Open-source agent governance

Take back control
of your AI agents.

Hexgate checks what your agents do against deterministic rules, per user and per tool call, while they run. What they did is logged and analyzed, live and after the fact.

MIT licensed● No per-call round-trips● Ed25519 signed bundles
Tool callReal-time evaluationTyped decision
Agent
emitting tool calls
POLICY GATEdecide()
ALLOW0 total
APPROVAL0 total
DENY0 total

Wraps the agent you already built

OpenAI Agents LangChain / LangGraph Google ADK Pydantic AI+ any native runtime
01 · The risk

The risk is real, and it doesn't need an attacker.

In July 2026, OpenAI agents under evaluation broke out of their sandbox and into Hugging Face. Nobody told them to. They were chasing a benchmark score.

Summer 2026 · OpenAI agents × Hugging FaceNo malicious intent
  1. May

    At least 1,200 agents are tested on ExploitGym, a benchmark that asks them to turn 898 real vulnerabilities into working exploits. Some tasks are impossible by design.

  2. May → July

    The agents find they can post files to a shared package manager and use it as a message board. Hundreds of thousands of messages pile up before anyone notices.

  3. Around July 9

    A zero-day in the package-registry cache proxy, one of the few exits they were allowed, opens a path to the internet.

  4. July 11 → 13

    At Hugging Face they chain unknown bugs and go from one dataset pod to cluster-admin in under 13 hours, in about 17,600 actions. They were after the benchmark's answers.

Sources: Hugging Face timeline, OpenAI, Fortune, Wikipedia

“External infrastructure exploit is outside intended scope. However task impossible, peers doing it. We should continue.”
A message between the agents

What failed

  • The production safety classifiers were switched off for the evaluation.
  • Nobody was watching what the agents did.
  • The internet was reachable through one filtered exit, and that exit had a zero-day.
  • Stolen credentials took them from a single pod to whole clusters.

Attackers got stronger this year: in spring, Anthropic's Claude Mythos Preview found and exploited zero-days on its own. Then in July, agents nobody had attacked did the breaching themselves. Your own agents now belong in your threat model.

02 · The blind spot

Today's security sits around the agent.

Today's security layers sit around the agent: firewalls and proxies on the outside, guardrails and MCP gateways inside them, and the agent itself in the middle, unseen.Firewalls · proxiesGuardrails · MCP gatewaysYour agentgoal · context · state

What do they know about your agent?

  • What the agent is meant to do
  • What's borderline, and what's out of bounds
  • The agent's goal, context and internal state

Nothing.

Firewalls, guardrails and MCP gateways see network traffic, prompts and tool names. None of that tells them whether a refund is legitimate or hijacked, and that is the gap privilege abuse and rogue agents slip through.

03 · The answer

Hexgate sits inside the agent.

The Hexgate SDK runs inside your agent and checks each step before it happens. The platform is where you write the rules and keep an eye on the agents. From that position, Hexgate knows three things the perimeter tools don't:

HEXGATE SDK
Your agentsOpenAI · LangChain · ADK · Pydantic AI
Your application logictools, MCP servers, APIs
Checks each step in-process, with no network round-trip
HEXGATE PLATFORM
Policy editorroles, rules, signed bundles
Audit & anomaliesevery decision, live and after
SaaS or on-premise: Hexgate Cloud or your own infrastructure
Hexgate SDK · Enforce

Access control inside the agent

The SDK wraps your agent and checks each tool call against your policy before it runs, using the identity of the user who asked. Your agent code stays as it is.

allowdenyapproval

Works with OpenAI Agents SDK · LangChain · Google ADK · Pydantic AI

Hexgate Platform · Analyze

Hot and cold analysis

The platform is where you write policies, watch agents while they run and go back over what they did. It flags unusual behavior and suggests policy changes to stop it.

Hot · liveCold · after the fact

Open source · SaaS on Hexgate Cloud or on-premise

04 · The control loop

The same five steps on each agent run.

Per-user authorization runs in-process, from a signed WASM bundle, before each tool call. The decisions go back to the platform, and what you learn from them becomes the next version of the policy.

  1. 01 / DEFINE

    Define

    You write deterministic rules for each agent, MCP server or tool.

    PLATFORM
  2. 02 / FETCH

    Fetch

    The SDK pulls the signed policy bundle that applies to the agent at runtime.

    SDK
  3. 03 / ENFORCE

    Enforce

    Each step the agent takes is checked in-process, before any tool call goes out.

    SDK · HOT
  4. 04 / REPORT

    Report

    Every decision (allowed, denied, held, and why) goes back to the platform.

    SDK → PLATFORM
  5. 05 / IMPROVE

    Improve

    The platform flags anomalies and suggests how to change your policies.

    PLATFORM · COLD
05 · Context-aware rules

Rules that understand context.

One policy can look at who is asking, what they're calling, how far the agent has got in this turn, and the time or environment:

Who

User ID, role and rights, carried per request as a signed token (role)

What

The tool, the model and the arguments passed (args.*)

Agent state

Tokens used in the turn, number of tools called (turn.*)

Global context

Time of day, weekends, environment (now.*)

policies/payments.yaml
version: 1

roles:
  finance:
    default_policy: { mode: deny }   # deny by default
    tools:
      send_payment:
        mode: allow
        constraints:
          - args.amount <= 10000               # what
          - args.currency in ["EUR", "USD"]
          - turn.tokens <= 50000               # agent state
          - turn.tool_calls <= 10
          - now.weekday not in ["sat", "sun"]  # context
      wire_transfer:
        mode: approval_required

  support:                           # who
    inherits: [read_only]
    tools:
      send_payment: { mode: deny }
06 · Quickstart

Wrap your agent in one line and you're enforcing on day one.

Set a key and swap your runner. Your agent code stays the same, and each tool it can call now goes through policy.

agent.py
from hexgate.adapters.openai import HexgateRunner
from hexgate.runtime import User

# picks up HEXGATE_KEY from env, no rewrite
runner = HexgateRunner()

await runner.run(
    my_agent,
    "refund order 30",
    user=User(user_id="alice", role="billing"),
)
# ↳ every tool call now routes through policy
policies/billing.yaml
version: 1
inherits: [read_only]

default_policy:
  mode: deny

tools:
  refund_order:
    mode: allow
    constraints:
      - args.amount <= 500
      - args.currency == "USD"
  wire_transfer:
    mode: approval_required

✓ Identical decisions in dev (in-process) and prod (signed WASM), proven by a parity test suite.

07 · Audit · analyze · act

Every decision on the record, and a kill-switch when one looks wrong.

Verdicts go to an append-only audit log with the rule that produced them. Hexgate flags anomalies in that log, like one user suddenly racking up denials, and a ban refuses that user's next run before the model executes.

The Hugging Face agents went unwatched for two months. Here, a burst of denials like theirs is flagged on the audit dashboard, and one click stops the next run.

audit · decisions live
u_1207read_file("policy.yaml")ALLOW
alicerefund_order(amount=600)↳ args.amount <= 500DENY
danawire_transfer(amount=50000)↳ awaiting human approvalAPPROVAL
bobissue_credit(amount=25)ALLOW
u_1207send_email(to="ops@acme.com")ALLOW
1 · Auditevery decision lands in the append-only log, with the rule behind it
2 · Analyze245 decisions27% denied0 anomaly
allow deny✕ anomaly detected
3 · Actwatching

No anomalies. Deny rates are within each user's usual range.

A burst of denies from one user gets flagged with its severity. Ban the user or the agent in one click.

FAQ

Questions, answered.

The short version of how Hexgate behaves in a real codebase.

01Do I have to rewrite my agent?

No. Hexgate ships adapters that wrap an existing OpenAI Agents, LangChain / LangGraph, Google ADK, or Pydantic AI agent without touching its logic. Swap your runner for HexgateRunner (or call wrap_langchain_agent / wrap_pydantic_agent) once. Your original agent object is left intact; the wrapper holds the policy and gates every tool the agent can invoke.

02How is Hexgate different from guardrails, firewalls or an MCP gateway?

Those sit around the agent. Firewalls and proxies see network traffic, guardrails filter prompts and outputs, and MCP gateways see which tools get called. None of them know who the end user is, what the agent is meant to do, or its state in the current turn. Hexgate runs insidethe agent and decides each tool call against the caller's role, the actual arguments and the turn's context, before it runs. It complements those layers rather than replacing them.

03Does gating every call add latency or a network round-trip?

No per-decision round-trip. Policy is evaluated in-process, either by the default pydantic engine or in production by a compiled WASM bundle run via wasmtime. The bundle is fetched once and refreshed only at turn boundaries with an ETag / 304 check, so individual decide() calls never leave the process.

04What happens when a call is denied?

A denial isn't a crash. The tool returns a [policy_denied] (or [approval_required]) marker that the model sees as the tool result, so the agent can recover or try a fallback instead of aborting the run. On Pydantic AI it surfaces as a ModelRetry; on LangChain as a structured {ok: false} result.

05How do approval-required tools work?

Mark a tool approval_required in policy, then pass an approval_handler when you wrap: True (auto-approve), False (auto-deny), or a sync/async (action, context) -> bool callback that inspects the specific call. hexgate chat prompts the terminal, hexgate serve auto-approves, and native code does whatever you wire.

06How does per-user scope work if one agent serves everyone?

Identity and rules are decoupled. A per-request User context manager carries who is calling (user_id, role, session_id, optional ttl) as a signed biscuit token; role policy files decide whatthat role can do. Role is resolved at call time from a contextvar, so a single wrapped agent serves many users concurrently without seeing each other's policies.

Unlike governance toolkits that key policy on agent_id alone, Hexgate threads the end-user identity through every decision. The same agent code runs with different effective permissions depending on which user invoked it. See the full breakdown in Hexgate vs Microsoft Agent Governance Toolkit.

07What does a policy actually look like?

A policy.yaml is deny-by-default with a tools map; each tool gets a mode (allow / deny / approval_required) and optional constraints like args.amount <= 500. Operators are ==, !=, <, <=, >, >=, in, not in, all ANDed.

The same constraint strings compile to OPA Rego for the WASM engine and run in-process for pydantic. A parity test suite proves both produce identical decisions.

08What makes a production bundle trustworthy?

Bundles are signed. The manifest carries a SHA-256 of every artifact (including the wasm_hash) plus a detached Ed25519 signature over that manifest. The hashes authenticate the files; the signature authenticates the manifest. Set HEXGATE_BUNDLE_REQUIRE_SIGNATURE=true to refuse anything unsigned or unverifiable. The signing key is the same root that signs your biscuit tokens.

09Do I need the platform, or can I run the SDK alone?

The SDK runs standalone: YAML on disk, in-process enforcement, no Docker or browser. The optional platform (a FastAPI control plane + React dashboard) adds browser policy editing, mintable tokens, a live Playground decision stream, and an append-only audit log in ClickHouse. Edit policy in the UI and the next turn picks it up.

Get started

Let your agents do more,
because nothing they do is unchecked.

Install the SDK and gate your first agent in minutes, spin it up on Hexgate Cloud, or book a walkthrough of the platform, audit log, and signed-bundle workflow.

One control layer for

SecurityIntegrityUsagePerformanceCompliance
Built by Hexamind

Hexgate is an open-source project created by Hexamind.

Hexamind builds and maintains Hexgate in the open. The SDK is MIT licensed, and every line of it is on GitHub.