Statio

Documentation
API Reference
Changelog

Govern what your AI agents can reach

Statio is the security layer for MCP. Credentials stay server-side, permissions are per tool, and every call your agents make is written down.

Credentials never leave

Secrets live in Statio's vault and are injected into the upstream request at proxy time. Your agent never receives them — so a compromised agent cannot leak what it was never given.

Permissions per tool

A server exposing twelve tools can expose exactly the two you meant. Grants go to people and teams through the roles that already govern your org.

An audit trail you didn't have to build

Who called what, on whose behalf, and what came back. Produced as a side effect of normal use, which is the only kind that stays complete.

Managed MCP servers

Install from the catalog and Statio runs it. Or point it at an OpenAPI spec and it generates, builds and deploys the MCP server for you.

Built for CI

A deploy API keyed to your organization: cut a release, poll it, roll it back. No browser session, no device enrolment.

Egress you control

Managed servers run with no direct route out. An allowlist you set decides what they may reach, enforced outside the container.

© Statio