AgentGate
Runtime authorization, containment and audit for AI agents. Every privileged tool call is authenticated, scoped to a task, checked against deterministic policy, executed through a credential-injecting proxy and written to a keyed, hash-chained audit log.
AI proposes. Policy decides. Automation enforces. Humans approve exceptional risk. Audit records everything.
AUTHORIZED BY: POLICY · AI AUTHORIZATION: NEVER
Live gateway
Counters for the synthetic tenant Northwind, read from this server's running gateway.
Try the policy engine
Pick a request an agent might make, or edit the JSON. The simulator runs the same decision chain the gateway uses (identity → task → tool → schema → resource → sequence → destination → rate → budget → risk) without executing anything. No model is consulted.
Full demo run
Output of python -m agentgate.demo.run: five scenarios, including prompt-injection exfiltration and a runaway agent.
Design decisions worth knowing
Sequence before allowlist
Reading .env then POSTing to an allowlisted host is still blocked, and the agent is suspended with its tokens revoked.
Critical ≠ needs approval
A critical op needs an explicit per-task grant and SECURITY_ADMIN approval. Without the grant it's denied outright.
Keyed audit chain
HMAC-keyed, so someone with DB write access can't recompute a plain SHA-256 chain after tampering.
Credentials stay server-side
The proxy injects secrets at execution time and redacts them from anything the agent or the audit log sees.
API
The demo API is open at /v1/… with interactive docs at /docs. Demo auth is an X-Demo-User header; production swaps this for OIDC. State is in memory and resets when the service restarts.
| Demo user | Role | Tenant |
|---|---|---|
USR-A-VWR | VIEWER | Northwind |
USR-A-ANL | ANALYST | Northwind |
USR-A-APR | APPROVER | Northwind |
USR-A-SEC | SECURITY_ADMIN | Northwind |
USR-A-OWN | OWNER | Northwind |
USR-B-SEC | SECURITY_ADMIN | Contoso |
