Two perspectives
See what your agents see
Agents get a clean tool manifest. Admins get the policy engine behind it. One system, two views.
| Tool | Status | Scope |
|---|---|---|
| github.list_repos | ● active | read |
| github.create_issue | ● active | write |
| slack.post_message | ● active | write |
| jira.get_ticket | ● active | read |
| aws.s3_list_buckets | ○ denied | — |
| db.raw_query | ○ denied | — |
> 4 tools available · 2 blocked by policy
> session: usr_k8x2m · org: acme-corp · ttl: 3600s
Three channels
Every protocol, one hub
Connect any tool source through the channel that fits. Airelock normalizes them all into governed MCP endpoints.
OpenAPI Bridge
Any REST API becomes MCP tools automatically.
MCP Proxy Remote
Proxy remote MCP servers with auth and audit.
Stdio Hosting
Host stdio MCP servers centrally. Users connect remotely.
Built for enterprise
Security isn't a feature. It's the architecture.
RBAC & Multi-tenancy
Role-based access control with tenant isolation. Groups, roles, and policies scoped per organization.
Credential Vaulting
API keys and tokens stored encrypted, injected at runtime. Agents never see raw credentials.
Immutable Audit Trail
Every tool call logged with identity, parameters, and response. Tamper-proof and exportable.
OAuth 2.1 Authorization
Standards-compliant auth flow with PKCE. Integrates with your existing identity provider.
Admin Control Plane
Manage sources, users, groups, and policies from a single dashboard. No YAML required.
Identity-Aware Routing
Route tool calls based on user identity, group membership, and policy evaluation at the edge.
Integration
One endpoint. All your enterprise tools.
Point your MCP client at Airelock. The hub resolves identity, evaluates policy, and routes to the right tools — automatically.
{ "mcpServers": { "airelock": { "url": "https://hub.airelock.dev/mcp", "headers": { "Authorization": "Bearer <your-token>" } } }}Ready to secure your AI tool access?
Deploy Airelock and give your agents governed access to every tool they need — without exposing credentials or bypassing policy.