Access layer for AI agents

GIVE AGENTS
THEIR OWN KEYS

They secure people using AI. We give agents their own identity. One scope. One key. One place it all shows up.

Book a demo ~2 minutes. No credentials needed.
CONNECTS TO WHAT YOU ALREADY RUN:
MCPNotion
MCPStripe
MCPPostHog
APIYour OpenAPI spec
MCPSlack
APIYour internal endpoints
MCPNotion
MCPStripe
MCPPostHog
APIYour OpenAPI spec
MCPSlack
APIYour internal endpoints
Live in a day

HOW IT WORKS

Six moves. No roles to design first, no migration weekend.

1

Add the API

Point at your MCP servers. Paste an OpenAPI spec for anything that's yours. No credentials needed for the first look.

2

Classify

Gateway reads every endpoint and sorts it: read, write, or no undo. Unclassified calls stay locked until someone says otherwise.

3

Scope it

Pick exact scopes and save them as a bundle. No roles to invent, no permission tree to maintain.

4

Mint the key

One key per agent. It opens only the doors that bundle allows, nothing wider.

5

Proxy every call

Agent traffic runs through one endpoint. Gateway never ships a naked proxy, so nothing passes unrecorded.

6

Log and revoke

Full payloads land in the logbook, 90 days by default. Pause or kill any key in one click.

For the team shipping the agent

SHIP THE AGENT
SECURITY BLOCKED.

Security said no because nobody could say what the agent could touch. Now you can, in one sentence, before the meeting ends.

1ENDPOINT FOR ALL TRAFFIC
1KEY PER AGENT
90DLOGS, ON BY DEFAULT
0SEATS EVER BILLED
For the dev spreading it

ONE ENDPOINT.
ONE KEY. NO
3AM MYSTERY.

Wire every MCP server and every API behind one gateway. When a call fails at 3am, the logbook already knows why.

Apache-2.0, not a teaser

ALL THIS
IN THE OSS.

The engine and the control plane are both open. Nothing here is a locked upsell.

Traffic dashboard

Every agent, every call, one screen. See what's moving before someone asks.

Logbook, full payloads

90 days by default. Turn it off per connector. Live tail while you debug.

Access map

Every scope, every agent, edit in place. No spreadsheet required.

Stop levers

Pause a key, revoke it, or pause with a message. Works both directions, key or job.

Scopes and policies

Direct grants, saved as bundles. No role tree to design before you start.

tool_search

One search tool instead of every definition loaded up front. Less context, same job.

No fine print

WE KEEP IT
SIMPLE.

Same rules, OSS or managed. Nothing changes underneath you when you outgrow one and move to the other.

Apache-2.0, always
Never per seat, ever
Priced per agent, per traffic
Flat multiplayer, invite by email
Self-host it, cancel is uninstall

AGENTS NEED
ACCESS. GIVE THEM
THEIRS.

Book a 20-min demo
Or send a spec first. No credentials, nothing installed.