$HEADLESS SYSTEMS
$ cat /blog/agent-tollbooth

AI agent pricing: the seat became the entry toll

Petr Pátek··15 min·systems
AI agent pricing: the seat became the entry toll

Inside one quarter of 2026, three enterprise software vendors shipped the same new component. ServiceNow called it Action Fabric. SAP called it the Agent Gateway. Salesforce called it Headless 360.

Workday got there first and named the meter rather than the gate: Flex Credits, announced at Workday Rising in September 2025 and “available to purchase starting today.”

At ServiceNow and SAP the component is an identity-verified, permission-scoped, audited entry point for a caller that is neither a human at a screen nor a first-party integration. Salesforce shipped the programmable surface without the governance vocabulary, and Workday re-metered without building a new gate at all. The component is the story, and AI agent pricing is downstream of it. Once a machine can trigger a flow, fire an approval, or execute a business rule, the interface stops being where value is captured, and the seat stops being a coherent meter.

ServiceNow’s own announcement supplies the word for this. It describes external agents tapping “directly into secure, governed enterprise actions headlessly through our generally available Model Context Protocol (MCP) Server,” and states that “headless actions consume the same Assist currency customers already use for Now Assist and AI Agents.” A vendor pricing announcement now uses “headless” to mean machine-initiated business action. That is the shift, stated by the party with the most to lose from stating it.

Three vendors built the same gate in one quarter

On May 5, 2026, ServiceNow opened its system of action to third-party agents, and the framing was unusually direct. “We are opening the ServiceNow AI Platform and its full system of action to any AI agent, whether it’s built on ServiceNow, or, for example, with Claude, Copilot, or a customer’s own homegrown agent.”

What passes through the gate is execution, not retrieval. ServiceNow says agents can “execute governed work: flows, playbooks, approvals, catalogs,” which it calls the full system of action. It adds that “every action runs through ServiceNow AI Control Tower (AICT), so it’s identity-verified, permission-scoped, and fully auditable.” Identity, scope, and audit come first, and billing is a property of the same chokepoint.

The gate is not a separate paywall, which matters for the honest version. “The MCP Server is generally available today and included in every Now Assist and AI Native SKU, with additional features available 2H 2026.” Entry is bundled into what customers already buy. Consumption is what gets metered.

Salesforce shipped the programmable half of the same shape, under a name that says it out loud. Headless 360 makes “everything, data, workflows, and actions” reachable “via an API, MCP tool, or CLI command,” and “More than 60 new MCP tools are usable from Claude Code, Cursor, or any MCP-compatible runtime,” as Techzine documented. We wrote about that release when Salesforce went headless and ended its own UI argument.

The gate came first. AI agent pricing is what got attached to it afterwards.

What AI agent pricing meters is business action, not API calls

This is where agentic pricing models diverge from anything software has priced before. A per-request meter prices traffic. These meters price completed work. What each vendor has actually published about AI agent pricing varies far more than the shared architecture does.

VendorMachine entry pointMetered unitPublished rateSeat underneath
ServiceNowAction Fabric MCP ServerCompleted actionNone, model onlyNot published
SAPAgent GatewayNot meteredNo new pricing for endorsed routesNot applicable
SalesforceHeadless 360Agent action$0.10 per standard actionEnterprise Edition or above
WorkdayExisting subscriptionCompleted work, unit varies by agent1 to 750 Flex Credits, no dollar conversionPer-user subscription retained

Workday publishes the clearest rate card, and its Flex Credits page states the principle without hedging: “Flex Credits charge for the work AI completes on your behalf, not the number of employees in your organization.” The published consumption figures are per unit of completed work, with the unit varying by agent (Workday’s page for the first two, CIO’s breakdown for the rest):

  • Self-Service Agent, instant information retrieval: 1 credit per action
  • Self-Service Agent, autonomous task completion: 5 credits per action
  • Recruiting Agent, screening and grading a resume against a job opening: 6 credits per candidate
  • Recruiting Agent, identifying leads in existing talent pools: 750 credits per requisition
  • Contract Negotiation Agent, contract review and redlining against a playbook: 500 credits

Workday publishes no dollar-per-credit conversion, so these are credits and nothing more.

Inside the Self-Service Agent alone, autonomous task completion costs five times what an information lookup costs, a 5-to-1 spread between two actions billed in the same unit. Batch work sits in another league entirely: identifying leads across existing talent pools runs 750 credits per requisition. Neither number describes traffic, and Workday Flex Credits are calibrated to labor, which is the tell. The vendor is pricing what an employee used to do, not what a server used to serve.

Salesforce prices in the same shape. Third-party analysis of Agentforce pricing puts Flex Credits at “$500 per 100,000 Flex Credits,” a standard agent action at “20 credits ≈ $0.10,” and a voice action at “30 credits ≈ $0.15.” Compare the model it replaces: roughly “$2 each” per conversation, where a conversation is “a 24-hour session of interaction between a user (or customer) and an agent.” Moving from a session price to a per-action price shrinks the unit by roughly 20x for a simple exchange, which is the direction per-action pricing pushes: smaller units, priced closer to the work.

ServiceNow is the one vendor here with no published number. PYMNTS reports that a ServiceNow spokesperson confirmed the pricing is action-based, with customers paying according to how many operations an agent completes via the layer, and that COO Amit Zavery told The Information the company will meter and charge for that usage. No list per-action price and no Assist pool sizes are public. Anyone quoting one is quoting a guess.

The same reporting notes that JPMorgan analyst Mark Murphy described the ServiceNow charge as effectively a tax on customers using outside AI agents to interact with data they already store in ServiceNow’s apps. That is his characterization, and it is the reading the phrase agent tollbooth encodes.

SAP did not block agents, it set the same gate to route through itself

We got this wrong in June. Our earlier piece on SAP’s API policy said the June 9, 2026 enforcement technically blocks third-party AI agents from calling SAP APIs. SAP had already clarified otherwise, in a statement to The Register published on May 19, thirteen days before that piece ran. We missed it, and the correction makes the argument stronger rather than weaker.

Section 2.2.2 of SAP API Policy v4/2026 “prohibits the use of SAP APIs by AI systems that independently schedule or execute calls,” per Techzine’s reading. But SAP told The Register that the policy does not restrict third-party agents from accessing SAP, and that what it “defines is how agentic traffic should be routed, specifically through purpose-built APIs exposed via A2A through the Agent Gateway and via Model Context Protocol.” The policy also “explicitly states it does not change contractual license grants, functional entitlements, or licenses.”

Both vendors built a governed gateway with identity, routing, and audit for machine callers, and both require agents to arrive through it. The difference is one setting on the same component: ServiceNow meters what passes, SAP restricts who may pass.

SAP’s practical answer is still narrow. Techzine reports Chief Customer Officer Thomas Saueressig arguing that for agentic use cases A2A via Joule is the only route, and that the public APIs are for static applications rather than dynamic third-party AI agents. Gartner senior director analyst Christian Hestermann reads it as door-closing plus enclosure: “SAP is closing the door to third-party AI environments, especially agentic environments, but at the same time, sort of offering Anthropic Claude as something within a ‘walled garden’ of SAP.”

The commercial motive shows up in adoption numbers, with a caveat about who was counted. The DSAG Investment Survey 2026, with fewer than 100 respondents, puts Joule in production at 3% of SAP customers against Microsoft Copilot at 77% of AI-active SAP enterprises, per Techzine. SAP disputes the survey, citing 68% of Fortune 500 customers using SAP AI, a figure that does not specifically cover Joule. A gate is most attractive to the vendor whose own agent is losing, which is the same conclusion we reached about architecture rather than AI deciding the agentic ERP race.

AI agent pricing did not kill the seat, it made it the entry toll

The tempting headline for AI agent pricing is the death of per-seat pricing. The evidence does not support it.

The vendors with published rates kept the seat and bolted a meter on top. Salesforce still requires Enterprise Edition or above underneath consumption-billed Agentforce, a cost the buyer may already carry. Workday Flex Credits sit alongside the existing per-user subscription, not instead of it. The ServiceNow Action Fabric MCP Server is the exception that shows the mechanism: entry is bundled into Now Assist and AI Native SKUs, and those SKUs run on the same Assist currency, so the meter goes all the way down.

The survey most often cited for the death of per-seat pricing contains its own refutation. Cruxy surveyed 300 B2B SaaS CEOs across the UK and US, reported in April 2026. 97% said they were likely to retire seat-based pricing within two years, and 94% said seat-based pricing still reflects product value today. Both halves are real, and reporting only the first is how this story gets overstated.

Cruxy CEO Carrie Osman gives the reason for the first half: “Seat-based pricing was built for a world where humans did the work.” She adds: “AI doesn’t log in and doesn’t require a user license.”

So state the defensible version. The seat stopped being the unit of value and became the entry toll. The action became the unit of value.

Workday CTO Gabe Monroy says it on the record: “The value is no longer derived by a fixed factor, like how many employees you have.” He names the replacement in the same breath: “It’s now going to be derived by how much use are you getting out of the system.”

A seat that no longer measures value is a seat that no longer assumes a human.

Per-action billing is old, application software admitting it is new

The obvious objection: consumption metering is 20 years old and proves nothing about machine consumers. Infrastructure has billed this way since the first cloud services shipped. Lago’s survey of usage-based pricing catalogs the shape: AWS charges no flat fee and no minimum, Twilio bills per message and per minute with no seats and no base fee, and Snowflake bills per credit of compute and per terabyte stored.

Concede it. Nobody had to invent per-action pricing in 2026.

What is new is where it arrived. Metering was normal in infrastructure, which was always machine-consumed, and rare in application software, which was sold on the premise of a person logged in and clicking. Nobody ever bought a seat of S3. Everyone bought seats of Workday.

Application software is converging on infrastructure pricing because it is converging on infrastructure consumption: bursty, programmatic, unattended. That is the same movement we described as a correction rather than a collapse. Agentic pricing models are not an invention, they are enterprise applications discovering they were infrastructure all along.

Datadog picked a third setting on the same gate. Rather than block or bill, it capped its MCP server at 5,000 daily requests or 50,000 monthly, with room for exceptions, per PYMNTS citing The Information. A quota is what you ship when the caller is a machine and you do not yet know what it will cost you.

Where the meter comes off: Amazon backed out

The strongest argument against everything above is not theoretical. It already happened, in the same window.

Amazon announced SP-API developer fees in November 2025: a $1,400 annual subscription starting January 31, 2026, tiered monthly usage from $1,000 per month, and $0.40 per thousand calls in overage. It then delayed the program repeatedly and cancelled the fees outright in May 2026 after developer pushback. The fees appear never to have been billed. Amazon preserved the option in its wording, saying it will not move forward with the fees “at this time.”

That is a metered API gate on one of the largest platforms in commerce, removed in a little over six months. Any thesis that treats the agent tollbooth as inevitable has to account for it.

The account is leverage, not architecture. The party being metered could refuse, and Amazon needed third-party seller tooling more than it needed the fee revenue. A ServiceNow or SAP customer with two decades of approvals, catalogs, and business rules living inside the vendor’s platform has no equivalent option, which is why those gates hold and Amazon’s did not.

So narrow the claim. AI agent pricing is not a law of agent economics, it is a function of switching cost. The same gate gets a meter where the caller cannot leave, a quota where the vendor cannot predict its own costs, and nothing at all where the ecosystem can walk.

HubSpot shows the low-switching-cost end while still charging per outcome. Announced on April 13, 2026 and effective the next day, it moved Breeze agents to outcome pricing and cut prices doing it: Customer Agent went “from $1.00 per conversation to $0.50 per resolved conversation,” and Prospecting Agent moved “from a recurring monthly charge for every contact enrolled to $1.00 per lead recommended for outreach.” Same architecture, opposite price direction.

That separates two claims this story conflates. “Vendors are re-metering around machine action” is well supported by everything above. “Vendors are re-metering to extract more” is not, and it belongs to Murphy, not to us.

Where agent work is measurable and substitutable, the meter drives price down. Where it gates proprietary workflow nobody can rebuild, it drives price up.

The rates are announced, not settled

Deloitte named this pattern in June 2026 and defined it as tollgating: “charges imposed for accessing data that enterprises previously considered their own.” It also declines to call the outcome, noting that pricing models and data-access rules will likely evolve “as the market decides what it will tolerate.”

Analysts are actively telling buyers not to tolerate it. Forrester’s guidance to CIOs on SAP is four imperatives long:

  • “Hedge with discipline.”
  • “Negotiate with leverage.”
  • “Do not migrate.”
  • “Do not capitulate.”

It also dates the consequence: “2027 is when the bill arrives.”

The buyer-side mechanics are worse than the headline rates suggest. CIO reports that Flex Credits expire after one year with no rollover, so an aggressive pilot can burn an annual allotment early. The same article cites KPMG research putting the share of CIOs with complete visibility into their AI operating expenses at 35%. Committing to consumption pricing while two thirds of buyers cannot see their consumption is how surprise renewals happen.

Workday concedes the friction on the record. Monroy says the shift will be hard on some customers, and that “it’s incumbent on us to provide them with tools to forecast and navigate that transition effectively.” The demand forecast underneath all of it is a vendor citing an analyst inside its own pricing announcement: ServiceNow quotes IDC projecting active AI agents growing “from roughly 28.6 million in 2025 to over 2.2 billion by 2030.” Treat that as the reason a gate got built, not as a measurement of anything.

So the verifiable state of AI agent pricing is narrow. The gates exist and are generally available. One vendor publishes dollar rates, one publishes credit rates with no dollar conversion, one confirms an action-based model with no numbers, and one charges nothing new for entry but restricts who may pass. Whether any of those rates survive the 2027 renewal cycle is open.

The architectural consequence does not wait for that fight to resolve. Every vendor here independently concluded that machine callers need their own commercial unit, and three of them built a governed entry point to enforce it, distinct from the UI and distinct from the general-purpose public API. That component is where identity, scope, audit, and billing converge, which is why the useful question about a vendor is now who it permits through its API, not whether it has one.

That changes the question you ask when you buy software: not “does it have an API,” because everything does, but what the gate costs per completed action, who is permitted through it, and what the exit looks like if the rate moves at renewal. Those read like infrastructure procurement questions because that is what enterprise applications are turning into.

The seat was always a proxy. It counted how many people you employed, and it worked for as long as people were the ones doing the work. AI agent pricing is what a vendor charges once it stops pretending that is still true.