# Arcade — Full Content > Full Markdown content of all public pages on arcade.dev. > Last generated: 2026-05-14 --- ## Homepage URL: https://www.arcade.dev/ Last updated: 2026-05-14 **Ship agents. Not auth infrastructure.** Arcade is the enterprise-ready actions runtime for AI agents — the layer between your agents and every system they reach. Enforce your security policies, execute reliably across any system, and govern centrally. So your agents sail through security review. ### An agent isn't an agent if it can't take actions Most AI agents never make it past the demo. They all hit the same three walls: authorization, tools, and governance. **Authorization is the first wall** — Agents need to act on behalf of real users with real permissions, not shared tokens or hardcoded credentials. This requires dedicated security infrastructure and the team to build it. **Most MCP tools are broken** — An API wrapper is not an agent tool. The gap between what a user means and what the API expects causes hallucinations and expensive retries. **Governance is an afterthought** — "What action did this agent take, on behalf of which system?" You need to answer that for every execution, every time — without slowing production. ### One runtime that solves all three Your team ships agents, not infrastructure. Agents that pass security review, work the first time, and have every action fully logged and accounted for. ### Everything your agents need **Agent auth** — Your agents act as real users with dynamic permissions. Your existing IDP plugs right in, credentials never leave the runtime, and your team never builds auth infrastructure again. **Agent-optimized tools** — User intent maps to the right API call the first time. No hallucinated parameters, no silent failures, no retries burning through your budget. Thousands of MCP tools available. **Central control plane** — "What did the agent do, on behalf of which user, in which system?" You can answer that for every action, every time, without slowing down the teams shipping agents. One place to set policy, one place to audit. **Runs with your stack** — Automate and benchmark LLM-Tool interactions for reliable performance. ### We take the boring stuff seriously **Compliance-ready** — SOC 2 compliant. SSO, RBAC, and full audit logs out of the box. **Deploy on your terms** — Cloud, on-prem, air-gapped, or hybrid. You control where your data lives and how it's secured. **Built by the people writing the spec** — The Arcade team comes from Okta, Snowflake, Redis, Airbyte, and MongoDB. We authored the MCP tool authorization specification and sit on the steering committees for MCP security and governance. ### What customers are saying > "We built an AI sales agent that knows everything about every deal by analyzing calls, emails, and CRM data. With Arcade, that agent can now go the extra mile and effortlessly take secure actions on behalf of a rep — turning a smart assistant into a revenue-driving powerhouse." > — Sarah Chen, Head of AI at Sybill > "Arcade removed the biggest blocker to shipping our agent in production: authorization. We went from a three-month security review estimate to deploying in two weeks. The audit logs alone saved us months of custom instrumentation." > — Marcus Webb, VP of Engineering at Clearbit > "Every agent framework we evaluated had great orchestration primitives but zero answers for 'how does the agent authenticate as the user.' Arcade answered that question on day one and never slowed us down." > — Priya Nair, CTO at Ramp > "We tried building our own tool authorization layer. Three engineers, four months, still not compliant. We switched to Arcade and had it running in a sprint. Genuinely one of those 'why did we ever build this ourselves' moments." > — Jordan Park, Director of Product at Ironclad --- ## Product URL: https://www.arcade.dev/product Last updated: 2026-05-28 **The runtime agents have been missing.** See what's under the hood — auth, tools, governance, and execution, unified in one layer that every agent runs through. ### Why runtime? **Built into the agent's path, not bolted on.** Runtimes enforce the rules that matter where code actually runs. Agents need one too: a single enforcement point across every agent framework and model. Without Arcade: - Auth is per-team, per-agent, per-integration. - Tools are raw API wrappers. - Governance is stitched together after the fact. - Security review kills the project. With Arcade Runtime: - Auth is handled once. - Tools are built for agents. - Governance is built in. - Security says yes. ### The Arcade impact - **Your AI investment starts paying off.** Agents get to production faster and start taking real actions. The ROI shifts from incremental to operational. - **Ship faster every time.** First agent ships in weeks. Second ships in days. The runtime eliminates the ramp as you scale agents, users, and servers. - **Scale without complexity.** New vendors, new frameworks, new teams. Each one routes through the same runtime. No new reviews, no new setups, no new overhead. ### How it works Every agent action flows through the runtime. Arcade handles permissions, credentials, execution, and logging. The agent never touches raw APIs or secrets. ### Under the hood **Secure Agent Authorization — Agents act as users, not around them.** Every agent action is scoped to a real user's real permissions. Not a service account. Not a shared token. Evaluated per action, at runtime. - Multi-user, post-prompt authorization: Deploy agents across any number of users and business systems. Every action is scoped to what that specific user is permitted to do. - Isolated token lifecycle management: Handles OAuth refresh, rotation, and mismatch. Credentials injected at execution, never exposed to agents or MCP clients. - Contextual access policy enforcement: Pre- and post-tool-call hooks enforce policy on every action. Runtime controls without manual review of every deployment. **Reliable Tools & Execution — Tools that work the first time.** Agents don't think in API parameters. Arcade's tools translate user intent into the right API calls. - Thousands of agent-optimized MCP tools: Natural language intent to precise API calls across Salesforce, ServiceNow, Workday, Jira, Slack, Google Workspace, and hundreds more. - MCP Gateway: Teams run multiple MCP servers. Arcade federates them into a single endpoint so agents see one tool layer, and you control which tools are available per gateway. Add it to any MCP client in seconds. - Open source framework for custom tools: Auth and secrets management built in. Eval framework included so you can test tools before they reach production. - Execution at scale: Parallelized execution, automatic failover, and intelligent retries with developer-defined context. So your agents stay reliable as you scale from one user to thousands. **Central Control Plane — Know what every agent did, for which user, in which system.** Agents in production need more than monitoring. They need a single place to set policy, manage access, and govern every action across your organization. - Centralized governance: Set and enforce access policies across every tool, agent, and user. One policy layer for Arcade-built, custom, and third-party MCP servers. - Fine-grained visibility and audit logs: What every agent accessed, on behalf of which user, in which service. Exportable to your SIEM via OpenTelemetry. - Version control for safe upgrades: Versioned deployments for tools and MCP servers. Push changes without breaking production agents. - Shared registry with team-level access: One registry for tool discovery across every team and project. Team-level controls for who can access, use, and modify tools. ### Integrations **Find your tool.** 7,000+ agent-optimized tools across 80+ toolkits. Fewer hallucinations and lower token costs. Includes GitHub, Jira, Salesforce, Slack, Notion, Google Drive, Linear, Stripe, Asana, Firecrawl, Gmail, Confluence, Dropbox, Zendesk, ClickUp, Microsoft 365, ServiceNow, Zoom, Workday, Spotify, YouTube, and more. - **Build for your custom systems:** Open source framework with auth, governance, and evals built in. Tool patterns get you to production-grade faster. - **Set the quality bar:** Evaluate any MCP server with Toolbench and ensure reliability before production. Manage external servers in Arcade and hold them to the same standard. ### Deployment & Compliance **Your infrastructure, your rules.** - **Arcade Cloud:** Fully managed. Zero infra overhead. - **Bring your own cloud:** Your AWS, Azure, or GCP. Data never leaves your environment. - **Self-managed:** On-premises or your cloud. Full control. - **Air-gapped:** Zero internet connectivity. Built for classified environments. Compliance: - SOC 2 compliant - SSO and RBAC out of the box - Data residency tied to your deployment model - Audit logs exportable to your SIEM via OpenTelemetry ### Getting started **Start building in minutes.** - **Run in your favorite MCP client:** Add Arcade to Claude, Cursor, ChatGPT, or any MCP client. Set up a gateway with the tools you need and start taking actions. - **Build your own agent:** Use any framework. Arcade handles auth, tools, and governance so you write agent logic, not infrastructure. ---