SAML / OIDC through WorkOS. Okta, Azure AD, Google Workspace, Ping. Your users type your domain, browser bounces through your IdP, we mint the JWT. Zero password reuse.
/marketplace/sso →Deploy RailCall across your team — your keys, your SSO, your policy.
Everyone on your team gets governed AI writes on their machine. SSO through your identity provider, RBAC across five roles, private modules only your team sees, signed receipts streamed to your vault. $100 per seat per month, two seats minimum, with a 14-day free trial — and the runtime itself is never metered, on any tier.
- Studio + CLI + VS Code extension for everyone
- SSO via WorkOS (Okta, Azure AD, Google, Ping)
- 5-role RBAC + SCIM directory sync
- Private modules — visible only to your team
- Shared receipt vault (local · S3 · SMB/NFS · custom driver)
- Admin audit log + org data export (GDPR Art. 20)
- Long-lived API keys for CI/CD publishing
- Priority Discord + email support
The local runtime stays free and unmetered on every tier · your card is not charged until the trial ends · solo use is free forever on one seat · marketplace modules are billed separately from seats.
Every surface a team-admin needs, wired end-to-end.
viewer / operator / publisher / admin / owner. Higher implicitly grants lower. WorkOS webhook mirrors IdP changes — flip a user in Okta, membership updates within 15 min.
/marketplace/org/members →Publish internal modules that only your org's Studio installs can see. Public marketplace never lists them. Same signing + license machinery as public modules, gated on org membership.
Enterprise plan · Week 8 →local (filesystem / NAS / USB) · s3 (also MinIO, R2, GCS) · SMB/NFS network share · custom loader for your compliance layer. Secrets never in our DB — env:/file:/keyring: references.
/marketplace/org/vault-config →Self-contained tarball with every file + governance ruleset + station bundle + MANIFEST.txt sha256 + verify.sh. Move to network-isolated host, run verify + install. No outbound at install OR runtime.
/trust/air-gap →Append-only. Every admin mutation (invite, role change, vault reconfigure, subscription event) is a signed row. Owner+ view with event-slug filter + keyset pagination. Exportable for compliance.
/marketplace/org/audit →Full trust surface at /trust · subprocessors at /trust/subprocessors · live status at /status.
Negotiated BAA · air-gap install · custom retention · SOC 2 documentation under NDA · dedicated onboarding · custom vault drivers. Same code, formal contract.