Announcing CIMD support for MCP Client registration
Learn more

Best Self-Hosted Agent Integration Platforms (2026)

Best self-hosted agent integration platforms (2026): a Scalekit deployment running inside your boundary, connecting an agent to per-user connected apps across VPC, customer infrastructure and air-gapped modes
Vishal Dhawani
Founding Architect @ Scalekit

TL;DR

  • The agent integration layer is the part of the stack that holds your users' credentials and executes every action an agent takes in another system. When a bank, a health system or an agency says the platform has to run inside their boundary, this is the layer they mean, and it has to arrive as the same product you built on, not a cut-down edition.
  • Scalekit AgentKit self-hosts the full runtime, in your VPC, inside each customer's infrastructure, or air-gapped with offline license validation, with the same SDKs and APIs in every mode. Every tool call runs as the authorizing user, the root key can live in your Google Cloud KMS, and tool-call inputs and responses are not stored.
  • Nango self-hosts auth and an API proxy for free, with the full runtime on Enterprise; its center of gravity is data sync. Composio self-hosts on Enterprise terms. Arcade self-hosts on Enterprise, including air-gapped, and its cloud edition retains tool inputs and outputs as training data unless you opt out. Paragon is an embedded iPaaS with agent actions added, self-hosted on Enterprise with a license check that reaches its cloud.
  • Every vendor here publishes SOC 2. The questions that separate them are per-user authorization, what the platform retains after a call, who holds the root key, whether licensing works offline, and whether the SDK is the same once it is inside your network.

What “self-hosted” has to mean for an agent integration platform

An agent that acts in other apps needs a layer between it and those apps. That layer runs the OAuth flows, stores each user's tokens, refreshes them before they expire, and executes tool calls with the right credential attached. It holds standing access to every connected account and it is in the execution path of every action. A security architect reviewing an agent product looks at this layer first, because it is the one most often bought as a third-party service and the one with the widest reach into the customer's systems.

Vendors offer self-hosting in one of three ways: free images you can run today, a full runtime under an enterprise license, or not at all. That tier tells you how you get the software. For a deployment review it is the smallest of the questions. The larger ones are what you are getting once it runs inside your network: whether it is the same product as the cloud edition, whether each action still runs as the individual user, what the platform keeps after a call completes, who holds the encryption root key, and whether the license survives with no outbound connectivity.

This comparison is written for teams that already know the answer has to be self-hosted. It ranks five platforms on those questions, with every competitor fact taken from that vendor's own pages.

Five questions a self-hosted deployment review asks

1. Does every action run as the user?

This is the question that separates an agent integration platform from a generic integration platform. An iPaaS or a sync engine typically connects once, with a service account or an admin's credential, and moves data on a schedule. An agent acting for a person needs that person's own authorization, scoped to what they are allowed to do, so that a tool call in Salesforce or an EHR carries the same permissions the user has and shows up in the target system's audit log under their name. Inside a regulated customer's boundary this matters more, not less: a shared service account that writes clinical notes or moves funds fails the audit on its own. Check whether per-user connected accounts, scoped tool sets and per-call attribution are part of the self-hosted product or a managed-cloud feature.

2. Is it the same product inside the boundary?

Teams build against a managed cloud for months before a customer's security review asks for a private deployment. If the self-hosted edition has a smaller feature set or a different API, that review becomes a rewrite and you maintain two integrations for the life of the contract. Ask which components ship in the self-hosted runtime, and run your own integration tests against both editions before a deal depends on it.

3. What does the platform keep after a call?

Tool calls return business data: a record, a thread, a file listing. The question for a review is retention. Some platforms execute the call and return the result without keeping it. Others log the response, cache it for retries, store it as part of a sync, or keep inputs and outputs to improve their own product. Each retained copy is a data store with its own retention period, backup policy and place in the subprocessor list. Ask what persists after a call completes, where, for how long, and what it is used for. In regulated deployments, a platform that retains nothing is a much shorter conversation.

4. Who holds the root key?

Token vaults use envelope encryption: each credential is encrypted with a data key, and the data keys are encrypted with a root key held in a key management service. A vendor-managed root key in a KMS is a sound default, and it is how most platforms, including Scalekit, encrypt credentials out of the box. Bring your own key adds a layer of control on top: when the root key is in your KMS, you set the rotation policy, every wrap and unwrap appears in your own audit log, and revoking the vendor's access makes stored credentials unreadable until you restore it. Some self-hosted platforms instead take the key as a configuration secret you set on the deployment; that works, but more of the rotation, revocation and audit work falls to your team. Bring your own key is also easy to confuse with bringing your own LLM API key, which is a credential, not an encryption feature.

5. Does the license work with no outbound connectivity?

A license check that calls home at boot fails in a sealed network. For defense, government and some financial buyers, ask whether the license validates offline, whether images can be served from an internal registry, how upgrades reach the cluster, and what happens at renewal. Residency is a smaller version of the same question: if the customer's requirement is a region rather than their own network, confirm the managed cloud has one.

What sits inside the boundary

Self-hosted Scalekit deployment: tool-calling gateway, token vault, root key and audit events inside your infrastructure, calling external apps with a per-user token; no customer data reaches Scalekit.

In a full self-hosted deployment, the agent calls the gateway, the gateway reads the user's credential from a vault in your database, the vault is encrypted under a key you control, and audit events go to your own logging. No step in that call path goes through the vendor. Depending on the deployment mode, license validation and update checks may still call out, so ask each vendor which connections remain. The gateway still calls each app's API and OAuth token endpoint, so the cluster needs outbound HTTPS to the providers your connectors use. Connectors for apps inside your own network need no internet access.

Comparison at a glance

Deployment, authorization and retention (checked October 7, 2026)

Platform
Self-host tier and modes
Per-user authorization
Root key
Retention of tool-call data
Scalekit AgentKit
Enterprise-licensed. Your VPC; your customer's infrastructure; air-gapped
Yes: per-user connected accounts, scoped Virtual MCP servers, per-call attribution
Your Google Cloud KMS key (Enterprise)
Inputs and responses not stored; logs keep call metadata
Nango
Free (auth + proxy) and Enterprise (full). Docker Compose; Helm or BYOC on Enterprise
Per-connection credentials; sync-oriented
NANGO_ENCRYPTION_KEY configuration secret when self-hosted, optionally wrapped by your KMS
Synced records cached; tool-call payload retention not documented
Composio
Enterprise-licensed. Helm on your infrastructure
Per-user connected accounts
Customer-managed keys through a keyring proxy you run (Enterprise)
Zero data retention on select features (Pro add-on, Enterprise)
Arcade
Enterprise-licensed. Your VPC (Azure Marketplace, AWS private offer, Helm); air-gapped; hybrid MCP servers connect to Arcade Cloud
Per-user auth for MCP tools
Arcade-managed KMS in Arcade Cloud; your KMS when self-hosted
Cloud: execution logs and audit trails kept for a period you set; tool inputs and outputs kept as training data up to 5 years unless the organization opts out
Paragon ActionKit
Enterprise-licensed. Unmanaged, managed or forward-deployed, in Kubernetes
Per-end-user credentials for embedded integrations
Platform-managed, per-credential keys
Event logs stored with sensitive values redacted

Parity, air-gapped and compliance (checked October 7, 2026)

Platform
Same product across modes
Air-gapped
SOC 2 / ISO 27001
BAA / DPA
Scalekit AgentKit
Yes, same SDKs and APIs
Yes, with offline license validation
Type II / Yes
BAA on Enterprise (cloud and self-hosted) / Standard DPA on all plans, custom on Enterprise
Nango
Free edition covers auth and proxy only
Not documented
Type II / Not published
Enterprise / Not on pricing page
Composio
Not documented
Not documented
Type II / 27001:2022
Pro add-on, included on Enterprise / Self-serve on Pro, included on Enterprise
Arcade
Marketplace and Helm deployments run the complete platform
Yes (Enterprise); offline license validation not documented
“SOC 2 compliant” / Not published
Not published / Not published
Paragon ActionKit
Paragon says the platform is the same in every mode
License check and billing metadata reach Paragon; airgap on request
Type II / “Coming soon”
HIPAA compliant, plan not stated / In Trust Center

Region and fit

Platform
Managed EU region
Best for
Scalekit AgentKit
Yes
Agent products that act as each user, deployed inside a regulated customer's boundary
Nango
No (BYOC in any region on Enterprise)
Code-first teams whose main job is data sync
Composio
Not documented
Prototyping across a large tool catalog
Arcade
No; Arcade Cloud is US-only
MCP tool access across clients such as Cursor and Claude, with central governance
Paragon ActionKit
Yes
SaaS products embedding customer-facing integrations

“Not documented” and “not published” mean the detail is not on the vendor's public pages as of the check date. It may exist. Ask them.

Read across the tables and one thing stands out: Scalekit is the only platform in this comparison whose public pages answer every column. It is also the only one that documents all five things a self-hosted review checks: per-user authorization, a customer-held root key, no storage of tool-call payloads, offline licensing for air-gapped installs, and the same SDK in every mode. Each of the others documents some of those and leaves the rest to a sales conversation.

1. Scalekit AgentKit

Self-host tier: Enterprise-licensed · Best for: agent products that act as each user across SaaS apps and internal systems, deployed inside a regulated customer's boundary.

Scalekit AgentKit is an authorization and tool-calling runtime for agents, and the whole runtime self-hosts. Connections, connected accounts, the token vault, tool execution and Virtual MCP servers run in your Kubernetes cluster alongside auth and sessions. The SDKs, the REST API and the dashboard are the same as the managed cloud; a self-hosted app points SCALEKIT_ENVIRONMENT_URL at its own instance (docs). The integration you built is the integration that runs in the customer's environment.

Deployment modes. Scalekit self-hosted runs three ways, and you can use different modes for different customers:

  • Your VPC on AWS, GCP or Azure, for your own requirement or for customers who accept a single-tenant deployment in your account. License validation and update checks may call out in this mode; both are configurable and can be routed through your egress controls.
  • Your customer's infrastructure, one isolated instance per customer, with you holding the license keys and controlling upgrades. Licensing is per deployment.
  • Air-gapped, with no outbound calls to Scalekit, offline license validation, images served from your own registry, and connector assets bundled in the image. This is the mode for networks with no route to the internet. Connectors work for any app the cluster can reach, so a fully sealed network runs internal apps and custom connectors.

Every action runs as the user. Each end user connects their own accounts, and every tool call runs with that user's credential, so the target system records the action under the user, not a service account. Virtual MCP Servers give each agent or role its own tool set, so a read-only agent does not see write tools. The catalog covers 500+ connectors and 20,000+ actions, including SMART on FHIR for healthcare, plus custom connectors for internal APIs that never leave the network.

Key custody. Credentials are encrypted with AES-256-GCM under a per-environment data key, and that key is wrapped by a root key in KMS. On Enterprise the root key can be yours: you register a key from your own Google Cloud KMS, and Scalekit calls it for each wrap and unwrap without storing the key material. Disabling the key or revoking Scalekit's access leaves stored credentials unreadable to Scalekit, once Google Cloud applies the change, until you restore it. The encryption keys docs walk through the setup with Google Cloud KMS.

Retention and audit. Tool-call requests and responses are not stored. They are processed in memory for the duration of the call and are not written to Scalekit's database or logs (HIPAA page). Because payloads are not kept, they are not used for training. Tool-call logs keep metadata: tool, connection, connected account, identifier, status, error code and duration (security docs). An optional Store connector error details setting also keeps the app's error response for debugging; leave it off outside debugging. On Enterprise, logs can stream to your SIEM. Self-hosted, Scalekit has no database access, no default telemetry, and no log access unless you share logs for support.

Compliance: SOC 2 Type II, ISO 27001, GDPR and CCPA. HIPAA BAA, custom DPA, BYOK and a 99.99% uptime SLA on Enterprise (pricing). Self-hosted, customer data stays in your deployment, so Scalekit is not a sub-processor for it. A BAA is available on Enterprise for both cloud and self-hosted deployments.

What to plan for:

  • Self-hosting, BYOK and the BAA are Enterprise features. You can build and test on the managed cloud first.
  • A self-hosted instance cannot use Scalekit's shared OAuth apps. You register an OAuth app with each provider and a redirect URI on your own domain.
  • It is an action and authorization layer, not a bulk data-sync engine, and it does not normalize responses into a unified data model.
  • Kubernetes with Helm is the production recommendation. You provide Kubernetes 1.27 or later, PostgreSQL 15 or later (CockroachDB also works), Redis 6.2 or later, SMTP and a domain with TLS.

2. Nango

Self-host tier: Free (auth and proxy) and Enterprise (full runtime) · Best for: code-first teams whose main job is data sync, with agent tool calling as a second use case.

Nango publishes a free self-hosted edition that runs from public images with docker-compose and covers managed auth and the API proxy, under the Elastic License, according to its docs. It is the quickest of the five to stand up for an evaluation. The full platform, including syncs, tool calls, webhooks and the MCP server, ships on Enterprise, with Helm deployment and bring-your-own-cloud in any AWS, GCP or Azure region, according to its pricing page.

What to check:

  • The free edition is auth and proxy. The self-hosted feature set differs from the cloud one until you sign an Enterprise agreement.
  • Self-hosted credentials and cached records are encrypted with a NANGO_ENCRYPTION_KEY you set in configuration, which you can supply wrapped by your own KMS. Ask how rotation and re-encryption work in a self-managed install.
  • Nango's design centers on syncing records into your own store. That is the right tool for a data pipeline and a different shape from per-user tool calling.
  • Nango states it does not currently have an EU cloud. Residency means BYOC on Enterprise.
  • SOC 2 Type II. BAA on Enterprise.

More in Scalekit vs Nango.

3. Composio

Self-host tier: Enterprise-licensed · Best for: fast prototyping across a large tool catalog.

Composio's self-hosting is an Enterprise feature, aimed at teams whose infrastructure, network or residency requirements put the action layer inside their own environment, according to its enterprise page. Its strength is catalog breadth and a short path from signup to a working agent. It holds SOC 2 Type II and ISO 27001:2022.

What to check:

  • Customer-managed keys are Enterprise-only and work through a keyring proxy you run; Composio's pricing page notes the feature covers secret storage and not data residency.
  • Zero data retention applies to select features. It is a Pro add-on and included on Enterprise. The BAA follows the same pattern.
  • Composio's public pages do not describe an EU region, an air-gapped mode or offline licensing.
  • Composio disclosed a security incident in May 2026. Its updates describe a move to envelope encryption and, in a later update, a customer-managed KMS option. Expect reviewers to ask about it.

More in Composio alternatives.

4. Arcade

Self-host tier: Enterprise-licensed · Best for: MCP tool access across clients such as Cursor and Claude, with central governance.

Arcade describes itself as the actions runtime between agents and the systems they reach. Its homepage leads with developer SDKs and framework support, and alongside that it offers MCP gateways: a single gateway URL that works in Cursor, Claude Desktop, VS Code, ChatGPT and other MCP clients, with SSO, RBAC and audit logs for the organization. That second use, governed tool access for people already using MCP clients, is where much of Arcade's recent material points. For an agent vendor whose end users are customers rather than a workforce, the question is whether that governance model fits your product's users. Arcade co-authored the MCP URL elicitation proposal and holds per-user authorization for MCP tools as its core.

Deployment. Arcade Cloud has a free tier (2,000 auth events and 2,000 tool calls a month) and a Team plan at $25 a month plus usage, both cloud-only. The Enterprise plan adds your VPC or a fully air-gapped deployment, SSO, RBAC, audit logs and private registry access. Self-hosted deployments run as an Azure Marketplace managed app, through an AWS private offer (a GCP listing is in progress), or with Helm on your own cluster; Arcade's docs say the marketplace and Helm options run the complete platform. Arcade also offers hybrid MCP servers that run in your environment and connect to Arcade Cloud.

Keys and retention. In Arcade Cloud, tokens sit in Arcade's encrypted vault, protected by a KMS Arcade manages, with application-level AES-256 on sensitive fields. Self-hosted, Arcade's July 2026 post says the tokens stay in your KMS and the keys never leave your control. Arcade Cloud retains tool execution logs and audit trails for a period you set, and its infrastructure docs state that tool queries and execution inputs and outputs are retained as training data for up to five years, with an organization-level opt-out. All Arcade Cloud infrastructure is in the United States; for residency, Arcade points to self-hosting.

What to check:

  • The hybrid pattern keeps tools near private resources but still depends on Arcade Cloud. A sealed network needs the VPC or air-gapped deployment.
  • Offline license validation is not described, so ask how an air-gapped install licenses and upgrades.
  • Confirm the training-data opt-out is in place before any production traffic, and ask whether the self-hosted edition carries the same default.
  • Arcade's public pages do not describe a BYOK option in Arcade Cloud, a managed EU region, ISO 27001, a BAA or a DPA. “SOC 2 compliant” is stated on the homepage without a report type.

More in Arcade alternatives.

5. Paragon ActionKit

Self-host tier: Enterprise-licensed · Best for: SaaS products embedding customer-facing integrations, with agent actions as an extension.

Paragon is an embedded integration platform, and ActionKit adds agent actions on top of it. Its January 2026 self-hosting post describes three models: unmanaged, where you install with its Terraform installer and Helm charts; managed, where Paragon runs it in your account; and forward-deployed, where Paragon deploys into your customer's VPC. It runs on AWS, Azure and GCP and its security page lists SOC 2 Type II, HIPAA and GDPR.

What to check:

  • The footprint is Kubernetes plus Postgres, an S3-compatible object store and Redis in your VPC, and it needs a Paragon license key. Billing, license verification and anonymized usage analytics reach Paragon's cloud by default; Paragon says the analytics can be disabled and that it has arrangements for a complete airgap, so ask what those involve.
  • Third-party credentials are stored in a separate vault under per-credential keys that Paragon manages. Its public pages do not describe a customer-managed KMS option.
  • The platform is built around a per-tenant integration model for SaaS products. Check how per-user authorization and per-call attribution work for an agent acting on behalf of an individual.
  • No free plan is published. ISO 27001 is listed as coming soon, and the security page says “HIPAA compliant” without naming the plan that includes a BAA.

More in Paragon alternatives.

How to choose

  • Your agent acts on behalf of individual users, and a regulated customer requires the stack in their VPC, their own infrastructure or a sealed network → Scalekit. The full runtime self-hosts in all three modes with the same SDK, every action runs as the user, the root key can sit in a Google Cloud KMS key you control, tool-call inputs and responses are not stored, and the air-gapped license validates offline. A BAA is available for both cloud and self-hosted.
  • Your users are an organization's own staff working in MCP clients like Cursor or Claude, and you want a governed gateway for them → Arcade, on Enterprise, after confirming the licensing path for a sealed network and the training-data opt-out.
  • Your main job is syncing records into your own store and you want to run something free this week → Nango's free edition, knowing the full runtime is Enterprise.
  • You are prototyping across the widest possible catalog and self-hosting is a later conversation → Composio.
  • You are a SaaS product embedding customer-facing integrations and want the vendor to operate the deployment → Paragon, managed or forward-deployed.

Questions to ask every vendor before a self-hosted deployment

  1. Which components ship in the self-hosted runtime, and which still call your cloud?
  2. Does every action run as the individual user, with that user's permissions and attribution, inside the self-hosted edition?
  3. Is the SDK I built against in your cloud the same one that runs in my network?
  4. What does the platform retain after a tool call completes, where, for how long, and is any of it used to train or improve your product?
  5. Can the root key live in my KMS, and what happens to stored credentials when I revoke it?
  6. How does the license validate with no outbound connectivity, how do upgrades reach the cluster, and what happens at renewal?
  7. Where is the OAuth callback registered, and on whose domain?
  8. Which plan includes the BAA and a custom DPA, and do they cover the self-hosted deployment?

For the deployment, residency and key custody questions regulated buyers put to agent vendors, with Scalekit's answer to each, see the security questionnaire for AI agent vendors.

Frequently asked questions

What does self-hosted mean for an agent integration platform?

It means the layer that stores user credentials and executes tool calls runs on your infrastructure or your customer's, not the vendor's. Platforms fall into three tiers: free self-hosting from public images, enterprise-licensed self-hosting, and managed-only.

Which agent integration platforms can be self-hosted for free?

Nango publishes a free self-hosted edition that covers managed auth and the API proxy; its syncs, tool calls, webhooks and MCP server require Enterprise. Scalekit, Composio and Arcade have free managed plans, with self-hosting on Enterprise. Paragon's self-hosting is also an enterprise arrangement.

Can an agent integration platform run air-gapped?

Scalekit supports air-gapped deployment with no outbound calls, offline license validation and images from your own registry. Arcade lists a fully air-gapped deployment on its Enterprise plan without describing how licensing works offline. Paragon says it can support a complete airgap on request. Nango and Composio do not document air-gapped operation.

Which platforms support customer-managed encryption keys?

Scalekit supports a root key in your own Google Cloud KMS on Enterprise. Composio offers customer-managed keys through a keyring proxy on Enterprise. Arcade's self-hosted deployment keeps tokens in your KMS; its cloud edition uses a KMS Arcade manages. Nango's self-hosted edition uses an encryption key you set in configuration, which can be wrapped by your own KMS. Paragon does not document customer-managed keys.

Do self-hosted deployments still send data to the vendor?

It depends on the vendor and the mode. A self-hosted Scalekit instance keeps credentials, tool calls and logs in your network and sends no telemetry by default. In VPC mode, license validation and update checks may call out and can be routed through your egress controls; in air-gapped mode, the instance makes no calls to Scalekit. Paragon's self-hosted deployment contacts Paragon for license verification, billing metadata and anonymized usage analytics; the analytics can be disabled. Arcade's hybrid MCP servers connect to Arcade Cloud. Ask each vendor for a list of outbound connections.

Is Merge Agent Handler self-hostable?

Merge's Agent Handler pricing lists “custom deployments, including on-prem” on its Enterprise plan, and its security page describes single-tenant hosting and US, EU and APAC regions. Merge does not publish the details of its on-prem option, so ask during evaluation.

No items found.
Agent
Auth Quickstart
On this page
Share this article
Agent
Auth Quickstart

Acquire enterprise customers with
‍zero upfront cost.

Every feature unlocked. No hidden fees.