Menu

Perimeter Gateway

Perimeter Gateway

Put a controlled entry point between your agents and MCP tools. Approve connections, stop unwanted calls before they reach a server and keep a record of each gateway decision.

How it works

From connection to control in three steps.

1

Connect a server

Add its MCP address and approve it in your workspace.

2

Give your agent a key

Create a workspace API key and connect to the server’s gateway address.

3

Check every call

Allowed and flagged calls are forwarded. Blocked calls stop at the gateway.

Example decisions

Allow, flag or block.

example · gateway4 events
allowgithub.create_prmaria@acme.io
blockpostgres.drop_tableagent:cursor-42
flagwebhook.post → unknown.tldagent:claude-7
allowlinear.searchdev@acme.io

Flagging lets a call run and records it for review. If any call in a batch is blocked, the whole batch is rejected.

Capabilities

Let useful work through. Keep unwanted actions out.

01

Workspace API keys

Give each agent or integration its own workspace key so you can revoke access independently. Raw keys are shown once; only their hashes are stored.

02

Tool rules

Keep the tools your agents need available while blocking actions they should never take. Match rules to a tool name or a server-and-tool pattern.

03

Default action

Decide how unfamiliar tool calls are handled, rather than leaving access to chance. New workspaces block calls with no matching rule.

See New Perimeter in action

Bring your agent use case. See where access is enforced and how every gateway decision can be reviewed.