Perimeter Gateway
Put a controlled entry point between your agents and MCP tools. Approve connections, stop unwanted calls before they reach a server and keep a record of each gateway decision.
How it works
Add its MCP address and approve it in your workspace.
Create a workspace API key and connect to the server’s gateway address.
Allowed and flagged calls are forwarded. Blocked calls stop at the gateway.
Example decisions
Flagging lets a call run and records it for review. If any call in a batch is blocked, the whole batch is rejected.
Capabilities
Give each agent or integration its own workspace key so you can revoke access independently. Raw keys are shown once; only their hashes are stored.
Keep the tools your agents need available while blocking actions they should never take. Match rules to a tool name or a server-and-tool pattern.
Decide how unfamiliar tool calls are handled, rather than leaving access to chance. New workspaces block calls with no matching rule.
Bring your agent use case. See where access is enforced and how every gateway decision can be reviewed.