All documents · Competition research

Competition research — 18 September 2026

Scope: LLM observability, MCP gateways, agent governance, agent evals, AI spend controls, agent audit receipts. Prices and claims below are from vendor pages opened on this date, plus a small set of first-party blogs/docs. Secondary aggregators were used only as pointers, never as the source of a price.

Verdict for CryptoBook: do not ship a Langfuse/Helicone/LangSmith clone. Observability is cheap, open-source, and fully occupied. Enterprise agent governance just had a two-week vendor rush (Okta, IBM, Broadcom, Dataiku). The remaining wedge is a small-team permit plane: English allow/deny/ask rules, hard spend caps on the user’s own keys, and a signed shareable receipt — not GRC, not a trace UI, not a prepaid model wallet.


Helicone / Mintlify — CONFIRMED maintenance mode

The brief’s claim is true, with two caveats.

Confirmed from both parties, 3 March 2026:

Caveats (do not overstate):

  1. The product is not shut down. Pricing is still live (Hobby free / Pro $79 / Team $799 / Enterprise). Signup CTAs still work. Source: helicone.ai/pricing
  2. Status is operational as of 18 Sep 2026 04:24 UTC. helicone.ai reports 100% uptime on the marketing site; api.hconeai.com 98.15%; EU API 94.76% with multi-hour outages in July–August. Source: status.helicone.ai
  3. Competitor pages (Preloop, OpenObserve, Curate-Me) claim “new signups closed” and “roadmap frozen.” Helicone’s own pricing page still offers “Get started for free.” Treat “closed to new signups” as unverified competitor marketing, not a first-party fact.
  4. Mintlify is absorbing the team into docs/knowledge infrastructure, not continuing Helicone as an observability company.

Implication: Helicone’s 16k-org proxy install base is a migration pool, not a hole to clone into. Anyone who ships another request-log dashboard will be compared to a dead-but-still-running product and to Langfuse at $29.


Competitor table

Vendor What they do Public price (Sep 2026) Who they serve Gap vs a new product
Langfuse Open-source LLM/agent tracing, prompt mgmt, online+offline evals, cost tracking, OTel. MIT core; ClickHouse-backed. Cloud + free self-host. Hobby free (50k units, 2 users, 30d). Core $29/mo (100k units, unlimited users, 90d). Pro $199/mo (3y retention, SOC2/ISO/HIPAA). Teams add-on $300/mo. Enterprise $2,499/mo. Overage $8/100k units, down to $6/100k at 50M+. Devs and AI teams who want traces/evals without LangSmith lock-in. Canva, Twilio, Ramp, Khan Academy listed. Already the cheap default. A unit = every trace+span+score, so chatty agents burn units — but Core at 1M units is ~$101. Cloning this is instant death.
Helicone Proxy-first LLM gateway + observability (change base_url). Caching, rate limits, fallbacks, cost analytics. Apache 2.0. Acquired by Mintlify 3 Mar 2026; maintenance mode. Hobby free (10k req, 1 seat, 7d, 1 GB). Pro $79/mo. Team $799/mo. Enterprise contact. Usage-based over Hobby 10k. YC/startup LLM apps that wanted one-line proxy logging. Historical 16k orgs, 14.2T tokens. Frozen product. Do not clone the proxy-log dashboard. Do not become “Helicone 2”; Preloop/LiteLLM/Langfuse already pitch that.
LangSmith (LangChain) Closed observability + evals + Deployment / Engine / Fleet / Sandboxes / LLM Gateway. Full agent lifecycle, not just traces. Developer $0/seat (1 seat, 5k base traces). Plus $39/seat/mo (unlimited seats, 10k traces). Enterprise custom (self-host/hybrid). Usage: LCU $1.50, LSU $1.00. Base traces 14d; extended 400d (SaaS max long-lived retention changing to 180d from 14 Sep 2026). LangChain/LangGraph shops, teams who want managed agent hosting + evals. Expensive at volume vs Langfuse. Owns the “platform for agents” story. Do not clone traces, evals, or agent hosting.
AgentOps Agent-native tracing: LLM calls, tools, multi-agent graphs, time-travel replay, cost tracking, 400+ LLM/framework SDKs. Basic $0 (5k events/mo). Pro from $40/mo (unlimited events/retention, export, Slack). Enterprise custom (SSO, on-prem, SOC2/HIPAA/NIST AI RMF). Agent builders (CrewAI, AutoGen, OpenAI Agents). Logo wall is consultancies + Fortune logos. Event = each LLM/tool/action, so 5k free is a few hundred runs. Replay/debug is their wedge. Do not clone session replay.
Arize Phoenix / AX OSS local-first tracing + evals + experiments (ELv2). Cloud AX for production monitors, online evals, agent-as-judge. Native OTel/OpenInference. Phoenix self-host $0, no event cap. AX Free: 25k spans, 1 GB, 15d. AX Pro $50/mo (50k spans, 10 GB, 30d, unlimited evals/users). AX Enterprise custom (self-host, SSO, HIPAA). AI engineers, RAG/eval-heavy teams, path from notebook → AX. Best-in-class evals/RAG drift. Do not clone LLM-as-judge, datasets, experiments.
Braintrust Evals-first: datasets, offline/online scores, playgrounds, Loop agent, optional gateway. Starter $0 ($10 credits, 1 GB, 10k scores, 14d). Pro $249/mo ($100 credits, 5 GB, 50k scores, 30d). Enterprise custom. Scores $2.50 then $1.50 per 1k. AI-native product teams whose job is “is this prompt better.” Evals are a mature category. Do not clone score dashboards or experiment runners.
Portkey (now Prisma AIRS AI Gateway, Palo Alto Networks) AI gateway: universal API, fallbacks, caching, guardrails, virtual keys + budgets, org audit logs, MCP Gateway (auth, registry, RBAC, tool-call logs). Developer free (10k recorded logs, 3d logs / 30d metrics; requests not blocked past cap). Production $49/mo (100k logs, +$9/100k up to 3M). Enterprise custom (VPC, SSO, HIPAA/SOC2). OSS self-host exists. Production LLM apps; now enterprise security buyers via Palo Alto. Gateway+MCP+guardrails is occupied and being absorbed into a firewall vendor. Do not clone routing/caching/MCP registry.
LiteLLM Self-hosted OpenAI-compatible proxy for 100+ providers. Hard budget caps per key/user/team/provider/model (reject, not just alert). MCP + Agent gateway. 53k+ GitHub stars, 240M+ Docker pulls. OSS $0 forever. Enterprise: annual, sized to request capacity, never per token. 30-day Enterprise trial key, no card. AWS Marketplace. Platform teams who already run a proxy (NVIDIA, Netflix, AT&T, Okta, Stripe logos). Spend control on model traffic is solved for anyone willing to self-host. Do not clone virtual keys or $/day caps on chat/completions. Tool-call (MCP) policy + human ask + shareable receipt is still thin in OSS.
Cloudflare AI Gateway Managed gateway with spend limits (block 429 or fall back to cheaper model). BYOK or Unified Billing. Up to 20 rules / gateway. Gateway itself is in Cloudflare’s product set; Unified Billing has a 5% fee in some configs (not re-verified on this pass). Spend-limits docs updated 9 Sep 2026. Teams already on Cloudflare. Spend limits exist as a checkbox on big-cloud gateways. They do not govern tools, only tokens.
Okta Agent SSO / Okta for AI Agents First-class identity for agents. Agent SSO (GA 24 Aug 2026) registers Cross App Access (XAA) agents in Universal Directory, short-lived tokens instead of static keys. Bundled in core Okta SSO at no extra cost. Paid Okta for AI Agents (GA May 2026): shadow-agent discovery, A2A, certifications, kill switch. Agent SSO: $0 extra on existing SSO. Okta for AI Agents: separate subscription, no public list price. Enterprises already on Okta (~20k customers). Identity is Okta’s. A new product must not be “SSO for agents.” XAA/MCP enterprise-managed auth is becoming a standard; ride it, don’t reimplement IdP.
IBM watsonx Orchestrate Enterprise agent control plane: build/orchestrate/govern/observe, catalog, policy, identity (IBM Verify / Entra). AgentOps Agent GA 31 Aug 2026 (NL eval→fix loop, GEPA/ACE). Trace Inspector + custom LLM-as-judge. AI Gateway discovers Bedrock agents (Azure/Vertex “end of September”). 30-day trial. Essentials from $530/mo (4k MAU, 200k msgs). Standard from $6,360/mo (40k MAU, 2M msgs). Premium contact (data isolation, HIPAA). Fortune IT orgs buying from IBM/AWS Marketplace. Sales-led, $530 floor, not a 60-second playground. Do not clone enterprise control planes or “AgentOps” branding.
Broadcom AgentMinder Enterprise runtime governance: agents as identities bound to mission + intent + approved tools. Protocol-aware gateway including MCP. Scoped A2A delegation. OTel tamper-proof audit. AuthZEN. Unveiled 31 Aug 2026 at VMware Explore; GA, bundled with VMware Private AI Cloud. No public price. Sold into VMware/Broadcom accounts. VMware Private AI Cloud / vSphere Kubernetes enterprises. Intent-aware enforcement is the interesting idea — packaged as six-figure infrastructure. Unreachable on a single VPS, and not a self-serve wedge.
Dataiku Agent Management Cross-platform control tower: discover agents on Copilot Studio, Agentforce, Bedrock, Vertex, LangChain, etc.; measure business KPIs not uptime; drift/cost flags; governance workflows. Standalone (does not require full Dataiku). Announced 9 Mar 2026 (early access); secondary sources say GA aimed at Oct 2026. No public price. Enterprise sales. Dataiku platform is already a six-figure buy. Data/analytics orgs that already run Dataiku or need a multi-vendor inventory. “Is this agent worth keeping?” is a real job — sold as enterprise GRC, not a drop-in URL.
Preloop OSS agent control plane (Apache 2.0): MCP firewall (YAML + CEL allow/deny/require-approval/require-justification), model gateway with hard budgets, human approvals (mobile/watch/Slack), session timeline, tamper-evident audit, preloop agents discover rewires Claude Code/Cursor/Codex/etc. with no SDK. Positions vs Helicone/LiteLLM/Bedrock AgentCore. OSS self-host free (one operator/account). Cloud + Enterprise: teams, RBAC, quorum approvals, user/team budgets, billing reconciliation — no public $. GitHub ~62 stars as of 17 Sep 2026 (small). DevEx/security teams rolling out coding agents who want policy + spend + approvals in one box. Closest product to candidate A. Differences a new product can still own: (1) English rules, not CEL; (2) shareable third-party receipt, not an in-console ledger; (3) 60-second playground / one URL, not a control-plane install; (4) honest “not a certification” posture they already take — lean harder into receipts people can forward.
Obot OSS MCP gateway + AI control plane (MIT): catalog, OAuth broker, per-tool policy, audit, shadow-MCP scan (Sentry), hosted MCP servers, LLM gateway. $35M seed. Hosted cloud trial (14 days). Community: self-host free, up to 100 users / 100 devices. Cloud: hosted, SSO, no user limit, trial. Enterprise: contact (unlimited, support). No list price for Cloud/Enterprise. Enterprise IT that wants to say yes to MCP. Claude/Cursor/ChatGPT clients. Catalog + OAuth + Kubernetes hosting is a platform, not a permit. Too heavy for a VPS-first wedge. Do not clone MCP hosting or IdP brokering.
Agent Receipts / Obsigna Open protocol for signed, hash-chained action receipts (W3C VC, Ed25519). Daemon/MCP proxy/hook/SDKs (Go/TS/Python). Keys live outside the agent. Tiny: obsigna ~20 GitHub stars, updated 17 Sep 2026. Free protocol/tooling. Not a SaaS. Protocol/security tinkerers. Receipts exist as spec + SDK, not as a product a freelancer or client can open in a browser and verify in 60 seconds. White space is the hosted verifier + human-readable receipt, not another protocol.
agent-custody Sidecar: Cedar policy, Merkle log, signed receipts, MCP gateway. Provenance labels (attested / observed / claimed). OSS tooling (npm + PyPI). No SaaS price found. Engineers who want cryptographic custody, not a UI. Same as Obsigna: infrastructure, not a product. Heavy (Cedar, Merkle, sidecar).

Adjacent (not in the brief’s vendor list, but they close the same jobs)

Vendor Note
Datadog LLM Observability Incumbent APM adding LLM spans. Entry ~$160/mo + per-span. Enterprises already on Datadog will not buy a trace clone.
WSO2 Agent Manager GA 17 Sep 2026. Cross-framework inventory, agent identity, MCP-level governance, 40+ guardrails, sandbox. Another enterprise control plane.
AWS Bedrock AgentCore AWS-native runtime/gateway/observability/policy. Preloop’s stated alternative. Lock-in.
MintMCP / Lunar.dev / Runlayer MCP access + logging. Preloop’s own comparison pages treat them as “centralize MCP, log calls, no model gateway / no human ask.”

Category map (what is actually crowded)

                    IDENTITY                 RUNTIME POLICY              EVIDENCE
                 Okta Agent SSO           Broadcom AgentMinder        Agent Receipts (spec)
                 IBM Verify/Entra         Preloop MCP firewall        Preloop ledger
                                          Obot / Portkey MCP          IBM Trace Inspector
                                                                          Langfuse traces

  MODEL TRAFFIC                 EVALS                     SPEND
  LiteLLM / Portkey             Phoenix / Braintrust      LiteLLM hard caps
  Helicone (frozen)             LangSmith / Langfuse      Cloudflare spend limits
  LangSmith LLM Gateway         IBM AgentOps Agent        Portkey virtual-key budgets
                                                          Preloop per-agent budgets

Every cell above has a funded incumbent except the intersection of:

That intersection is candidate A in BRIEF.md. Preloop covers 70% of the mechanism (firewall + budgets + audit) but is still a control plane for operators, not a permit + receipt for the person who hired the agent.


What a new product must NOT clone

Instant kill if the homepage, SDK, or pricing looks like any of these:

  1. Trace / span / session-replay UI — Langfuse $29, Phoenix $0, AgentOps $40, LangSmith, Datadog. Commodity.
  2. Prompt manager + playground + datasets + LLM-as-judge — Langfuse, LangSmith, Phoenix, Braintrust $249. Evals are a category, not a wedge.
  3. OpenAI-compatible proxy whose value is “we log every request” — Helicone’s dead body. LiteLLM/Portkey already do this better and are alive.
  4. Virtual keys, fallbacks, semantic cache, load-balancing — LiteLLM OSS, Portkey $49, Cloudflare. Gateway features are table stakes, not a product.
  5. Enterprise agent directory / shadow-AI discovery / access certifications — Okta for AI Agents, IBM Orchestrate, Dataiku, WSO2, Obot Sentry. Requires IdP sales motion.
  6. “SSO for agents” / first-class agent identity — Okta Agent SSO is free on core SSO as of 24 Aug 2026. Competing with free Okta is suicide.
  7. Mission/intent policy engines sold to CISOs — AgentMinder. VMware-shaped deal.
  8. Prepaid model credits / unified billing wallet — Helicone Credits, LangSmith Gateway Credits, OpenRouter. Brief forbids reselling model access as a prepaid wallet. Also a money-transmission-adjacent mess.
  9. MCP server catalog + hosting — Obot, Portkey registry. Platform, not a permit.
  10. “We make you EU AI Act / SOC2 / CRA compliant” — Preloop already warns this is evidence not certification; the brief forbids fake compliance. Do not sell certificates.
  11. AgentOps-the-name or “control plane” as the headline — IBM shipped an “AgentOps Agent” GA 31 Aug 2026. The phrase is burnt.
  12. Heavy SDK / instrumentation as the only path — Langfuse/LangSmith/AgentOps. Drop-in URL or base_url + a yaml file only.

Safe to borrow as a thin implementation detail (not the product): OpenAI-compatible proxy hop, OTel export out to Langfuse if the user wants traces, hash-chained signatures (Obsigna/agent-custody patterns), BYOK.


White space that is still real in September 2026

These gaps survived the vendor rush. They are specific enough to be a product, small enough to run on one VPS, and not a me-too of the table above.

1. Permit gateway in English, not CEL/YAML-for-operators (strongest)

Preloop’s MCP firewall is real: ordered allow/deny/require-approval with CEL on arguments. Obot/Portkey do RBAC on tools. AgentMinder does mission/intent for VMware.

Nobody ships “paste a URL, write three English rules, the agent is now capped” for a freelancer, a five-person startup, or a client who does not have a platform team.

Example rules the incumbents do not productize as a playground:

This is BRIEF candidate A. Preloop is the threat; beat it on time-to-first-permit and receipts a non-engineer can open.

2. Shareable, third-party-verifiable receipts as the product (strong)

Obsigna, agent-custody, IETF draft-sahu-agent-action-receipts-00 (16 Aug 2026), PipeLab, and Preloop’s ledger all exist. All are logs or protocols. None is:

Freelance/client receipts (BRIEF candidate C) are narrow as a market but the receipt object is the differentiator for A. Do not build only for freelancers; make the receipt the viral artifact.

3. agent-permit.yaml in the repo, Dependabot-shaped (real, secondary)

No incumbent makes policy-as-a-file that PRs itself the way Dependabot made dependabot.yml viral. Preloop has YAML+CEL in git, but the product is the console. A GitHub App that comments “this PR’s agent would have been denied rm -rf / would have spent $40” is unoccupied.

Risk: looks like a feature of Preloop/Obot in 6–12 months. Ship the hosted permit URL first; yaml-in-repo as the viral loop, not the MVP.

4. Spend caps on tool actions + BYOK, not just tokens (narrow remaining)

LiteLLM/Cloudflare/Portkey/Preloop cap model dollars. Almost nobody productizes:

Stay on the right side of the brief: never take a prepaid balance, never resell tokens.

5. What is not white space (kill list for idea agents)


Pricing cheat-sheet (self-serve only)

Product Floor Typical paid Notes
Langfuse Cloud $0 $29 / $199 / $2,499 Unlimited seats on paid
Helicone $0 $79 / $799 Maintenance mode
LangSmith $0 $39/seat + usage Traces get expensive
AgentOps $0 $40+ 5k events free
Phoenix / AX $0 OSS AX $50 Evals unlimited on AX
Braintrust $0 $249 Evals-metered
Portkey $0 $49 Now Palo Alto motion
LiteLLM $0 OSS Enterprise quote Hard $ caps in OSS
IBM Orchestrate trial $530 / $6,360 Not a startup tool
Okta Agent SSO $0 on SSO AI Agents = sales Identity only
Preloop / Obot / AgentMinder / Dataiku OSS or sales unpublished Control-plane class

A CryptoBook SaaS should sit under $29 to start (Langfuse Core is the psychological ceiling for “infra I might not need”) or be usage-priced on permits/receipts, not traces.


Implications for the pivot

  1. Confirm Helicone maintenance mode — yes. Use it as a distribution story (“point the same base_url at a living permit plane”), not as a reason to rebuild Helicone.
  2. Do not compete with Langfuse on price or with Okta/IBM/Broadcom on GRC. They will crush a me-too.
  3. Preloop is the product to differentiate against, not Langfuse. Same job (govern agents), wrong UX (control plane, CEL, operator console, no shareable receipt). If we cannot explain the difference in one sentence, kill the idea.
  4. Receipts are a protocol today, not a business. Hosted, human-readable, third-party-verifiable receipts are still open.
  5. Spend control is solved for tokens, unsolved for “what the agent is allowed to do with my tools, on my keys, with a proof I can forward.”

One-sentence wedge that still holds on 18 Sep 2026:

A single URL that sits in front of an agent’s tools and model key, enforces English allow/deny/ask plus a hard dollar cap on your key, and emits a signed receipt anyone can open — without becoming your LLM vendor, your IdP, or your auditor.


URLs actually opened

First-party product / pricing / status:

Pricing numbers for Braintrust were taken from the live page https://www.braintrust.dev/pricing (search extract of that URL, 18 Sep 2026). LiteLLM Enterprise licensing detail: https://docs.litellm.ai/docs/enterprise.