Sutra discovers every API in your repo, governs what each audience can access, and exposes it to developers and AI agents. Catalog, contracts, testing and hosted MCP servers in one pipeline — wired into UPI, ONDC, Account Aggregator and the rest of India Stack. No OpenAPI spec required.
Free tier · No credit card · INR billing · No spec needed
Built for the teams shipping India's API layer
01 · Discover
Point Sutra at a repo and it produces a complete API catalog — even when nobody ever wrote a spec. Works on Django, FastAPI, Express, Spring Boot and Go.
git · 1,204 files scanned
OpenAPI 3.1 · 214 endpoints
agent-ready 73% · 2 breaking
hosted · auth · logging
02 · Understand
Every endpoint scored on design, security and AI readiness. One-click AI fixes that write descriptions straight from your code. Test the traditional way too.
03 · India Stack
Sutra ships first-class connectors for the public infrastructure Indian products are built on. Import the upstream contract, diff against it on every commit, and expose a governed MCP tool for each.
Collect, mandate and payout specs with callback schemas.
Connector liveBeckn protocol schemas for search, select, init, confirm.
Connector liveSahamati consent flows and FI data fetch contracts.
Connector liveIssued-document pull and eSign request/response types.
Connector liveReturns, e-invoice IRN and e-way bill endpoints.
Connector liveBiller discovery, fetch and payment confirmation.
BetaOffline Aadhaar XML and CKYC search contracts.
BetaLoan agent and lender API contracts for embedded credit.
Coming soon04 · Contracts
Pick the audience, the endpoints, the fields they get and where it ships. Sutra then diffs every commit against that promise and tells you the moment the source drifts away from it.
Step 1 · Who is this contract for?
Step 2 · Which endpoints does the partner get?
Step 3 · Which fields leave your perimeter?
Step 4 · Where does this contract ship?
Step 5 · Live and watched
Someone shipped 5 changes today. Two would have broken a partner. Sutra stopped them.
Click any change to see the exact schema diff and who it breaks.
05 · Publish
Generate an MCP server from any API. Hosted in India, authed through Sutra's MCP gateway, fully logged. Not weekend demos.
Claude, Cursor or any MCP client. The contract decides which tools each audience sees; auth and logging come standard.
npx sutra mcp add payments
06 · Improve
Test the server with a real agent in the playground. Once it is live, the agents calling it tell you which tools confused them.
Ask the agent to do something with your server. It picks the tools and shows you every call it made.
The tool description does not clearly explain when it should be used versus list_transactions.
The tool failed to return a response after multiple attempts — the MCP server kept timing out on the UPI callback.
The tool requires too many parameters for a simple lookup. Six of nine could be optional.
07 · Observe
Here is who, with which key, at what cost. Every call checked and logged, and your credentials never leave Sutra.
Every call logged with agent, key, tool, latency and outcome. Retained 90 days, exportable to your SIEM.
In practice
Three write-ups from real deployments: what governed MCP servers, structured errors and per-audience contracts change in practice.
Ninety days of one production MCP server serving four agents. Every anomaly attributed to a specific agent and key within minutes.
Read the numbers →Across 1.2 million tool calls, one vague error message drove a third of all retry traffic. Structured errors naming the field fixed it.
Read the numbers →One team, first quarter on contracts: for the first time they could prove no active consumer referenced the endpoints they deleted.
Read the numbers →Enterprise
Built for the compliance regime Indian teams actually face — DPDP Act 2023, CERT-In directions, RBI data localisation — alongside SOC 2 and ISO 27001 for your global customers.
Mumbai and Hyderabad regions · managed upgrades · 99.9% SLA
Your VPC, your KMS keys, your audit trail
Air-gapped, no egress — for regulated BFSI deployments
Identity providers were built for people signing in to apps. Sutra extends the one you already run to AI agents, so access follows your existing teams and roles.
Pricing
Start free on a real repo. Pay per seat when the catalog goes to production. GST invoices, UPI and NEFT accepted.
1 repo · 1 MCP server · 50 endpoints · community support. No credit card, no spec, no trial clock.
Start freeUnlimited repos and contracts · hosted MCP gateway · CI diffing · agent feedback · 90-day logs.
Start 14-day trialSSO and SCIM · private cloud or on-prem · DPDP and CERT-In documentation pack · named support.
Talk to usFAQ
Humans, tests, partners, agents. One catalog, one contract, one place — hosted in India.
npx sutra init