Kaiten is the open-source control plane for B2B SaaS: one model for what each customer bought, what they can use and what runs for them — licenses, entitlements, feature flags and releases. Self-host it, or join the private beta of Kaiten Cloud.
Apache 2.0 ·OpenFeature over OFREP ·MCP server for agents ·Self-hosted or Cloud
THE GAP
Three systems, one customer, no agreement.
Every B2B SaaS that sells to enterprises ends up running three systems that do not talk: the deal in a CRM, the switches in a flag tool, the deployment in a pipeline. Nothing holds them to the same answer.
WHAT WAS SOLD
The CRM
Plans, seats, custom clauses, the discount that closed the deal. Readable by humans, enforceable by nobody.
WHAT'S SWITCHED ON
The flag tool
It knows cohorts and percentages. It has never heard of a contract, so somebody ANDs two systems in application code.
WHAT'S RUNNING
The pipeline
It ships versions to clusters. Which customer is on which release lives in a spreadsheet, and the spreadsheet is wrong.
THE COST OF THE GAP
Glue code nobody owns, access nobody paid for, and an incident call where three engineers reconstruct what the customer bought.
THE CONTROL PLANE
One plane in the middle. Everything else keeps its job.
Your CRM still closes deals. Your billing engine still invoices. Your pipeline still deploys. Kaiten holds the one answer they need to agree on: what each customer bought, can use and runs.
Billing & Invoicing
Where subscription and usage state originate.
StripeLago
CRM & Business APIs
Where deals and customer context live.
HubSpotSalesforceAttio
Kaiten Control Plane
Business-to-Infrastructure State Controller
Licenses & Entitlements
Holds what each customer bought, and meters usage against it: a report past the allowance is refused on the server.
OpenFeature Engine
Evaluates flags over OFREP, with rules that read the license, the usage and the zone, and progressive rollouts.
Transactional Orchestration
Records releases, zones and deployments, and commits every change as an event, in the same transaction.
Kaiten Console & Admin APIREST · OFREP · MCP
DevSecOps Platform
Pipelines that deploy, then report what runs where.
GitHubGitLabAzure DevOps
Customer Instance
Evaluated server-side, cached in the SDK.
OpenFeatureEntitlementsGo, TS, Python
Billing & Invoicing
CRM & Business APIs
Kaiten Control PlaneBusiness-to-Infrastructure State Controller
Licenses & Entitlements
OpenFeature Engine
Transactional Orchestration
Kaiten Console & Admin APIREST · OFREP · MCP
DevSecOps Platform
Customer Instance
Kaiten Control Plane
Business-to-Infrastructure State Controller
Licenses & Entitlements
Holds what each customer bought, and meters usage against it: a report past the allowance is refused on the server.
OpenFeature Engine
Evaluates flags over OFREP, with rules that read the license, the usage and the zone, and progressive rollouts.
Transactional Orchestration
Records releases, zones and deployments, and commits every change as an event, in the same transaction.
Kaiten Console & Admin APIREST · OFREP · MCP
Billing & Invoicing
Where subscription and usage state originate.
StripeLago
CRM & Business APIs
Where deals and customer context live.
HubSpotSalesforceAttio
DevSecOps Platform
Pipelines that deploy, then report what runs where.
GitHubGitLabAzure DevOps
Customer Instance
Evaluated server-side, cached in the SDK.
OpenFeatureEntitlementsGo, TS, Python
WHO IT IS FOR
One model. Every team that touches the customer.
Engineering wires Kaiten in once; product, sales and customer success read the same answer. Pick a team to see what it stops doing by hand.
Developer / SDK Integrator
Integrate once. Read the contract everywhere.
“Report usage, evaluate flags, receive events — without wrestling the integration.”
The person who wires Kaiten into the SaaS. Flags evaluate through the OpenFeature SDK you already use, usage goes through one call, and every change comes back as a typed event. Types generated from your catalog and React components are on the roadmap.
Today
Plans hard-coded as if statements across the codebase
A flag tool and a billing tool that each hold half the answer
Every new plan means a code change and a deploy
With Kaiten
OpenFeature-standard evaluation: the app never couples to a vendor SDK
One call reports usage; past the limit, a 409 the SDKs surface as a typed error
Typed clients for Go, TypeScript and Python, generated from the OpenAPI contract
/integrations/webhooks
What Dev ships with
Feature Flags over OFREP
Usage Reporting
Go, TypeScript & Python SDKs
Event Stream & Webhooks
MCP Server
Service Accounts & Tokens
DevOps / Platform Engineer
The record your pipelines report to.
“Know what runs for every customer — from the CI/CD I already run.”
Kaiten deploys nothing; your pipelines do. They report the release each zone runs through the API, with a scoped token, and every change becomes an event and an audit entry — so which customer runs which release is a query, not a spreadsheet. The CLI and a read-only Kubernetes operator are on the roadmap.
Today
No link between the CI/CD pipelines and the record of what runs where
Which customer runs which version lives in a spreadsheet
Correlating a version, an instance and an incident is manual work
With Kaiten
Components, immutable releases and deployment zones, recorded as your pipelines report them
A rollback is a new entry in the deployment log; a retried report records nothing
Scoped, revocable service-account tokens for your CI
/releases/deployment-zones/production-eu
What DevOps ships with
Releases, Zones & Deployments
Instance Health
Service Accounts & Tokens
Event Stream & Webhooks
Audit Trail
SaaS Product Manager
Ship to the right customers.
“Which customers get which features, on which release?”
Packaging and rollouts without a ticket: licenses carry the entitlements, flags read the license and the usage, and releases are recorded per zone. Adoption analytics and the feature lifecycle are on the roadmap.
Today
Every packaging change waits on an engineering sprint
Flags, licenses and usage live in three tools only a BI pipeline can join
Releases ship with no link to the customers who get them
With Kaiten
Licenses, entitlements and flags defined in the console, versioned and audited
Progressive rollouts by plan, usage or zone, with CEL targeting rules
Quota consumption per customer, in the console
/feature-flags/beta-access/targeting
What Product ships with
Feature Flags & Rollouts
Licenses & Entitlements
Usage & Quotas
Releases & Zones
Audit Trail
Sales / RevOps Analyst
Consumption you can price.
“Who consumes the most, who is hitting their limits — and how do we adapt the offer?”
What each customer bought and what they consume, in one model: licenses and the entitlements they grant, usage against each limit, and a typed event every time a customer crosses one. Vouchers, add-ons and native billing with Stripe and Lago are on the roadmap.
Today
Usage lives in product tools, revenue in the CRM — the join is manual
Limit-reached moments, the best upsell signal, go unnoticed
Custom offers wait on an engineering sprint
With Kaiten
Usage against every limit, per customer and per window
An event when a customer reaches a warning threshold or the limit, or goes past it
A custom deal as its own license version, without a code branch
/customers/instances/acme-production/entitlements
What Sales & RevOps ships with
Licenses & Packaging
Entitlements & Quotas
Threshold Events
AI Credits
Account Manager — Customer Success
Every customer’s contract, in one view.
“What does this customer run, under which license — and are they close to a limit?”
The console shows each customer’s instances, license and usage against every limit, and the audit trail answers “what changed?” without asking engineering. Customer 360, activity alerts and CRM sync are on the roadmap.
Today
Quota and expiry problems arrive as support tickets
Answering “what does this customer run?” means asking engineering
The contract lives in the CRM, the usage somewhere else
With Kaiten
Each customer’s instances, license version and dates in one place
Usage against every limit, per customer, in the console
An audit history shared with Ops: who changed what, and when
/customers/acme-corp
What Account Manager ships with
Customers & Instances
Licenses & Packaging
Usage & Quotas
Audit Trail
ONE DATA MODEL
One data model. Four pillars.
Every customer, license, flag and release in one queryable graph, behind one API. Kaiten does not replace your billing engine or your CRM — it gives them one answer to agree on.
LICENSING & MONETIZATION
Every plan, as a versioned license.
A license is a numbered version of a product, with the entitlements it grants. Publish a new version and customers stay on theirs until you move them. Add-ons, prices and vouchers are on the roadmap.
On/off features, quotas, AI credits and configuration, with usage windows from an hour to a year. Past the allowance, a usage report is refused with a 409.
OpenFeature over OFREP, with CEL targeting rules that read the customer’s license, recorded usage and deployment zone. Progressive rollouts and a kill switch.
Kaiten Edge, which will enforce the same contract inside air-gapped sites, is in private preview, by invitation. About Kaiten Edge →
HOW IT WORKS
Kaiten decides. Your code and pipelines act.
Four moments, and where each one is enforced. Kaiten never touches your clusters: it keeps the record, and your pipelines do the work.
01
A flag resolves on the server
Any OpenFeature SDK calls one OFREP endpoint. When the targeting key names the customer, Kaiten reads their license, usage and zone itself, and evaluates the rules against them — not against what the caller claims.
OFREP · SERVER-SIDE
02
Usage meets its limit
Each report is folded into the current window, or refused with a 409 past the allowance. Crossing the warning threshold, the limit or the allowance emits a typed event.
409 PAST THE ALLOWANCE
03
Every change becomes an event
Each write commits its event in the same transaction. On Kaiten Cloud it reaches your endpoints as a signed webhook; self-hosted, it is on the event stream you run. Point it at Argo CD, Flux, GitHub Actions or Slack.
SIGNED WEBHOOK · EVENT STREAM
04
Your pipeline reports back
When a rollout finishes, your CI records the release a zone now runs, through the API. The console shows what your pipelines reported.
REST API
IN YOUR CODE
A standard protocol, not a proprietary client.
Kaiten speaks OpenFeature over OFREP, so leaving does not mean rewriting your codebase. Where a typed client helps — reporting usage, reading a license — there is one for Go, one for TypeScript and one for Python.
A bearer token and a base URL. The Core API and the Platform API are two listeners with two credential families: the Go and Python SDKs give each its own client, and the TypeScript packages speak the Core API only.
Java, .NET, Ruby: no Kaiten package, and none needed for flag evaluation — OpenFeature publishes an OFREP provider for each.
OPEN SOURCE
Your revenue gates should never be a black box.
The engine is open source under Apache 2.0 — the full control plane, the console, the event pipeline and the MCP server — and so are the SDKs and the CLI. Audit it, fork it, run it — if we disappear, your SaaS keeps working.
✓No billing provider, and no usage reported to us — console sign-in is the one hosted service it needs today
✓The hosted offer lives in a separate repository and calls the same public API you do
✓Go’s internal-package rule keeps the hosted layer out of the engine’s internals