One endpoint, one key The logbook already knows why Apache-2.0, engine and control plane Per agent, per traffic, never per seat One endpoint, one key The logbook already knows why Apache-2.0, engine and control plane Per agent, per traffic, never per seat
ACCESS LAYER FOR AI AGENTS

The access layer for AI agents.

They secure people using AI. We give agents their own identity: one key, one endpoint, a record of every call.

logbook · live tail
09:41:03 stripe.invoices.listscope PASS
09:41:04 support-agent-01 → GET /refunds/884112ms
09:41:06 notion.pages.searchscope PASS
09:41:09 posthog.insights.queryscope PASS
agent key
sk_live_a91xK4mQ7vTf2Lp8
invoices:read customers:read refunds:never
support-agent-01: need to issue a refund for order 8841
gateway: refunds are hard-never for this key. escalate to a human?
CONNECTS TO WHAT YOU ALREADY RUN
Notion Stripe PostHog Slack OpenAPI Internal endpoints
HOW IT WORKS

Live in a day,not a quarter.

01

Connect

Add your MCP servers. Paste an OpenAPI spec for anything that's yours. No credentials needed for the first look.

02

Classify

Gateway reads every endpoint and sorts it: read, write, and the calls with no undo.

03

Scope

Build a key from scopes and policies, not roles. Widen it later; nothing is locked in.

04

Deploy

One key, one endpoint. Swap it into your agent's config in a single line.

05

Watch

Every call lands in the logbook with the full payload. Live tail if you want to watch it happen.

06

Adjust

Widen, narrow, or pull a key in one move. Nothing waits on a ticket or a redeploy.

Every agent,one door.

MCP servers, your OpenAPI endpoints, internal APIs. Gateway puts all of it behind a single scoped key per agent.

notion · mcp stripe · mcp posthog · mcp /invoices · api internal · api one endpoint
FOR TEAMS

Ship the agentsecurity blocked.

Infrastructure to say yes. Scope the key, not the whole API, and hand security a map instead of a promise.

1

Scopes stop over-reach

A key opens only the endpoints its job needs. It does not stop a compromised credential from acting within that scope.

2

Hard nevers stay hard

Calls you mark as no-undo are blocked at the gateway, not just discouraged in a prompt. No prompt can talk around them.

3

Every call is recorded

The logbook holds full payloads by default, 90 days, per-connector off switch. It shows what happened, not what might have.

access map · support-agent-01edit in place
EndpointAccessSource
stripe.invoices.listreadMCP
notion.pages.searchreadMCP
GET /customers/{id}readOpenAPI
POST /refundsneverOpenAPI
slack.messages.postwriteMCP
logbook · full payloadlive tail
09:12:44notion.pages.search200 · 41ms
09:12:51stripe.invoices.list200 · 88ms
03:04:12api.customers.get — key scope check403 · denied
09:13:02posthog.insights.query200 · 120ms
FOR DEVELOPERS

One endpoint,one key. That's it.

Swap five wired-in servers for one connector. Point tool_search at your org and it returns the three tools that match, already scoped.

~55k → ~2k tokens up front

312 loaded definitions become 4. The context you save is context your agent spends on the actual task.

3am

The log that explains itself

Every call, every scope check, every denial. When something breaks at 3am, the logbook already knows why.

OUR MODEL

Same principles,open or managed.

What
Open source
Managed
Engine + control plane
Apache‑2.0, self-hosted
We run it for you
Multiplayer, invite by email
Included
Included
Always-on token refresh + alerts
Bring your own ops
Included
SSO / SCIM, retention controls
Not built for this
Included
Pricing
Free, forever
Per agent / per traffic

Humans are never the metering axis. Not on the free plan, not on the paid one.

Give your agents their own identity.