Getting started with Statio
Five steps from scattered API keys to a governed, audited gateway, in about five minutes.
STEP 1
Connect your AI clientInstall the desktop app or the mcphub CLI and pick the servers your team is approved to use. It writes the correct MCP configuration for Claude Code, Claude Desktop, Cursor, Windsurf, VS Code, Cline, Continue, Zed and Amazon Q, so nobody hand-edits JSON.
STEP 2
Vault your credentialsAdd the API keys your agents call through, whether that is Stripe, GitHub, Slack or something internal. They are encrypted with AES-256 at rest, fetched at call time inside the gateway, and never handed to an agent.
STEP 3
Grant access per toolTurn individual tools on and off rather than whole servers. An agent allowed to read charges is not thereby allowed to issue refunds, and the gateway checks that on every request before it decrypts anything.
STEP 4
Point the agent at StatioThe scattered keys in the agent config become one STATIO_TOKEN, which expires after 24 hours and refreshes through the SDK. If it leaks it is useless within a day, and you can revoke it immediately.
STEP 5
See what your agents didEvery tool call is logged with the identity behind it, a timestamp, the latency and the outcome. Run a scan to find MCP servers installed across the team that nobody approved, and stream the whole record to your SIEM.
Connect your first server.
Three MCP servers and 5,000 calls a month, free and without a card. If you outgrow it the next plan is $19, and it stays $19 as the team grows.- Keys are encrypted at rest and never handed to an agent
- Cancel anytime. You drop to Free, nothing is deleted
- No card required, and no way to spend money on Free