How it works

Every agent decision,
checked against your rules.

Hexgate has two parts: an SDK that runs inside your agents and a platform that governs them. Both are open source.

$ pip install hexgate
Try the cloud version
HEXGATE SDK
Your agentsOpenAI · LangChain · ADK · Pydantic AI
Your application logictools, MCP servers, APIs
Enforces on every step, in-process, no round-trip
HEXGATE PLATFORM
Hotreal time
Coldafter the fact
SaaS or on-premise: Hexgate Cloud or your own infrastructure
01 · Two components

Hexgate = SDK + Platform

Both are open source. The platform is available as SaaS on Hexgate Cloud or on-premise.

The Hexgate SDK · inside your agent

The SDK wraps your agent and your application logic. It fetches policies from the platform, enforces them on every step and reports each decision back. You keep your agent code as it is.

Compatible with OpenAI Agents SDK · LangChain · Google ADK · Pydantic AI

pypi.org/project/hexgate →
The Hexgate platform · your control center

The platform is where you define policies, watch agents live and analyze their behavior over time. It runs as SaaS or on-premise.

Open source · self-host or managed

github.com/HexamindOrganisation/hexgate →
02 · The control loop

Five steps, on every agent run

Updated policies flow back to step 1. The loop keeps going.

  1. 01 / DEFINE

    Define

    You write deterministic rules for each agent, MCP server or tool.

    PLATFORM
  2. 02 / FETCH

    Fetch

    The SDK pulls the signed policy bundle that applies to the agent at runtime.

    SDK
  3. 03 / ENFORCE

    Enforce

    Each step the agent takes is checked in-process, before any tool call goes out.

    SDK · HOT
  4. 04 / REPORT

    Report

    Every decision (allowed, denied, held, and why) goes back to the platform.

    SDK → PLATFORM
  5. 05 / IMPROVE

    Improve

    The platform flags anomalies and suggests how to change your policies.

    PLATFORM · COLD
03 · Hot and cold governance

Stop it before it runs. Learn from it after.

Hot · real time
  • Checks every decision before it runs
  • Blocks calls that break a policy, or holds them for a human
  • No change to your agent logic
Cold · after the fact
  • Stores every policy decision in an append-only log
  • Detects anomalies and drift in agent behavior
  • Suggests policy changes
04 · Context-aware rules

Rules that understand context

A single policy can combine:

Who

User ID, role and rights, carried per request as a signed token (role)

What

The tool, the model and the arguments passed (args.*)

Agent state

Tokens used in the turn, number of tools called (turn.*)

Global context

Time of day, weekends, environment (now.*)

policies/payments.yaml
version: 1

roles:
  finance:
    default_policy: { mode: deny }   # deny by default
    tools:
      send_payment:
        mode: allow
        constraints:
          - args.amount <= 10000               # what
          - args.currency in ["EUR", "USD"]
          - turn.tokens <= 50000               # agent state
          - turn.tool_calls <= 10
          - now.weekday not in ["sat", "sun"]  # context
      wire_transfer:
        mode: approval_required

  support:                           # who
    inherits: [read_only]
    tools:
      send_payment: { mode: deny }

Ready to wire it in? See the quickstart →

Get started

Take back control of your AI agents.

Open source. Runs as SaaS or on your own infrastructure.

Built by Hexamind

Hexgate is an open-source project created by Hexamind.

Hexamind builds and maintains Hexgate in the open. The SDK is MIT licensed, and every line of it is on GitHub.