Agent Gateway

A control layer for agentic AI.

A unified control layer that governs AI usage and safeguards sensitive data across every agent interaction — with verifiable identity, policy enforcement and full observability.

Surfaces LIVE
Access Point  https://gateway.example.com/v1/message
Human Caller Access Point Managed Agent External Target Caller Context Identity Credential Delegation
Gateway Logslive · 300 logs
Gateway Logs
REFUSED12:04:19
Unknown agent
did:key:z6Mk…8vRa
DID resolved
Signature valid
Credential presented
Issuer in trust registry
Credential— none presented
TrustRegistry · no match
Policyrefuse · unverified identity
Root of trustno issuer resolved
Why it's different

Most gateways route traffic. Agent Gateway routes trust.

Identity-first

Not traffic-first

Every agent, person and organisation gets a verifiable identity at birth — before a single request is routed.

SSI stack

Not just API keys

Built on self-sovereign identity: decentralised, user-held W3C credentials and DIDs. No central honeypot, no lock-in.

Cross-boundary

Not walled off

DIDComm tunnels and trust networks carry trust across orgs, clouds, protocols and borders — it travels with the agent.

Whole path

Not a bolt-on layer

It is the gateway — not an identity layer added on top of one. A single self-hosted binary owns the whole request path.

The Agent Gateway

One console. The whole trust story.

Design the path an agent travels, watch every call logged in real time, and hand the receiver proof of why each request was trusted, or refused.

Use cases

Practical applications across your stack.

How teams put Agent Gateway to work in real deployments — from authentication and telemetry to deployment, ecosystem connectivity and private networking.

Multi-client authentication

Move beyond shared credentials to a scalable security model as your ecosystem grows.

  • Unique API keys per client or partner
  • Protect specific routes with precision
  • Multiple auth headers, especially in MCP

Stronger security, cleaner access isolation.

Your telemetry, your control

Stream telemetry wherever your business needs it — no vendor lock-in.

  • Prometheus/Grafana + AWS CloudWatch
  • Emit via OpenTelemetry (OTEL) spans
  • Pipe to long-term storage

Full observability on your terms.

Deployment on your terms

Fully on-premises or hosted on Affinidi infrastructure — complete operational freedom.

  • Complete control over data
  • Align with internal security policy
  • Run in restricted / air-gapped environments

Enterprise-grade security without compromise.

Powering the MCP ecosystem

Enable dynamic, connected ecosystems for agents to discover and use tools.

  • Agents discover and retrieve tools
  • Connect via Linked Gateway or Direct URL
  • Faster onboarding, smoother interop

A more connected ecosystem, less overhead.

Private network connectivity

VPC peering extends the Gateway securely into private environments.

  • Direct, private comms with internal systems
  • Avoid public-internet exposure
  • Strict control over network traffic

Stronger security, low-latency connectivity.

Govern agents behind your corporate IdP

Keep Entra or Okta as the source of truth for identity while the Gateway adds verifiable per-agent identity, policy enforcement and audit.

  • Verify every request against your OIDC provider
  • Derive a portable agent DID from the IdP token
  • One audit trail across agents, tools and services

Enterprise identity you already trust, extended to agents.

Where it fits

A single enforcement point for agentic traffic.

Agent Gateway sits between your apps and agents and the AI backend services they rely on — MCP servers, databases and external actors — routing all AI traffic through one point.

Applications & agents
Operator agentsInternal teams
Customer appsWeb & mobile
Partner agentsBuyers / vendors
Agent swarmsMulti-team flows
All AI traffic
Unified enforcement point Agent Gateway
  • Compliance
  • Security
  • Operational policy
  • Audit & observability
Policy enforced
AI backend services
MCP serversTools & capabilities
External actorsThird-party APIs
AgentsA2A interoperable

Single enforcement point

One place to apply compliance, security and operational policies — instead of scattered SDK wrappers and bespoke middleware.

Protocol-native

Native support for MCP, A2A, AP2 and emerging agentic protocols. Add new transports without re-architecting.

Evolves with the stack

Drop-in deployment today, ready for next-generation agent meshes and cross-boundary orchestration tomorrow.

Core capabilities

What the Gateway does.

Six capabilities work together to give every agent interaction the right level of trust, visibility and control.

Agent Flow Builder

Visual, protocol-agnostic design layer. Compose flows by connecting endpoints, identity and validation rules — no manual schemas.

  • Visual builder
  • MCP
  • A2A
  • AP2

Observability

OpenTelemetry metrics, logs and traces into CloudWatch, Prometheus and Grafana. Tamper-evident, exportable audit records.

  • OpenTelemetry
  • Audit trails
  • Traceability

Multi-client authentication

Defence-in-depth across transport, session and application layers. Validate OIDC tokens from providers like Entra and Okta, or pick what fits: mTLS, API keys, JWT or DID Auth.

  • mTLS
  • API keys
  • JWT / OIDC
  • DID Auth

Policy enforcement

Block requests early with expressive OPA policies. Fine-grained, agent-surface-level controls based on identity, claims and context.

  • OPA
  • Agent surface
  • Identity-aware

Credential delegation

Agents access external resources on a user’s behalf without exposing user credentials — with a transparent audit trail of who accessed what.

  • Delegation
  • Auditable access

Verifiable agent identity

Every agent gets a cryptographic, portable identity at the point of communication — no agent-code changes. Backed by W3C DIDs and VCs.

  • W3C DID
  • Verifiable Credentials
  • Portable
Trust controls

More than routing — trust in the request path.

Beyond routing and authentication, the Gateway applies cryptographic trust controls inline — the things a bolt-on identity layer can’t.

Workload context binding

Every request carries a signed attestation binding the caller context, delegation actions and the actual policy decisions made — verifiable long after the call, not just a log entry.

  • Signed VP
  • Caller context
  • Non-repudiation

Trust-registry verification

Check an agent against external trust registries in the request path — is it recognised, is it authorised — and feed the result straight into policy.

Explore Trust Registry
  • TRQP
  • Recognition
  • Authorisation

Cross-org trust fabric

Gateway-to-gateway over encrypted DIDComm. Each side keeps its own policy and identity and verifies the caller’s signed identity on arrival — no shared IdP required.

  • DIDComm v2.1
  • Gateway-to-gateway
  • No shared IdP

Payment-aware routing

Require and verify payment conditions in the request path before a call proceeds, using the open x402 standard.

  • x402
  • Pay-per-call
  • In-path
Enterprise identity

Plugs into the IdP you already run.

The Gateway doesn’t replace your identity provider — it verifies its tokens and layers verifiable agent identity, policy and audit on top.

Bring your own IdP

Validate inbound requests against any standard OAuth 2.0 / OIDC provider — Microsoft Entra ID (Azure AD), Okta and others — with per-surface JWT Bearer verification.

Local JWT verification

Tokens are verified at the Gateway against the provider’s published keys (JWKS, fetched and cached, or configured inline) — checking issuer, expiry and audience.

Entra Agent ID → portable agent identity

Turn a validated token claim (the Entra oid by default) into a stable, portable agent DID. It stays the same across token rotation and identical across every gateway in the fabric — with no agent-code changes.

Corporate SSO for the console

Sign in to the management dashboard with SAML 2.0 single sign-on.

Explore the suite

The rest of the Trust Fabric.

Agent Gateway pairs with two companion products that extend the same identity, policy and audit model end to end.

Agent Stream

Where AI execution flows are governed and evaluated in real time.

  • Unified execution layer across models, tools and databases
  • Continuous evaluation and intelligent routing
  • Built-in policy, safety and output-integrity safeguards
Explore Agent Stream
Agent Pay Coming soon

Secure agent-driven payments enabled through recognised standards.

  • Enforce payment conditions before execution
  • Verify payment proofs and settle under policy
  • Support x402 and MPP payment protocols
Get started

Ready to take control of your agents?

Agent Gateway is in closed beta. Join the future of agentic AI governance.

Cookie Preferences

We use cookies to enhance your experience. You can manage your preferences below. For more information, read our Cookie Policy.

Strictly Necessary Always Active

These cookies are essential for core website functions such as security, session integrity, and cookie preference storage. They cannot be disabled.

  • _cf_bm: Distinguishes humans from bots (Cloudflare) · 30m
  • _cfuvid: Ensures secure browsing (Cloudflare) · Session
  • __hs_initial_opt_in: Prevents HubSpot's banner · 7 days
  • _gtm_debug: GTM debug mode (testing only) · Session
Analytics

These cookies help us understand how visitors interact with the site so we can improve content and performance. All data is aggregated and anonymous.

  • _ga, _gid, _gat: Google Analytics · Session – 2 years
  • __hstc, hubspotutk, __hssrc: HubSpot visitor tracking · 13 months
  • __hs_opt_out: HubSpot opt-out preference · 6 months
Marketing & Targeting

These cookies allow us and our partners to serve personalised ads and measure campaign performance.

  • _gcl_au, _gcl_dc: Google Ads conversion tracking · 90 days
  • IDE: Google Display Network personalisation · 1 year
  • _fbp: Meta / Facebook remarketing · 90 days
  • li_gc, _li_fat_id, bcookie: LinkedIn tracking · 1–24 months
  • guest_id, personalization_id: Twitter/X analytics · 2 years