Roadmap

What Ceiba does today, what is being built, and what we are still weighing up. There are no dates here on purpose, we would rather say less and have it be true.

Available now

Shipped, documented, and running in production.

  • Projects and API keys

    Create projects, issue keys, and revoke, expire, or archive them. Keys are hashed at rest and can be managed from the Control Plane or programmatically.

  • Endpoint policies

    Decide per method and path which callers may reach which routes, without moving your API behind a gateway.

  • Rate limits and monthly quotas

    Per-minute rate limiting and monthly request quotas, enforced at the point of the request rather than reconciled afterwards.

  • Usage tracking

    Every authorization decision is recorded, allow or deny, with the reason. Daily and monthly views in the Control Plane.

  • Subscription-gated access

    Plan state drives real access behaviour. When a subscription lapses, enforcement follows.

  • Express and Fastify SDKs

    A thin Node SDK that sits in your own handler. Your routes, framework, and hosting stay exactly as they are.

In progress

Actively being built. Not available yet.

  • NestJS support

    A guard and module for NestJS, this way access decisions are wired like the rest of a Nest application. Not dropped in as raw middleware.

  • Per-endpoint pricing

    Attach a cost to an individual endpoint rather than only to a plan, so a single expensive route can be priced on its own terms.

  • Metered usage records

    Usage records that carry amounts, so consumption can be billed by what was actually used.

Exploring

Researched and deliberately not started. Listed so you know where we stand, not as a commitment.

  • Pay-per-request access for machine callers

    Letting a caller pay for a single request instead of holding an account. Useful for high-value, low-frequency endpoints where signing up is more friction than the call is worth.

  • Priced tools for AI agents

    Exposing a protected endpoint as a tool an agent can call, metered and enforced the same way a normal route is.

  • Spend controls for agent owners

    The other side of the same problem: budgets, approval thresholds, and an audit trail for teams whose agents can spend money.

  • Guided API productization

    Help deciding what to charge for, which plan shape fits, and what policy configuration to start from, rather than leaving that to a blank page.

Something you need that is not here, or sitting in the wrong column? contact@useceiba.com. What is available today is described in full in the documentation.