# Self-hosted enterprise

Coming soon: Kastra governance in your infrastructure, with local licensing, enterprise identity, and controlled recovery.

Updated: 2026-09-22

Canonical: https://docs.kastra.ai/reference/self-hosted

## Coming soon

Kastra self-hosted brings policy enforcement, human approvals, and decision evidence into your own infrastructure. It is designed for enterprise teams with private-network, data-control, and operational requirements.

The enterprise appliance is coming soon, with an assisted pilot as the first delivery path. It is not yet generally available. [Talk to Kastra](https://kastra.ai/enterprise) about your deployment requirements and pilot availability. You can start using the [hosted service](https://app.kastra.ai) today.

## Designed for your environment

The appliance brings together these capabilities for the assisted deployment:

| Capability | What it enables |
| --- | --- |
| Runtime governance | Policy decisions, human approval, and decision recording for connected workflows |
| Dedicated workspace | One workspace per installation, with owner-controlled membership and administration |
| Local licensing | Signed, installation-bound licenses verified locally without contacting Kastra |
| Enterprise identity | SAML sign-in, invitation-based access, and a local owner recovery path |
| Private services | Configurable model endpoints, scoped CA trust, and operator-controlled webhook destinations |
| Email | Your SMTP relay for invitations and password recovery, with encrypted credentials and verified TLS |
| Evidence | Configurable content retention, offline verification, and encrypted backups |
| Recovery and upgrades | Paused recovery, explicit activation, and assisted upgrades for supported release pairs |

Kastra will work with your team to agree on the host, client, model, identity, network, and operating scope for your deployment. This page introduces the appliance; installation instructions and supported configurations will accompany its release.

## Ownership and signup

Each installation has one bound workspace. Owners manage members, deployment settings, and licensing. Invitation-only signup lets your team control who joins.

Keep a tested local OWNER recovery account alongside SAML. Changing bootstrap credentials does not reset an existing account, and workspace creation and deletion are locked after bootstrap.

## License lifecycle and renewal

License verification runs locally against trusted public keys and the installation's stable identity. The appliance includes a 30-day evaluation and reports its effective license status in Deployment settings.

After evaluation or license grace ends, authoring and licensed configuration become limited. **Existing runtime policy enforcement, approvals, and decision recording continue.** The [hosted subscription model](https://docs.kastra.ai/admin/billing) has different lapse behavior.

Renewals preserve the database and installation identity. Owners manage signed licenses in Deployment settings; private signing keys remain outside the appliance. Disconnected installations receive revocations through imported signed data, rather than an immediate remote check.

## SSO and email recovery

Existing active members can continue using an enabled, configured SAML identity provider through license expiry. New just-in-time memberships require the SSO entitlement. Keep your recovery account current and test login and recovery with your identity provider. [SAML and SCIM guide](https://docs.kastra.ai/admin/sso-scim).

Your SMTP relay handles invitations and password recovery. Verify both flows with your own relay. A failed invitation submission preserves the invitation for resend; relay acceptance and inbox delivery are separate events. After recovery, email delivery stays paused until the owner confirms the relay and supplies fresh credentials.

## Network boundary and clients

Choose where model traffic, identity, email, webhooks, and evidence exports are allowed to go. Appliance console builds exclude hosted analytics, error reporting, and captcha integrations. Private model endpoints and scoped CA trust support deployment-specific network controls.

Offline licensing does not by itself make a deployment air-gapped. A workflow using an external model still sends requests to that provider. Disconnected operation and supported integrations must be agreed and validated for your configuration.

Edge and the local MCP gateway connect to the installation's configured Kastra API. Set the API deployment root and console URL before login, and verify the chosen client and workflow. [Platform support](https://docs.kastra.ai/start/platform-support) · [Authentication](https://docs.kastra.ai/start/authentication).

## Recovery, execution and upgrades

Recovery starts paused so your team can confirm current access, MFA, execution state, and evidence custody before activation. Preserve current erasure custody independently of database backups so restoring older data cannot make later-erased content available again. [Retention and recovery](https://docs.kastra.ai/evidence/data-handling).

The assisted proxy workflow supports a non-streaming request with console approval and durable execution accounting. Preserve the operation identity and request bytes when resuming. An uncertain execution outcome requires reconciliation before another attempt; it must not be retried automatically. [Proxy approvals](https://docs.kastra.ai/proxy/approvals).

Plan a maintenance window for assisted upgrades. Use the supported source/target release pair and follow its recovery procedure. The source is fenced before the final backup; restarting it or using an old image against a migrated database is not a rollback procedure.

## Plan your deployment

Share your target environment, identity provider, model endpoint, approval workflow, data-retention needs, and expected workload with Kastra. Together, we can define the supported configuration, recovery checks, operating responsibilities, and support terms for your team.

[Discuss self-hosting](https://kastra.ai/enterprise) · [Plan an evaluation](https://docs.kastra.ai/security/evaluation) · [Operational guide](https://docs.kastra.ai/security/operations)
