xpander.ai
Also known as: xpander, Xpander
Governed runtime for enterprise AI agents: runs the agents teams already use, with approvals, audit, memory, knowledge and cloud, hybrid or air-gapped deployment.
xpander.ai describes itself as the governed runtime for enterprise AI agents: it runs the agents teams already use and governs every action they take. Agents are created with instructions, a harness and model, skills, approval rules and a runtime environment that acts as the agent's computer, or imported from existing definitions such as Claude Code agents. Skills come from a built-in catalog of API connectors, the customer's own OpenAPI specs and remote or local MCP servers, and workflows turn an agent into a graph of nodes with branching and human steps.
Work reaches agents through Xpander Chat, Slack and Microsoft Teams threads, email, WhatsApp, the API and MCP clients, or on recurring cron schedules. Agents carry organization-wide memories, per-user memories and thread history, and can search RAG knowledge bases. Risky actions wait for a named person's sign-off, each task records the agent's reasoning and call parameters, and an organization audit log keeps governed actions for up to 400 days.
Every model call passes through xpander's AI gateway, and sign-in runs through the customer's OIDC identity provider with credentials held in an external vault. xpander runs on its own cloud, as a Hybrid deployment with the runtime in the customer's cluster, or fully air-gapped, and states it is SOC 2 Type II certified, with ISO 27001, HIPAA and FedRAMP in progress. A REST API, Python SDK and MCP endpoint expose agents to outside systems.
Vendor details
Canonical URL
https://xpander.ai
Category
Agent infrastructure
Subcategory
Agent runtime and backend
Funding status
Independent. Headquartered in Tel Aviv, Israel, with around 50 employees and roughly $3M raised. Founded around 2024.
Company status
independent
Use cases & customers
Primary use cases
Target customers
Deployment options
Integrations
Agents draw on a repository of more than 2,000 MCP connectors and tools, plus custom tools for any private API, with Agentic RAG to search within large API responses. They are invocable from API, SDK, MCP, webhooks, Slack, CI/CD pipelines, cron triggers, or other agents, with unified event streaming from sources like Slack and Teams.
In practice
Your team prototyped an agent in a framework but stalled for months building deployment, monitoring, and rollback. You rebuild it on xpander, which ships the harness, versioning, and CI/CD so it reaches production fast.
You run a long, multi step task that spans hours and must pause for a human approval midway. The agent harness checkpoints state and resumes without losing context after the approval.
A regulated enterprise cannot send agent data to a vendor cloud. You self deploy xpander air gapped on your own Kubernetes with your own models, keeping execution and data inside your boundary.
Sources & related URLs
Related / legacy domains
Agentic Index coverage score
12.0 / 14 capabilities · 86%
| Integrations & Tool Calling | Full |
|---|---|
|
Agents hold skills of four kinds, including API connectors from a built-in catalog, connectors generated from the customer's own OpenAPI spec, and remote or local MCP connectors, each governed with actions that can be held for approval. Sourcexpander, docs.xpander.ai/connectors and connectors/add-a-skillread 2026-09-21 |
|
| Workflow Orchestration | Full |
|
A workflow is an agent whose behavior is a graph of nodes rather than a single loop, with node types, branching and human steps, alongside agents that call other agents as skills. Sourcexpander, docs.xpander.ai/use/agents/workflowsread 2026-09-21 |
|
| Knowledge Grounding & RAG | Full |
|
Agents attach RAG knowledge bases whose documents are added, listed and removed programmatically and queried by semantic search, managed through the REST API and Python SDK, which is a maintained retrieval structure over the customer's own documents. Sourcexpander, docs.xpander.ai/developers/knowledge/document-management and developers/knowledge/semantic-searchread 2026-09-21 |
|
| Human Oversight & Guardrails | Full |
|
Risky actions wait for a named person's sign-off, with approval rules and gated commands set per agent, permission modes on each run, and connector actions that can be held for approval, and approval requests and decisions are recorded on the task. Sourcexpander, docs.xpander.ai/use/approvals and use/agents/permissionsread 2026-09-21 |
|
| Security, Identity & Governance | Full |
|
xpander states it is SOC 2 Type II certified, with the report available under NDA, and documents an access surface of sign-in through the customer's OIDC identity provider such as Okta, Entra ID or Keycloak, scoped permissions on who may use, edit and share each agent, and an external vault for credentials. Sourcexpander, docs.xpander.ai/resources/security-compliance/certifications-compliance and run/integrations/identity-providersread 2026-09-21 |
|
| Observability & Auditability | Full |
|
Each task records the agent's reasoning entries and the parameters it chose for every call, so a failure can be traced to the model, the skill or the prompt, and a separate organization audit log records governed actions such as agent changes, skill connections, credential use and sign-ins, with filters, download and stated retention of 90 or 400 days by event type. Sourcexpander, docs.xpander.ai/use/agents/auditread 2026-09-21 |
|
| Memory & State Persistence | Full |
|
Memory comes in three documented scopes: agent memories the agent always carries across the organization, user memories holding per-user facts that persist across sessions, and session storage keeping conversation history within a thread in Postgres. Sourcexpander, docs.xpander.ai/developers/memory pagesread 2026-09-21 |
|
| Deployment & Data Residency | Full |
|
xpander runs three ways: on xpander cloud, as a Hybrid deployment with the runtime in the customer's own cluster and the control plane on xpander cloud, or fully air-gapped with every component in the customer's environment, with documented EKS setup and a choice of cloud or self-hosted locations per agent. Sourcexpander, docs.xpander.ai/self-hosted and run/locationsread 2026-09-21 |
|
| Prebuilt Agents, Templates & Packs | Partial |
|
xpander ships one built-in agent, Omni, plus a skills registry of skill bundles and import of existing agent definitions such as Claude Code agents; these are one agent and assets the customer assembles, and no set of separate ready-made agents is documented. Sourcexpander, docs.xpander.ai/use/skills-registry and use/agents/importread 2026-09-21 |
|
| Triggers & Channel Coverage | Full |
|
Recurring cron schedules start agents without a person asking, and agents can book their own one-off re-checks; work also reaches agents through Slack and Microsoft Teams threads, email, WhatsApp, the API and MCP clients. Sourcexpander, docs.xpander.ai/use/agents/schedules and use/agents/channelsread 2026-09-21 |
|
| Model Flexibility & Routing | Full |
|
Each agent's model is chosen in its configuration from the documented model providers, with the customer's own keys supplied on cloud, hybrid and air-gapped installs, and every model call passes through xpander's AI gateway, which enforces the organization's model policy, so model choice sits with the customer. Sourcexpander, docs.xpander.ai/run/integrations/ai-vendors and run/integrations/ai-gatewayread 2026-09-21 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A documented REST API creates and configures agents, starts runs and reads their record, and manages skills, knowledge and workflows, alongside a Python SDK and an MCP endpoint with OAuth 2.1 that lets outside clients reach xpander agents. Sourcexpander, docs.xpander.ai/api-reference/rest-api, api-reference/sdk and api-reference/mcpread 2026-09-21 |
|
| Testing, Debugging & Optimization | Partial |
|
The documented surface for quality is debugging: each task records reasoning entries and call parameters so a failure can be traced to the model, the skill or the prompt, and Omni can review instructions. No evaluation harness, scored test cases or quality gate is documented. Sourcexpander, docs.xpander.ai/use/agents/auditread 2026-09-21 |
|
| Browser & Computer Use | Not documented |
|
The agent's runtime environment is a computer of CLIs, packages, config files and scripts for running code, which is autonomous execution rather than browser, desktop or computer control; browsing comes only through Anchor Browser and Browserbase connectors, third-party products bought separately. Sourcexpander, docs.xpander.ai/use/agents/runtime-environments and connectors/browserbaseread 2026-09-21 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
xpander.ai added a Secrets section that declares an agent's required credentials, validates personal connections, and resolves secrets on every turn. Its September 20 release also adds skill visibility scopes, grants for individual agents, and a public skill publishing API. Gated mode now holds web fetch and search calls for approval, with gated command editing available for Claude Code, Codex, and OpenCode agents.
Bears on: Security / enterprise
View sourcexpander introduced Slack Native AI Agents, allowing users to deploy custom AI agents directly into Slack workspaces. These agents can respond to mentions, maintain memory context across conversation threads, and execute real-time tool calls within the collaboration platform.
Bears on: Integrations
View sourcexpander released a platform update introducing External Vaults for Azure Key Vault integration and agent credential bindings. The release also adds human-in-the-loop approval workflows for individual tool calls, local MCP server support within agent workspaces, and an import and export contract for MCP clients like Claude Code.
Bears on: Security / enterprise
View sourcePricing
Free (no card) · pay as you go (usage in packs) · Team & Custom tiers
usage
Included quota
Free: 100 interactions, 100 actions, 1M input + 100K output tokens, 100 threads, 5 serverless agents, 10 vector objects, 5 builder seats/month. Pay as you go: usage billed in packs (~$10/100K actions, ~$10/200K interactions, $2.5/1M input tokens, $10/1M output tokens, plus thread/vector/agent rates). Team: higher limits + governance. Custom: full self hosting, SSO, SLA, onboarding, A/B testing, external logging, vector DB access.
What is public
The free tier limits and pay as you go per unit rates are public; Team and Custom dollar pricing are not.
Billing mechanics
Free tier with monthly caps that pause agents, then pay as you go billed in fixed monthly packs across multiple usage meters. Team and Custom are higher tiers, the latter sales contracted with full self hosting.
Cost watchouts
Multiple meters bill in parallel (actions, interactions, input and output tokens, threads, vector objects), and always on embedded agents consume dedicated compute continuously; without bring your own license, token spend at scale can dominate the bill.
Variable cost rationale
Beyond the free tier, cost is purely usage based across many meters at once: agent actions, interactions, input and output tokens, threads, vector objects, and running agents. Production agents that call tools heavily, process long contexts, or run always on embedded containers accumulate cost across several axes, though bring your own license can reduce token spend and spend caps limit overages.
Additional watchouts
Usage is metered across many axes simultaneously, so cost can come from actions, interactions, tokens, threads, vectors, and always on embedded agents at once. Always on embedded agents carry dedicated compute cost; model usage at scale benefits from bring your own license.
Overage / add-ons
Free tier caps pause agents at the monthly limit; adding a card activates pay as you go, which removes caps and bills usage monthly in fixed packs. You can set a spend cap that throttles or pauses agents to prevent overages.
Sales call required
No, self serve available
Free / trial
Free tier (no credit card, indefinite): core features, 50+ tools, 5 serverless agents, 100 interactions and 100 actions/month, 1M input + 100K output tokens, 100 threads, 10 vector objects, 5 builder seats. Agents pause at caps.
Lowest paid plan
Pay as you go: usage billed monthly in packs (e.g. ~$10/100K actions, ~$10/200K interactions, $2.5/1M input tokens, $10/1M output tokens)
Commercial notes
Self serve, developer first with an indefinite free tier and pay as you go, scaling to Team for production governance and Custom for enterprise self hosting and compliance. Billing through Stripe or AWS Marketplace. Vendor neutral with bring your own model and license.
Key ambiguities
Team and Custom pricing and the complete pay as you go pack rate card are not fully public.
Cancellation / refund
Free and pay as you go are self serve. Custom and self hosting are contractual.
Support SLA / resale
Community and self serve on Free and pay as you go; governance on Team; dedicated support with an SLA on Custom. Available via AWS Marketplace.
Missing data
Team and Custom dollar pricing, and the full pack rate card for threads, vector objects, and agent containers, are not public.
Related vendors
- AgentOps — Agent observability and debugging platform: open source SDKs trace…
- Agno — Python agent framework and AgentOS runtime (formerly Phidata) for…
- AIsa — Resource and payment gateway for AI agents: one key to 110+ models…
- AlphaBitCore — AI control plane for regulated financial firms: one gateway enforces…
- Anchor Browser — Cloud hosted browser infrastructure that lets AI agents operate real…
- Apify — Cloud platform and marketplace of more than 73,000 ready-to-run…
Alternatives to xpander.ai
The closest documented capability profiles to xpander.ai among agent infrastructure platforms tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Kestra12.5 / 14Fuller documented coverage on Prebuilt Agents, Templates & Packs
- Agno13.0 / 14Fuller documented coverage on Prebuilt Agents, Templates & Packs and Testing, Debugging & Optimization
- Sourcegraph11.0 / 14A lighter documented profile than xpander.ai
- Thread AI11.0 / 14A lighter documented profile than xpander.ai
- Tray.ai13.0 / 14Fuller documented coverage on Prebuilt Agents, Templates & Packs and Testing, Debugging & Optimization
- Cartesia10.5 / 14A lighter documented profile than xpander.ai
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded