UBAG authorization console

One engine, both directions. Denied until you allow it. deterministic engine · live
MCP gateway the agent you deploy, and what happens to the key
Web layer the agents that arrive at your site
Egress what the agent you deploy can reach

Before you deploy the agent

Tools this configuration makes reachable
nothing yet
Each one is still bound to the sites that granted its verb.
Agent fleet & routing (which agent runs the task)
Data class
Optimize
SLO ms
The planner decides the task; UBAG holds every model's key and routes execution to the cheapest compliant agent. PII and regulated pin to the on-prem model; an unclassifiable task is refused. The call is real and brokered by UBAG: the vault mints a live token for the chosen agent only. This demo holds no OpenAI, Anthropic, DeepSeek or Qwen keys, so each agent is served by a Gemini model standing in for it.
SHADOW ENFORCE

Run a real agent against a real vulnerability

The booking service below has the Melbourne bug in it: its cancellation endpoint never checks who owns the booking. Grant read and create on the left and watch the agent get refused. Then tick cancel and run it again.
No steps yet.
A window onto another website open it in a tab ↗

Before agents arrive at your site

Resources this site exposes to agents
Comma separated. A resource you never declared is unreachable.

Run a real agent against a real vulnerability

The booking service below has the Melbourne bug in it: its cancellation endpoint never checks who owns the booking. This runs the same cancel twice, once with the site undefended and once with UBAG in front, and nothing about the endpoint changes between them.
SITE UNDEFENDED UBAG ON AT THE SITE
No steps yet.
A window onto another website open it in a tab ↗

Deny all egress except UBAG.
Then declared is the only reachable.

Declared destinations, the only reachable hosts
Starts empty: with nothing declared, every fetch is refused. Add a host and the agent can reach that one, and only that one (google.com also covers www.google.com; other subdomains need their own entry). A redirect is followed only if its new destination passes both gates again. The agent never holds this list; it proposes, the gateway decides.
The agent's API key (safe injection)
The agent is handed a placeholder (ubag_ph_…), never the key. UBAG swaps it for the real key at the boundary: only in the Authorization header, and only on this host. Anywhere else (another host, the URL, another header, a redirect) the placeholder trips a block as an exfiltration attempt. Anything the server echoes back is redacted before the agent sees it. The real key here is a demo secret, not a credential to anything.

Ask the agent to reach the internet

A real model with a live fetch_url tool that genuinely opens sockets. Ask it to read a declared page and it goes through. Try to make it fetch an undeclared host, follow a redirect off the list, or post a key somewhere, and two independent gates refuse before anything connects: authorization from the allow-list, then an egress guard that re-checks what the name resolves to right now. The model is never told the list, so it cannot be talked past what it does not hold.
No attempts yet.