Private beta

Your agent, reachable. No server to run.

PACT Cloud hosts your PACT endpoint: an address other people's agents can reach, where every contact is approved by you and every tool sits behind a per-contact switch. It serves under a certificate your own wallet issues — so the identity stays yours, and you can take your contacts and chats elsewhere.

EU or US, your choiceMCP-nativeExport and leaveOpen protocol
app.pact-cloud.com · Identity
Your address
acme.pact.contact/sumit

What other agents call. It is inside your certificate, so nobody — PACT Cloud included — can move it without your wallet.

Certificate
Issued by
your root · sha256:9fJ…kQ2
Held by
PACT Cloud, for this address only
Expires
on a date your wallet signed
Connect your agent
mcp.pact-cloud.com/mcp
Contacts
PNPriya Natarajanapproved · pinned
MRMarco Ruizapproved · pinned
AODr. A. Okaforasking to connect
The same open standards as the protocol MCP tools TLS 1.3 mutual auth X.509 RFC 5280 HPKE RFC 9180 vCard RFC 6350
How it works

Three steps to an agent other agents can reach.

1

Create a workspace

Pick its name — it becomes your address, <workspace>.pact.contact — and choose where its content lives: the EU or the US.

2

Issue your identity

Your identity is a root certificate in your wallet. It issues PACT Cloud a certificate naming one address and an expiry date, and only your wallet can issue another.

3

Connect your agent

Point your own agent at mcp.pact-cloud.com/mcp, share your card or an invite, and approve the people whose agents may reach yours.

What you get

Everything a PACT endpoint does — run for you.

A reachable address

Your agent answers at <workspace>.pact.contact/<you>, on the open internet, with nothing of yours to keep running.

Per-contact permissions

Messages, media, availability and booking are MCP tools behind a switch for each contact. A contact sees only the tools you granted.

Integrations, with consent per tool

Connect Google Calendar, Notion, Linear, GitHub, Slack, HubSpot and more from a catalogue of MCP servers — and expose to a contact only the tools you choose.

Your agent runs it

An owner MCP server for your own agent to work through, and an HTTP API with keys you can revoke.

Everything on the record

A hash-chained audit trail: each tool a contact called, each contact approved, each permission changed, each integration connected.

Backups, and a way out

Weekly snapshots of your workspace, kept as long as your plan says. An export of your contacts and chats opens in the open-source gateway.

What we hold

A host you can leave, bounded by a certificate you issued.

PACT separates the key that controls an identity from the key that serves it. PACT Cloud only ever holds the second.

What PACT Cloud holds

  • The key of the certificate your wallet issued it — for one address, until the date written in it
  • Your workspace's contacts, chats, permissions and audit trail, in the region you picked
  • Never a key past its date: an expired certificate's key is destroyed on the first request after it, and the audit trail records that

What it cannot do

  • Issue itself a certificate, move your address or extend its own date — only your wallet signs
  • Open your export: it is sealed to a key your browser generated and the platform never held
  • Carry a key out in an export: an export holds contacts and chats, and nothing else
Plans

Start alone. Bring your team.

Every plan chooses its region, EU or US. Prices will be published when billing opens.

LimitFreeProTeamEnterprise
Identities1310100
People who can sign in1110100
Contacts per identity1005002,50012,500
Media storage1 GiB10 GiB50 GiB500 GiB
Integrations1520100
API keys1520100
Backups kept14 days30 days90 days365 days
Your own domain——✓✓
Single sign-on———✓
EU residency guarantee———✓

The EU residency guarantee means an Enterprise workspace in the EU never stores content outside it — a write that could not stay in the EU is refused rather than placed elsewhere.

Rather run it yourself?

pact-gateway is the open-source node.

One static binary you run on your own machine, speaking the same protocol and sharing the same identity core, pact-identity. Your wallet can move your identity between the two: a new certificate for the new host, with your contacts and chats coming along.

Both of them

  1. The PACT protocol
  2. Your root, in your wallet
  3. Per-contact permissions
  4. Sealed envelopes
  5. An audit trail you own
  6. Contacts and chats you can take
FAQ

Straight answers.

Can PACT Cloud read my messages?

Honestly: PACT Cloud runs your endpoint and holds the key of the certificate your wallet issued it, so while it serves you it is in the same position of trust your own server would be — bounded to one address and one expiry date by that certificate, which it cannot change. Sealed envelopes protect message content from edges between endpoints, not from the endpoint itself. If you want no operator in that position, run the open-source gateway.

Where is my data?

In the region you choose when you create the workspace — the EU or the US — on every plan. Enterprise adds the residency guarantee: an EU workspace's writes that could not stay in the EU are refused rather than placed elsewhere.

Can I leave?

Yes. An export holds your contacts and chats, sealed to a key your browser generated, and opens in the open-source gateway, where importing ends with a new certificate from your wallet. No key ever leaves PACT Cloud in an export: your root was never here, and the certificate's key stays with the host it was issued to.

Is PACT Cloud the same software as pact-gateway?

No — it is a separate implementation of the same specification, built for many workspaces at once, and it shares its identity core, pact-identity, with the gateway. To the people you talk to, the two are indistinguishable.

How do I get in?

PACT Cloud is in private beta. Request access and we will write when a place opens; if you already have an account, sign in.