Arcade
Also known as: Arcade AI
Actions runtime for AI agents: delegated user authorization, 8,000+ permission-aware tools and MCP servers, inline policy hooks and a per-action record for every agent call.
Arcade calls itself the actions runtime for AI agents: one control point between agents and the systems they reach, which enforces policy, executes the action and records it. Its team comes from identity and data infrastructure companies including Okta, and its core idea is that an agent should act as its user, never past that user's permissions, without the model ever holding a credential.
When an agent calls a tool, authentication runs against the customer's identity provider and authorization is delegated, so the agent acts within the user's scope and the user consents to each scope before a tool acts for them. Arcade offers more than 8,000 permission-aware tools and connects custom or third-party MCP servers, including hosted servers from Salesforce, ServiceNow, GitHub and Atlassian.
Contextual access lets a customer run its own policy code inline at three points: which tools a user can see, whether a call may run and with what inputs, and what output comes back. Each action leaves a record naming the agent, the user and the system, streamed to the customer's SIEM, and administrative changes land in a separate audit log with an API. An evaluation command scores how models choose and call tools across providers.
Arcade runs as a managed cloud, as an Arcade-operated platform inside the customer's own Azure or AWS account, or self-hosted with Helm, with VPC and air-gapped options on Enterprise. It works with any model and framework the customer already uses; it does not run agents, orchestrate workflows or keep agent memory. Pricing is published: a free plan with monthly allowances, Team at $25 a month plus $0.10 per auth event and $0.01 per tool call, and custom Enterprise.
Vendor details
Canonical URL
https://arcade.dev
Category
Agent infrastructure
Subcategory
Agent auth and tool calling
Funding status
Independent; Arcade AI, Inc. Its team comes from Okta, Snowflake, Redis, Airbyte and MongoDB, per its homepage.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
8,000+ permission-aware tools plus custom and third-party MCP servers, hosted remote MCP servers for Salesforce, ServiceNow, GitHub, Atlassian, Snowflake, Splunk, AWS and others, OAuth auth providers across dozens of services, identity sources Okta, Microsoft Entra ID, Auth0 and Stytch, and guides for LangChain, CrewAI, OpenAI Agents, Google ADK, Mastra, Vercel AI SDK and MCP clients such as Cursor, Claude and Copilot Studio.
In practice
You want your agent to act in Gmail and Salesforce for a user without the model touching OAuth tokens. Arcade authorizes the user against your identity provider and runs the tool within that user's scope, keeping credentials out of the prompt.
Your security team blocks the agent because no one can tell who authorized which action. You route tool calls through Arcade, which runs your policy hooks before and after each call and records every action with the agent, the user and the system for your SIEM.
You keep rebuilding OAuth and token handling for every new integration. You pull from Arcade's catalog of permission-aware tools or bring your own MCP servers, and let Arcade handle the auth for each.
Sources & related URLs
Related / legacy domains
Research sources
Agentic Index coverage score
7.5 / 14 capabilities · 54%
| Integrations & Tool Calling | Full |
|---|---|
|
As an actions runtime, Arcade offers 8,000+ permission aware tools plus custom or third party MCP servers the customer builds or brings (homepage). Authorization is delegated so the agent acts as its user within scope, Arcade handles OAuth across dozens of auth providers, and hosted remote MCP servers connect through Arcade to systems such as Salesforce, ServiceNow, GitHub, Atlassian and Snowflake, among others (docs). Agents take authenticated action in outside systems through that framework. Sourcearcade.devread 2026-09-22 |
|
| Workflow Orchestration | Not documented |
|
Arcade executes the tool calls an agent makes and returns results. Sequencing, branching and multi agent handoff live in the customer's own framework, and Arcade publishes setup guides for frameworks such as LangChain, CrewAI, OpenAI Agents, Google ADK and Mastra, among others. No workflow runtime of its own is documented, so retries, routing and deterministic workflow steps sit outside the platform. Sourcearcade.devread 2026-09-22 |
|
| Knowledge Grounding & RAG | Not documented |
|
Agents get authenticated tools that read from and act in outside systems, but no retrieval structure that Arcade maintains over the customer's documents, such as an index, graph or embeddings layer, is documented. Sourcearcade.devread 2026-09-22 |
|
| Human Oversight & Guardrails | Partial |
|
Contextual access runs the customer's own policy logic inline. An access hook decides which tools each user can see, a pre execution hook allows, denies or modifies inputs before each tool call, and a post execution hook allows, denies or modifies the output. Users authorize each scope before a tool acts for them, and rate limits apply. These are customer controlled limits on what an agent may do, but no step where a person reviews or approves an action before it commits is documented, and consent to a scope is not review of an action. Sourcedocs.arcade.dev/en/operate/governance/contextual-accessread 2026-09-22 |
|
| Security, Identity & Governance | Full |
|
The access surface is deep and first party. Authentication runs against the customer's identity provider (Okta, Microsoft Entra ID, Auth0 and Stytch user sources in the docs), and authorization is delegated so an agent acts as its user and never past its own scope. Contextual access hooks enforce the customer's policies on every tool call, role based access control has organization admin, project admin and member roles, and SSO and audit logs are included on Enterprise (homepage and pricing page). No security attestation is published. Sourcearcade.devread 2026-09-22 |
|
| Observability & Auditability | Full |
|
Every action taken through Arcade leaves one record naming the agent, the user and the system, streamed to the customer's SIEM (homepage). Administrative actions are captured separately in an audit log that is on by default, with a filterable dashboard and a REST API for pulling events into the customer's SIEM or compliance tooling (Audit Logs page). Agent behavior and admin activity are recorded apart, and both export to the customer's own tools. Sourcedocs.arcade.dev/en/operate/governance/audit-logsread 2026-09-22 |
|
| Memory & State Persistence | Not documented |
|
Each user's OAuth tokens and authorization grants are kept so tools can act without asking for consent again. No memory layer that persists an agent's state or a user's context across runs is documented, and the stored credentials carry no such state. Sourcearcade.devread 2026-09-22 |
|
| Deployment & Data Residency | Full |
|
Customers choose between Arcade Cloud and their own infrastructure. A turnkey Arcade operated platform can be deployed into the customer's cloud account (Azure Marketplace managed app, AWS private offer), or a self managed Helm deployment can run on the customer's Kubernetes cluster, for data residency, network isolation or compliance (Hosting options page). The pricing page adds VPC and fully air gapped deployment on Enterprise. Sourcedocs.arcade.dev/en/operate/deployread 2026-09-22 |
|
| Prebuilt Agents, Templates & Packs | Not documented |
|
The catalog holds tools and MCP servers, which give an agent actions rather than doing work when selected, and the sample apps are example code. No ready made workflows, templates or named prebuilt agents of Arcade's own are documented. Sourcearcade.devread 2026-09-22 |
|
| Triggers & Channel Coverage | Not documented |
|
Tools in Arcade run when an agent or MCP client calls them. No schedule, event, webhook or inbound queue that starts an agent run is documented, so nothing wakes an agent without a caller. Sourcearcade.devread 2026-09-22 |
|
| Model Flexibility & Routing | Full |
|
Any client, any model and any framework the customer picks can use Arcade's tools (homepage), with setup guides for the customer's own LLM and for frameworks such as LangChain, OpenAI Agents, Google ADK, CrewAI, Mastra and Vercel AI SDK, among others. The evaluation command runs against the providers and models the customer names, so the model stays the customer's choice throughout. Sourcearcade.devread 2026-09-22 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Developers get a documented API (the Arcade API Reference and a Contextual Access Webhook API), SDKs used in the framework guides, the Arcade CLI, and an MCP framework for building MCP servers that Arcade hosts or connects. The Audit Logs page shows the REST API called with an Arcade API key. Sourcedocs.arcade.dev/llms.txtread 2026-09-22 |
|
| Testing, Debugging & Optimization | Full |
|
The arcade evals command runs evaluation suites the customer writes against its tools, with detailed results and critic feedback, a failures only view, multiple runs and output formats, and comparisons across providers and models in one run (Run evaluations page), alongside a documented comparative evaluations guide. The results are scored and comparable, showing how the customer's agent uses its tools. Sourcedocs.arcade.dev/en/build/create-tools/evaluate-tools/run-evaluationsread 2026-09-22 |
|
| Browser & Computer Use | Not documented |
|
Arcade acts through authenticated APIs and MCP tools, and no browser, desktop or remote computer session that it runs for an agent is documented. The toolkits that reach other vendors' scraping and sandbox services lead to those vendors' capabilities rather than Arcade's own. Sourcearcade.devread 2026-09-22 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Arcade announced a new Snowflake toolkit that lets agents discover warehouses, databases, schemas, tables, and columns, then run queries using the requesting user's identity. Existing Snowflake grants determine what the agent can access. The toolkit permits read only queries and blocks writes, schema changes, and role switches.
Bears on: MCP / tool calling / API
View sourceArcade has introduced the ability for developers to bring any third-party Model Context Protocol (MCP) server to the Arcade.dev platform. This update enables teams to integrate external or custom MCP servers directly into their Arcade environment.
Bears on: MCP / tool calling / API
View sourceArcade has launched Role-Based Access Control for its platform, allowing teams to assign organization admin, project admin, and member roles. This introduces an administrative layer that controls who can manage the workspace and configure the underlying tools.
Bears on: Deployment / data residency
View sourcePricing
Free tier · Team $25/mo + usage · Enterprise custom
Monthly platform fee plus usage: auth events and tool calls
Included quota
Free tier includes 100 user challenges, 1,000 standard tool executions, 50 pro tool executions, and unlimited tools with prebuilt auth. Growth ($25/mo) includes 600 user challenges, 2,000 standard tool executions, and 100 pro tool executions. Rate limit is 1,000 API calls per minute on all tiers.
What is public
Arcade publishes its rate card: a free plan with monthly allowances, Team at $25 a month plus per-event and per-call rates, and custom Enterprise with deployment options and governance features.
Billing mechanics
A monthly platform fee on Team plus metered usage: an auth event is connecting an agent to a user's account, a tool call is one action taken. Free includes monthly allowances on Arcade Cloud. Enterprise buys annual bundles with discounted additional rates.
Cost watchouts
Every new connection of an agent to a user account is a billed auth event at $0.10 on Team, so onboarding many end users costs more than steady tool use; tool calls add $0.01 each. VPC, air-gapped deployment, SSO and audit logs are Enterprise.
Variable cost rationale
Included allocations are generous and standard tool executions are cheap at $0.01 each, so light and mid usage is predictable. Cost grows with high volume production agents, and pro tool executions at $0.50 each can add up.
Additional watchouts
Cost scales with tool execution volume, which is hard to predict for high traffic production agents. Pro tool executions are priced fifty times higher than standard ones.
Overage / add-ons
Team bills every auth event at $0.10 and every tool call at $0.01 on top of the $25 platform fee; Enterprise buys annual bundles with discounted additional rates.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free plan: 2,000 auth events and 2,000 tool calls a month, no credit card
Lowest paid plan
Team: $25 a month platform fee plus $0.10 per auth event and $0.01 per tool call
Commercial notes
Arcade is sold to engineering teams building production agents and to enterprises with strict security review. Its differentiator is auth: built by former Okta engineers, credentials never reach the model. Deploys to cloud, VPC, on premises, and locally.
Key ambiguities
Total cost depends on how many users connect accounts (auth events) and how many actions agents take (tool calls); Enterprise bundle sizes and rates are quoted.
Cancellation / refund
Self serve plans are month to month and usage is billed in arrears. Cancellation details for paid plans are not publicly detailed.
Support SLA / resale
Self serve support for free and Growth tiers; enterprise terms and higher rate limits are by contact at contact@arcade.dev.
Missing data
Enterprise pricing is not public. The most recent public pricing iteration dates to 2025, so current rates should be confirmed on arcade.dev.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Arcade
The closest documented capability profiles to Arcade among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Portkey7.5 / 14Matches Arcade across all 14 documented capabilities
- Kong8.5 / 14Adds documented Knowledge Grounding & RAG
- Freeplay8.0 / 14Adds documented Triggers & Channel Coverage
- Metorial8.0 / 14Adds documented Triggers & Channel Coverage
- Stacklok8.0 / 14Adds documented Prebuilt Agents, Templates & PacksArcade vs Stacklok →
- Clawvisor6.5 / 14Fuller documented coverage on Human Oversight & Guardrails
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded