whether the product requires ML, optimization, real-time systems, or years of specialized expertise. | 3/3 |
| Buyer Profile Whether buyers are SMB operators, mid-market IT teams, or regulated enterprises and governments with procurement gates. | 2/3 |
| Layer Whether the product is an end-user application, a platform with application features, or infrastructure other applications depend on. | 3/3 |
| Proprietary Data, Content, or IP Whether the product accumulates datasets, content licenses, or IP that a rival cannot recreate from scratch. | 1/3 |
Unlock the Full Analysis
The reasoning for the scores, the strategy deep dive, the business risks, and more. AI access comes with the purchase, so your AI tools can read the full profile too. You keep 12 months of access.
One-time purchase: $20 per profile.
UnlockReading several? Unlock the entire catalog.
| Id | Source | Tier | Accessed |
|---|---|---|---|
| f1 | Keycard: The Federated Trust Fabric for the Agent-Native Era | official | 2026-06-24 |
| f2 | FinSMEs: Keycard Raises $38M in Seed and Series A Funding | press | 2026-06-24 |
| f3 | SiliconANGLE: AI agent security startup Keycard reels in $38M | press | 2026-06-24 |
| f4 | Keycard homepage | official | 2026-06-24 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Keycard homepage “Keycard scopes agent access by department, identity, and policy. Every install, block, and denial. In real time.” | official | 2026-06-24 |
| s2 | Keycard: The Federated Trust Fabric for the Agent-Native Era “Introducing Keycard: Identity & Access Management for AI Agents, with $38M in Funding” | official | 2026-06-24 |
| s3 | SiliconANGLE: AI agent security startup Keycard reels in $38M “The initial $8 seed raise was led by Andreessen Horowitz and boldstart, while Acrew Capital led the subsequent $30 million Series A investment.” | press | 2026-06-24 |
| s4 | SiliconANGLE: AI agent security startup Keycard reels in $38M “its software enables developers to implement "per-task" access controls for AI agents. Those controls don't give AI agents broad access to an application, but instead limit them to performing specific actions.” | press | 2026-06-24 |
| s5 | Keycard about page “Jared Hanson, Technology. Creator of Passport.js. Expert in identity, security, and scaling companies from startup to acquisition.” | official | 2026-06-24 |
| s6 | FinSMEs: Keycard Raises $38M in Seed and Series A Funding “Keycard, a San Francisco, CA-based provider of an identity and access platform for AI agents that integrates with organizations' existing user identity solutions, raised $38m in Seed and Series A funding.” | press | 2026-06-24 |
| s7 | Keycard: Support for ID-JAG and Cross-App Access from Okta “Today we're announcing Keycard support for ID-JAG, the Identity Assertion Authorization Grant, the open standard behind Cross-App Access by Okta.” | official | 2026-06-24 |
| s8 | Keycard Labs Trust Center (SafeBase) “Compliance: SOC 2 Type 1, SOC 2 Type 2. Documents: SOC 2 Report, plus access, change-management, backup, and business-continuity policies.” | official | 2026-06-24 |
| Id | Source | Tier | Accessed |
|---|---|---|---|
| s1 | Keycard homepage: The Control Plane for Autonomous Agents “Agents prove who they are. Workload attestation (SPIFFE, k8s SA, cloud instance ID, mTLS) binds agent to a verified runtime. Combined with user, device, and task for composite identity.” | official | 2026-07-07 |
| s2 | Keycard pricing: usage-based pricing with a single metric “A transaction is recorded each time Keycard is involved in a request, issuing a credential, validating an access request, exchanging a credential, or handling a step-up approval. Each plan includes a monthly allocation. Paid plans bill additional transactions at $1 per 1,000.” | official | 2026-07-07 |
| s3 | Keycard pricing: Starter plan, free, gated by early access “Starter. Try Keycard personally. Free. 5,000 transactions/mo (hard cap). Get early access” | official | 2026-07-07 |
| s4 | Keycard about page: founders “Jared Hanson. Technology. Creator of Passport.js. Expert in identity, security, and scaling companies from startup to acquisition.” | official | 2026-07-07 |
| s5 | Keycard about page: individual investors “Individual Investors. Matias Woloski, CTO, Auth0. Karl McGuinness, Chief Product Architect, Okta. Ian Andrews, CRO, Grok. Ryan Carlson, President, Chainguard. Emilio Escobar, CISO, Datadog. Dane Knecht, CTO, Cloudflare. Angie Lai, Head of Security Engineering, Anthropic.” | official | 2026-07-07 |
| s6 | Keycard: The Federated Trust Fabric for the Agent-Native Era “Today we're incredibly excited to introduce Keycard and announce our agent identity and platform is now available in early access. To support our mission, we've raised a $38M combined inception round led by Andreessen Horowitz, Acrew Capital, and Boldstart Ventures” | official | 2026-07-07 |
| s7 | Keycard: Announcing Keycard for Coding Agents “Keycard for Coding Agents is available in early access today. We've been building and iterating on this platform over the past year, and it's already in production with customers like Chime.” | official | 2026-07-07 |
| s8 | Keycard: Announcing Keycard for Multi-Agent Apps “The SDKs for TypeScript and Python let you add scoped auth to anything you're building, with out-of-the-box support for LangChain, MCP, A2A, or any API.” | official | 2026-07-07 |
| s9 | Keycard: Support for ID-JAG and Cross-App Access from Okta, June 23, 2026 “Today we're announcing Keycard support for ID-JAG, the Identity Assertion Authorization Grant, the open standard behind Cross-App Access by Okta.” | official | 2026-07-07 |
| s10 | Keycard docs: quickstart and SDK surface “Quickstart. Run Claude Code in a Keycard-protected session, with policy enforcement and audit.” | official | 2026-07-07 |
| s11 | Keycard Labs Trust Center (SafeBase), rendered via agent browser “Compliance: SOC 2 Type 1. SOC 2 Type 2. Documents: SOC 2 Report. Reports: Data Flow Diagram (DFD). Network Diagram. Pentest Report.” | official | 2026-07-07 |
| s12 | SiliconANGLE: AI agent security startup Keycard reels in $38M “The initial $8 seed raise was led by Andreessen Horowitz and boldstart, while Acrew Capital led the subsequent $30 million Series A investment.” | press | 2026-07-07 |
| s13 | SiliconANGLE: AI agent identity startup Keycard acquires Anchor.dev (February 10, 2026) “Keycard Labs Inc., a startup developing software to manage identity and access security for agentic artificial intelligence, today announced it has acquired Anchor.dev, a startup focused on security certificate management.” | press | 2026-07-07 |
| s14 | Help Net Security: Keycard helps developers secure autonomous AI agents with scoped access “"We wanted our engineers deploying agents and tools into production without needing to be security or identity experts. Keycard's platform made that possible. We had agents running against production systems in days," said Dennis Yang, Principal Product Manager for Generative AI at Chime.” | press | 2026-07-07 |
| s15 | Help Net Security: Keycard emerges from stealth with identity and access solution for AI agents “Keycard contributes to emerging standards including Model Context Protocol (MCP), WIMSE and OAuth extensions for agents and is the first production implementation with support for OAuth 2.1 Client ID Metadata Documents in MCP.” | press | 2026-07-07 |
| s16 | Biometric Update: 1Password, Keycard present tools for secure AI agent credential delegation “most teams currently connect agents using shared API keys, inherited credentials, or persistent access grants, none of which limit privileges to what a given task actually requires. As agents gain autonomy, that exposure widens.” | press | 2026-07-07 |
| s17 | Biometric Update: Keycard delegation mechanics via OAuth token exchange “Access is scoped at each delegation hop using OAuth 2.0 Token Exchange (RFC 8693), so no agent holds more privilege than the task requires. Every token in the chain is traceable, revocable, and expires at the end of the session.” | press | 2026-07-07 |
| s18 | WorkOS (competitor comparison page, November 4, 2025): Keycard for AI Agent Security “However, Keycard emerged from stealth just weeks ago in October 2025. The platform lacks production battle-testing at enterprise scale, with no publicly disclosed customer deployments or case studies.” | official | 2026-07-07 |
| s19 | Keycard: Making MCP Production-Ready, Keycard acquires Runebook (November 20, 2025) “Their team joins Keycard to accelerate our ecosystem of integrations and drop-in SDKs for building production-ready, trusted agents and tools powered by the Model Context Protocol (MCP).” | official | 2026-07-07 |
| s20 | Keycard: Runebook acquisition, the team joining Keycard “We're thrilled to add Peter Cho and Matte Noble's deep experience building beloved developer ecosystems at Heroku, Mezmo, and Sentry.” | official | 2026-07-07 |
| s21 | Help Net Security: Keycard CEO on the agent access trade-off “"Right now the developers building these systems have to choose: give agents broad access and they're ungovernable or lock them down and lose what makes them valuable," said Ian Livingstone, CEO of Keycard.” | press | 2026-07-07 |
| s22 | Keycard about page: founders, Matthew Creager “Matthew Creager. Product & Marketing. Platform engineering leader obsessed with making infrastructure invisible.” | official | 2026-07-07 |
This site is an experimental research aid created by Zeltser Security Corp. All its data gathering and analysis was performed autonomously without human review, and it can contain errors of fact, interpretation, and judgment that a human reviewer might catch.
The analyses are statements of opinion, not statements of fact. Machine analysis produced the scores, summaries, and matrix placements by weighing the public sources each page cites, and reasonable people can weigh the same sources differently. Where a page states a fact, it cites the public source and the date it was checked, and the statement is only as accurate as that source. Unless a profile expressly says otherwise, the analysis involves no hands-on testing and no independent validation of any company's products or services.
Nothing here is professional, security, legal, financial, investment, or purchasing advice, and nothing here is a recommendation to invest in, do business with, or avoid any company. Inclusion of a company is not an endorsement, and absence of a company is not a judgment about it. Reading this site creates no advisory or client relationship. Verify any detail you plan to act on against the vendor's current materials.
The content is provided "as is" and "as available," with all warranties disclaimed, express or implied, including merchantability, fitness for a particular purpose, accuracy, and non-infringement. No entry is warranted to be complete, current, or correct. Companies change, vendors update their claims, sources can be wrong, and automated analysis can misread them.
To the fullest extent permitted by law, the operator, Zeltser Security Corp, is not liable for any damages that arise from using this site or relying on its content, including direct, indirect, incidental, special, and consequential damages and lost profits, even if advised that such damages were possible. If you are dissatisfied with the site or disagree with these terms, your remedy is to stop using it.
Entries link to vendor pages, press coverage, and other external sites that Zeltser Security Corp does not control and is not responsible for. A link is not an affiliation with the destination or an endorsement of it. Product and company names and trademarks are the property of their owners, used here nominatively to identify the companies described. Short quotations from cited sources appear for identification and commentary.
Do not republish its content or share access without the operator's permission.