Klavis AI
Also known as: Klavis, Strata
Hosted MCP servers with per-user OAuth across more than a hundred apps, the open source Strata server, and sandboxed real-app environments for training and evaluating agents.
Klavis AI builds MCP integration infrastructure and live environments for training and evaluating AI agents. Its hosted MCP servers connect agents to more than a hundred applications, from GitHub, Gmail and Slack to Salesforce, HubSpot, Notion and Jira, with OAuth 2.0 handled per end user so an agent acts in each user's own accounts.
Strata puts every connected server behind a single MCP server that lets the agent discover categories and actions progressively instead of loading every tool at once. The servers and Strata are open source, with Docker images for running them in the customer's own infrastructure, and a REST API with Python and TypeScript SDKs manages servers, users, authentication and white-labeled OAuth, with US and EU production endpoints.
The same API provides sandboxes of real applications for training and evaluation. A sandbox is seeded with a deterministic state, the agent works against it through MCP, the final state can be exported and checked against ground truth, and the sandbox resets for the next run. Benchmark environments and a task verification endpoint report whether an agent completed a task.
Klavis's homepage now leads with coding and agentic training data for frontier AI labs, and its pricing page offers the sandbox environment by quote. The FAQ describes a free plan with paid Pro and Enterprise tiers for the MCP platform, without publishing their prices.
Vendor details
Canonical URL
https://www.klavis.ai
Category
Agent infrastructure
Subcategory
Tools and MCP
Funding status
Independent and backed by Y Combinator. The MCP servers and Strata are open source on GitHub.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Hosted MCP servers for more than a hundred applications, including GitHub, Gmail, Slack, Salesforce, HubSpot, Notion, Jira, Google Workspace and Microsoft 365, with per-user OAuth 2.0 or API-key authentication, reached by MCP URL, through Strata or through the Call Tool API. REST API with an OpenAPI specification and Python and TypeScript SDKs; guides for LangChain, LlamaIndex, CrewAI, Agno, Mastra, Google ADK and the major model APIs; open source servers with Docker images for self-hosting.
In practice
Your agent needs to act in each user's GitHub, Gmail and Notion, and you do not want to build OAuth for each. Klavis runs hosted MCP servers with per-user OAuth and returns a server URL the agent connects to.
Your agent loses accuracy as its tool list grows. Strata puts every connected server behind one MCP server the agent explores by category and action before executing one.
You need to test an agent's tool use against realistic data before production. Klavis sandboxes are seeded with a deterministic state, exported for checking against ground truth, and reset between runs.
Sources & related URLs
Agentic Index coverage score
7.0 / 14 capabilities · 50%
| Integrations & Tool Calling | Full |
|---|---|
|
Klavis runs hosted MCP servers for more than a hundred applications, from Affinity and Airtable to Zendesk and Zoho Mail in its docs catalog, and connects each one per end user through OAuth 2.0 or an API key, so an agent reads and writes in that user's own accounts. Tools are reached through each server's MCP URL, through Strata (one MCP server that lets the agent discover categories and actions across every connected server before executing one), or through the Call Tool API for plain function calling. Sourceklavis.ai/docs/mcp-server/overviewread 2026-09-22 |
|
| Workflow Orchestration | Not documented |
|
The product executes the tool calls an agent makes and returns the results. Sequencing, branching and handoff live in the customer's own framework, for which Klavis publishes guides (LangChain and LangGraph, LlamaIndex, CrewAI, Agno, Mastra, Google ADK and the major model APIs). Strata's discover, browse and execute tools help the agent pick an action, which is tool selection rather than orchestration. No workflow runtime of Klavis's own is documented to sequence, branch, retry or route work, or to combine deterministic workflow nodes with autonomous agent steps. Sourceklavis.ai/docs/ai-platform-integration/overviewread 2026-09-22 |
|
| Knowledge Grounding & RAG | Not documented |
|
There is no retrieval structure over the customer's own content. Klavis's MCP servers for Notion, Google Drive, Confluence and similar tools let an agent query those systems live, which is integration rather than grounding. Strata finds tools rather than documents, by browsing categories and actions instead of semantic search. No ingestion, indexing, retrieval or RAG layer of the product's own is documented, and no retrieved passages or sources are shown. Sourceklavis.ai/docs/concepts/strataread 2026-09-22 |
|
| Human Oversight & Guardrails | Partial |
|
The agent works inside constraints. Each end user authorizes an integration through OAuth consent before its tools act, and a server connection can be set read only through the API. Klavis Guardrails is described as a proxy between MCP clients and servers that detects tool poisoning and prompt injection, enforces least privilege access and checks tool invocations against allowlists. No approval step a person acts on before an action commits is documented, whether at a node, workflow or policy layer. Sourceklavis.ai/docs/enterprise-security/klavis-securityread 2026-09-22 |
|
| Security, Identity & Governance | Partial |
|
The API enforces HTTPS with API key authentication, each end user's credentials are scoped per integration and returned only to the key owner that controls the instance, and customers can run OAuth through their own white label OAuth apps. Connections can be set read only, and Klavis Guardrails enforces least privilege tool access. No attestation or certification is published: the FAQ's security answer names built in OAuth only, and the site footer links terms, privacy and cookie policies with no trust center. SSO, roles and an audit trail are not documented either. Sourceklavis.ai/docs/api-reference/overviewread 2026-09-22 |
|
| Observability & Auditability | Not documented |
|
No record of what an agent did through Klavis is documented for the customer: the API returns server instances, tools, users and authentication status, and the docs send users to the dashboard to check authentication, but no log, trace, execution history or audit event of tool calls is documented, and no export to a SIEM. Guardrails' real time threat detection is enforcement, not an inspectable record. Sourceklavis.ai/docs/api-reference/overviewread 2026-09-22 |
|
| Memory & State Persistence | Not documented |
|
Each end user's credentials and integration status are stored so tools act without asking for consent again, and a sandbox holds application state for one training or evaluation run, but no memory layer that keeps an agent's context across runs is documented; Klavis's Mem0 server connects an agent to another vendor's memory product. Stored credentials and a test environment's data are not agent memory, and no memory scope or lifetime is stated. Sourceklavis.ai/docs/api-reference/user/get-user-integrationsread 2026-09-22 |
|
| Deployment & Data Residency | Full |
|
Hosted servers run on Klavis's infrastructure with a stated 99.9% uptime SLA, and the API specification names two production servers, api.klavis.ai for the US and api.eu.klavis.ai for the EU. For on premises or custom deployments every MCP server ships as a Docker image to run in the customer's own infrastructure, and Strata is open source. Buyers can pick the US or EU region, or run the servers in their own environment. Sourceklavis.ai/docs/concepts/mcpread 2026-09-22 |
|
| Prebuilt Agents, Templates & Packs | Not documented |
|
The catalog holds MCP servers and tools, which give an agent actions rather than doing work when selected, and the framework guides build example agents as tutorial code. No ready made workflow, template or role specific agent of Klavis's own is documented for a buyer to adopt. Sourceklavis.ai/docs/mcp-server/overviewread 2026-09-22 |
|
| Triggers & Channel Coverage | Partial |
|
Slack and Discord clients come alongside the hosted servers, the FAQ says, so a person can put MCP tools to work from those chat channels. The documentation index carries no setup page for either client. Nothing that starts work without a person asking is documented: no schedule, webhook, event subscription or inbound queue. Sourceklavis.ai/faqread 2026-09-22 |
|
| Model Flexibility & Routing | Full |
|
Tools are served to whatever model the customer runs: the List Tools API returns a server's tools in several model formats, and the docs carry integration guides for OpenAI, Anthropic's Claude, Gemini, Mistral, Cohere, Together AI and Fireworks AI, each using the customer's own provider key. Klavis names no model of its own, so the model, the provider and the key are the customer's throughout. Sourceklavis.ai/docs/ai-platform-integration/overviewread 2026-09-22 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Klavis is callable from outside through a documented REST API at api.klavis.ai with a published OpenAPI specification, and Python and TypeScript SDKs cover servers, Strata, users, OAuth, white labeling and sandboxes. It serves MCP as an addressed service, each hosted server and each Strata instance having its own URL, and the servers and Strata are open source for self hosting. Sourceklavis.ai/docs/installationread 2026-09-22 |
|
| Testing, Debugging & Optimization | Full |
|
Isolated sandboxes of real applications let the customer test and train its agent. The Klavis Sandbox concept page describes a sandbox loaded with a deterministic world state, which the agent works against through MCP; the full state can be exported to compare against ground truth, and the sandbox resets for the next run. The Universe API acquires benchmark task environments, and its verify endpoint runs the task's check and returns whether the task passed, with the failure reason. Sandboxes can also be configured for the MCP-Atlas, Toolathlon and MCP-Mark benchmarks. Sourceklavis.ai/docs/api-reference/universe/verify-taskread 2026-09-22 |
|
| Browser & Computer Use | Partial |
|
The API specification's Local Sandbox API starts a virtual machine hosting interconnected MCP servers, among them Playwright for a browser plus a terminal and Desktop Commander for the machine. Klavis describes it as serving filesystem, terminal, browser and document workflows during agent training and evaluation. Klavis restricts it to use outside production, and no Klavis page describes driving a browser through the hosted Playwright server any further. The hosted MCP servers and Strata work through application APIs, not interfaces. Sourceklavis.ai/docs/api-reference/local-sandbox/acquireread 2026-09-22 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Pricing
Free (open source servers and a hosted free plan); Pro and Enterprise unpriced; sandboxes by quote
not published (plan tiers named in the FAQ; sandbox environments by quote)
Included quota
Free plan: hosted API at a default rate limit of two requests per second. Open source servers and Strata: no vendor limit when self hosted. Pro, Enterprise and sandbox quotas are not published.
What is public
The free paths are public: open source servers and Strata, and a hosted free plan at a stated rate limit. No paid plan price is published, and the pricing page quotes sandbox environments on request.
Billing mechanics
Self host the open source servers for free, or use the hosted platform on a free plan with a rate limit and move to Pro or Enterprise on terms that are not published; sandbox environments for training and evaluation are quoted by sales.
Cost watchouts
No paid plan price is published, so hosted use beyond the free plan's two requests per second needs a quote. Sandbox capacity for training and evaluation is priced on request. Self hosting moves the cost to your own infrastructure and operations.
Variable cost rationale
The free plan's rate limit is the only published usage term and paid usage terms are unpublished; self hosting the open source servers lets heavy users take the vendor cost to zero.
Overage / add-ons
Not published. The free plan is rate limited at two requests per second and paying users have no rate limit; self hosting has no vendor metering.
Sales call required
Mixed (some tiers require a call)
Free / trial
Open source servers and Strata free to self host, plus a hosted free plan
Lowest paid plan
None published; Pro and Enterprise plans are named in the FAQ without a price
Commercial notes
Independent and backed by Y Combinator. The homepage and pricing page now lead with training environments and agentic data for frontier AI labs; the MCP integration platform runs on the same account and API.
Key ambiguities
The pricing page no longer covers the MCP platform: klavis.ai/pricing redirects to sandbox environment pricing, while the FAQ still names free, Pro and Enterprise plans and no self-serve purchase path for a paid plan is published. Scope plan limits and prices with the vendor.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Klavis AI
The closest documented capability profiles to Klavis AI among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Arcade7.5 / 14Adds documented Observability & AuditabilityKlavis AI vs Arcade →
- Inworld AI8.5 / 14Adds documented Workflow Orchestration and Observability & Auditability, among others
- Maxim AI8.5 / 14Adds documented Workflow Orchestration and Observability & Auditability
- Portkey7.5 / 14Adds documented Observability & Auditability
- Freeplay8.0 / 14Adds documented Observability & Auditability
- Guardrails AI7.0 / 14Adds documented Observability & Auditability and Prebuilt Agents, Templates & Packs
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded