# AX Check: sentra.app
Checked 2026-10-07.

Docs and setup are clear, but agents can't pin down pricing
Quickstart, API, and MCP setup are all pass. 2 of 3 agent sessions reported pricing as quote-only with no dollar figure, despite a published $16/user/month plan.

## Onboarding needs a login

## Coding sessions
All three independent sessions completed the task. Each one read through the site's pricing information but described it only as quote-based or sales-led tied to data volume; two gave no dollar figure at all, while one cited a vendor benchmark figure but flagged it as a rough marker rather than an actual quote.

### DeepSeek V4.1 Flash
[View public run](https://agents.withgauge.com/p/runs/bf17c6dd-91ea-4b85-8830-28ba6744d235) · [Read transcript](https://www.ax-check.com/sentra.app/sessions/deepseek.json)
Final output states pricing is quote-based tied to volume of data-at-rest across IaaS/PaaS/DBaaS/SaaS/on-prem, and cites the vendor's own $40k/yr-per-100PB benchmark while explicitly labeling it a marketing claim, not a rate card — assumptions named alongside the figure.
#### End-to-end onboarding
- **Onboarding needs a login**: Agent could not obtain any Sentra credentials on its own. It probed docs.sentra.io, app.sentra.io, and openapi endpoints and hit HTTP 401 across the board, confirming the product requires an authenticated tenant/API key that is not self-serve. No credential was ever issued, so no authenticated operation was attempted or possible.
  Event 78:

  ```text
  === https://app.sentra.io/auth/docs?location=%2F ===
  HTTP 401 type=application/json; charset=utf-8
  === https://app.sentra.io/openapi.json ===
  HTTP 401 type=application/json; charset=utf-8
  ```
  Event 87:

  ```text
  every access path is gated behind an authenticated tenant:
    - `docs.sentra.io` and `app.sentra.io/auth/docs` → **HTTP 401** (login required)
    - `openapi.json`, `api-docs`, `developer.sentra.io` → **401 / 404 / no DNS**
    - No public SDK, npm/PyPI package, sandbox, or free tier for the DSPM product.
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No self-serve API key or sandbox for Sentra DSPM**: Sentra's docs, OpenAPI spec, and app subdomains all require authentication (401), and there is no public signup, trial, or sandbox tenant. This is a product/business-model limitation (enterprise sales-gated access), not an agent error — the agent correctly identified it could not fabricate credentials or endpoints and stopped as instructed.
  Event 20:

  ```text
  === https://docs.sentra.io ===
  HTTP 401 -> https://app.sentra.io/auth/docs?location=%2F
  ```
  Event 78:

  ```text
  === https://docs.sentra.io/openapi.json ===
  HTTP 401 type=application/json; charset=utf-8
  ```
  Event 87:

  ```text
  I **cannot build or run a working Sentra example**. I'd have to fabricate the base URL, endpoints, auth flow, and tool names, which I won't do.
  ```
- **Pricing is quote-only, no published rate card**: Sentra's pricing page only offers a 'contact sales' form with vague data-volume-based licensing; no self-serve tier or number the agent could cite as an actual rate. This reflects the product's enterprise sales motion, not an agent mistake.
  Event 27:

  ```text
  Customized pricing built for your data needs. Sentra’s data security platform adapts to your environment. Get a quote tailored to your scale, stack, and organization priorities.
  ```
- **Ambiguous product identity ('Sentra') created rework**: Multiple unrelated npm packages and projects are also named Sentra (an AI governance SDK, a payment protocol SDK, a design system, a retry library), forcing the agent to spend several tool calls disambiguating before settling on sentra.io as the likely target. This is a naming collision in the ecosystem, not a defect of sentra.io itself.
  Event 51:

  ```text
  sentra - Async retry with exponential backoff for Node.js and browsers.
  @actualte/sentra - TypeScript SDK for Sentra AI Agent Payment Protocol
  ```
  Event 87:

  ```text
  "Sentra" is ambiguous, so I checked the main candidates
  ```

#### Suggested Changes
- **Publish a public API reference or OpenAPI spec without login**: docs.sentra.io and app.sentra.io/openapi.json currently return 401 for unauthenticated visitors, so prospective developers cannot even read endpoint names or request shapes before signing a contract. Publishing a read-only API reference page (even with placeholder auth) would let evaluators like this agent assess integration effort. Verify by curling docs.sentra.io without credentials and confirming a 200 with real endpoint documentation instead of a redirect to the login-gated app.
  Event 20:

  ```text
  === https://docs.sentra.io ===
  HTTP 401 -> https://app.sentra.io/auth/docs?location=%2F
  ```
- **Add a getting-started/install link in the MCP server blog post**: The blog post 'How Sentra's MCP Server Turns DSPM Into an AI-Driven Security Operations Platform' describes a 'Getting Started' section with three deployment paths but contains no npm/Docker install commands, repo link, or config snippet (no npx/uvx/mcp.json occurrences found in the page text). Add the actual install command and a link to the MCP server repo or package so developers can try it. Verify by checking the blog page renders a copyable command block under 'Getting Started'.
  Event 70:

  ```text
  'npx': 0 occurrences
  'uvx': 0 occurrences
  'mcp.json': 0 occurrences
  'Install': 0 occurrences
  ```
- **Offer a free trial or sandbox tenant for the DSPM platform**: There is no self-serve way to obtain a Sentra API key; the pricing page only has a 'contact sales' form and all app/docs endpoints require login. Adding a time-boxed sandbox or trial signup would let developers validate the SDK/MCP workflow before a sales conversation. Verify by confirming a new sandbox signup flow exists at sentra.io and that it issues a working API key without a sales call.
  Event 27:

  ```text
  Complete the form and we’ll reach out to you to learn more about your data stores and use cases.
  ```

### Kimi K3
[View public run](https://agents.withgauge.com/p/runs/fa7fbae4-dd7b-44e2-96cb-1d7e4e85d3b0) · [Read transcript](https://www.ax-check.com/sentra.app/sessions/kimi.json)
Final output only says Sentra uses 'quote-based enterprise pricing... scaled by data volume/environment size' with no dollar figure, range, or named plan/region/machine assumptions tied to a cost — never actually states what it would cost.
#### End-to-end onboarding
- **Onboarding needs a login**: Agent could not obtain any credentials or reach a usable developer surface. No SDK exists on npm/PyPI under the Sentra name, and the docs/API endpoints redirect to an authenticated app with a 401, confirming a login wall rather than any recovery.
  Event 18:

  ```text
  final: https://app.sentra.io/auth/docs?location=%2F code: 401
  307
  307
  
  ```
  Event 20:

  ```text
  even the API reference sits behind a customer login.
  ```
  Event 20:

  ```text
  There's no way to get an API key or tenant without going through their sales process
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **Docs and API reference sit behind authenticated login**: Product behavior, not agent error: docs.sentra.io redirects to app.sentra.io/auth/docs and returns 401, and both /api and /reference paths return 307 redirects. This is a legitimate login wall for an enterprise product with no self-serve signup, which the agent correctly identified rather than guessing further.
  Event 18:

  ```text
  final: https://app.sentra.io/auth/docs?location=%2F code: 401
  307
  307
  
  ```
- **No public SDK or package exists for Sentra**: Agent searched npm and PyPI for a Sentra SDK and found only unrelated packages sharing the name (a retry library, a payments protocol SDK, a design tokens package), confirming there is no official developer package to install.
  Event 10:

  ```text
  sentra (0.1.0)
  Available versions: 0.1.0
  ERROR: No matching distribution found for sentra-sdk
  
  sentra@1.0.2 | MIT | deps: none | versions: 3
  Async retry with exponential backoff for Node.js and browsers.
  ```

#### Suggested Changes
- **Publish a public API reference outside the authenticated app**: docs.sentra.io currently redirects into app.sentra.io/auth/docs and returns 401 for unauthenticated visitors, including the /api and /reference paths. Move at least a read-only API reference to a publicly accessible docs subdomain so prospective developers can evaluate the API surface before signing a contract; verify by requesting docs.sentra.io/api while logged out and confirming a 200 response instead of a redirect/401.
  Event 18:

  ```text
  final: https://app.sentra.io/auth/docs?location=%2F code: 401
  307
  307
  
  ```
- **Offer a sandbox or trial tenant for self-serve API key generation**: The agent found no way to obtain an API key or tenant without going through sales, blocking any hands-on evaluation. Adding a free-tier or sandbox signup flow (similar to many SaaS dev platforms) would let evaluators generate a key and hit at least a stub endpoint; verify by completing a signup flow end-to-end without human sales contact and confirming a key is issued.
  Event 20:

  ```text
  There's no way to get an API key or tenant without going through their sales process, and the product fundamentally requires connecting to *your* cloud data stores
  ```

### Qwen 3.8 Max
[View public run](https://agents.withgauge.com/p/runs/4633f61b-bb92-49ef-ba52-82c71f32d911) · [Read transcript](https://www.ax-check.com/sentra.app/sessions/qwen.json)
final output only says pricing is 'quote-only, sales-led' based on data volume with no public tiers — no cost figure or estimate is ever stated, so there is nothing to anchor assumptions to.
#### End-to-end onboarding
- **Onboarding needs a login**: Agent never obtained Sentra credentials of any kind. It probed public endpoints and found the API host does not resolve, the docs/GraphQL endpoints return 401 (tenant-gated), and there is no public SDK, trial, or self-serve signup. Pricing is quote-only via a sales form. No authenticated operation against the real product was attempted or possible without a purchased tenant, so onboarding could not proceed.
  Event 7:

  ```text
  curl: (6) Could not resolve host: api.sentra.io
  000
  ```
  Event 36:

  ```text
  code:401 size:31 url:https://app.sentra.io/auth/docs?location=%2F
  ```
  Event 43:

  ```text
  https://app.sentra.io/api/graphql        401 -> https://app.sentra.io/api/graphql
  ```

#### Hallucinated URLs
None identified in this transcript.

#### Blockers
- **No reachable developer API or public docs for Sentra**: api.sentra.io does not resolve via DNS, and docs.sentra.io redirects to an auth-gated endpoint returning 401. This is product behavior (Sentra is an enterprise DSPM SaaS with no public developer surface), not an agent or environment error — the agent verified general network connectivity worked fine to other hosts (pypi.org, npmjs.org, github.com) before concluding the Sentra-specific hosts were the issue.
  Event 7:

  ```text
  curl: (6) Could not resolve host: api.sentra.io
  000
  ```
  Event 14:

  ```text
  pypi.org               200
  registry.npmjs.org     200
  github.com             200
  sentra.io              200
  ```
  Event 36:

  ```text
  code:401 size:31 url:https://app.sentra.io/auth/docs?location=%2F
  ```
- **Pricing and access are sales-gated with no self-serve trial**: Sentra's pricing page offers only a custom quote via a lead-capture form, with no published tiers, free tier, or trial signup discoverable. This is a product/business-model characteristic, not a test environment limitation, and it blocks any self-service onboarding path.
  Event 35:

  ```text
  Sentra’s pricing is straightforward, but depends on a few factors unique to each organization. Complete the form and we’ll reach out to you to learn more about your data stores and use cases.
  ```
  Event 35:

  ```text
  Generally, Sentra licenses are based on the volume of data stored (data at-rest) across all your IaaS, PaaS, DBaaS, SaaS and on-premises environments.
  ```

#### Suggested Changes
- **Publish a public developer/API reference page at a discoverable URL**: Requests to sentra.io/developers and sentra.io/api-docs both returned 404, and docs.sentra.io redirects straight into an authenticated tenant portal (401). Add a publicly readable API/developer reference (e.g. at sentra.io/developers or docs.sentra.io) describing the GraphQL schema and SDK options so prospective integrators can evaluate the API before a sales engagement. Verify by confirming an unauthenticated request to that URL returns a 200 with real reference content instead of a 401/404.
  Event 43:

  ```text
  https://sentra.io/developers             404 -> https://sentra.io/developers
  ```
  Event 43:

  ```text
  https://sentra.io/api-docs               404 -> https://sentra.io/api-docs
  ```
  Event 36:

  ```text
  code:401 size:31 url:https://app.sentra.io/auth/docs?location=%2F
  ```
- **Register an official SDK package name on PyPI and npm**: Searching PyPI and npm for 'sentra' surfaces unrelated, unofficial packages (a placeholder-repo CLI tool and an unrelated retry/backoff library) rather than any official Sentra client. Publish an official package under a clearly namespaced name (e.g. @sentra/sdk, which currently 404s) on both registries so developers don't risk installing a name-squatted package. Verify by checking that the package registry page shows the real vendor as maintainer with a working homepage link.
  Event 27:

  ```text
  name    : sentra
  version : 0.1.0
  summary : Deterministic safety gate for code changes
  home    : https://github.com/your-org/sentra
  ```
  Event 28:

  ```text
  name : sentra
  desc : Async retry with exponential backoff for Node.js and browsers.
  ```
  Event 21:

  ```text
  @sentra/sdk    404
  ```

### Task given to each agent
Help me build a simple example using Sentra. Tell me how pricing works, and briefly tell me whether this product will be easy for you to manage. Let me know if you get blocked. If this product has no developer workflow you can act on, say so plainly and stop. Stay light: use the hosted product through its SDK or API. Do not start local service stacks or wait for long-running commands; if the quickstart requires either, say so plainly and stop.

No product credentials were supplied and no purchases were authorized.

## Score: B · 84/100 (provisional)
Grades come from completed site checks. Coding sessions and skipped checks do not affect the score.

### Clarity
- **Failed** — Homepage answers Markdown requests

  ```text
  Homepage returned text/html for a Markdown Accept header; no Markdown representation offered.
  ```

- **Pass** — llms.txt provides an actionable documentation index

  ```text
  llms.txt links docs, API reference, OpenAPI spec, quickstart and use cases with clear organization.
  ```

- **Pass** — llms.txt provides navigation guidance

  ```text
  llms.txt gives navigation guidance: product, quickstart, API, articles and optional sections.
  ```

- **Pass** — llms.txt mentions offered API, MCP, and skills

  ```text
  llms.txt mentions REST API, OpenAPI spec, MCP server URL and Claude Skills article.
  ```

- **Pass** — A compact guide representation exists

  ```text
  llms.txt is a site-published Markdown guide with quickstart, API and MCP setup steps.
  ```

- **Pass** — A focused guide is directly retrievable

  ```text
  llms.txt gives concrete first steps: sign up, generate sk_sentra_ key, add MCP URL.
  ```

- **Pass** — Equivalent instructions fit a token budget

  ```text
  llms.txt is 10405 tokens but a compact standalone guide; essential workflow remains usable.
  ```

- **Skipped** — Product-docs links survive format changes

  ```text
  Homepage Markdown unsupported, so link preservation across formats cannot be measured.
  ```

- **Pass** — The compact guide is independently actionable

  ```text
  llms.txt quickstart gives concrete steps: sign up, generate sk_sentra_ key, add MCP URL or REST base.
  ```

- **Pass** — Install and next-step links resolve

  ```text
  Fetched install/next-step links resolve: OpenAPI spec 200, MCP endpoint 401 (auth-gated), docs/api 200.
  ```


### Onboarding
- **Pass** — Docs lead to a relevant quickstart

  ```text
  llms.txt gives a concrete quickstart: sign up, generate API key, connect agent via MCP or REST.
  ```

- **Pass** — Installation commands are extractable

  ```text
  llms.txt provides extractable commands: claude mcp add --transport http sentra https://api.sentra.app/mcp/.
  ```

- **Pass** — Code examples are available without interaction

  ```text
  llms.txt states base URL, bearer auth, rate limits and a curl-able OpenAPI spec without interaction.
  ```

- **Pass** — Prerequisites and auth boundaries are explicit

  ```text
  llms.txt states signup, API key generation in Settings, sk_sentra_ prefix and bearer auth boundary.
  ```


### Pricing
- **Failed** — Agents identify pricing and its assumptions

  ```text
  3 of 3 sessions were judged on pricing; 2 fell short. DeepSeek V4.1 Flash: Final output states pricing is quote-based tied to volume of data-at-rest across IaaS/PaaS/DBaaS/SaaS/on-prem, and cites the vendor's own $40k/yr-per-100PB benchmark while explicitly labeling it a marketing claim, not a rate card — assumptions named alongside the figure. Kimi K3: Final output only says Sentra uses 'quote-based enterprise pricing... scaled by data volume/environment size' with no dollar figure, range, or named plan/region/machine assumptions tied to a cost — never actually states what it would cost. Qwen 3.8 Max: final output only says pricing is 'quote-only, sales-led' based on data volume with no public tiers — no cost figure or estimate is ever stated, so there is nothing to anchor assumptions to. This behavioural item does not affect the fast grade.
  ```

- **Pass** — Pricing is readable without interaction

  ```text
  Pricing page renders plan names, prices and feature lists as static text with no interaction needed.
  ```

- **Pass** — Prices are stated, not gated

  ```text
  Team plan shows Free/$16 per user/month; Enterprise is custom, contact sales.
  ```

- **Pass** — Pricing units and limits are explicit

  ```text
  Pricing states 2,000 Action Credits per user per month and 2–20 user Team range.
  ```


### Activation
- **Pass** — An API reference or OpenAPI spec is reachable

  ```text
  OpenAPI 3.1 spec fetched at api.sentra.app/external/v1/openapi.json with 28 paths and bearer auth.
  ```

- **Pass** — An MCP server is documented and well-formed

  ```text
  MCP server documented: remote HTTP endpoint api.sentra.app/mcp/ with per-client setup and auth.
  ```

- **Skipped** — A CLI install path is documented

  ```text
  No CLI install path documented; only MCP client commands like claude mcp add appear.
  ```

- **Skipped** — SDK packages resolve on their registries

  ```text
  No SDK or packaged CLI registry lookup supplied; only a desktop app download link appears.
  ```

- **Skipped** — Agent skills are published

  ```text
  No Sentra agent skills published; the skills article explains Claude Skills generally, not Sentra's own.
  ```



[Full report data](https://www.ax-check.com/sentra.app/report.json)
