The enforcement hook
One authorisation point on every request, joining admission, policy and evidence.
The single authorisation target
The components we ship and support today. Any of them can be substituted without changing what the hook does.
-
Envoy terminates the connection
TLS 1.3 at minimum. Envoy routes to the Agent Router with no authorisation filter of its own: the router calls the hook.
-
oauth2-proxy federates to your identity provider; commercial federation is in build
The only component that talks to your OIDC identity provider; it passes the subject and groups onward. Federation to a commercial identity provider is in build, and the demonstration runs against a local stub.
-
The hook authorises; the router forwards
The Agent Router calls the hook before it forwards, and the hook forwards nothing. It resolves the caller, joins entitlement to admission state and asks the policy engine. Anything unreachable or unparseable is a deny.
-
A small, stable client surface
The OpenAI-compatible surface, with model listing limited to the admitted catalogue. On the client the change is a base URL and a key, not a new tool.
Virtual keys
A virtual key is an issued credential with a subject, role and groups. The gateway issues, rotates and revokes them through its admin API. The secret is never stored, only its fingerprint.
Revocation
Checked on every request, with no cache. A revoked key is rejected on the next request.
Lifecycle
Issue, rotate and revoke are audited. The key change and its audit event commit in one transaction.
Browser sessions
A request authenticated by a session rather than a key is recorded with a session identifier, so the ledger still names how the caller was authenticated.
Virtual key record an example, not a live record
{
"id": "vk_7f3a91",
"subject_id": "8f1c2e",
"groups": ["engineering"],
"role": "standard",
"issued_at": "2026-09-01T00:00:00Z",
"expires_at": "2026-11-30T00:00:00Z",
"revoked_at": null,
"fingerprint": "sha256:9f2c..."
}
Entitlement, and what the substrate owns
OPA decides which admitted models a role may reach. A virtual key only reaches a model the gate admitted, at a named attestation version, and an unknown id is denied with a reason rather than passed through.
Role-to-model entitlement
Group-keyed: each model id resolves only at the attestation version the gate named.
Rate limits
Per-minute request and token limits are enforced by the routing substrate, whose integration is in build; your own Rego can also decide on them.
Token budgets
Monthly, per role or per team (a set of groups). The month-to-date figure comes from the ledger, so a restart cannot reset it.
Scope
- Built on Agent Router. Routing, retries and caching come from the Agent Router substrate, whose integration is in build. You pay for the governance on top.
- Entitlement, not content. The hook decides who may reach which model; it leaves prompts and completions as they are.
- Your tools stay yours. Your coding agent runs its tools on the client side and keeps working as it does today.
Seeing where the enforcement hook sits in your estate? Heliast runs the gateway inside your environment, on your policy.
Book a discovery session