Startup Spotlight: Metorial puts access controls between agents and company tools
Founders Karim Rahme and Tobias Herber are positioning Metorial as infrastructure for developers and enterprises, with identity, permissions and tracing alongside more than 1,000 integrations. Metorial's public evidence of demand remains early and largely company-reported.
By RuntimeWire Staff · Published
Primary source: Y Combinator
Why it matters
Metorial is betting that as companies give agents access to real systems, identity, permissions and audit trails become shared infrastructure rather than one-off integration work.

Karim Rahme and Tobias Herber built Metorial around a problem they encountered while trying to make AI workflows useful: connecting an agent to company software meant stitching together authentication, permissions, retries and monitoring before the agent could do much at all. Their answer is an infrastructure layer that routes those connections through one governed system.
The Y Combinator profile lists Rahme as CEO and Herber as CTO, and places Metorial in the Fall 2025 batch. Y Combinator is also Metorial's confirmed backer. A Dealroom entry lists a $125,000 YC seed figure, but does not verify Metorial's total funding or disclose a valuation. Metorial's founders described Linz, Austria, and San Francisco as their locations in Metorial's Fall 2025 application.
The founders have been building together for more than a decade. They met as students at a technical high school in Austria, then co-led technical development at Valicit, an Abu Dhabi ticketing startup. Rahme studied computer science and mathematics at NYU Abu Dhabi and worked on earlier ventures including DigiKraft and Valicit, according to NYU Abu Dhabi's startup directory.
Herber's background includes a run of technical projects before Metorial. On his personal site, he describes himself as an Austrian software engineer and founder, and lists Weekrise, a calendar-based task-planning tool; Loopbound, a developer-tools company; and Cargo, an experimental browser with a minimal interface. He says Weekrise reached more than 3,000 active users. Those are project and usage details reported by Herber; they do not establish the commercial outcomes of those ventures. His technical work has included a computer-science master's thesis on bytecode and program visualization, which his site says led to an IEEE publication that received a 2025 IEEE Vissoft Best Paper Award. Johannes Kepler University Linz's 2025 Adolf-Adam award page records Herber as the first-place winner for the best computer-science master's thesis. A separate JKU news report identifies him as working at Metorial. The prize is sponsored by Raiffeisen Software and the Austrian Computer Society.
That history informs Metorial's origin story. Metorial began as a no-code AI workflow builder. While building it, the founders said they kept spending time on integration plumbing: authentication, retries and unreliable MCP servers. They shifted toward the infrastructure itself. In Rahme's account of Metorial's two YC applications, the founders describe an initial rejection for the Summer 2025 batch, followed by acceptance to Fall 2025 after they broadened the product beyond a simple integration shortcut.
From one-line integration to operating layer
Metorial uses the Model Context Protocol, or MCP, a standard for connecting AI clients and agents with external services and internal tools. Its current product description presents the platform as a common route from clients such as Codex, Claude Code and Cursor to company-approved software. Metorial supplies managed integrations, can connect custom or remote MCP servers, and says it handles authentication, hosting, routing and monitoring.

Its Magic MCP product packages that approach into a single URL for an MCP-compatible client. An employee signs in through the company's identity system; the agent can then reach the tools and actions the employee is authorized to use. Metorial says calls are recorded for tracing, and access policies can be applied across users, groups, agents and individual tools. In practice, an administrator could allow an agent to read from a service while blocking a more consequential action, such as sending a message or changing a record.
The product is aimed at the control plane around agent use. A connector catalog can shorten the time it takes to connect an agent to a service. Enterprise operators also need to know who authorized that connection, what the agent could do and what happened when it acted. Metorial is trying to make those decisions reusable across clients and integrations instead of leaving each engineering team to reproduce them.
That positioning draws a specific line through a crowded MCP market. In its YC application retrospective, Metorial characterizes Zapier MCP as a hosted gateway that exposes Zapier's app catalog and actions to MCP clients, and Smithery as a registry and basic SDK for discovering and running MCP servers. Zapier's own documentation describes a product centered on connecting MCP clients to its apps and actions, with tool calls using existing Zapier tasks. Metorial's case is that developers embedding tools in their own products need SDKs, managed runtime, authentication, monitoring and logging alongside the connections.
Composio is a closer comparison for developer and enterprise use. Metorial's comparison page describes Composio as focused on breadth-first connectivity, while pitching Metorial as MCP-native infrastructure with deployment, observability, session replay, per-user isolation and self-hosting. That is Metorial's own comparison, not an independent product test; the practical distinction is whether a team wants a managed connection and action layer, or also wants to run and inspect MCP workloads through the same platform. Pipedream is another developer-facing integration option, with a broad catalog of tools exposed to MCP clients. These products overlap on connectivity, while Metorial is making governance and runtime controls central to its pitch.
Metorial's product also reflects the founders' effort to move past the framing that first drew scrutiny from YC. In the application retrospective, Rahme recounts feedback that the early pitch made Metorial sound like a convenient integration feature rather than a defensible business. The founders say they responded by expanding into developer tooling, runtime infrastructure and enterprise controls. Their account is self-reported, while the current product's scope is consistent with that repositioning.
Metorial's integration catalog lists more than 1,000 integrations and shows 1,063 entries. Its GitHub repository describes the platform as an identity and access layer for agents and advertises more than 1,200 integrations, a higher figure than the catalog page. These are Metorial-maintained counts. Catalog size alone says little about how many integrations customers use in production or how reliably each performs as underlying services change.
Metorial also markets Protoguard, which it says checks agent messages and tool calls for prompt injection and unsafe requests. The feature extends Metorial's pitch from controlling which tools an agent can reach to inspecting what it is trying to do. That capability is a company claim, not an independently verified security test.
Evidence of demand, with the caveats attached
The founders' YC application gives a snapshot of early traction, rather than a current operating metric. In the Fall 2025 application, they reported 350 developers on an early-access list, 2,600 GitHub stars and a pilot with a pharmaceutical company. They later updated the application to say Metorial had its first paying customer. Those figures describe the application period; they do not establish current customer count, revenue, retention or production usage.
Herber's personal site says Metorial's runtime powers hundreds of thousands of MCP connections. That is a founder-reported activity figure, and the site does not define the measurement or provide customer-level deployment data. It offers another indication of use, but it cannot be read as a count of customers or paying production deployments.
Metorial's customer page features testimonials from Moonfire and Crunched. Crunched says the platform lets it handle connector requests while focusing on its AI analyst product; Moonfire describes using it to bring data sources, tools and messaging platforms together. Those references give the product a concrete use case, but the testimonials do not disclose contract size, deployment volume or measurable results.
The public pricing gives teams a way to try the product without an enterprise sales process. Metorial's pricing page lists a free Dev plan with 500,000 tool calls a month, two team members and up to 10 integrations. Its Scale plan costs $250 per month and includes 2.5 million tool calls and 20 workforce seats, with additional seats priced at $20 each. Enterprise pricing is custom, with options including role-based permissions, SAML single sign-on, advanced compliance and on-premises deployment. The tiers show how Metorial packages individual developer access and larger organizational controls; the public page does not disclose how much of its business comes from either segment.
The problem moves from connection to control
The market includes integration catalogs, MCP registries, gateways and security products. Metorial's chosen position is to combine connections with identity, policy enforcement and tracing in one path. If companies adopt agents across different models and clients, the infrastructure between those agents and internal systems could become a place to set and review access rules. That possibility is the business thesis, not evidence that Metorial has become a standard layer.
The implementation has to work beyond the product description. A large catalog is useful only when its integrations are maintained. A policy layer has to preserve the right user context across systems. Tracing has to produce records operators can use when an agent does something unexpected. Metorial describes these capabilities on its integration and access-control pages, but those descriptions are product claims, not independent measurements of reliability or security. Metorial does not publish revenue, retention or production deployment figures in the materials cited here, so its commercial scale cannot be inferred from its integration count or developer interest alone.
The founders' transition gives Metorial a broader job than connecting tools. Metorial started by helping developers wire them up; it now sells the operational layer meant to govern how people and agents reach them. That gives Metorial a larger potential role inside an organization and a harder test: becoming a trusted point of control rather than a connector developers can swap out.
Rahme and Herber have described changing both their product and their pitch after YC questioned whether the business could become defensible. The next proof will come from customers using the controls in real deployments, and from whether Metorial can turn those deployments into durable revenue. For now, Metorial has a defined infrastructure thesis, early customer references and a product aimed at the work that starts when agents leave a demo and meet company systems.