v2026.8.1 is out. The first full release: security-reviewed, hardened, and out of beta. What's new →
Features

46 capabilities, 1 control point

Everything the gateway does, grouped and searchable. Each capability links straight to its guide in the documentation.

  • Free to run
  • Self-hosted
  • No usage limits

Threat detection & response

9 capabilities

Custom security policies

213 JSON-defined rules holding 1,100+ patterns across 15 policy packs and 8 compliance templates. Injection, path traversal, prompt injection, and jailbreaks are graded by severity, assigned per proxy, and evaluated in a deterministic priority order.

Regex engineRisk scoringReal-time block
Read the guide

Data redaction & unmasking

Mask PII, secrets, and sensitive content before it reaches the provider, then restore the original values in the response. The end user never sees the difference; the provider never sees the data.

PIISecretsRound-trip
Read the guide

MCP vulnerability scanner

Runtime security analysis of live MCP endpoints: tool-permission auditing, API-surface assessment, malicious-payload detection, and tool-schema safety analysis, all wired into the policy engine with a triage workflow.

Runtime scanAuto-blockTriage
Read the guide

MCP conformance enforcement

Requests that declare the modern spec are held to it: batches, missing or mismatched protocol headers, and versions below your pinned floor are refused with spec-correct errors, and a server prompt phishing for credentials raises an alert. Enforce or observe, per proxy.

Batch rejectionVersion pinningEnforce / observe
Read the guide

Canary token detection

A tripwire for data leakage. It detects when a canary from 1 user or session surfaces in another, using sliding-window extraction that defeats evasion, plus provider memorization and stale-canary signals.

Cross-userCross-sessionMemorization
Read the guide

Rug-pull detection

Continuously watch MCP tools and A2A AgentCards for silent changes: URL redirects, dropped skills, and capability flips. Baselines are fail-closed and severity scales with how much actually changed.

Card diffTool baselinesFail-closed
Read the guide

Traffic analysis

An always-on heuristic engine over every MCP and LLM proxy request, flagging automated scanning, attack sequences, and anomalous content patterns. Monitor-only by design, so it surfaces behaviour without blocking it.

Always onHeuristicMonitor-only
Read the guide

Session quarantine

A surgical kill switch. Block 1 user, API key, or IP without stopping the proxy or disrupting anyone else. Quarantined sessions are rejected at the earliest point in the pipeline, before any content analysis or upstream call.

Kill switchPer-userPre-analysis
Read the guide

Alerting & notifications

Send alerts where your team already watches: SIEM, SOAR, Slack, email over SMTP, and webhooks, each with its own severity threshold and delivery rules.

SIEM · SOARSlack · EmailWebhooks
Read the guide

Guardrails & testing

5 capabilities

Guardrail providers

Fan out to Groq Safeguard, EnkryptAI, DynamoAI DynamoGuard, GuardrailsAI, and Fiddler concurrently. Configure per proxy or per team, with fail-open and fail-closed modes, health checks, and a test playground.

5 providersFan-out / fan-inFail-closed
Read the guide

Guardrails evaluation

Automated penetration testing for your AI safety controls: 85 built-in cases across 14 attack categories, scored against OWASP LLM Top 10 and NIST AI RMF, including multi-turn escalation attacks. Runs are async and cancellable.

OWASPNIST AI RMFMulti-turn
Read the guide

Custom test cases

Author your own single-turn and multi-turn cases with a guided turns editor. Compliance mappings are inherited from the category, and whole suites import and export as JSON. Built-in cases stay immutable.

Turns editorJSON import/export
Read the guide

API auth playground

An in-dashboard playground for exercising proxy authentication end to end, including the full OAuth flow, so you can confirm a client will connect before you wire it up for real.

OAuth flowLive requests
Read the guide

System prompt governance

Inject security controls and behavioural guidelines into LLM requests automatically, priority-selected per proxy or user group, with template variables and full audit logging.

Priority-basedTemplated
Read the guide

Identity & access

10 capabilities

OAuth 2.1 proxy & DCR

RFC 7591 Dynamic Client Registration with RFC 8414 discovery and full PKCE. Run as an upstream pass-through or as a complete gateway authorization server. Cursor and Claude Desktop connect with no manual setup.

RFC 7591/8414/7636PKCE
Read the guide

Cryptographic agent identity

Verify the agent workload itself: SPIFFE JWT-SVIDs and X.509-SVIDs over mTLS, plus DIDs (did:key and did:web). Deny-biased per-agent tool rules, autonomy floors, and proof-of-possession step-up.

SPIFFEDIDX.509
Read the guide

Full DPoP proof verification

RFC 9449 enforced end to end. Proofs must be signed by their own embedded key, match the pinned thumbprint, bind to the live request, stay fresh within 60 seconds, and carry a single-use jti checked against a replay cache.

RFC 9449Replay cache
Read the guide

Delegation & revocation

Verifiable on-behalf-of delegation chains with a confused-deputy guard. Revoking an identity tears down its live A2A streams and SSE connections within seconds.

Delegation chainsLive revocation
Read the guide

Hybrid auth & attribution

OAuth tokens and API keys work side by side on the same proxy. Every request is attributed to a user identity, email, timestamp, and risk score.

Tokens + keysFull attribution
Read the guide

MCP tool permissions & rate limits

Tools are discovered automatically but disabled by default. A 3-tier hierarchy (user override, then group, then global) decides what each caller may invoke, with sliding-window limits keyed down to user, proxy, and tool.

Secure by default3-tier permsPer-tool limits
Read the guide

RBAC & user groups

Admin, user, and viewer roles with resource-ownership checks, plus user groups and assignment rules that map identity-provider claims onto teams, proxies, and tool permissions automatically.

3 rolesGroup rules
Read the guide

Session management

Admins can list and revoke any user's active sessions. Role changes and account disables invalidate sessions immediately, logout revokes server-side via a JTI blacklist, and per-user session caps stop unbounded growth.

JTI blacklistSession capsForced rotation
Read the guide

Custom API keys

Use your existing downstream service tokens as gateway credentials instead of managing a second set of keys, which removes the dual-authentication step from client configuration.

Bring your ownNo dual auth
Read the guide

Cross App Access (XAA)

Identity Assertion Authorization Grants let an IdP such as Okta authorize 1 app's agent to reach another app's MCP server, with single-use grants and signed, audience-bound access tokens. Verified against the xaa.dev reference implementation. Experimental

IETF draft-04Okta ID-JAGRFC 9470 step-up
Read the guide

Governance & discovery

7 capabilities

Shadow-AI discovery & inventory

A governed inventory of every AI asset the gateway sees (providers, models, MCP tools, A2A agents, skills) that auto-flags anything observed but never sanctioned, with 15-minute auto-sync and live WebSocket alerts.

In-bandIngestFingerprints
Read the guide

Enforcement, not just reporting

Move an asset to quarantined or denied and it is blocked at the proxy on its next request, whether that is an MCP tool, an LLM model, or an entire provider, via a live denylist.

Auto-quarantineLive denylist
Read the guide

Agentic Resource Discovery

Publish a standards-compliant /.well-known/ai-catalog.json and answer "what is available for this task?" through search, explore, and federation. It is the discovery layer in front of A2A, MCP, and skills.

ARD standardFederation
Read the guide

A2A agent registry

Auto-discover agents via AgentCard URLs, invoke them with streaming responses, and track stateful tasks through their lifecycle. Built on the a2a-go v2 SDK with native spec v1.0 support, and every call is scored by the policy engine.

AgentCardsSpec v1.0Task lifecycle
Read the guide

AI Security Skills Hub

A full MCP server that assistants connect to directly. Submit skill source for content-addressable approval, where any change resets the skill to pending, and report suspicious runtime behaviour back to the gateway.

MCP serverSHA-256 approval
Read the guide

Built-in MCP servers

3 MCP servers ship inside the gateway over Streamable HTTP: proxy discovery, ARD discovery, and the Skill Security Hub. All 3 answer modern 2026-07-28 clients and legacy 2024-11-05 clients alike.

Streamable HTTPDual-era
Read the guide

Agent orchestration

Compose registered A2A agents and MCP tools into multi-step flows that run behind the same policy engine, attribution, and audit trail as every other request.

Multi-stepPolicy-scored
Read the guide

Cost & observability

6 capabilities

Budget limits & cost control

Monthly USD limits per team or per API key with configurable warning thresholds. Choose to warn or hard-block at the limit, where exceeded requests receive an HTTP 402 and stop costing you money immediately.

Per-teamAuto-resetHTTP 402
Read the guide

Token usage tracking

Input and output tokens, cost, and usage patterns tracked per proxy, per model, and per key, surfaced in the AI Usage Metrics dashboard so spend is attributable rather than aggregate.

Per-modelPer-keyCost
Read the guide

Real-time monitoring

A live dashboard of request rates, error rates, and security alerts pushed over WebSocket with no polling, plus a security timeline, theme-aware charts, and a full alert status workflow.

WebSocketLive alertsTimeline
Read the guide

Observability & tracing

Send LLM traces to Langfuse, expose native Prometheus metrics, visualize in Grafana, and emit OpenTelemetry and Jaeger spans with p50, p95, and p99 percentiles.

LangfusePrometheusOTel · Jaeger
Read the guide

User attribution & activity

A user activity dashboard tying every request, alert, and blocked call back to the person and the verified agent behind it, across MCP servers and LLM APIs alike.

Per-userCross-proxy
Read the guide

Audit logging

Auth events, authorization failures, data changes, config changes, privileged admin actions, and security events are all logged and browsable in-dashboard, built for SOC 2, ISO 27001, HIPAA, and GDPR evidence.

Compliance-readyIn-dashboard
Read the guide

Operations & platform

9 capabilities

Multi-proxy management

Run unlimited MCP and LLM proxy instances side by side. Create, configure, start, stop, and restart each from 1 dashboard over HTTP, WebSocket, or SSE, with port conflicts caught at edit time.

MCP + LLMHTTP · WS · SSE
Read the guide

Dual-era MCP proxying

Proxy servers on the 2026-07-28 MCP spec and the 2024-11-05 spec side by side. A compatibility bridge lets modern clients reach legacy servers, every downgrade is alerted rather than silent, and deprecated feature use is reported before it breaks.

2026-07-28Legacy bridgeDowngrade alerts
Read the guide

Modern web interface

A Vue 3 dashboard with real-time status, an interactive alerts view, a visual policy editor, usage analytics, and full light and dark theming, responsive on desktop and mobile.

Vue 3Light / dark
Read the guide

Guided in-app tours

Built-in walkthroughs for the proxy and settings screens, so a new operator can be productive without reading the manual first.

OnboardingIn-product
Read the guide

Single binary, your network

One pre-built Go binary for Linux, macOS, and Windows, with no Docker required for the API server and no runtime to install. Configuration, alerts, and logs persist to SQLite via GORM.

Go binarySQLite37MB RSS
Read the guide

Upstream resilience

A shared upstream transport with configurable response-header timeouts and per-proxy circuit breakers, so 1 failing provider cannot take the rest of your traffic down with it.

Circuit breakersShared transport
Read the guide

External long-term storage

Replicate audit logs, alerts, and token usage to an external RDS database (PostgreSQL or MySQL) for long-term retention, via real-time, batch, or hybrid sync.

RDSPostgreSQL · MySQL
Read the guide

Automated backups & restore

Schedule database snapshots from hourly to weekly with compression and a retention cap, browse every backup, and restore in 1 click from the Settings dashboard.

ScheduledCompressionOne-click restore
Read the guide

Zero-config clients

Thanks to OAuth DCR and well-known discovery endpoints, MCP clients like Cursor IDE and Claude Desktop authenticate and start working without manual configuration.

CursorClaude Desktop
Read the guide

Run all of it on your own network

One binary, no licence key, no usage limits. Download it and point a client at it.