Workflow canvas
Compose triggers, agents, tools and branches visually. Each node keeps its own state, so a failure points at a step, not a mystery.
Theme
Palette
Your own colour
Saved for this browser, on every page.
Build agents and workflows, run them against real systems, and watch every step, cost and failure live. Your model bill goes straight to your provider at cost — we charge a flat fee for the platform, never a cent on tokens.
Runs
| Workflow | Run | State | Duration | Started |
|---|---|---|---|---|
| Support triage | wf_8fa2c41 | 1.2s | 2 min ago | |
| Lead scoring | wf_8fa1b07 | — | 3 min ago | |
| Invoice parse | wf_8f9ed22 | 2.0s | 11 min ago | |
| Contract review | wf_8f9e118 | 0.4s | 24 min ago | |
| Nightly digest | wf_8f9d904 | — | 1 hr ago |
Bring the models you already pay for
How it works
Most AI work stalls between the demo and production. Vendor.sh gives each step an owner, a state and a cost, so the work survives contact with real systems.
Define agents with instructions, tools and a structured output schema. Chain them on the workflow canvas.
Trigger from the console, a schedule, an embed or one HTTPS call. Every run gets a state the whole team can read.
Trace each step, its tokens and its latency. Budgets stop spend before the invoice does.
The platform
One workspace for the people who design the work and the people who answer for it.
Compose triggers, agents, tools and branches visually. Each node keeps its own state, so a failure points at a step, not a mystery.
Agents return typed data, not paragraphs. Schemas are made strict for the provider automatically.
Every span carries tokens, latency and the exact input it saw. Debug the step that failed, not the whole run.
Set a ceiling per workspace or per member. Runs are refused at the limit and say why, before finance has to ask.
Drop a deployed workflow into any site, or call it over HTTPS with a scoped token. Visitors stay anonymous.
Bring your own key
Connect the provider accounts you already have. The provider bills those tokens to you at its own price, and a call on your key creates no managed debit here. Our plans meter runs and members — the work we actually do for you.
| Provider | Key | Used by | State |
|---|---|---|---|
| OpenAI | sk-proj-…4f2a | Support triage, Invoice parser | Verified |
| Anthropic | sk-ant-…9c01 | Contract review, Lead scoring | Verified |
| Google Gemini | AIza…Qm7x | Nightly digest | Verified |
| OpenRouter | sk-or-…d33e | Fallback route | Disabled |
Run a support agent on Anthropic and a parser on OpenAI, each against your own account. Change the model without rebuilding the workflow around it.
Spend is recorded per call, per provider and per agent, and the route that paid for it is on the row — so you can read the bill before your provider sends it.
Set a daily or monthly ceiling. A run is refused at the limit instead of surprising finance, whichever route served it.
A provider key is encrypted at rest and never returned to a browser. After you save it, no screen in the product can show it again.
For developers
Every deployed workflow gets a versioned endpoint, a typed contract and a run you can poll or stream. No SDK lock-in: if it speaks HTTP, it can run your agents.
$ curl -X POST https://vendor.sh/api/v1/workflows/support-triage/runs \
-H "Authorization: Bearer $VENDOR_TOKEN" \
-H "Idempotency-Key: 7d1f…" \
-d '{"input": {"ticket": "Refund for #4471"}}'
$run = Http::withToken(config('services.vendor.key'))
->withHeaders(['Idempotency-Key' => $ticket->uuid])
->post('https://vendor.sh/api/v1/workflows/support-triage/runs', [
'input' => ['ticket' => $ticket->subject],
])->throw()->json();
run = httpx.post(
"https://vendor.sh/api/v1/workflows/support-triage/runs",
headers={"Authorization": f"Bearer {token}",
"Idempotency-Key": ticket.uuid},
json={"input": {"ticket": ticket.subject}},
).raise_for_status().json()
const run = await fetch(
"https://vendor.sh/api/v1/workflows/support-triage/runs",
{ method: "POST",
headers: { Authorization: `Bearer ${token}`,
"Idempotency-Key": ticket.uuid },
body: JSON.stringify({ input: { ticket: ticket.subject } }) },
).then((r) => r.json());
{
"data": {
"id": "01J9Z4K2QXV7M8T3B6R0YHWCE5",
"status": "pending",
"mode": "async",
"deployment": { "slug": "support-triage", "environment": "production" },
"workflow": { "slug": "support-triage", "name": "Support triage" },
"release": { "number": 3 },
"usage": { "cost": "0.0000", "tokens": 0, "duration_ms": null }
}
}
Security
Our threat model names each adversary, the control that answers it and the test that proves the control fires. It also lists what is not covered, because an unlisted gap reads as a solved one.
Read the threat modelRate limits, CSRF, and embed sessions that carry a hashed token.
Every query is scoped to a workspace. Keys never cross one.
Permissions are checked on the server for every action, not in the browser.
Output is validated against a schema before anything acts on it.
Pinned packages, audited installs, and no source maps shipped.
Settings and provider keys are encrypted at rest and never logged.
Pricing
Plans meter runs and members — the work we actually do for you. Every call on your own provider key goes on that provider's invoice, never ours.
USD 0
Build and test a small AI product.
USD 19
Deploy AI workflows for one product.
USD 49
Operate production workflows across environments.
USD 149
Run governed AI workflows with a larger team.
Custom
Use custom limits, security, and support terms.
Calls on your own key cost nothing here. On every plan.
Your provider bills those tokens at its own price. Credit packs exist only for managed usage you choose to run through Vendor.sh.
Free to start. Connect your own model key, invite your team and ship a run in under ten minutes — with zero markup on a single token.