Open-Source AI Agent Gateway Secures Credentials by Acting as Intermediary
Tuskira releases AI Agent Gateway, an open-source tool designed to prevent sensitive credentials and API keys from being embedded directly into AI agent configurations.

Tuskira has introduced an open-source solution named AI Agent Gateway, designed to act as a crucial intermediary layer for AI agents. This gateway sits between the AI agents and the services they interact with, such as GitHub and Jira, as well as the model providers they communicate with. By running within an organization's own environment, the gateway aims to significantly enhance the security posture of AI agent deployments.
The primary security concern addressed by AI Agent Gateway is the common practice of embedding sensitive credentials and API keys directly into agent configuration files. This practice, often seen across multiple agent instances on various laptops and CI runners, creates a significant risk: if any of these configuration files are compromised, the embedded secrets are exposed. Tuskira's solution mitigates this by ensuring that agents never directly handle these sensitive tokens.
When an AI agent makes a request, it registers the gateway as its intermediary server, sending a unique gateway key and a profile name. The gateway first validates this key, which is linked to a specific tenant and role. It then checks if the agent's profile is authorized to access the requested tool or service. If the request is denied, an error is logged, and the request does not proceed to the backend. For authorized requests, the gateway retrieves the necessary real credential from a secure, encrypted store and attaches it to the outgoing request, effectively shielding the agent from direct exposure to sensitive information like GitHub tokens.
This authorization and credential management process occurs in real-time, at the moment of the call. Furthermore, the gateway can dynamically trim the list of available tools that each agent sees, preventing agents from attempting to access tools they were not intended to use, even if they are tricked into doing so. The gateway also supports model traffic by allowing SDKs to point to its base URL, covering providers like Anthropic (directly or via AWS Bedrock), OpenAI, and Gemini, while also logging token usage and estimating costs for each interaction.
AI Agent Gateway offers a robust profile binding mechanism. By default, keys are bound to specific profiles, ensuring that a compromised key can only access the tools and resources permitted by its associated profile. An unbound key, however, allows the caller to specify any profile in a request header, making it crucial for administrators to bind each key to a specific profile to limit the blast radius of any potential compromise. Tuskira provides a sample CI profile that restricts access to a single tool, demonstrating a secure default configuration.
The gateway's logging capabilities can be configured to store LLM request and response bodies, capped at 1 MiB each, for debugging and analysis purposes. However, this feature can be disabled for privacy. The provided Docker Compose file includes configurations for outbound connections to the host machine and loopback addresses for local testing. Tuskira strongly advises removing these exceptions in production environments. By default, the gateway blocks connections to private and loopback addresses, and critically, it always blocks access to cloud metadata addresses, preventing common cloud-based credential theft techniques.
AI Agent Gateway is available for free on GitHub and supports macOS and Linux operating systems, with Windows support via WSL2 being untested. The repository includes worked examples for various popular tools and environments, including Claude Code, Cursor, VS Code, Codex CLI, Python agents, and Kubernetes, facilitating easy integration and adoption for developers and security teams.