The SDK wraps your agent and your application logic. It fetches policies from the platform, enforces them on every step and reports each decision back. You keep your agent code as it is.
pypi.org/project/hexgate →How it works
Hexgate has two parts: an SDK that runs inside your agents and a platform that governs them. Both are open source.
Both are open source. The platform is available as SaaS on Hexgate Cloud or on-premise.
The SDK wraps your agent and your application logic. It fetches policies from the platform, enforces them on every step and reports each decision back. You keep your agent code as it is.
pypi.org/project/hexgate →The platform is where you define policies, watch agents live and analyze their behavior over time. It runs as SaaS or on-premise.
github.com/HexamindOrganisation/hexgate →Updated policies flow back to step 1. The loop keeps going.
You write deterministic rules for each agent, MCP server or tool.
PLATFORMThe SDK pulls the signed policy bundle that applies to the agent at runtime.
SDKEach step the agent takes is checked in-process, before any tool call goes out.
SDK · HOTEvery decision (allowed, denied, held, and why) goes back to the platform.
SDK → PLATFORMThe platform flags anomalies and suggests how to change your policies.
PLATFORM · COLDA single policy can combine:
User ID, role and rights, carried per request as a signed token (role)
The tool, the model and the arguments passed (args.*)
Tokens used in the turn, number of tools called (turn.*)
Time of day, weekends, environment (now.*)
version: 1
roles:
finance:
default_policy: { mode: deny } # deny by default
tools:
send_payment:
mode: allow
constraints:
- args.amount <= 10000 # what
- args.currency in ["EUR", "USD"]
- turn.tokens <= 50000 # agent state
- turn.tool_calls <= 10
- now.weekday not in ["sat", "sun"] # context
wire_transfer:
mode: approval_required
support: # who
inherits: [read_only]
tools:
send_payment: { mode: deny }
Ready to wire it in? See the quickstart →
Open source. Runs as SaaS or on your own infrastructure.
Hexamind builds and maintains Hexgate in the open. The SDK is MIT licensed, and every line of it is on GitHub.