Metorial vs Runlayer (2026)

TL;DR

Metorial and Runlayer both sit between AI agents and the systems those agents are allowed to interact with, handling identity, access, and audit logging. The difference shows up before either product does anything. Turning on Metorial is something one person can do this afternoon, using the company sign-in that already exists. Turning on Runlayer starts with a form. Its identity and access product, Agent Accounts, is still in beta and needs Runlayer's approval before a team can use it. Every path off its site, including its own pricing page, leads to booking a call with sales. On the contrary, Metorial is open source and fully self-serve.

An MCP Gateway sits between agents and the systems they're allowed to touch: who can connect, what they're allowed to call, and what gets logged when they do. Every vendor in this category promises identity, access, and an audit trail. What varies is what it takes to turn that on: whether a team can do it themselves this week, or whether the vendor's own core access feature needs weeks of conversations first.

Metorial's self-serve sign-in and policy setup next to Runlayer's book-a-demo flow

Why the setup step is the first real difference

A rollout that depends on a vendor's own staff to configure moves on the vendor's calendar, not yours. If turning on access control means booking a call, waiting for a callback, and scheduling an implementation window, that is weeks added to a project before a single agent is connected. That happens at a stage when you haven't even seen the product itself. On the other hand, a rollout a team configures itself, using the identity system it already runs on, jump starts the whole process and gives the team the immediate benefits of the product.

Can a team turn on agent access control itself, or does it need approval first?

Metorial's access control starts with a company single sign-on (SSO) - the same login employees already use for email - connecting agents to real identity from the first step. From there, an administrator sets policy per user group, think sales, HR team or engineering. Then, they define what each agent can access, and that policy applies everywhere at once, across all of Metorial's products: Portals, Magic MCP, and the API. Connecting is pasting one URL into an AI client, something anyone on the team can do without help from IT.

Runlayer's equivalent, Agent Accounts, works differently today. It's still in beta, and a team has to be approved by Runlayer before they can turn it on, with rollout timing worked out directly with Runlayer's team rather than started on their own. That holds across the rest of the site too: the homepage, the identity policy page, and every other page route a visitor back to booking a call instead of signing up.

Agent Accounts, Runlayer's core identity feature, is still in beta and requires Runlayer's approval before a team can use it

Is the code handling that access something you can inspect yourself?

Metorial's core is open source, split across two public repositories under two licenses, Apache 2.0 for the integration catalog and FSL-1.1 (Functional Source License 1.1) for the engine, with over 3,900 stars in total across its public repos.

Runlayer's GitHub organization lists exactly two public repositories: a plugin marketplace and a fork of Okta's own MCP server with version pinning. Neither is the access platform itself. A team evaluating Runlayer can't read the code making its access decisions the way it can with Metorial's.

What does it cost, and can you find out without a phone call?

Metorial publishes its pricing. The free Dev plan covers up to 500,000 tool calls a month and two workforce seats. The Scale plan is $250 a month, includes 20 seats with an additional flat seat-based pricing rate and covers 2.5 million tool calls a month. Enterprise pricing is scoped with sales.

Runlayer's pricing page loads with no visible numbers. Across the site, booking a call is the only option, on the homepage, on the identity policy page, and on pricing itself. A team can't compare the two vendors' costs without first getting on a call with Runlayer.

Metorial's published pricing next to Runlayer's book-a-demo pricing page

Where the two overlap

MetorialRunlayer
Single sign-onYesYes
Role-based permissionsYes, per user and groupYes, via Agent Accounts (beta, requires approval)
Audit loggingYesYes
SOC 2YesYes
Self-serveYesNo
Transparent pricingYesNo
Core platform open sourceYesNo

Both hold SOC 2, both offer single sign-on, both describe role-based permissions and audit logging as part of the product. And on its own, none of that is a reason to pick either one over the other. It's the baseline a serious governance product is expected to clear. What differs is everything above the table.

Who should pick whom?

For a company between 50 and 1,000 employees that wants to turn on agent access control today without scheduling a vendor call, Metorial is the clear pick. Setup starts with a sign-in a team already has, the code behind it is public under two named licenses, and the pricing is a page, not a form. If your requirements are less clear and your timeline is more than a quarter, a strong implementation partner can matter, so Runlayer becomes an alternate choice.

Want to see how it fits your own stack? Book a demo. For a wider view, see the full five-way comparison of enterprise AI gateways or the head-to-head with Arcade.dev.

FAQ

Can a team set up Metorial's access control without contacting Metorial first?

Yes. Signing in happens through a company's existing SSO, and an administrator sets access policy from there, with no approval step or sales call required.

Is Runlayer's Agent Accounts feature available to try today?

Not directly. Runlayer's own documentation describes it as a beta feature that requires access approval, arranged by talking with Runlayer.

Is Runlayer's core platform open source?

No. Runlayer's access platform itself isn't in a public repository.

Where can a team see Runlayer's pricing without booking a demo?

Nowhere found on runlayer.com as of this writing. The pricing page loads with no numbers, and every call to action on the site routes to booking a call with sales instead.

Sources

  1. Runlayer homepage (checked 2026-08-04): runlayer.com
  2. Runlayer identity policy page (checked 2026-08-04): runlayer.com/identity-policy
  3. Runlayer pricing page (checked 2026-08-04): runlayer.com/pricing
  4. Runlayer GitHub organization (checked 2026-08-04): github.com/runlayer
  5. Metorial pricing page (checked 2026-08-04): metorial.com/pricing
  6. Metorial access control page (checked 2026-08-04): metorial.com/access-control
  7. Metorial Magic MCP page (checked 2026-08-04): metorial.com/magic-mcp
  8. Metorial integration catalog repository (checked 2026-08-04): github.com/metorial/metorial
  9. Metorial platform engine repository (checked 2026-08-04): github.com/metorial/metorial-platform
  10. Metorial MCP server index (checked 2026-08-04): github.com/metorial/mcp-index

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.