VaultProof

API key protection that scales with your workload.

Every account begins with permanent Free limits. Paid plans increase protected calls, active keys, projects, MCP connections, policy controls, and activity retention without changing the VaultProof protection model.

Choose the capacity that fits now.

Monthly prices are shown first. Annual plans cost the equivalent of ten monthly payments. Prices exclude applicable tax.

Free

For protecting one personal project.

$0forever

No card required

  • Calls5k / mo
  • Active keys5
  • Projects1
See Free features

Starter

For a small protected workload.

$5/ month

or $50 / year

  • Calls50k / mo
  • Active keys20
  • Projects3
See Starter features

Builder

For growing applications and agents.

$9/ month

or $90 / year

  • Calls150k / mo
  • Active keys50
  • Projects5
See Builder features

Pro

For higher-volume protected traffic.

$20/ month

or $200 / year

  • Calls500k / mo
  • Active keys100
  • Projects10
See Pro features

Every limit, plan by plan.

Limits apply per VaultProof account across all projects, provider integrations, developer keys, and protected-key slots.

Free

Permanent account entitlement

$0 forever
  • Users1
  • Projects1
  • Environments / project2
  • Active protected keys5
  • MCP connections1
  • Protected calls / month5,000
  • Requests / second2
  • Activity retention7 days
  • Retained security events500
  • Origin rules2
  • IP rules2
  • Spending budgets1
  • Webhook endpointsNot included

Starter

Monthly or annual subscription

$5 / month · $50 / year
  • Users1
  • Projects3
  • Environments / project3
  • Active protected keys20
  • MCP connections3
  • Protected calls / month50,000
  • Requests / second10
  • Activity retention30 days
  • Retained security events5,000
  • Origin rules10
  • IP rules10
  • Spending budgets10
  • Webhook endpoints1

Builder

Monthly or annual subscription

$9 / month · $90 / year
  • Users1
  • Projects5
  • Environments / project4
  • Active protected keys50
  • MCP connections5
  • Protected calls / month150,000
  • Requests / second20
  • Activity retention60 days
  • Retained security events15,000
  • Origin rules25
  • IP rules25
  • Spending budgets25
  • Webhook endpoints3

Pro

Monthly or annual subscription

$20 / month · $200 / year
  • Users1
  • Projects10
  • Environments / project5
  • Active protected keys100
  • MCP connections10
  • Protected calls / month500,000
  • Requests / second50
  • Activity retention365 days
  • Retained security events50,000
  • Origin rules100
  • IP rules100
  • Spending budgets100
  • Webhook endpoints10

Core protection is included in every plan.

  • CLI setup with a dry-run preview before changes
  • Managed runtime values and provider-compatible routes
  • Provider-key splitting before upload
  • Separate authenticated ciphertext shares at rest
  • Credential reconstruction only inside the proxy request path
  • Safe activity metadata for protected calls
  • Key rotation, token deletion, and access revocation controls
  • Read-only VaultProof MCP connection capacity

Billing without surprises.

Capacity changes are explicit, protected data is preserved, and paid billing remains under your control.

Do I need a card to start?

No. Free requires no card, and an eligible account can start one 30-day trial without creating a Stripe customer, subscription, invoice, or payment method.

What happens when the trial ends?

Your account returns to Free limits with no charge. Existing protected data is preserved; creating new resources is blocked until usage is within the current plan limit.

How do annual plans work?

Annual prices equal ten monthly payments: $50 for Starter, $90 for Builder, and $200 for Pro. The annual amount is billed on the annual cadence.

Can I change or cancel a paid plan?

Higher-tier upgrades show a server-generated proration preview before confirmation. Downgrades, cancellations, payment methods, invoices, and billing-cadence changes remain in the Stripe billing portal.

Protect your first provider key for free.

Install the CLI, preview the changes, make one protected provider request, and confirm it in Activity Logs.