Point your client here.
Change the API base URL or remote MCP URL. Authenticate gateway access and configure the destination credential separately.
API base_url https://gateway.example.com MCP URL https://gateway.example.com/mcp
Least Privilege, Least Agency.
Least privilege limits access.
Least agency bounds autonomous action.
Open-source AI Security Gateway for model APIs, HTTP services, and MCP tools. Complement existing IAM and destination permissions with action and data policies.
Control supported calls routed through TrapDefense. Add agent identity for per-agent scopes, delegation and approval controls.
Start with a Docker deployment and a mapped destination. Connect your client, add agent identity when needed, and verify the decision before expanding coverage.
Change the API base URL or remote MCP URL. Authenticate gateway access and configure the destination credential separately.
API base_url https://gateway.example.com MCP URL https://gateway.example.com/mcp
Issue an expiring local agent credential, or map a verified JWT from your existing IAM. User delegation is optional for explicitly authorized autonomous agents.
Authorization: Bearer <agent-credential>
Allow a read. Block a delete. Redact protected data. Review a high-risk request, then authorize one matching execution. Inspect the decision evidence.
Choose a connection guide ↗One fixed provider or destination per installation. Native model profiles support text, function calls, and buffered SSE; generic HTTP/MCP routes remain bounded and stateless. Customer network controls must prevent bypass.
The console and the enforcing data plane now run as separate services. Policy reaches the data plane only as an Ed25519-signed snapshot, and evidence returns through an append-only spool. When the console stops, crashes, or its database is locked or damaged, the data plane keeps enforcing its last verified policy. Unavailable inspection or evidence storage still fails closed.
Tampered, partial, foreign-key or older snapshots are rejected and audited while the last verified policy stays in force. Policy apply answers after the data plane confirms the new revision.
Each decision is fsynced to a data-plane spool and imported transactionally when the console returns. If inline evidence cannot be written, the request fails closed.
Docker tests kill the console, lock its database, tamper with snapshots, remove the snapshot at startup and stop Envoy. No request reaches the destination without an inspection verdict.
Failure-domain separation on one host, not multi-node HA. Approvals and agent registration still need the console. In one synthetic run, gateway first-content p95 stayed within ±3% of 0.46; the separate console process adds about 110 MiB of memory.
Read the plane separation guide ↗Buffered SSE collects and inspects the complete supported response before delivering content. First-content latency includes upstream collection and inspection, not just scanner time. Version 0.46 adds a finite admission wait and optional 2 or 4 same-host inspector processes; both settings require workload-specific qualification.
Reproduce direct-versus-gateway tests at 1, 8 and 32 concurrent requests. Review first-content and completion latency, failures, CPU and memory.
In the default single-inspector mode, the console shows gateway and inspector timings. With multiple inspector processes, request timelines cover the gateway only. Independent phase percentiles cannot be subtracted.
Test the default fail-closed admission limit before tuning capacity. Interactive chat needs explicit first-content latency acceptance; SSE is not token-by-token delivery.
One local synthetic run: with 32 concurrent long responses, first-content p95 was 89 ms direct versus 3,014 ms through the gateway. A 64-request burst completed 32 and rejected 32 with HTTP 503. These 0.44 fixture results are not live-model latency, minimum hardware, or a production SLA. The 0.46 admission and process controls do not provide cross-host HA or guaranteed throughput.
Read the methodology, results and limitations ↗Manage one gateway with explicit settings, visible outcomes and a recovery path.
Choose a model provider or HTTP/MCP profile. Validate mappings, protect destination secrets and stage changes separately from live traffic.
Evaluate synthetic input against local content and routing policy without calling the destination. Review readiness and observed request outcomes.
Restore saved settings and policy snapshots. Activation requires a maintenance restart, with checks against changing a running stack.
A live OpenAI gpt-4.1-mini model selected a tool, received its inspected result, and completed its answer through two separate gateway deployments. The MCP service and business data were synthetic.
An authorized agent read a synthetic customer note. The response email was masked before returning to the model.
A second agent’s read was denied. A policy-blocked deletion never reached the tool. Revoked and seeded-expired credentials were rejected.
The default Docker example uses a scripted model with no paid calls. Live OpenAI mode requires an explicit model and your private test key.
One live model/account qualification, not production certification. SSE is buffered. Customer MCP integration, other live providers and cross-host HA remain unqualified; local load tests encountered 503 responses from 50 requests/second in the measured setup.
Reproduce the workflow and review the limits ↗Actual console screens from local synthetic environments. Inspect runtime decisions, review agent permissions, and confirm the configured provider and response limits.

OpenAI Chat and Responses, Anthropic Messages, Google Gemini native and OpenAI-compatible calls, and OpenRouter Chat. Use a gateway connection key or an individual agent credential in your SDK; keep the real provider key on the gateway.
Deploy one provider profile per instance, choose allowed models, and inspect both request and response. Unknown routes and models are denied.
Supported SSE responses are buffered until inspection completes. This preserves SDK event formats, not real-time token delivery. Text and client-executed function calls only; media and provider-side tools are outside this profile.
Verified with official Python SDKs through Gateway, Envoy, and synthetic TLS providers. OpenAI gpt-4.1-mini has also passed a live model-to-tool workflow with a synthetic MCP target. Other live provider accounts and JavaScript SDKs remain unqualified. Model calls and separately executed tools need their own routed paths.
Provider profiles and SDK examples ↗AI agents turn model output into API calls and tool execution. The missing control is an independent decision point that understands the action, resource, data, and delegated authority before execution.
Map supported HTTP routes and MCP tools to explicit actions and resources. Unmapped inline traffic is denied.
Inspect bounded requests and responses for supported PII and secret patterns. Allow, block, or redact by policy.
Add a local agent credential or verified external JWT. Enforce registered agent scopes, with user delegation and one-time approval when required.
Clients call a configured TrapDefense endpoint. The gateway authenticates the caller, binds the request, inspects content and policy, evaluates optional agent or delegated authorization, and forwards only to configured destinations.
Gateway identity and destination credentials stay separate. The target service still enforces its own permissions; TrapDefense does not turn an agent token into a universal downstream credential.
One self-hosted installation targets one fixed origin with explicit route and tool mappings. Direct, local, closed SaaS-internal, stateful, and bypass traffic remain outside this profile.
Use local agent credentials or your existing JWT issuer. Enforce registered agent scope; add user and task delegation when the workflow needs it.
Register agent ownership, allowed tools, fixed resources, runtime metadata, risk tier, and enabled state.
In delegated mode, require matching tenant, user, agent, task, action, resource, and unexpired delegation. Autonomous mode requires explicit agent permission.
High-risk actions produce a pending approval bound to the request digest. Approval expires and is consumed once.
The destination independently checks its own credential and permissions. Broker decisions add a runtime boundary; they do not replace service IAM.
No Community/Enterprise feature gate, private Python provider, edition switch, or license key is required. Runtime inspection and agent authorization live in the same MIT repository.
Runtime Gateway, request/response inspection, Agent Registry, delegation, Access Broker, one-time approval, local evidence, operations console, six UI languages, and Docker Compose packaging.
Install 0.47 ↗Managed deployment, fleet operations, multi-node HA, immutable external audit, customer integrations, and support may become paid services. No hosted signup or SLA is available today.
See Cloud & Support direction ↗Yes. The current version publishes the Runtime Gateway and built-in Agent Access Broker together under MIT. Future managed operations and customer services can be commercial without hiding the current enforcement code.
No. Your issuer authenticates the caller, TrapDefense evaluates runtime agent context, and the target service enforces its own permissions. These are separate boundaries.
Only when the traffic is routed through a supported HTTP JSON or stateless remote MCP path. Changing a model API base_url alone does not route separately executed tools. Clients need a configurable endpoint. Local stdio, direct database access, closed SaaS-internal calls, stateful MCP, unbounded SSE, WebSocket, and bypass paths are not covered.
Version 0.42 adds a live OpenAI gpt-4.1-mini workflow with synthetic MCP data, plus measured buffering and overload limits. The codebase also has synthetic and local coverage for Runtime Gateway decisions, broker isolation and approval replay protection, provider-shaped OAuth, a real local Keycloak token path, official MCP SDK flows, VS Code MCP discovery, Docker self-hosting, and six-language UI consistency. Customer IdPs, production routes, HA, and capacity still require acceptance testing.
Tell us the client, HTTP/MCP transport, identity issuer, destination authentication, and actions you need to protect. We will assess whether the open-source deployment contract fits.
hellocosmos@gmail.com ↗