Arcade
Arcade supplies an MCP runtime that sits between AI agents and the systems they act on. Per the vendor's own homepage, it enforces permissions through the customer's existing OAuth and identity-provider flows: every action runs at the intersection of what the authenticated user may do and what the agent is scoped to do, and the action stops if either boundary is crossed. The vendor states actions are logged and reviewable, with one place to set policy and one place to audit; no tamper-evidence, hash-chaining or immutability is claimed anywhere on the page. It can be deployed in the customer's own cloud, a virtual private cloud, on-premises or fully air-gapped, and offers a catalogue of pre-built Model Context Protocol tools for systems including Google Workspace, Slack, Microsoft and Salesforce. It works with any LLM and with major agent frameworks, and a Python and JavaScript framework is open-source. Pricing is free to start and charged by usage; payment is not tied to a verified outcome. SOC 2 compliance is self-declared, with no Type, report or certificate published. No insurance, indemnity or regulatory-alignment claim appears on the page checked.
17 fields evidenced · 42 with no public information. Every value below links to the document it came from and the date we checked it.
12 of those are quoted but not yet interpreted: we hold the source sentence and the date we read it, but nobody has written the answer to the question yet. Those rows show the quote and say so rather than repeating it back as an answer. Why these exist
1 of the evidenced values quotes wording our own later capture of the same page no longer contains. Marked below, awaiting an editor.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
Vendor states permissions are enforced at run time through the customer's existing OAuth and identity-provider flows, with every action bounded by the intersection of the authenticated user's permissions and the agent's scope, and the action stopping if either line is crossed. Scope and authority are therefore enforced at run time, not merely documented. Not 3: no spend or budget limit is published, and the enforcement is vendor-asserted with no independent verification on the page checked.
Is there a tamper-evident record of what it actually did?
Vendor states every action is logged and reviewable - "one place to set policy, one place to audit" and "full audit logs out of the box" - so a customer-reviewable record is claimed at product level. Not 3: nothing on the page claims the record is tamper-evident, hash-chained or append-only. The audit_trail_immutable field was recorded as no_public_information this run for exactly that reason.
Are compliance obligations attached per engagement?
The page states "SOC 2 compliant" and nothing further: no Type, no report, no certificate, no auditor named, and no per-engagement compliance schedule. Self-declared compliance with a single framework only.
How this gap gets closed →Does payment depend on a verified result?
Pricing is "Free to start. Priced by usage." Payment is metered by usage and does not depend on a verified result, which is the rubric's definition of 0. The outcome_based_pricing field previously filed against this same span was rejected this run as an inversion - usage pricing recorded as outcome-based pricing.
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
No public evidence found. The vendor homepage, the only document captured for this entity, makes no mention of insurance cover, a named carrier, published limits, or any customer indemnity.
How this gap gets closed →Assurance
- Insurance available
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Insurance carriers
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Coverage limits
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Indemnification
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Liability cap
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Audit trail
“You can answer that for every action, every time, without slowing down the teams shipping agents. One place to set policy, one place to audit.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 17, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
arcade-ai.com · checked Aug 1, 2026- Tamper-evident log
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Explainability
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Runtime governance
“Arcade enforces permissions through your existing OAuth and identity provider flows. Agents act on behalf of the authenticated user, never through broad service accounts. Every action runs at the intersection of what the user can do and what the agent is scoped to do. Cross either line and the action stops.”
arcade-ai.com · checked Aug 1, 2026- Permission scopes
“Agents act on behalf of the authenticated user, never through broad service accounts. Every action runs at the intersection of what the user can do and what the agent is scoped to do.”
arcade-ai.com · checked Aug 1, 2026- Compliance certifications
- SOC 2 compliance self-declared on the vendor homepage; no Type, report or certificate published on the page checked
“Compliance-ready SOC 2 compliant. SSO, RBAC, and full audit logs out of the box.”
arcade-ai.com · checked Aug 1, 2026 - Regulatory alignment
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Outcome-based pricing
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Settlement mechanism
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Dispute process
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- SLA terms
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Evaluation coverage
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Service type
- Actions runtime / governance layer sitting between AI agents and the business systems they act on.
“Arcade is the actions runtime between your agents and every system they reach.”
arcade-ai.com · checked Sep 10, 2026 - Regulatory status
- no public informationarcade-ai.com · checked Sep 10, 2026 · source did not state this
- Underwriting backing
- no public informationarcade-ai.com · checked Sep 10, 2026 · source did not state this
- Client types
- Developers/teams on a free tier through to enterprise customers.
“Ready to actually ship your agent? Free to start. Ready for enterprise when you are.”
arcade-ai.com · checked Sep 10, 2026
Agency
- Autonomy level
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Human oversight
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Goal complexity
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Action space
- Executes actions through 8,000+ permission-aware tools across connected business systems, plus custom MCP tools.
“Execute 8,000+ permission-aware tools, plus support for custom MCP you build or bring.”
www.arcade.dev · checked Sep 9, 2026 - Operating environment
“AI agents using Arcade access a catalog of pre-built Model Context Protocol tools for major systems like Google Workspace, Slack, Microsoft, and Salesforce.”
arcade-ai.com · checked Aug 1, 2026- Initiative
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
Safety
- Safety evaluations
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Red teaming
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Safety policy
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Usage restrictions
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Model or system card
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Incident reporting
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Third-party evaluations
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Data handling
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
Practicality
- Pricing model
“Free to start. Priced by usage.”
arcade-ai.com · checked Aug 1, 2026- Price point
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Availability
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Deployment options
“You can deploy the Arcade MCP runtime in your own cloud environment, a virtual private cloud, on-premises, or in a fully air-gapped environment.”
arcade-ai.com · checked Aug 1, 2026- Integrations
“AI agents using Arcade access a catalog of pre-built Model Context Protocol tools for major systems like Google Workspace, Slack, Microsoft, and Salesforce.”
arcade-ai.com · checked Aug 1, 2026- Supported regions
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Support model
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
Foundation models
- Base models
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Model provider
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Model swappable
“Build with LangChain, LlamaIndex, Mastra, CrewAI, Pydantic, Google ADK, or OpenAI Agents. The same flexibility extends across the stack: any agent client, including Claude, Cursor, ChatGPT, Copilot, or your own, and any LLM.”
arcade-ai.com · checked Aug 1, 2026- Open weights
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Fine-tuning
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Context window
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
Ecosystem
- Protocols supported
“AI agents using Arcade access a catalog of pre-built Model Context Protocol tools for major systems like Google Workspace, Slack, Microsoft, and Salesforce.”
arcade-ai.com · checked Aug 1, 2026- Tool use
“The runtime gives you visibility and control over every tool your AI agent accesses.”
arcade-ai.com · checked Aug 1, 2026- Multi-agent
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- API access
“Drop Arcade into your agent with our SDKs, quickstarts, and copy-paste examples.”
arcade-ai.com · checked Aug 1, 2026- Open source
“Developers can also build custom tools using the open-source Arcade framework in Python or JavaScript”
arcade-ai.com · checked Aug 1, 2026- Marketplace presence
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
Impact
- User base
- Named customer testimonials include Harrison Chase (Co-Founder & CEO), Jacky Koh (Founder), Dilan Shah (Founder & CEO), Brace Sproul (AI/ML Engineer), and Randall Degges (Head of Developer & Security Relations).
“What customers are saying The runtime layer from Arcade makes MCP enterprise-ready. Connects to identity providers, enforces agent authorization, and enables real actions in Google, Slack, and Salesforce. Harrison Chase Co-Founder and CEO Arcade is the best platform to facilitate secure and interactive MCP. Jacky Koh Founder Integrating with Arcade's MCP runtime has been remarkably easy, so we can focus on delivering personalized coaching experiences. Plus, the composability across LLM architectures gives us the architectural freedom to scale, accelerating our product development without compromising quality or flexibility. Dilan Shah Founder & CEO By using Arcade, we're able to authenticate users' Twitter/LinkedIn accounts without worrying about refresh tokens, broken auth, or any of the other hassle that comes with setting up auth connections. Brace Sproul AI/ML Engineer Arcade nails the sweet spot between AI, auth, and developer experience. We're using it and it's insanely useful - finally a product that lets AI agents actually do stuff. Randall Degges Head of Developer & Security Relations”
arcade-ai.com · checked Sep 10, 2026 - Deployment scale
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Target sectors
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- High-risk domains
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this
- Documented incidents
- no public informationarcade-ai.com · checked Aug 1, 2026 · source did not state this