Tuskira has released AI Agent Gateway, an open-source tool designed to enhance the security of AI agent deployments by centralizing credential management and access control. The gateway operates as an intermediary between AI agents and the services they interact with, including both tool servers (referred to as MCP tools) for platforms like GitHub and Jira, and various large language model (LLM) providers.
Traditionally, AI agents often store model keys and MCP credentials directly within their configuration files, distributed across developer laptops and continuous integration (CI) runners. This practice creates multiple points of exposure, as compromise of any single configuration file can lead to the theft of sensitive credentials. Furthermore, without a centralized control mechanism, there is no inherent check on an agent's permissions when it attempts to use a tool.
The AI Agent Gateway addresses these vulnerabilities by ensuring that agents never directly possess sensitive credentials. Instead, an agent registers the gateway as its MCP server and includes a gateway key and a profile name with each request. Upon receiving a request, the gateway first authenticates the gateway key, which is linked to a specific tenant and role. It then verifies whether the designated profile is authorized to use the requested tool. If the request is denied, an error is logged, and the call is blocked from reaching the backend. If approved, the gateway retrieves the actual credential from an encrypted store and attaches it to the outgoing request, effectively abstracting the credential from the agent.
This access control is enforced in real-time at the moment of the call, augmenting the gateway's ability to prune the list of tools an agent is even aware of. Consequently, even if an agent is manipulated into attempting to call a tool it was never shown, the gateway will still refuse the request.
The gateway also supports routing LLM traffic, allowing organizations to manage access to providers such as Anthropic (directly or via AWS Bedrock), OpenAI, and Gemini. By adjusting an SDK's base URL, model traffic can be directed through the gateway, which then records token usage and estimates costs for each call.
Tuskira highlights two default configurations that require careful attention. First, profiles are only bound to keys when explicitly configured. An unbound key allows the caller to specify any profile in a request header, meaning a leaked unbound key could grant access to any profile's permissions. Tuskira recommends binding each key to its specific profile to limit the scope of a leaked key, such as a CI key, to only what its associated profile permits. The sample CI profile provided by Tuskira allows access to only one tool.
Second, the demo stack of the gateway stores LLM request and response bodies, capped at 1 MiB each, for display in the console. These bodies can contain sensitive prompts and code sent by agents. Tuskira advises users to disable this storage setting if privacy is a concern.
The shipped Docker Compose file for the gateway permits outbound connections to the host machine and the loopback range for local testing. Tuskira instructs users to remove these exceptions in any shared or production environment. By default, the gateway otherwise blocks connections to private and loopback addresses and consistently blocks the cloud metadata address.
The AI Agent Gateway is available for free on GitHub and runs on macOS and Linux, with Windows support through WSL2 being untested. The repository includes practical examples for integration with various tools and platforms, including Claude Code, Cursor, VS Code, Codex CLI, Python agents, and Kubernetes.






