> **Building with AI coding agents?** Install the authstack plugin with one command. This equips your agent with accurate Scalekit implementation patterns.
>
> **Recommended**:
> ```bash
> npx @scalekit-inc/cli setup
> ```
>
> Global:
> ```bash
> npm install -g @scalekit-inc/cli
> scalekit setup
> ```
>
> Supports Claude Code, Cursor, GitHub Copilot, Codex + skills for other Agent Skills-compatible agents.
> Skills: integrate-agentkit, implement-saaskit, add-mcp-oauth, implement-sso, implement-scim.
> [Full setup guide](https://docs.scalekit.com/dev-kit/build-with-ai/)

---

# Self-host AgentKit

Run AgentKit in your own Kubernetes cluster with no connection to Scalekit infrastructure. What changes for connectors, OAuth apps, network access and SDKs.
AgentKit runs in your own Kubernetes cluster with an enterprise license. Connections, connected accounts, the token vault, tool execution and Virtual MCP servers all run in your cluster. Once it's installed, your instance has no connection to Scalekit's infrastructure: credentials, tool calls and logs stay in your network.

Use it when credentials and tool calls must stay in your network for data residency, compliance or network isolation. To get access, [talk to an engineer](https://scalekit.com/demo). Installation, configuration and upgrade guides come with your license.

## What you provide

| Dependency | Requirement |
| --- | --- |
| Kubernetes | 1.27 or later, managed or self-managed, with Helm 3.12 or later |
| Ingress | Kubernetes Gateway API or the nginx ingress controller |
| PostgreSQL | 15 or later (CockroachDB is also supported) |
| Redis | 6.2 or later |
| SMTP | Any provider, for team invitations and sign-in email |
| Domain | A domain and TLS certificate for your instance |

## Network access

No traffic goes to Scalekit, but tools still call the apps they connect to. Your instance calls each connector's API and OAuth token endpoint directly, so allow outbound HTTPS from the cluster to the providers you use, such as Google, Slack or Salesforce. Your users' browsers must reach the provider's consent screen when they authorize a connected account.

A connector works only if your cluster can reach its provider. Connectors for apps that run inside your network, including [your own connectors](/agentkit/bring-your-own-connector/overview/), need no internet access.

## OAuth apps

Scalekit's own OAuth credentials, offered as **Use Scalekit credentials** when you create a connection, belong to Scalekit's cloud and aren't available on a self-hosted instance. Create an OAuth app with each provider and use it for the connection, as in [Use your own OAuth app](/agentkit/advanced/bring-your-own-oauth/). Register the redirect URI your instance shows in the connection form, which is on your own domain.

## Point your app at your instance

The SDKs and the REST API work the same way. Set `SCALEKIT_ENVIRONMENT_URL` to your instance's environment URL, and use a client ID and secret from **API credentials** in your instance's dashboard at `https://app.<your-domain>`. See [API credentials](/agentkit/api-credentials/).

## Next

  - [Security and compliance](/agentkit/security/): How credentials are stored, and what your app is responsible for.
  - [Launch checklist](/agentkit/advanced/launch-checklist/): What to check before real users connect accounts.


---

## More Scalekit documentation

| Resource | What it contains | When to use it |
|----------|-----------------|----------------|
| [/llms.txt](/llms.txt) | Structured index with routing hints per product area | Start here — find which documentation set covers your topic before loading full content |
| [/llms-full.txt](/llms-full.txt) | Complete documentation for all Scalekit products in one file | Use when you need exhaustive context across multiple products or when the topic spans several areas |
| [sitemap-0.xml](https://docs.scalekit.com/sitemap-0.xml) | Full URL list of every documentation page | Use to discover specific page URLs you can fetch for targeted, page-level answers |
