Self-host AgentKit
Run AgentKit in your own Kubernetes cluster with no connection to Scalekit infrastructure. What changes for connectors, OAuth apps, network access and SDKs.
AgentKit runs in your own Kubernetes cluster with an enterprise license. Connections, connected accounts, the token vault, tool execution and Virtual MCP servers all run in your cluster. Once it’s installed, your instance has no connection to Scalekit’s infrastructure: credentials, tool calls and logs stay in your network.
Use it when credentials and tool calls must stay in your network for data residency, compliance or network isolation. To get access, talk to an engineer. Installation, configuration and upgrade guides come with your license.
What you provide
Section titled “What you provide”| Dependency | Requirement |
|---|---|
| Kubernetes | 1.27 or later, managed or self-managed, with Helm 3.12 or later |
| Ingress | Kubernetes Gateway API or the nginx ingress controller |
| PostgreSQL | 15 or later (CockroachDB is also supported) |
| Redis | 6.2 or later |
| SMTP | Any provider, for team invitations and sign-in email |
| Domain | A domain and TLS certificate for your instance |
Network access
Section titled “Network access”No traffic goes to Scalekit, but tools still call the apps they connect to. Your instance calls each connector’s API and OAuth token endpoint directly, so allow outbound HTTPS from the cluster to the providers you use, such as Google, Slack or Salesforce. Your users’ browsers must reach the provider’s consent screen when they authorize a connected account.
A connector works only if your cluster can reach its provider. Connectors for apps that run inside your network, including your own connectors, need no internet access.
OAuth apps
Section titled “OAuth apps”Scalekit’s own OAuth credentials, offered as Use Scalekit credentials when you create a connection, belong to Scalekit’s cloud and aren’t available on a self-hosted instance. Create an OAuth app with each provider and use it for the connection, as in Use your own OAuth app. Register the redirect URI your instance shows in the connection form, which is on your own domain.
Point your app at your instance
Section titled “Point your app at your instance”The SDKs and the REST API work the same way. Set SCALEKIT_ENVIRONMENT_URL to your instance’s environment URL, and use a client ID and secret from API credentials in your instance’s dashboard at https://app.<your-domain>. See API credentials.