Keep your native SDK.
OpenAI, Anthropic, Google Gemini and OpenRouter. Select a provider profile, store its key on the gateway, then change your SDK base URL and gateway credential.
Configure a model provider ↗Choose a model API, an HTTP/MCP service, or the complete two-agent workflow. These are the current 0.47 entry points. Each gateway targets one fixed origin; model calls and separately executed tools need their own routes.
Gateway credentials authenticate the caller. Provider or target-service credentials stay separate. Agent identity is optional; gateway authentication is required.
OpenAI, Anthropic, Google Gemini and OpenRouter. Select a provider profile, store its key on the gateway, then change your SDK base URL and gateway credential.
Configure a model provider ↗Start the Docker fixture below, then map a fixed HTTP service or stateless remote MCP server. Set its destination credential independently. Local stdio and closed SaaS-internal calls are outside this route.
Install the 0.47 gateway ↗Run two separately scoped agents. Allow a read, mask PII, deny an unauthorized read and block deletion. The default scripted-model example needs no paid API key.
Run the two-agent workflow ↗Requires Git and Docker Compose v2. This builds from source and starts the included synthetic target. Use the provider guide above for live model APIs.
git clone https://github.com/hellocosmos/ai-security-gateway.git cd ai-security-gateway/deploy/selfhost docker compose build app docker compose run --rm app init docker compose --profile smoke up -d
Choose a unique administrator password during initialization. Open the console at http://localhost:18080; the gateway listens at http://localhost:18084. Keep these loopback defaults for local evaluation. Follow the installation guide to configure gateway credentials, target credentials, TLS ingress and real destination mappings.
Connection key, local agent key or external JWT. Register scope and choose autonomous or delegated access.
AISG quickstart ↗ · Identity boundaries ↗Fixed-origin routing, independent destination authorization and bypass prevention.
Deployment fit ↗ · Architecture ↗Policy, agent scopes, approvals and decision evidence. The source-based synthetic console is separate from the Docker profile.
Console guide ↗ · Security scope ↗Review tested clients and explicit unsupported paths. Historical version numbers belong in migration notes.
Evidence matrix ↗ · Migration history ↗Prepare model API or HTTP/MCP connections in the Docker console. Validate and stage changes, store destination credentials without redisplaying them, and restore saved revisions.
Preview local policy with synthetic JSON before applying it. Inspect component readiness and observed request outcomes. Changes become active only after an explicit stopped-stack activation and restart; gateway identity trust remains managed in the deployment file.
Docker verification covered fresh installation, allow/redact/deny requests, rejection of activation while services run, restart persistence and revision recovery. Local policy preview does not call the destination or prove agent authorization. Customer MCP qualification remains separate.
Use the 0.43 operator workspace ↗Live OpenAI gpt-4.1-mini completed the three model-to-tool scenarios with a synthetic MCP target. Official provider SDK fixtures, a real local MCP server, Docker installation and same-host inspector recovery have separate evidence.
SSE is fully buffered before delivery; immediate upstream cancellation is not guaranteed. The short local load test encountered 503 responses from 50 requests/second. Customer MCP, other live provider accounts and cross-host HA remain unqualified.
Read the qualification and measured limits ↗Compose now runs app (console, policy publisher and CLI), dataplane (gateway, inspector and evidence spool) and envoy. The data plane never reads the console database or the deployment file; it verifies each Ed25519-signed policy snapshot and keeps the last verified one on any rejection.
docker compose stop app dataplane envoy, then docker compose run --rm app activate-config, then docker compose up -d app dataplane envoy.dataplane and app; restart dataplane after rotation.state and generated volumes. Lost signing or trust keys are regenerated at the next console start.Buffered SSE waits for the complete supported response. Compare direct and gateway client first-content latency and completion time before rollout. The operator console adds process-local p50/p95 timing observations; it does not infer upstream generation time from unrelated percentiles. With multiple inspector processes, request timelines cover the gateway only.
Use the reproducible synthetic Docker benchmark to evaluate response size, concurrency, resource use and fail-closed limits. Version 0.46 offers a bounded admission wait and optional 2 or 4 supervised same-host inspector processes; neither setting provides cross-host HA. The current sample is not a real-model performance claim or a production capacity guarantee. Real provider validation from earlier versions remains separately identified.