Ship AI Agents Your Customers Can Trust.

The governed infrastructure layer for building and deploying agents — connectors, permissions, audit trails, and cost controls built in — for your product, or your own stack.

Free to start, no credit card · for enterprise & air-gapped

Reaches on-prem & air-gapped systems

Behind your firewall, outbound only

Scoped, revocable access

Signed tokens, rotate anytime

Free to act, never to overreach

Scoped to the sources and actions you allow

Usage you can see

Cost per user, before it surprises you

Developer-first

A few lines to ship

Sign a scoped token for each of your users — source allowlists, rate limits, read-only by default — then drop in the widget or call the SDK. The governance rides in the token, so there's no glue code to maintain.

typescript
1// Server-side: sign a scoped token for this user
2const token = cb.widgetToken(user.id, {
3 sources: ["orders", "invoices"],
4 limits: { daily: 50 },
5});
6
7// Client-side: drop the governed widget into your app
8import "@corebasehq/widget";
9
10CorebaseWidget.init({
11 publicId: "proj_•••",
12 getAuthToken: () => token,
13});
Connect

Give your agents the data they run on

Every agent you ship reads straight from your real systems — databases, REST & GraphQL APIs, and 50+ apps. No ETL, no glue code, no integration sprint.

See all integrations
GitHub
Slack
Jira
Notion
Salesforce
Stripe
PostgreSQL
MSSQL
Gmail
HubSpot
Zendesk
Shopify

Cloud & SaaS

Connect in one click

Paste a connection string or sign in — PostgreSQL, MySQL, REST & GraphQL APIs, Slack and Microsoft 365 connect directly, live and read-only.

On-prem & legacy

When a customer needs it

When a customer's data lives behind the firewall, reach it too: the open-source CoreMCP agent runs inside their network to serve SQL Server 2000+, Firebird, and on-prem ERP / POS. It connects outward from the inside — nothing to open up, no VPN. Even works fully offline.

Why CoreBase

Everything you need to ship on real data

Guardrails, attack screening, per-user isolation — the governance you'd otherwise build yourself, already here. Batteries included, self-host optional.

Agents that stay on the rails

Draw the steps your assistant works through — what data each step can touch, what it may do, when it must ask for approval. It reasons freely inside; the rails are enforced, not suggested.

Every visitor connects their own

Gmail, Jira, or any of 50+ apps — each visitor links their own account, and the assistant acts on it alone. Isolation is the OAuth grant itself, not a filter that could slip.

Bring your own model

Use the built-in AI, or plug in your own keys — Claude, GPT, Gemini and more. Switch anytime.

Private by design

Read-only by default, isolated per customer, encrypted in transit and at rest — and every action is logged.

Screened at the door

Every message is checked for prompt injection, jailbreaks and abuse before it reaches the model — on chat, widget, voice and API alike.

It learns your schema

Query Memory remembers the queries that worked and what your tables mean — so natural-language → SQL gets sharper the more you run it.

Explore

Ask across every system — answers from live data

One query can hit your database, your CRM, and your inbox at once — read straight from the source, never a stale copy.

One question, every source

CoreBase fans your question out across the systems you have connected and assembles a single answer — with every step logged.

Real numbers, straight from the source

Answers come back as figures and tables computed from live data — not summaries of a stale copy.

Always current

Every answer is computed at ask time, straight from the live system.

Only their own rows

Each question runs as the person asking it, so one customer can never be answered with another’s data.

Asks before it changes

Nothing is written until someone says so — the customer for their own data, your team for anything you gated.

Full audit trail

Every question, query, and action is recorded — nothing happens off the record.

Govern

Room to think, rails that hold

Draw the steps your agent works through — the data each step can reach, the actions it may take, when it must ask first. It reasons freely inside; the rails are enforced in code, never just suggested in a prompt. Watch one hold:

Refund request · #1043running
In this rail, the agent canEnforced
Read orders & payments
Refund over $100 — waits for a human OK
Anything else — never runs

Enforced, not suggested

A blocked action is never called; a required approval is never skipped. Your rules compile to real gates — not a line in a prompt the model can talk itself out of.

Scoped, step by step

Each step grants only the data and actions it needs. The agent physically can’t reach a source you didn’t hand it there — even if it tries.

Approval gates & full audit

Hold an action for a human OK before it runs — and every query, step, and block it hits lands in the audit trail.

Open source

CoreMCP — the open-source bridge.

The agent that reaches behind the firewall is open source. Audit it, run it yourself, or keep it fully offline. The managed platform is built on the same code your team can read line by line.

View on GitHub
Pricing

Start free. Scale when you're ready.

Every plan includes AI usage on built-in models — no key required to start. Bring your own LLM key any time and pay your provider directly instead.

Save 25% on annual billing

Free

Build against one source, free.

$0/ mo

Free forever

Get started
  • 1 data source
  • $1 one-time model credit — built-in models, no key needed
  • BYOK LLM keys (optional, your provider)
  • Developer API + embeddable widget
  • Query Memory + Unified Context (RAG)
  • Per-tenant isolation at the database — every plan
  • Read-only by default
  • Community support

When the $1 runs out we pause model calls before any charge — top up a prepaid balance or add your own LLM key. Everything else here stays free.

GrowthMost popular

For developers wiring agents to real systems.

$79/ mo

billed monthly

Get started
  • Everything in Free, plus:
  • 5 data sources · 3 projects
  • $5/mo included AI usage
  • REST / GraphQL + cloud DB connectors
  • On-prem database access via CoreMCP
  • Guardrails — enforced conversation rails
  • Email support

Team

For teams that need governance and scale.

$249/ mo

billed monthly

Get started
  • Everything in Growth, plus:
  • Unlimited data sources & projects
  • $15/mo included AI usage
  • RBAC + full audit log
  • Usage & cost analytics per member
  • Priority support

Enterprise

Air-gapped or regulated environments, dedicated infrastructure, and SSO.

  • Air-gapped / on-prem container
  • Dedicated infrastructure
  • SSO / SAML
  • SLA + dedicated support
Contact sales

Need the full breakdown across every plan?

Compare all plans

FAQ

Frequently asked questions

Reach, safety, isolation, and deployment — what security and data teams ask before connecting an agent to live systems.











Can't find what you're looking for? Contact our support team

Ship your first agent today.

Connect a source, wire up an agent, and stream your first answer in minutes. Free to start — no credit card.

Need air-gapped or enterprise?