AI Agent Gateway: Open-source tool keeps credentials out of agent configs
Tuskira’s AI Agent Gateway is an open-source solution that sits between AI agents and everything they call: the MCP tool servers that connect them to services like GitHub and Jira, and the model providers they send prompts to. The gateway runs in your own environment without a Tuskira account.

The full picture (Source: Tuskira)
A team running Claude Code, Cursor and a homegrown ticket bot usually has model keys and MCP credentials copied into each agent’s config, on every laptop and CI runner. Anyone who gets hold of one of those files gets the credentials inside it, and in Tuskira’s account nothing checks the agent’s permissions when it acts.
What happens on a call
An agent registers the gateway as its MCP server and sends a gateway key and a profile name with every request. The gateway checks the key, which is tied to a tenant and a role, then checks whether that profile may use the requested tool. A denied call returns an error and lands in the log without reaching the backend. An allowed call gets the real credential pulled from an encrypted store and attached on the way out, so the agent never holds the GitHub token.
The gateway runs that check at the moment of the call, in addition to trimming the tool list each agent sees. An agent talked into calling a tool it was never shown still gets refused. Model traffic can go through the same gateway by changing an SDK’s base URL. It covers Anthropic directly or through AWS Bedrock, plus OpenAI and Gemini, and it records tokens and an estimated cost for each call.
Two defaults to check
Profiles bind only when you bind them. A key with no profile attached lets the caller name its own profile in a request header, so a leaked unbound key can ask for any profile it wants. Bind each key to its profile and a leaked CI key reaches only what that profile allows. Tuskira’s sample CI profile allows one tool.
The demo stack also stores LLM request and response bodies, capped at 1 MiB each, so the console can display them. Those bodies hold whatever prompts and code your agents send, and one setting turns storage off. The shipped Docker Compose file allows outbound connections to the host machine and the loopback range for local testing, and Tuskira’s instruction is to remove both on anything shared. Outside those exceptions, the gateway refuses connections to private and loopback addresses by default and always blocks the cloud metadata address.
Download AI Agent Gateway
The gateway runs on macOS and Linux, and Windows through WSL2 is untested. The repository ships worked examples, covering Claude Code, Cursor, VS Code, Codex CLI, a Python agent and Kubernetes.
AI Agent Gateway is available for free on GitHub.

Must read:
- 20 open-source cybersecurity tools to keep your team ready for anything
- GitHub CISO on security strategy and collaborating with the open-source community

Subscribe to the Help Net Security ad-free monthly newsletter to stay informed on the essential open-source cybersecurity tools. Subscribe here!
