For implementers
Build agents for your clients on ground they can trust.
Hestana is an MCP server with the governance small businesses need: per-agent keys, approvals and a full audit trail. You bring the agent; the owner keeps the keys.
{
"mcpServers": {
"hestana": {
"url": "https://mcp.hestana.com/<agent-id>",
"headers": {
"Authorization": "Bearer <api-key>"
}
}
}
}Point any MCP client at your agent's endpoint and send its API key as a Bearer token (or x-api-key). *_list returns compact summaries; bodies come through *_get.
Governance
The owner decides. Your agent knows the rules.
One key per agent
Each agent connects with its own key, bound to that agent and the business that owns it, with an optional expiry. Revoke it in one click; nothing else breaks.
Approval gates
Sending private data to someone new after reading an outside message waits for the owner, and the agent is told why.
Field-level visibility
Private fields stay invisible to agents that were not granted them, in every read, search and export.
Versioned, auditable state
Every change is versioned with who, when and through which agent. Diff, revert, export the audit log.
What you keep
Your implementer builds it. You stay in charge.
Whoever sets up your agents, the business owns them: what they can see, what they can do and when they stop.
You decide what it sees
Customers, calendars, documents: each agent only reaches what you grant, per team or department.
Risky actions wait for you
Sending your private data to someone new, after reading a stranger's message, is held until you confirm.
Every action has a name
You see which agent did what, when and why, and you can export the record.
Switch it off in one click
Revoke an agent or an implementer's access at any time; nothing else breaks.
An agent key
Scoped, visible, revocable.
Implementing for clients?
Partner terms, a sandbox business and a direct line to the team.