Genspark’s AI agent builder: API access, custom agents, pricing, and safety

Aayushi Upadhyay Aayushi Upadhyay · Sep 2, 2026 · 16 min read · In-depth guide
Genspark’s AI agent builder: API access, custom agents, pricing, and safety

key takeaways

  • Genspark offers an AI agent builder called Custom Agent, with which you can create a reusable AI agent from a single prompt without any coding. You can also request API access it is available on paid plans.
  • The subscriptions begin with Free ($0), Plus (roughly $20-25/month), Pro (approximately $200-250/month), and Team ($30 per seat per month for 2-150 users), and Enterprise (custom pricing on top of the previous plans).
  • Genspark is a product of MainFunc Inc., a company established in 2023 with its headquarters in Palo Alto, CA, and a valuation of $645 million raised and a $2.6 billion valuation as of mid-2026
  • MainFunc promises in its privacy policy that it will not use the data for training and improving its  own AI models beyond fulfilling your request and is SOC 2 Type II and ISO 27001 certified for Team/Enterprise.
  • The real danger is that you give too much access to Genspark’s custom agents, API, and Super Agent browser, which is a risk with any agentic AI at present.

Introduction

Genspark’s agent builder allows you to describe an agent in natural language and generates it for you, ready to use in minutes, with no coding skills required. But once an agent has access to your accounts, convenience becomes secondary to two questions: what does it cost, and what can it access?

A founder is unlikely to give a card number to a software that, prior to the moment of purchase, had only been able to access a Google Drive, an email account, or a Slack team. While most reviews focus on  the speed of slide creation and comparisons with Perplexity, very few explore  the practical implications  of the permissions and whether the tool’s capabilities justify the level of risk.

Agentic AI applications do not simply provide information; they perform actions  within the user  account. The implications of this capability are considerably more significant than in the case of a chatbot. Security researchers at Zenity, an independent auditing company, have determined that agentic browsers  circumvent the same-origin policy that prevents websites from sharing or accessing each other’s data. This article will discuss the tangible differences in the permissions and data practices of Genspark’s agent builder, API, subscription views, and the implications for data security.

What “is Genspark safe” actually looks like operationally

Tuesday, 9:40 am. A four-person agency’s operations manager loads Genspark’s new Super Agent with her shared Google Drive and Gmail so that it can automatically find her team’s last quarter’s reports for clients and prepare a renewal reminder email. She skips ahead to the next  task after a brief OAuth consent screen.

Three things just happened that nobody in the room discussed:

  1. Genspark’s Super agent now has authorized access to that inbox and drive for this purpose.
  2. This access is embedded within the agency’s plan a free or personal plan may not have the same contractual data control as a team or enterprise plan
  3. No one was assigned ownership of reviewing or revoking that access later. It is simply a part of the stack.

This is the actual violation scenario that none of Genspark’s clients negotiated with their providers. It’s not about third-party data abuse but the permission inflation during the onboarding that rarely gets audited. And the “bad actor” here is not Genspark but the lack of the access review policy that would have been triggered had the initial setup taken more than five minutes.

Genspark’s AI agent builder, API, and custom agents explained

Genspark’s agent builder is called Custom Agent. You describe what you want in plain language, and it produces a reusable agent with no coding. Once you’ve built an agent, you can call it again by @mentioning it inside Genspark or publish it to the public Custom Agent Store for others to install.

The Custom Agent Store is worth noting. An agent someone else built and shared contains whatever instructions and connections its creator defined. Importing a community agent means trusting that person’s judgment, not just Genspark’s.

API access is available on paid tiers for developers who want to bind Genspark’s agents into their own custom workflows and internal tools, rather than worksolely inside Genspark’s interface. The Team plan supports 2 to 150 users, more than 70 underlying models including ChatGPT, Claude, and Gemini, and is SOC 2 Type II and ISO 27001 certified at that tier.

The Super Agent powers all of the above: Genspark’s original multi-step task engine. Give it one instruction (research competitors, build a slide deck, join a meeting and summarize it) and it will chain together the appropriate tasks across multiple AI models (web browsing, document creation,  application  integrations) with no manual chaining required. The desktop product, Claw, takes this further with computer-use automation: it can operate on files and applications locally, not just web pages.

Data privacy specifics what happens to your inputs

Before connecting Genspark to the company’s data, it is essential to comprehend where one’s inputs go. The following flowchart illustrates the process, as well as the privacy features that the service provides.

Genspark data privacy flow showing how user inputs are processed through third-party AI models and returned, with notes on Google Workspace, Stripe, data use, and paid-tier protections.
How Genspark handles your data: from your initial input through third-party AI models and back to you, with the key privacy controls called out.

Genspark subscription pricing and features compared

Genspark offers five plans: Free, Plus, Pro, Team, and Enterprise. Below is a description of what each of  them entails. The third-party source’s information may differ slightly in the listed prices due to ongoing promotions through 2026 double-check the pricing on the company’s website before finalizing a purchase decision.

PlanCostCreditsWhat you getStorage / team details
Free$0100 credits/dayBasic access with standard features; account reverts to Free after a paid plan endsIndividual plan
PlusMultiple paid tiersStarts at 10,000 credits/monthAll latest SOTA text, image, video and audio models; full access to AI Slides, Genspark Code and more agents; unlimited core chat and image creation at zero credit cost; commercial use50 GB AI Drive
ProMultiple paid tiersStarts at 125,000 credits/monthEverything in Plus, plus professional-level resources and access to all latest SOTA models; unlimited core chat and image creation at zero credit cost; exclusive access to select premium image models1 TB AI Drive
Team$30/seat/month12,000 credits/month per seatFull access to Genspark agents, latest video/audio models, unlimited top-tier chat and image generation at zero credit cost through Dec. 31, 2026; centralized billing/admin, usage analytics, SSO/SAML and connector management2–150 users; 60 GB AI Drive per seat
EnterpriseCustom pricing25,000 credits/month per seatFull access to Genspark agents and models, dedicated support, SLA, advanced governance, agent-level permissions, custom DPA and configurable data residency151+ users; custom storage

The security-focused protections SOC 2, ISO 27001, administrative control of connected agents are  not available until Team. That’s the pattern to watch in this features comparison, not the credits.

If you are trialing the agent builder on Free or Plus and planning to connect any sensitive data later,  then the Team upgrade is the level where practical governance controls exist. If your budget is the  current limiting factor, it’s worth considering what a free AI automation tool could support before  spending on capacity you won’t use.

Who’s actually behind Genspark

Genspark is built by MainFunc Inc., a venture-backed startup founded in 2023 and based in Palo Alto, California. For a skeptical founder, that backing is often a better safety signal than the privacy policy itself it tells you whether the vendor is likely to still exist, and be accountable, in eighteen months.

The company closed a $275 million Series B round in November 2025 at a $1.25 billion valuation, backed by Emergence Capital, SBI Investment, LG Technology Ventures, UpHonest Capital, and Pavilion Capital, a subsidiary of Singapore’s state-owned investor Temasek. By mid-2026, total funding reached $645 million at a $2.6 billion valuation.

Leadership has real track records. CEO Eric Jing previously built an early voice assistant at Microsoft valued at over $5 billion. COO Wen Sang holds an MIT PhD and previously built and sold an enterprise software company backed by Y Combinator and Khosla Ventures.

That’s a well-capitalized company with named leadership and institutional investors who did due diligence before writing checks. It’s not a two-person side project with an anonymous team the profile that should actually worry you. We’ve covered that failure mode before in our breakdown of AI tools that quietly changed direction or shut down. The risk with under-resourced tools usually isn’t malice, it’s abandonment, and abandonment with your data still connected is its own headache the way it played out with Articoolo. Genspark’s funding profile doesn’t guarantee good behavior, but it does lower the odds of the tool simply disappearing.

Genspark
AI Automation

Genspark

4.8
Freemium — Free

Genspark is an AI workspace built around autonomous agents that can research, create content, analyze data, build slides, write code, make calls, and handle multi-step workflows. Its Super Agent can coordinate different models and tools so you can describe the outcome instead of manually chaining AI tools.

Where people get nervous and whether it’s warranted

On the contrary, the underlying concern with “is Genspark safe” is not a generic criticism of the  provider. The fear is justified by the potential  for abuse inherent in an agent with complete  permissions through a browser, which can traverse accounts  and click on anything.

In its independent security analysis of Genspark’s browser-based Super Agent, the company found several concerning gaps, including deficient data classification and no safeguards for monitoring sensitive data transfers. It also discovered there are no independently published security auditing for Genspark’s  browser products, despite the Team and Enterprise plans carrying formal SOC 2 and ISO 27001 certification at the platform level. The same study identified that Genspark’s architecture has  connections to over 700 third-party integrations, increasing the attack surface for potential threats.

In general, cybersecurity researchers speaking to TechCrunch say that the danger posed by AI  browsers  to privacy is greater than traditional browsers do, if designed without sufficient  precautions.  They can be coerced into revealing emails and logins or make unwanted purchases or posts. Brave  Security  researchers have identified indirect prompt injection as a systemic vulnerability for  the whole  category of AI-powered browsers rather than a specific problem with Genspark. Every agentic browser, including Genspark’s Claw, is vulnerable to the issue.

Pause and think: if a genspark agent acting for you had a malicious instruction embedded in an email or a web page, would someone on your team know before it was too late? if the honest answer is no, the problem is not genspark. it’s that no one is watching what the agent is doing once it is deployed.

Wrong approach vs right approach

WRONG APPROACH
      ↓
Broad access
      ↓
One-time privacy check
      ↓
Assume funding = safe
      ↓
Everyone gets access
      ↓
React after a breach
      │
      ▼
────────────────────────────
        FIX THE SYSTEM
────────────────────────────
      │
      ▼
Narrow account access
      ↓
Re-check terms
      ↓
Assess data risk
      ↓
Assign an access owner
      ↓
Monitor continuously
      │
      ▼
RIGHT APPROACH

Tools that actually help you vet this properly

Most “is it safe” questions end up being answered by instincts. These tools take that instinct out and replace it with a process for Genspark and for whichever agentic tool your team ends up using

What each tool helps you check

1. Vanta

Problem solved: Founders aren’t going to double check that a vendor has that SOC 2 or ISO 27001  certification when they say they do, and this is where it comes in handy. You can use it to track your own compliance posture and have a baseline to check off against when a vendor provides this information to you before connecting their tool to your data.

Vanta
Enterprise

Vanta

4.7
Paid — Custom pricing

Vanta is a trust management platform for security, compliance, risk, and privacy programs. It automates evidence collection, monitoring, access reviews, vendor risk workflows, questionnaires, and other repetitive compliance work, with AI features integrated throughout the platform.

2. Nudge Security

Problem solved: Teams are connecting tools to their accounts so fast that it’s  hard to keep up and create visibility. This is where it comes in. It helps you know which SaaS and AI tools your teams are connecting to their accounts, including those you may not have approved. It’s critical to have visibility into what tools are being used to grant access to company data, and that’s why it matters.

Nudge Security
Enterprise

Nudge Security

4.6
Paid — $750/month billed annually for up to 150 users

Nudge Security is a SaaS and AI security platform designed to discover applications, accounts, identities, integrations, and AI usage across an organization. It combines continuous discovery with security posture monitoring, risk intelligence, governance workflows, and automated security nudges.

3. LayerX

Problem solved: Traditional tools such as AVs and firewalls simply do not see inside what an AI agent is doing while it is inside a browser session. It monitors the behavior of an AI agent inside a  browser  and understands when it is performing sensitive activities based on the data. This is one of the most critical layers to monitor agentic browsers as most teams do not have it today.

LayerX
Enterprise

LayerX

4.6
Paid — Custom pricing, priced per user per year

LayerX is an AI interaction security and browser security platform that provides visibility and enforcement across AI tools, browsers, applications, and IDEs. It focuses on risks including GenAI data leakage, shadow AI, browser threats, risky extensions, SaaS exposure, and web-based attacks.

4. Cerby

Problem solved: Many applications such as AI tools that are early in their  journey do  not rely on SSO for identity access and instead have a separate sign-in process. It consolidates those tools which have not been governed by identity standards and  policies to be seen and managed the same way as the rest of your SaaS tools. A tool such as Genspark could have been informally adopted and connected to your data by one team member and not reported back to governance which is why it matters.

Cerby
Enterprise

Cerby

4.6
Paid — Subscription

Cerby is an identity automation platform designed to secure and automate disconnected applications that lack modern identity standards such as SAML, SCIM, OIDC, or usable APIs. It extends existing IAM, IGA, and PAM systems with credential management, SSO, MFA, lifecycle automation, privileged access controls, and agentic AI-powered integration capabilities.

Operator opinion: Vanta and Nudge Security are quick to deploy and provide value to a small team within a week. LayerX is the most technically intensive of the four and should only be considered when there are more than a handful of agentic tools being used likely not by a solo founder trying out  Genspark. Cerby is focused on larger organizations with tens of people trying to manage app sprawl.  A two-person team should stick to a shared spreadsheet of connected apps and avoid Cerby at this stage. None of these tools can replace the domain expertise of a person who has primary responsibility for their organization’s AI tool access governance. They make that person’s job feasible.

Self-audit checklist before you connect Genspark to anything

  • Have you reviewed the current privacy terms of your specific plan tier (and not just the policy page)?
  • Does the account being connected (email, drive, CRM) contain customer or regulated data?
  • Is there an explicitly named person who will need to review it within 90 days?
  • Have you scoped the integration to the minimum access needed, or have you accepted the default all-access permissions?
  • Would you be comfortable telling a client what this connection does and why it’s there?

If you had cause to pause and think about any of these, you’ve found the right place  to stop and ask questions long before the review cycle on a comparison site.

Verdict and who should still be cautious

Genspark is an established and well-maintained product, with documented security certifications on its paying tiers. Its privacy policy explicitly confirms that customer data is not used to train its underlying models beyond the task requested. This is a materially different risk profile to an anonymous browser extension or unfunded side-project tool: exactly the concern we raised in pieces like is Cliptalk real, what does it actually do and is Mintlify worth it, where the first question is always about whether the product under review even exists in the form its marketing implies.

To separate out safety and reliability from the above, the product’s aggregated Trustpilot score is low  mainly due to complaints over credits being consumed on failed or incomplete tasks: a  product and  billing support issue, not one of data-handling. This should factor into the overall value proposition calculation for a subscription, independent of the trust question this piece seeks to answer.

The agentic permission layer presents the sort of risk we see with any agent at present: it’s a category risk across the AI browser space and not specific to this vendor. If you’re handling regulated client data,  operating a heavily agency-facing service business, or otherwise bound by an NDA, scope access narrowly and have someone in charge of reviewing it. If you’re a solo founder using the tool for internal drafting and research with nothing sensitive connected, the risk is lower. This pattern repeats across most of the “is it safe” questions we’ve pursued, including in our Tools Arena review: the tool is rarely the danger. The absence of a review process is the problem.

FAQ

Can I edit or delete a custom agent that I created?

You can. Genspark’s own documentation explains editing a custom agent by adjusting  the  configuration over chat or manually, testing the changes, and saving the updated version. The documentation also mentions deleting an agent, but refers to deletion is irreversible and final action – there is no option to restore a deleted agent.

Is API access billed separately from a Genspark subscription?

Not applicable. According to Genspark’s official pricing page, API access does not have separate billing tiers – instead, it is utilized within the main credits allotment. In other words, using the API will consume the same credits as interacting with Genspark in other ways.

Is Genspark GDPR compliant for EU customers?

According to Genspark’s official GDPR documentation, they are GDPR compliant in terms of processing personal data of EU residents. Nevertheless, that statement appears to be marketing language – for specifics on how customer data is processed, consult the data processing agreement for your specific billing plan, not the general documentation.

What’s Genspark’s reputation like on independent review sites?

Somewhat controversial, but not in a bad way. According to Trustpilot’s review  aggregator,  Genspark holds between 1.5 and 1.9 stars across approximately 112 reviews. The most common complaints regard billing issues such as being charged for failed requests, but these represent a product quality issue rather than a security concern – therefore, a  questionable  reliability rather than a privacy or security risk.

Where this goes next

Agentic AI tools will continue to demand more access, not less, that is their entire value proposition. The founders who get burned in the next eighteen months will not be the ones who chose wrong AI tools,  but the ones who did not build a process for reviewing every tool, safe or not, and what it’s allowed to touch. If your business cannot currently answer ‘what does every AI tool connected to our accounts actually have access to right now’ that is the question worth sitting with, not whether Genspark specifically passed a trust test.

Your next move

Open the Google account permissions or app integrations page right this second and look at exactly  what is connected to Genspark or otherwise currently. Anything you can’t readily identify or explain  it to me in one sentence should be revoked as soon as possible. One man’s ten-minute audit will see more risk than any review article, including this one.

Share this playbook:
Aayushi Upadhyay
Written by

Aayushi Upadhyay

AI Content Strategist at Aadhunik AI. I write about why most AI systems fail and how to build ones that actually drive results.