← All articles
Getting Started

Choosing a plan

Once you've created an organization, you'll be asked to choose a plan. Blacksands offers five tiers, and picking the right one mostly comes down to two questions: how many apps you're connecting, and how many MCP clients (AI agent connections) you need.

The tiers, briefly

  • Free — no cost, no card required. Ideal for individual developers or small pilots who want to try certificate-based identity and access on a handful of apps and agents before committing to anything.
  • Pro — self-serve, paid monthly via Stripe Checkout. A step up in app and MCP client limits for a single team or a small production footprint.
  • Team — self-serve, includes multiple seats out of the box and supports adding more (see Adding team seats). Built for a group of people jointly administering access.
  • Business — self-serve, the largest of the self-serve tiers, with the highest app and MCP client limits and priority support.
  • Enterprise — sales-assisted rather than self-serve. For government, defense, and large organizations that need custom SLAs, dedicated deployment options, or procurement processes that don't fit a credit-card checkout flow.

What a plan actually unlocks

A plan is not a feature switch so much as a set of limits — see Understanding your plan limits for the full breakdown. The two dimensions that matter most:

  1. Apps — the services, devices, or endpoints you're protecting with Broker or Bouncer.
  2. MCP clients — the number of distinct AI agent identities you can issue through Bursar.

Every tier runs on the same certificate-based zero-trust fabric; upgrading doesn't change how the platform works, it changes how much of it you can use at once.

Picking a starting point

If you're not sure yet, start on Free. It requires no payment information, and because upgrading is a self-serve Stripe Checkout flow for Pro/Team/Business (see Upgrading or changing your plan), you lose nothing by starting small and growing into a paid tier once you know your real usage. If you already know you need custom contracting, dedicated support, or a deployment model outside the standard self-serve tiers, reach out to sales directly rather than starting on a self-serve plan you'll need to migrate off of.

Next step

Once a plan is active, continue to Installing your first agent identity to connect your first app or agent.