GatewayStack is the MIT-licensed open core of Agentic Control Plane. It runs in your infrastructure, in the agent's runtime call path, and makes every tool and model call identified, policy-checked, and logged — whatever framework the agent runs on.

Which one do I want? GatewayStack (this repo) is the runtime: MIT-licensed npm modules — identity, policy, limits, PII redaction, audit — you compose into your own gateway and run yourself. No account, no phone-home. Agentic Control Plane is the hosted product built on it: the console, the priced cost X-ray, team policy UI, approvals — free for individuals. Most people start there and reach for this repo when they want the enforcement layer in their own infra.

Install

Coding agents (Claude Code, Cursor, Codex, OpenClaw) — one command, no code changes:

curl -sf https://agenticcontrolplane.com/install.sh | bash

First controlled call in about thirty seconds. The script documents what it does and won't do.

Hermes Agent uses a native Python plugin instead (why):

pip install hermes-acp && hermes plugins enable acp

Your own framework code — drop in a package:

npm install @gatewaystack/identifiabl express
import express from "express";
import { identifiabl } from "@gatewaystack/identifiabl";

const app = express();

app.use(identifiabl({
  issuer: process.env.OAUTH_ISSUER!,
  audience: process.env.OAUTH_AUDIENCE!,
}));

app.get("/api/me", (req, res) => {
  res.json({ user: req.user.sub, scopes: req.user.scope });
});

app.listen(8080);

Every request now requires a valid RS256 JWT. req.user is the verified identity.

What you get

  • Cost control. Budget caps and rate limits enforced per call (limitabl), with every call's usage logged and attributable. The priced cost X-ray — runs split into the orchestration loop vs leaf sub-tasks, per-model spend — is the hosted console built on this telemetry.
  • Tool-surface control. Allow / ask / redact / deny, per operation, scoped by agent, role, or user. Deny-by-default on the destructive stuff. Enforced at the call, outside the model — a prompt-injected agent can't talk its way past it.
  • Audit. Every tool and model call logged: who triggered it, which agent, what it returned, what it cost, how long it took. Attributable and exportable.

Every number we publish is metered from our own production workspaces, not estimated: agenticcontrolplane.com/data.

Modules

Each layer ships as a framework-agnostic -core package plus an Express middleware wrapper. Use one or all. Detailed breakdown →

Module npm What it does
@gatewaystack/identifiabl npm RS256 JWT verification, identity normalization
@gatewaystack/transformabl npm PII detection, redaction, safety classification
@gatewaystack/validatabl npm Deny-by-default policy engine, scope/permission enforcement
@gatewaystack/limitabl npm Rate limits, budget tracking, agent guard
@gatewaystack/proxyabl npm Auth mode routing, SSRF protection, identity-aware proxy
@gatewaystack/explicabl npm Structured audit logging, health endpoints

Full stack example

Wire all six layers together. Each is optional — use only what you need.

npm install @gatewaystack/identifiabl @gatewaystack/transformabl @gatewaystack/validatabl \
  @gatewaystack/limitabl @gatewaystack/proxyabl @gatewaystack/explicabl @gatewaystack/request-context express
import express from "express";
import { runWithGatewayContext } from "@gatewaystack/request-context";
import { identifiabl } from "@gatewaystack/identifiabl";
import { transformabl } from "@gatewaystack/transformabl";
import { validatabl } from "@gatewaystack/validatabl";
import { limitabl } from "@gatewaystack/limitabl";
import { createProxyablRouter, configFromEnv } from "@gatewaystack/proxyabl";
import { createConsoleLogger, explicablLoggingMiddleware } from "@gatewaystack/explicabl";

const app = express();
app.use(express.json());

// 1. Establish request context for downstream layers
app.use((req, _res, next) => {
  runWithGatewayContext(
    { request: { method: req.method, path: req.path } },
    () => next()
  );
});

// 2. Log every request
app.use(explicablLoggingMiddleware(createConsoleLogger()));

// 3. Require verified RS256 token
app.use(identifiabl({
  issuer: process.env.OAUTH_ISSUER!,
  audience: process.env.OAUTH_AUDIENCE!,
}));

// 4. Detect PII and classify content safety
app.use("/tools", transformabl({ blockThreshold: 80 }));

// 5. Enforce authorization policies
app.use("/tools", validatabl({
  requiredPermissions: ["tool:read"],
}));

// 6. Apply rate limits and budget caps
app.use("/tools", limitabl({
  rateLimit: { windowMs: 60_000, maxRequests: 100 },
  budget: { maxSpend: 500, periodMs: 86_400_000 },
}));

// 7. Route /tools to your tool/model backends
app.use("/tools", createProxyablRouter(configFromEnv(process.env)));

app.listen(8080, () => {
  console.log("GatewayStack running on :8080");
});

Or clone and run the reference gateway directly:

git clone https://github.com/agentic-control-plane/GatewayStack
cd GatewayStack
npm install
npm run dev   # gateway on :8080, admin UI on :5173

Why this is a separate layer

AI apps have three actors — user, LLM, backend — and no shared identity layer. The backend sees a service token, not a person, so it can't tell who the agent is acting for, whether the action was authorized, or what it cost. GatewayStack closes that gap at the tool-call boundary. The full argument →

Repository layout

Path Description
packages/ Six -core packages (framework-agnostic) + six Express middleware wrappers, plus request-context, compat, and integrations
apps/gateway-server Express reference server wiring all six layers, /protected/* samples, Docker image
apps/admin-ui Vite/React dashboard that polls /health
demos/ MCP issuer + ChatGPT Apps SDK connectors that mint demo JWTs
tools/ Echo server, mock tool backend, Cloud Run deploy helper
tests/ Vitest smoke tests
docs/ Auth0 walkthroughs, conformance output, endpoint references, troubleshooting

Testing

npm test

185 tests across 17 test files covering all six core packages.

Prerequisites

  • Node.js 20+
  • npm 10+ (or pnpm 9)
  • An OIDC provider issuing RS256 access tokens (Auth0, Okta, Entra ID, Keycloak, etc.)

Docs

Related repos

Contributing

GatewayStack is the runtime. The hosted console — dashboard, team management, cost X-ray, policy UI — is Agentic Control Plane. Free for individuals.