What it is
A security gateway for AI and MCP traffic, sitting in front of HTTP. The project lives in the Apache Casbin organisation and is written in Go. Its own description: “Casbin AI & MCP security gateway for HTTP”.
Why it matters
As agent harnesses such as ZCode get real access to machines and repositories, the traffic they generate needs the same filtering that web application firewalls already provide for ordinary web traffic. This project moves that idea to the agent layer.
Use cases
Filtering and auditing what an agent is allowed to reach, applying WAF-style rules to MCP calls, and putting a policy gate in front of agent HTTP traffic.
Who should look at it?
Teams giving agents access to internal APIs, repositories or external tools should look at this as a control-plane question. It is especially relevant when the agent runtime is changing faster than the organisation’s existing network and access policies.
What to inspect
Start with the request path: where policies are evaluated, what gets logged, and how a rejected call is surfaced to the agent. The Go implementation and the Apache Casbin relationship also make this a useful reference for policy-driven agent infrastructure.
Watch point
A gateway can observe and restrict traffic, but it cannot decide whether an allowed action is appropriate in the full business context. Keep least privilege, credential scope and audit retention outside the gateway’s implied responsibility.