---
title: "PgBeam pricing"
description: "Plans, limits and overage for PgBeam, from $9/mo with a 14-day trial. Every plan includes the full gateway: scoped agent credentials, wire-level guardrails, PII masking and an audit trail."
canonical: "https://pgbeam.com/pricing"
last-updated: "2026-10-11T14:24:48.177Z"
---

# PgBeam pricing

Every plan includes the full gateway: scoped agent credentials, wire-level guardrails, PII masking, and an audit trail. 14-day free trial. Overage: $0.10 / 1K queries + $0.20 / GB.

- Starter ($9/mo): 5 agent credentials, 7-day audit retention, 50K queries/day, 10 GB transfer, 5 projects.
- Pro ($29/mo): 25 agent credentials, 30-day audit retention, 250K queries/day, 50 GB transfer, 20 projects, priority support.
- Scale ($99/mo): unlimited agent credentials, 90-day audit retention, 2M queries/day, 200 GB transfer, 100 projects, dedicated support.

Custom plans for high volume: sales@pgbeam.com.

See https://pgbeam.com/pricing.

## FAQ

### How does PgBeam enforce what an agent can do?
Enforcement happens in the PostgreSQL wire protocol, between the agent and your database. PgBeam parses every statement an agent sends, checks it against the policy attached to that credential (read-only, table allowlists, masking, budgets), and only forwards it if it is allowed. Blocked statements never reach your database.

### Does PgBeam work with my Postgres?
Yes. Enforcement is at the wire, not inside the database, so PgBeam works with RDS, Aurora, self-hosted Postgres, or any managed provider. There is no extension to install and no change to your schema.

### Do I need to change my code?
No. The agent gets a scoped connection string or a hosted MCP URL. Every PostgreSQL driver, ORM, and agent framework works unmodified. Your own application keeps using its existing connection untouched.

### How does PII masking work?
You name the columns to protect and choose redact, null, or hash. PgBeam rewrites those values in the result before they leave the wire, so the agent receives masked data it can still join and group on. Your application reads the real values.

### Can I revoke an agent's access?
Yes, instantly. Revoke a single credential or hit the kill-switch to stop one agent or every agent on a project. The next statement is refused. No credential rotation and no database changes required.

### What is in the audit log?
Every statement an agent runs, allowed or blocked, with the decision, reason, rows, bytes, latency, and credential. Filter and export it in the dashboard. Recent entries are queryable in the control plane and archived for retention.

### What MCP tools does the hosted endpoint expose?
Ten tools: briefing (the schema, the credential's limits, and how to query within them in one call), query, validate_sql, list_tables, describe_table, explain, schema_catalog, and my_permissions (which tells the agent what its credential may do, so it does not find out by being blocked), each enforced against the same policy engine as the connection string, plus search_docs and read_doc for looking up how PgBeam works. An agent connected over MCP gets the same guardrails. Paste the URL into Claude Code, Cursor, or any MCP client. No install.

### Is there an SLA or uptime guarantee?
Uptime commitments and support terms are part of Enterprise plans. Contact sales@pgbeam.com to discuss an SLA for your team.

### What happens if I exceed my limits?
Overage is billed at $0.10 per 1K queries above your daily limit on all plans. Data transfer overage is $0.20/GB on all tiers. No surprises: usage is tracked in your dashboard.

### Can I switch plans at any time?
Yes. Upgrade or downgrade any time from your dashboard. Upgrades take effect immediately. Downgrades take effect at the end of the current billing period.

### Does the gateway add pooling and caching?
Yes. The gateway runs on a globally distributed wire-protocol proxy, so agent traffic gets connection pooling (which absorbs the connections agents leak) and optional query caching (which absorbs the questions they re-ask) at no extra setup.

### Can I self-host PgBeam?
Yes, on the Scale and enterprise plans. The self-hosted (BYOC) data plane runs the PgBeam proxy inside your own VPC or cluster, so agent traffic and your database credentials never leave your network, while the control plane, policy engine, and dashboard stay hosted by PgBeam. The proxy dials home only to fetch policy config and ship the audit trail. See the self-hosted data plane docs to enroll.
