AIRELOCK

Identity-aware RBAC · Credential vaulting · Full audit trails

Get Started

Two perspectives

See what your agents see

Agents get a clean tool manifest. Admins get the policy engine behind it. One system, two views.

airelock — session viewer
ToolStatusScope
github.list_repos● activeread
github.create_issue● activewrite
slack.post_message● activewrite
jira.get_ticket● activeread
aws.s3_list_buckets○ denied
db.raw_query○ denied

> 4 tools available · 2 blocked by policy

> session: usr_k8x2m · org: acme-corp · ttl: 3600s

Three channels

Every protocol, one hub

Connect any tool source through the channel that fits. Airelock normalizes them all into governed MCP endpoints.

OpenAPI Bridge

Any REST API becomes MCP tools automatically.

MCP Proxy Remote

Proxy remote MCP servers with auth and audit.

Stdio Hosting

Host stdio MCP servers centrally. Users connect remotely.

Built for enterprise

Security isn't a feature. It's the architecture.

RBAC & Multi-tenancy

Role-based access control with tenant isolation. Groups, roles, and policies scoped per organization.

Credential Vaulting

API keys and tokens stored encrypted, injected at runtime. Agents never see raw credentials.

Immutable Audit Trail

Every tool call logged with identity, parameters, and response. Tamper-proof and exportable.

OAuth 2.1 Authorization

Standards-compliant auth flow with PKCE. Integrates with your existing identity provider.

Admin Control Plane

Manage sources, users, groups, and policies from a single dashboard. No YAML required.

Identity-Aware Routing

Route tool calls based on user identity, group membership, and policy evaluation at the edge.

Integration

One endpoint. All your enterprise tools.

Point your MCP client at Airelock. The hub resolves identity, evaluates policy, and routes to the right tools — automatically.

mcp.json
{  "mcpServers": {    "airelock": {      "url": "https://hub.airelock.dev/mcp",      "headers": {        "Authorization": "Bearer <your-token>"      }    }  }}

Ready to secure your AI tool access?

Deploy Airelock and give your agents governed access to every tool they need — without exposing credentials or bypassing policy.