One endpoint, one key Deny by default, allow on purpose The logbook already knows why Apache-2.0, engine and control plane Per agent, per traffic, never per seat One endpoint, one key Deny by default, allow on purpose The logbook already knows why Apache-2.0, engine and control plane Per agent, per traffic, never per seat
ACCESS LAYER FOR AI AGENTS

The access layer for AI agents.

They secure people using AI. We give agents their own identity: one key, one endpoint, a record of every call.

logbook · live tail
09:41:03 stripe.invoices.listallowed
09:41:04 support-agent-01 → GET /refunds/8841denied
09:41:06 notion.pages.searchallowed
09:41:09 posthog.insights.queryallowed
agent key
sk_live_a91xK4mQ7vTf2Lp8
stripe.invoices · allowed customers · allowed refunds · denied
support-agent-01: need to issue a refund for order 8841
gateway: refund tools are denied for this key. escalate to a human?
CONNECTS TO WHAT YOU ALREADY RUN
Notion Stripe PostHog Slack OpenAPI Internal endpoints
HOW IT WORKS

Live in a day,not a quarter.

01

Connect

Point Gateway at your MCP servers. Paste an OpenAPI spec for your own APIs. No credentials needed to look around.

02

Pick

Every tool starts denied. You allow the ones each agent needs. Nothing else exists for that key.

03

Scope

Save your allowed lists as named bundles. Reuse them across agents. No role tree to design first.

04

Deploy

One key, one endpoint. One line in your agent's config and traffic flows.

05

Watch

Every call lands in the logbook, full payload included. Live tail when you want to watch.

06

Adjust

Allow more, allow less, or kill the key. One click. No ticket, no redeploy.

Every agent,one door.

MCP servers, OpenAPI endpoints, internal APIs. All behind one endpoint. Each agent gets a key that only opens what you allowed.

notion · mcp stripe · mcp posthog · mcp /invoices · api internal · api one endpoint support-agent search + read tools billing-agent invoice tools only deploy-bot deploy tool only
FOR TEAMS

Ship the agentsecurity blocked.

Infrastructure to say yes. Allow exactly what each agent needs and hand security a map, not a promise.

1

Allowed lists stop over-reach

A key only opens the tools you allowed. It does not stop a stolen key from using those same tools.

2

Denied means denied

Tools you deny are blocked at the gateway, not asked nicely in a prompt. No clever prompt can talk around a 403.

3

Every call is recorded

Full payloads, 90 days by default, per-connector off switch. It shows what happened, not what might have.

access map · support-agent-01edit in place
EndpointAccessSource
stripe.invoices.listallowedMCP
notion.pages.searchallowedMCP
GET /customers/{id}allowedOpenAPI
POST /refundsdeniedOpenAPI
slack.messages.postallowedMCP
logbook · full payloadlive tail
09:12:44notion.pages.search200 · 41ms
09:12:51stripe.invoices.list200 · 88ms
03:04:12api.customers.get — key scope check403 · denied
09:13:02posthog.insights.query200 · 120ms
FOR DEVELOPERS

One endpoint,one key. That's it.

Five wired-in servers become one connector. Your agent asks tool_search for what it needs and gets back just those tools, all within its allowed list.

~55k tokens becomes ~2k

312 loaded definitions become 4. The context you save goes to the actual task.

3am

The log that explains itself

Every call, every allow, every deny. When something breaks at 3am, the logbook already knows why.

The same agent's context window, two ways illustrative example, not a measured benchmark
Five servers, wired straight in312 definitions
notion.pages.search
notion.databases.query
gdocs.documents.get
gmail.threads.list
gmail.messages.send
stripe.invoices.list
stripe.refunds.create
posthog.insights.query
posthog.events.export
+ 302 more definitions
312 definitions · ~55k tokens, before the first message
One connector, tool_search4 definitions
search_tools("send an invoice reminder")
stripe.invoices.list
GET /invoices
GET /customers/{id}
1 search tool + 3 results · ~2k tokens
OUR MODEL

Same principles,open or managed.

What
Open source
Managed
Engine + control plane
Apache‑2.0, self-hosted
We run it for you
Multiplayer, invite by email
Included
Included
Always-on token refresh + alerts
Bring your own ops
Included
SSO / SCIM, retention controls
Managed only
Included
Pricing
Free, forever
Per agent / per traffic

We never charge per person. Not on free, not on paid.