Tray.ai
Also known as: Tray.io, Tray
Enterprise integration and automation platform with an agent layer: 700+ connectors, visual workflows, no-code agents grounded in a synced knowledge base, and an MCP gateway that governs which tools agents may call.
Tray.ai, formerly Tray.io, is an enterprise orchestration platform for data and AI: one governed foundation carrying integration, automation and the agents built on top of them. Workflows are built in a visual, low-code builder with conditional logic, branching, looping, retries and timeouts, drawing on a library of more than 700 managed connectors, and the same connectors are exposed to AI clients as MCP tools.
Merlin Agent Builder is where agents are assembled, from a scope that sets goals and limits, data sources, workflows as tools and a model. Connecting a data source such as Google Drive, Gmail, Confluence or SharePoint syncs the documents into a vector table the agent searches through a knowledge tool included by default, so answers are grounded in the customer's own material without live calls per query.
Agents can start from pre-configured accelerators, a Knowledge agent, an ITSM agent or a Support ticket agent, run on Tray's native model or on the customer's own OpenAI or AWS Bedrock keys, and reach people through Slack and Microsoft Teams as well as the API. A built-in test chat shows each reply with the tools considered, whether the knowledge base was searched, processing time and token usage.
Agents keep short and long term memory, so they can refer back to a user's earlier conversations. A person stays in the path where it matters: workflows take an approval step routed to Slack, email or a custom form, and agent guardrails pause for a human when confidence is low or an action falls outside the agent's scope. Tray also publishes an evaluation template in its library that scores agent responses with an LLM judge, so a team can compare versions of an agent over time.
Agent Gateway is the governance half: Tray workflows become composite MCP tools and connector operations become individual tools, with an access allowlist, RBAC, rate limits, OAuth2 or token authentication for the calling client, and a choice between shared service credentials and the end user's own.
Runs are logged step by step, streamed to the customer's own endpoint, and maskable or switchable off where data minimization matters. Instances are hosted in the US, EU or APAC so data stays in region, with an on-premise agent and AWS PrivateLink for systems behind the firewall. Tray states SOC 1 and SOC 2 Type 2, HIPAA, GDPR and CCPA. Pricing is quoted by sales across Pro, Team and Enterprise, metered in Tasks, with a free trial.
Vendor details
Canonical URL
https://tray.ai
Category
Agent infrastructure
Subcategory
Enterprise iPaaS + AI agent orchestration / MCP governance
Funding status
Independent; an established enterprise integration vendor, formerly Tray.io.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
700+ managed connectors (Salesforce, Workday, Snowflake, Jira, NetSuite, ServiceNow, and more), each governable through the same RBAC and publishable as MCP tools. Agent Gateway provides an MCP registry and governance layer — composite and connector-backed MCP tools, MCP consumption, and Agent-to-Agent (A2A) support — with audit trails streamable to Datadog and Splunk. Agents deploy to Slack, Teams, chatbots, or APIs.
In practice
Your team spins up AI agents faster than IT can govern them, and shadow MCP servers multiply. Tray's Agent Gateway is an MCP registry that lets IT build, version, and publish governed MCP tools.
An agent is only useful if it can reach your stack. Tray connects through more than 700 managed connectors, so agents act across Salesforce, Workday, Snowflake, and the rest.
Ops leads need to build agents without waiting on engineering. Tray's Merlin Agent Builder is a no-code environment with guardrails, PII protection, and human-in-the-loop baked in.
Sources & related URLs
Research sources
Agentic Index coverage score
13.0 / 14 capabilities · 93%
| Integrations & Tool Calling | Full |
|---|---|
|
Agent Gateway exposes Tray workflows as composite tools and individual operations from 700+ connectors as tools over MCP, with tools authenticating by shared service credentials or the end user's own, an access allowlist, OAuth2 or API token for the calling client, RBAC and rate limits; agents built in Merlin Agent Builder take actions by running Tray workflows as tools. Sourcetray.ai/documentation/platform/artificial-intelligence/agent-gateway/overviewread 2026-09-22 |
|
| Workflow Orchestration | Full |
|
Tray is a workflow platform with an agent layer on top: workflows sequence steps with conditional logic, branching and looping, retries and timeouts, and an agent project combines a scope, data sources, workflows as tools and a model, so autonomous agent steps run alongside deterministic workflow nodes. Composite tools package multi-step business logic as a single callable tool. Sourcetray.ai/documentation/platform/artificial-intelligence/agent-builder/overviewread 2026-09-22 |
|
| Knowledge Grounding & RAG | Full |
|
Adding a data source in Merlin Agent Builder connects a system (Google Drive, Gmail, Confluence, SharePoint or a custom connector), syncs and processes the documents and stores the content in a vector table that supports semantic search, which the agent queries through a Knowledge Search tool included by default. New customer knowledge joins a maintained index without retraining, one that persists, scales past the context window and stays queryable. Sourcetray.ai/documentation/platform/artificial-intelligence/agent-builder/data-sourcesread 2026-09-22 |
|
| Human Oversight & Guardrails | Full |
|
A person sits in the path at both layers. In workflows, an approval step can be inserted anywhere and routed to Slack, email or a custom form, and the run pauses and resumes automatically once the decision is made; agents built in Merlin Agent Builder act by running those workflows as tools. For agents directly, Tray states that guardrails pause an agent when confidence is low or when an action falls outside its defined scope, and surface the decision to a person before it continues, and the Merlin Agent Builder page lists approval workflows for sensitive actions. Around that sit the constraints: an Agent Gateway access allowlist, RBAC, rate limits, agent scope, log masking and an execution kill switch. So a person can approve before an action commits, inside the channels a team already uses. Sourcetray.ai/glossary/human-in-the-loopread 2026-09-25 |
|
| Security, Identity & Governance | Full |
|
SOC 1 and SOC 2 Type 2, HIPAA, GDPR and CCPA are stated across the platform, and Tray says every agent action, MCP tool call and workflow run is traceable to a user. The access surface is documented in the enterprise docs: organizations and workspaces, user roles, two-factor settings, an access allowlist and RBAC on Agent Gateway, log masking to hide a step's inputs and outputs, and administration of which Merlin AI features are enabled. Sourcetray.ai/platformread 2026-09-22 |
|
| Observability & Auditability | Full |
|
Every workflow run produces debug logs showing each step's input and output, agents have their own logs and debugging view, Agent Gateway has an observability and monitoring page for tool execution, and Tray streams workflow logs to an external endpoint for the customer's own tooling, with log masking, disabling of log storage and anomaly detection as controls. The platform page states every agent action, MCP tool call and workflow run is traceable to a user. Sourcetray.ai/documentation/platform/enterprise-core/logs-debugging/log-streamingread 2026-09-22 |
|
| Memory & State Persistence | Full |
|
Tray states that Merlin Agent Builder includes short and long term memory, so agents keep track of session history and refer back to a user's prior conversations automatically, with a sliding context window keeping each exchange focused. Tray frames the problem it solves as an agent forgetting a user's earlier issue every time that user returns, which places the memory across conversations rather than inside one. Knowledge synced into the agent's vector table is a separate retrieval structure over documents. Sourcetray.ai/company/news/merlin-agent-builder-user-adoption-releaseread 2026-09-25 |
|
| Deployment & Data Residency | Full |
|
A Tray instance is hosted in a data region the customer picks, US, EU or APAC, so business data does not leave the region it originated in, with region-specific API base URLs and multi-region setups for multinational or embedded use. For systems behind the firewall, Tray documents an on-premise agent and AWS PrivateLink connectivity. Sourcetray.ai/documentation/platform/enterprise-core/organisation-management/regional-hostingread 2026-09-22 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Buyers start from preconfigured agent accelerators, each with a predefined scope for its use case: a Knowledge agent, an ITSM agent and a Support ticket agent, alongside prebuilt tools and workflow templates that can be customized. Sourcetray.ai/documentation/platform/artificial-intelligence/agent-builder/configurationread 2026-09-22 |
|
| Triggers & Channel Coverage | Full |
|
Work reaches Tray without a person asking: workflows start from connector triggers and webhook subscriptions, scheduled polling for new data and an alerting trigger, and agents are reachable through interaction channels in Slack and Microsoft Teams as well as the API. Sourcetray.ai/documentation/platform/artificial-intelligence/agent-builder/interaction-channelsread 2026-09-22 |
|
| Model Flexibility & Routing | Full |
|
An agent's model is a configuration choice: Tray ships a native default model and documents bringing your own by connecting API keys from third-party providers such as OpenAI or AWS Bedrock, choosing the provider and the specific model version in the agent dashboard. Sourcetray.ai/documentation/platform/artificial-intelligence/agent-builder/configurationread 2026-09-22 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
Tray publishes OpenAPI specifications for the Tray Platform and Tray Embedded APIs, a Connector Development Kit for building and testing custom connectors, developer tools including a connector tester and operations explorer, embedded auth dialogs for the customer's own end users, and Tray Headless MCP for connecting Cursor, Windsurf, Codex or Claude Code to the platform. Sourcetray.ai/documentation/platform/tray-headless/tray-headless-mcpread 2026-09-22 |
|
| Testing, Debugging & Optimization | Full |
|
An AI evaluation framework sits in Tray's documentation library: a template that uses an LLM as a judge to review each input prompt and agent response against set criteria, covering response quality, conversation flow, edge cases and behavioral consistency. The judge returns structured feedback and quantitative metrics tracked over time, so a team can compare versions of an agent and see whether a change improved it. That sits beside the built in test chat, which shows each reply with the tools considered, whether the knowledge base was searched, processing time and token usage. Sourcetray.ai/documentation/library/template/6480885f-d884-469c-8c80-77a2f36a4b61-get-started-with-ai-evaluationsread 2026-09-25 |
|
| Browser & Computer Use | Not documented |
|
Tray acts through connectors, workflows and MCP tools that call APIs; no browser, desktop or remote computer session that Tray drives for an agent is documented. No headless fetch or third party browsing engine of Tray's own is documented either. Sourcetray.ai/documentation/platform/artificial-intelligence/agent-gateway/overviewread 2026-09-22 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
Tray.ai introduced Tray Helix, a governed runtime environment designed for AI-built applications. The release features a centralized credential broker that allows apps to reference authentication aliases, ensuring that raw secrets never touch application code or AI prompts.
Bears on: Security / enterprise
View sourceTray.ai made MCP dynamic authentication generally available. MCP tools can now run using end-user credentials instead of shared service accounts, with allowlists, authentication management, and a usage monitor.
Bears on: MCP / tool calling / API
View sourceTray Headless MCP added region-specific endpoints for US, EU, and APAC workspaces.
Bears on: Deployment / data residency
View sourcePricing
Custom quote · free trial · Pro / Team / Enterprise
usage (tasks)
Included quota
Pro covers up to 3 workspaces with 7 day insights retention. Team covers 20 workspaces with 30 day insights retention, enhanced insights, 24/7 support, and dedicated Slack. Enterprise covers unlimited workspaces with 180 day insights retention, regional hosting, log streaming, on premise connectivity, and embedded white label options. All plans include business hours support and a free trial. Task volume is quoted per customer.
What is public
Public: the three tiers and what separates them (workspaces, insights, support, regional hosting), that all plans include the 700+ connectors and connectors as MCP tools, and that usage is metered in Tasks. Not public: any rate, in any unit.
Billing mechanics
A usage-based subscription metered in Tasks across three tiers, quoted by sales on expected usage and the features required. Multi-step automations, real-time triggers and retries all consume Tasks. Agent Builder and Agent Gateway are enabled by Tray's account team rather than self-serve.
Cost watchouts
Task consumption is driven by automation complexity and trigger frequency, so real usage can exceed early estimates, and Agent Builder and Agent Gateway must be switched on by Tray's account team. Regional hosting is an add-on per region on Team and standard only on Enterprise; support SLAs, insights retention and workspace count all move with the tier.
Variable cost rationale
Billing is usage based on tasks, and task consumption scales with workflow complexity, trigger frequency, data volume, connector count, and retry logic, so heavy automation and agent activity drive cost up quickly. Add ons such as HIPAA, extended retention, and the separately licensed agent product add further cost, making exposure high.
Additional watchouts
Pricing is quote only with no public dollar figures. The agent builder is a separate line item from core iPaaS, HIPAA is an add on, and task based billing means cost scales with automation volume.
Overage / add-ons
Task usage is set by the quoted plan; exceeding it requires moving to a higher tier or a larger task allotment agreed with sales.
Sales call required
Mixed (some tiers require a call)
Free / trial
Free trial arranged through sales; no perpetual free tier
Lowest paid plan
Pro tier for up to 3 workspaces, priced by a custom usage based quote above a free trial.
Commercial notes
A single AI native platform spanning integration, automation, MCP governance, and agents, positioned to replace fragmented legacy iPaaS stacks. Tray reports customers ship faster and spend materially less than legacy iPaaS, though the usage based, quote driven model requires sizing task volume carefully.
Key ambiguities
No dollar figure appears anywhere on the pricing page: every plan routes to a custom quote based on usage and features. What a Task costs, and how agent usage is metered against Tasks, come from sales.
Support SLA / resale
All plans include business hours support (Tray Advantage). Team and Enterprise add 24/7/365 support, enhanced SLAs, and dedicated Slack channels (Tray Advantage Plus). An embedded white label bundle is available at Enterprise.
Missing data
Dollar rates for each tier, per task pricing, the separate Merlin Agent Builder license cost, and add on pricing for HIPAA and extended retention are not public.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to Tray.ai
The closest documented capability profiles to Tray.ai among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Agno13.0 / 14Matches Tray.ai across all 14 documented capabilities
- Kestra12.5 / 14A lighter documented profile than Tray.ai
- Haystack12.0 / 14A lighter documented profile than Tray.ai
- LlamaIndex12.0 / 14A lighter documented profile than Tray.ai
- Mastra14.0 / 14Adds documented Browser & Computer Use
- xpander.ai12.0 / 14A lighter documented profile than Tray.ai
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded