Your metal. Our engine.
One licence.

The same certified build, on your hardware, under an annual licence.

Talk to us about on-prem
Hosted instance, then your own metal under an enterprise licence, then sealed or air-gapped: your PostgreSQL at every step, and an exit marked leave without us. HOSTED a managed instance · start here the wire does not change YOUR METAL the same build · enterprise licence your data was always yours SEALED / AIR-GAP needs nothing from the public internet leave without us pg_dump · pg_restore · boot · no cooperation required
The same build at every step. Your users, sessions, and secrets in your own PostgreSQL throughout.

The licenceAgent-auth testingManaged agentsImplementationThe proof

What is sold here: the licence, quoted per production deployment, and the implementation engagement that lands it. Most first deployments buy both. Agent-auth testing is quoted separately, per deal. The vendor pack is on /buy.

The licence does not count SSO connections. Hosted Team is $299/mo flat with unlimited users and unlimited SSO connections. The argument is a dated note on /friday.

The same build, on your hardware.

The artifact you run is the artifact we run, so the wire your clients speak does not change when the engine moves.

same buildWhat we host and what you licence are the same certified build. Client code does not change; the wire is the contract.no rewrite
watermarkedEvery enterprise build is individually watermarked, so a leaked copy is attributable to the customer it was issued to.attributable
offline licenceValidity and expiry are enforced without a network call, and they fail closed: a tampered token refuses to boot rather than degrading quietly.air-gap safe
no seat countThe licence does not count users, sessions, or SSO connections. There is no meter to report, no true-up at renewal, and nothing to phone home about.nothing metered
your PostgreSQLUsers, sessions, and secrets stay in your own database, behind an /admin operator surface your team holds the key to.source of truth
How it is priced. Two rungs. Scale at $15,000/yr per production deployment, on standard terms: licence key, click-through agreement, email support. Enterprise · quoted, for what standard terms do not carry: air-gap delivery, source escrow, watermark attestation, security-questionnaire support, named support with an SLA. On-prem is a licence, never a free download: there is no community edition.

Prove your agent integration survives your customer’s real identity provider.

You know the deal that stalls in security review. They ask whether your SSO works with their identity provider. Now they ask a second question: does your MCP endpoint work with the one they run, and does the agent end up with less than the person who sent it?

We test that and hand you the list of what breaks. Per deal, per identity provider. We point the harness at two things: your MCP server, and the authorization server your customer actually runs.

audience bindingA token minted for the calendar must fail at the CRM.must refuse
narrowingThe agent should end up with less reach than the person, not the same.must narrow
revocationYou revoke. Does the agent stop?must stop
client registrationYour customer may still register clients one way while your stack expects the other.must match
the quiet oneThe token is issued, the sign-in looks fine, and then the tool call answers 401.must not
Re-runs, because the spec movesMCP revved twice inside a year, and the enterprise profile landed last month. Each move is a re-test your customer needs. That is what you pay us for, not something you should have to absorb.
Neutral by constructionWe test against the identity provider your customer runs, whoever sells it. We keep the quirks we find across all of them.
What this is notWe do not sell a badge, a certificate or a score. You get a report you can hand to a security reviewer, and a re-run when the spec moves.
How it is priced. Per deal and per identity provider, quoted when we see the pair. It is not a plan you pick from a table, and it is not bundled into the licence. Tell us which identity provider is blocking the deal →

Your customer’s own identity provider decides which agents reach what.

The MCP profile for enterprise-managed authorization went final on 28 July 2026. Under it, the company’s own identity provider signs a grant that says: this agent, on behalf of this person, for this API. The agent hands that grant to Signet. Signet reads the decision and mints a token to match. Nobody mails a per-tenant secret around.

the identity provider is registeredIt must already be registered against that customer’s organization here. Signet never learns whom to trust from the grant itself, and never fetches a key the grant points at.configured
the person holds a live seatThey must exist here and hold a live seat in that organization. Take them out of the org and their agents lose access the same minute.enforced
the grant names the APIA form field cannot widen it, narrow it or invent one.required
scope is the grant’s scopeCut down to what the client registered. A grant with no scope claim gets nothing, never the client’s defaults.intersected
the token never outlives the grantThe credential that authorized it sets the ceiling.bounded
no refresh token, everTo keep working, the agent presents the grant again.none issued
Where we stand on proof. We built this to the finished spec. We test each identity provider as its vendor turns the feature on. The first vendor to ship the enterprise profile has not opened it to every tenant yet, so a capture from a live commercial tenant is open work, not a claim. Read today’s evidence for exactly what it is: our reader is correct against a signing identity provider we run ourselves.
One more honest line. Two of the three ways an agent client can authenticate work end to end: a shared client secret, and a client whose credential is a signing key with no shared secret at all. The third is on what we refuse to do.

Named engagements. Fixed prices.

We do not sell hours. Each engagement below is a fixed scope at a fixed price, so the schedule risk sits with us, which is exactly the risk a first on-prem deployment should not be asked to carry.

Migration sprint · two weeks

$15,000

  • Stand Signet up on your infrastructure
  • Migrate your users off the incumbent
  • Cut one application over
  • Hand back a runbook your team owns

Enterprise landing · six weeks

$45,000

  • Everything in the migration sprint
  • SSO connections for your identity providers
  • Admin console rollout to your operators
  • On-call handover and security-questionnaire support

Advisory retainer · month to month

$4,000/mo

  • A named contact who knows your deployment
  • Architecture review before you build on it
  • Upgrade planning ahead of each release
  • Cancel at the end of any month

Prices are the engagement, not an estimate. Travel and any third-party licences you already hold are the only things quoted separately.

There is no installer. The first deployment onto your hardware is done with us, and the migration sprint is that work, priced. As the tooling lands, this becomes a choice instead of the only way in.

The proof a licence carries.

The engine is certified against better-auth 1.6.23: a differential conformance sweep of 280 / 280 with a compatibility gap of 0, and separately an end-to-end acceptance run of 14 / 14, both recorded 2026-07-25. Your instance renders its own receipt at /certification, from the same source as its machine-readable copy, so an auditor reads the build in front of them rather than a claim on this page.

Scope. The compatibility profile is a public, replayable set of checks; the same checks run against the better-auth reference implementation and against Signet, and the gap is the count of checks the reference passes and Signet does not. Gap 0 means that on every check in the profile, a client cannot tell the two apart. It is not a claim that every better-auth route is implemented: the profile is scoped to what those checks exercise, and anything they do not exercise sits outside it. Ask about a specific route and we will tell you plainly whether it is in the profile.

A licensed instance is also an OAuth 2.0 / OpenID Connect provider: other applications can sign users in with your instance, through the authorization-code flow with PKCE, and your instance mints the id_token. One boundary travels with that claim and always will until it moves: tokens are signed with EdDSA; RS256 is not supported.

No SLA outside a contractBusiness plans and enterprise agreements state response targets in writing. Outside a signed contract, none is offered or implied.
No third-party certification claimedWe hold no third-party audit attestation and do not imply one. On your own hardware, the control environment is yours. Our side of it is documented, and on Enterprise your security questionnaire is answered directly by the engineers who build Signet.
Operating envelope not publishedMaximum users, sustained request rate, and resource use under load have not been measured, so no capacity number is claimed here. Where an envelope matters to you, it belongs in the contract, measured against your workload.

Start the conversation.

Tell us what has to run inside your walls and by when. It is read and answered by an engineer who builds Signet, and on Enterprise the response target goes in writing.