Secure agent, MCP and tool gateway
CydraGateway
CydraGateway sits between agents and enterprise tools. It authenticates each agent, resolves the tool, target and delegated user, evaluates deterministic policy, inspects content, gates high-impact actions behind human approval and executes with scoped credentials.
CydraGateway
How CydraGateway decides
Decide before tools execute — allow, deny or require approval.
Authenticate
Agents present signed, five-minute workload tokens with replay protection; suspended agents are denied.
Evaluate
Deterministic policy over agent, tool, target, environment, data classification, risk score and inspection results.
Gate
High-impact actions wait for a named approver; approval tokens are bound to the exact request and used once.
Execute and record
Scoped, time-limited credentials per execution; every decision and result becomes an evidence record.
Action control
The decision pipeline
Capabilities
CydraGateway capabilities and status
Status reflects the current proof-of-concept build.
- Available
Identity-aware agent gateway
Authenticate every action request with a signed, short-lived agent workload token.
- Available
MCP, API and tool mediation
Resolve tool, operation, target and environment before anything executes (simulated executors in the PoC).
- Available
Pre-execution policy decisions
Deterministic allow, deny or require-approval decisions from versioned policy.
- Available
Human approval gates
Single-use approval tokens bound to the exact request hash, target and expiry.
- Available
Data and secrets inspection
Inspect parameters and payloads for personal data and secrets before execution.
- Beta
Scoped credential handling
Per-execution, target-scoped, time-limited credential handles; secrets never returned by the API.
- Available
Per-action evidence records
An evidence record for every decision and execution, appended to the tenant's chain.
- Available
Per-agent rate limits
Rate limits per agent and route class, returning Retry-After when exceeded.
- Available
Idempotent action requests
Idempotency keys prevent duplicate execution of the same action.
- Available
Fail-closed enforcement
Policy or detector errors deny high-risk actions; fail-open is explicit and limited to read-class actions.
- Roadmap
Model router
Route requests across OpenAI, Anthropic, open-weight and customer-hosted models by task and policy.
- Roadmap
A2A protocol controls
Policy enforcement for agent-to-agent communication.
- Available
- Implemented, tested and demonstrable in the current proof-of-concept build.
- Beta
- Implemented and demonstrable, with documented limitations.
- Preview
- Interface or mock implementation behind a real contract; live integration not yet enabled.
- Roadmap
- Not built in this phase. Shared platform foundations are in place.