For implementers

Build agents for your clients on ground they can trust.

Hestana is an MCP server with the governance small businesses need: per-agent keys, approvals and a full audit trail. You bring the agent; the owner keeps the keys.

{
  "mcpServers": {
    "hestana": {
      "url": "https://mcp.hestana.com/<agent-id>",
      "headers": {
        "Authorization": "Bearer <api-key>"
      }
    }
  }
}

Point any MCP client at your agent's endpoint and send its API key as a Bearer token (or x-api-key). *_list returns compact summaries; bodies come through *_get.

Governance

The owner decides. Your agent knows the rules.

One key per agent

Each agent connects with its own key, bound to that agent and the business that owns it, with an optional expiry. Revoke it in one click; nothing else breaks.

Approval gates

Sending private data to someone new after reading an outside message waits for the owner, and the agent is told why.

Field-level visibility

Private fields stay invisible to agents that were not granted them, in every read, search and export.

Versioned, auditable state

Every change is versioned with who, when and through which agent. Diff, revert, export the audit log.

What you keep

Your implementer builds it. You stay in charge.

Whoever sets up your agents, the business owns them: what they can see, what they can do and when they stop.

You decide what it sees

Customers, calendars, documents: each agent only reaches what you grant, per team or department.

Risky actions wait for you

Sending your private data to someone new, after reading a stranger's message, is held until you confirm.

Every action has a name

You see which agent did what, when and why, and you can export the record.

Switch it off in one click

Revoke an agent or an implementer's access at any time; nothing else breaks.

An agent key

Scoped, visible, revocable.

The Hestana app · an agent key, as the owner sees it

Implementing for clients?

Partner terms, a sandbox business and a direct line to the team.

Talk to us