2026-10-11 16:38 UTC

Casbin Gateway's maintainers claim its released local gateway centralizes coding-agent configuration and enforces Casbin policies on relayed requests, enabling shared provider and tool-access controls without replacing individual harnesses.

state: seedheat: mediumuncertainty: mediumconvergesscott: highagentic-security agent-harnesses authorizationCasbin

What is this?

Casbin Gateway is an Apache-incubating local gateway that discovers AI coding agents (Claude Code, Codex, Cursor, Gemini CLI, etc.) on a developer's machine, presents a single unified endpoint for 44+ model vendors, and compiles per-agent permission switches into Casbin policies that are enforced on every relayed request. The gateway does not replace the agents' harnesses; it sits in front of them, grading API authenticity (A–F), recording usage and prompts, and blocking disallowed tool/model/provider calls via a Casbin enforcer rather than hand-written checks. A relay token generated on first start gates access, and the system now includes egress monitoring for repository-upload risks. The claim owner's artifact is the Apache repository (github.com/apache/casbin-gateway).

Why it matters to Scott

Casbin Gateway is a concrete, Apache-incubating implementation of the local policy-enforcement gateway pattern Scott's frameworks (SiloOS, Decision Authority Infrastructure, Runtime Governance, Zero Trust for Decisions, Separation of Powers for Cognition, Architectural Containment) have argued for: a deterministic membrane in front of coding agents that compiles permission switches into Casbin policies, enforces them on every relayed request, grades API authenticity, records usage/prompts, and monitors egress for repository-upload risks. It arrives at the same architecture Scott built in OpenClaw's ve1 gateway and LiteLLM proxy, but as an open, multi-agent, Casbin-native component β€” a dated-receipts opportunity for his gateway/authority-infrastructure thesis.
ip:framework.siloosip:framework.decision-authority-infrastructureip:concept.runtime-governanceip:concept.zero-trust-for-decisionsip:framework.separation-of-powers-for-cognitionip:concept.architectural-containmentip:source.compliance-cosplayip:source.the-governance-stackdev:project.openclawdev:technology.litellmdev:concept.deterministic-agent-control-planedev:concept.padded-cell-agent-architectureradar:0pirate-ast-anonymizer-mcp-proxyradar:agentconnect-permissioned-shared-agentsradar:agent-chaperone-jev-tool-screeningradar:agent-iap-credential-brokeringradar:apiblaze-serverless-mcp-gatewayradar:ac2-agent-security-protocolradar:agentsight-ebpf-agent-observabilityradar:actualis-local-coding-agent-observability
queries asked of Scott's wikis
  • agent-harness gateway proxy pattern
  • local agent policy enforcement Casbin
  • tool-access control coding agents
  • multi-agent orchestration single endpoint
  • model sovereignty local gateway
  • agent egress monitoring data exfiltration

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 500h
points/hour across evidence Β· reading as of 2026-10-12 02:59:37.977291+11:00 Β· deterministic, not a model opinion

How the heat travelled

09-20 20:01⭐ origin directly observedCasbin Gateway: a security gateway for the AI coding agents on your machine
jhan667 on hacker news
β€”
09-21 03:23first on github (echo) Β· first seen by us Β· +7.4hThe gateway manages local coding agents and compiles permission switches into Casbin policies enforced on requests it relays; monitoring alo
Casbin Gateway maintainers
β€”
09-20 20:01amplified on hacker news πŸ‘‘hn.story.49779485
jhan667
peak 3 Β· 0 comments Β· 101% of case engagement
09-20 20:21our radar first saw it Β· +0.3hdiscovery anchor: hn.story.49779485β€”
pace: p32 vs 1032 stories at the 336h mark (now 500h old) β€” ahead of addom-local-coding-harness (1.5x), behind agentsec-static-config-auditing (0.8x)

Evidence (2) β€” ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐Casbin Gateway: a security gateway for the AI coding agents on your machine
Retrieved article excerpt

Open article Β· Retrieved 2026-09-20T20:22:46.507883+00:00

# πŸ“¦βš‘οΈ Casbin Gateway

### An open-source gateway for the AI coding agents on your machine, developed by Go and React.

[Lint](https://github.com/apache/casbin-gateway/actions/workflows/golangci-lint.yml)
[Build](https://github.com/apache/casbin-gateway/actions/workflows/build.yml)
[Go Reference](https://pkg.go.dev/github.com/apache/casbin-gateway)
[Release](https://github.com/apache/casbin-gateway/releases/latest)
[License](https://github.com/apache/casbin-gateway/blob/master/LICENSE)
[Issues](https://github.com/apache/casbin-gateway/issues)
[Stars](https://github.com/apache/casbin-gateway/stargazers)
[Forks](https://github.com/apache/casbin-gateway/network/members)
[Discord](https://discord.gg/S5UjpzGZjN)
[LINUX DO](https://linux.do "LINUX DO")

**English** | [δΈ­ζ–‡](https://github.com/apache/casbin-gateway/blob/master/README_zh.md)

**Every coding agent on the machine**

[Claude Code](https://claude.com "Claude Code")
[Claude Desktop](https://claude.ai "Claude Desktop")
[Codex](https://openai.com "Codex / Codex CLI")
[Gemini CLI](https://gemini.google.com "Gemini CLI")
[Cursor](https://cursor.com "Cursor / Cursor Agent")
[Windsurf](https://windsurf.com "Windsurf")
[Cline](https://cline.bot "Cline")
[Qwen Code](https://github.com/QwenLM/qwen-code "Qwen Code")
[iFlow CLI](https://platform.iflow.cn/en/cli "iFlow CLI")
[Kimi Code CLI](https://moonshotai.github.io/kimi-code "Kimi Code CLI")
[CodeBuddy Code](https://www.codebuddy.ai "CodeBuddy Code")
[Roo Code](https://roocode.com "Roo Code")
[Copilot CLI](https://github.com/github/copilot-cli "Copilot CLI")
[Continue](https://continue.dev "Continue")
[Zed](https://zed.dev "Zed")
[Aider](https://aider.chat "Aider")
[goose](https://github.com/aaif-goose/goose "goose")
[Crush](https://github.com/charmbracelet/crush "Crush")
[Droid](https://factory.ai "Droid")
[Trae](https://trae.ai "Trae")
[opencode](https://opencode.ai "opencode / opencode Desktop")
[OpenAgent](https://openagentai.org "OpenAgent")
[OpenClaw](https://openclaw.ai "OpenClaw")
[Hermes Agent](https://nousresearch.com "Hermes Agent")
[DeepSeek Harness](https://deepseek.com "DeepSeek Harness")
[Pi](https://pi.dev "Pi")

**Any model vendor behind one endpoint**

[OpenAI](https://openai.com "OpenAI")
[Anthropic](https://anthropic.com "Anthropic")
[Google Gemini](https://gemini.google.com "Google Gemini")
[xAI](https://x.ai "xAI")
[Mistral](https://mistral.ai "Mistral")
[Cohere](https://cohere.com "Cohere")
[Perplexity](https://perplexity.ai "Perplexity")
[DeepSeek](https://deepseek.com "DeepSeek")
[Moonshot](https://moonshot.cn "Moonshot")
[Zhipu GLM](https://z.ai "Zhipu GLM")
[Qwen](https://dashscope.aliyuncs.com "Qwen")
[MiniMax](https://minimaxi.com "MiniMax")
[Baichuan](https://baichuan-ai.com "Baichuan")
[StepFun](https://stepfun.com "StepFun")
[Volcengine Ark](https://volcengine.com "Volcengine Ark")
[Tencent Hunyuan](https://cloud.tencent.com "Tencent Hunyuan")
[Baidu ERNIE](https://baidu.com "Baidu ERNIE")
[01.AI](https://lingyiwanwu.com "01.AI")
[AI21 Labs](https://ai21.com "AI21 Labs")
[Reka](https://reka.ai "Reka")
[SiliconFlow](https://siliconflow.cn "SiliconFlow")
[Groq](https://groq.com "Groq")
[Together AI](https://together.ai "Together AI")
[Fireworks AI](https://fireworks.ai "Fireworks AI")
[Novita AI](https://novita.ai "Novita AI")
[DeepInfra](https://deepinfra.com "DeepInfra")
[ModelScope](https://modelscope.cn "ModelScope")
[PPIO](https://ppinfra.com "PPIO")
[Cerebras](https://cerebras.ai "Cerebras")
[SambaNova](https://sambanova.ai "SambaNova")
[Hyperbolic](https://hyperbolic.xyz "Hyperbolic")
[Nebius AI Studio](https://nebius.ai "Nebius AI Studio")
[Lambda](https://lambda.ai "Lambda")
[Baseten](https://baseten.co "Baseten")
[NVIDIA NIM](https://build.nvidia.com "NVIDIA NIM")
[Ollama](https://ollama.com "Ollama")
[LM Studio](https://lmstudio.ai "LM Studio")
[vLLM](https://docs.vllm.ai "vLLM")
[llama.cpp](https://github.com/ggml-org/llama.cpp "llama.cpp")
[OpenRouter](https://openrouter.ai "OpenRouter")
[AiHubMix](https://aihubmix.com "AiHubMix")
[302.AI](https://302.ai "302.AI")
[Vercel AI Gateway](https://vercel.com/docs/ai-gateway "Vercel AI Gateway")
[LiteLLM](https://litellm.ai "LiteLLM")

[Casbin Gateway](https://cdn.casbin.org/img/casbin-gateway.gif)

## Run it

One command. No database, no Go, no Node, no configuration.

On Linux and macOS:

```
curl -fsSL https://raw.githubusercontent.com/apache/casbin-gateway/master/scripts/install.sh | bash
```

On Windows, in PowerShell:

```
irm https://raw.githubusercontent.com/apache/casbin-gateway/master/scripts/install.ps1 | iex
```

Either one downloads the build for this machine, unpacks it into `~/.local/share/casbin-gateway` (`%LOCALAPPDATA%\casbin-gateway` on Windows), puts a `casbin-gateway` command on your PATH, starts it, and arranges for it to start again when you log in. The terminal you installed from is yours again straight away.

Gateway then opens in its own window β€” no sign-in: it serves this machine only and signs the local admin in on sight. Closing that window leaves Gateway running behind its tray icon, which is also where you reopen the window, turn **Start at Login** off and on β€” **Settings β†’ Startup** is the same switch β€” and quit for real. There is a **Casbin Gateway** entry on your desktop and in the Start menu, in `~/Applications`, or in the application menu, depending on the platform. An archive unpacked by hand gets the same entry the first time the launcher runs.

If you would rather use a browser, or you are on a machine with no desktop at all, everything is still at **<http://localhost:17000>**, and `casbin-gateway start` runs the server on its own with no window and no tray.

That is the whole installation. Gateway keeps its data in a SQLite file inside its own directory.

The password behind that account is `admin` / `123`, and it only matters if you open Gateway to the network β€” see [Serving other machines](https://github.com/apache/casbin-gateway#serving-other-machines).

## Screenshots

| Every agent on this machine | Everything those agents carry |
| --- | --- |
| [Agents](https://cdn.casbin.org/img/casbin-gateway-home.png) | [Skills, MCP & Prompts](https://cdn.casbin.org/img/casbin-gateway-skills.png) |
| What each one runs on, which account it is signed in to, what it has spent there, and whether it is running | Every skill, MCP server and instruction file of every agent, side by side, copied from one agent to another |



| What each agent is allowed to do | Which build each agent is on |
| --- | --- |
| [Permissions](https://cdn.casbin.org/img/casbin-gateway-permissions.png) | [Agent versions](https://cdn.casbin.org/img/casbin-gateway-versions.png) |
| Around forty switches over the agent's tools, models and providers, compiled to a Casbin policy and enforced on every request it relays | The build on this machine against the one its package manager publishes, installed, upgraded, rolled back or removed from the row it is on, whichever way it was installed |



| What the agents spent | One endpoint per model vendor |
| --- | --- |
| [Usage](https://cdn.casbin.org/img/casbin-gateway-usage.png) | [New Provider](https://cdn.casbin.org/img/casbin-gateway-new-provider.png) |
| Read from the transcripts the agents write themselves, so it counts what never went through Gateway too | 44 vendor presets, or any OpenAI- or Anthropic-compatible base URL |



| Everything the agents relayed | The whole request, not just a count |
| --- | --- |
| [LLM Records](https://cdn.casbin.org/img/casbin-gateway-llm-records.png) | [One record](https://cdn.casbin.org/img/casbin-gateway-llm-record.png) |
| Requests, tokens, cache hit rate and cost, broken down by model | The system prompt, every message, and the schema of every tool the model was offered |

## What Gateway does for each agent

| Agent | Monitoring | Provider | MCP | Skills | Prompt | Sessions | Install |
| --- | --- | --- | --- | --- | --- | --- | --- |
| **Claude Code** | βœ… | βœ… Anthropic | βœ… | βœ… | βœ… | βœ… | npm Β· brew Β· winget Β· script |
| **Claude Desktop** | βœ… | β€” | βœ… | β€” | β€” | βœ… | winget |
| **Codex CLI** | βœ… | βœ… OpenAI | βœ… | βœ… | βœ… | βœ… | npm Β· brew Β· winget Β· self |
| **ChatGPT Desktop (Codex)** | βœ… | βœ… OpenAI | βœ… | βœ… | βœ… | βœ… | store |
| **Gemini CLI** | βœ… | βœ… Gemini | βœ… | βœ… | βœ… | βœ… | npm |
| **Cursor** | βœ… | β€” | βœ… | βœ… | β€” | βœ… | brew Β· winget |
| **Cursor Agent** | βœ… | β€” | βœ… | βœ… | β€” | β€” | script Β· self |
| **Windsurf** | βœ… | β€” | βœ… | β€” | βœ… | β€” | brew Β· winget |
| **Cline** | β€” | βœ… OpenAI | βœ… | βœ… | β€” | β€” | npm |
| **Qwen Code** | βœ… | βœ… OpenAI | βœ… | βœ… | βœ… | βœ… | npm |
| **iFlow CLI** | β€” | βœ… OpenAI | βœ… | β€” | βœ… | β€” | npm |
| **Kimi Code CLI** | β€” | βœ… OpenAI | βœ… | βœ… | βœ… | β€” | npm Β· winget |
| **CodeBuddy Code** | β€” | βœ… OpenAI | βœ… | βœ… | βœ… | β€” | npm |
| **Roo Code** | β€” | β€” | β€” | β€” | β€” | β€” | β€” |
| **Copilot CLI** | β€” | β€” | β€” | β€” | β€” | β€” | npm |
| **Continue** | β€” | βœ… OpenAI | β€” | β€” | β€” | β€” | npm |
| **Zed** | β€” | βœ… OpenAI | β€” | β€” | β€” | β€” | brew Β· winget |
| **Aider** | β€” | βœ… OpenAI | β€” | β€” | β€” | β€” | β€” |
| **goose** | β€” | βœ… OpenAI | β€” | β€” | β€” | β€” | brew |
| **Crush** | β€” | β€” | β€” | β€” | β€” | β€” | npm Β· winget |
| **Droid** | β€” | βœ… OpenAI | β€” | β€” | β€” | β€” | β€” |
| **Trae** | β€” | β€” | β€” | β€” | β€” | β€” | brew Β· winget |
| **opencode** | βœ… | βœ… OpenAI | βœ… | βœ… | βœ… | βœ… | npm Β· winget Β· self |
| **opencode Desktop** | βœ… | βœ… OpenAI | βœ… | βœ… | βœ… | βœ… | winget |
| **OpenAgent** | βœ… | β€” | β€” | β€” | β€” | β€” | β€” |
| **OpenClaw** | βœ… | βœ… OpenAI | βœ… | βœ… | βœ… | βœ… | npm |
| **Hermes Agent** | βœ… | βœ… OpenAI | β€” | β€” | β€” | β€” | self |
| **DeepSeek Harness** | βœ… | βœ… OpenAI | βœ… | βœ… | β€” | βœ… | npm |
| **Pi** | β€” | βœ… OpenAI | β€” | βœ… | βœ… | β€” | npm |

- **Monitoring** β€” audit-only records of what the agent did: prompts, tool calls, permission prompts. Nothing an agent does waits on Gateway, and no answer changes because monitoring is on.
- **Provider** β€” Gateway writes the agent's own configuration to point it at a bound provider, in the wire format that agent's client speaks. An agent without it still reaches Gateway through the environment variables the UI shows.
- **MCP Β· Skills Β· Prompt** β€” read, compare and copy MCP servers, skills and the instruction file between agents.
- **Sessions** β€” prompts and token usage read straight from the agent's own transcripts, including what never went through Gateway.
- **Install** β€” what Gateway installs, upgrades and removes it with: a package manager (npm, brew, winget, the Microsoft **store**), the agent's own updater (**self**), or the vendor's own install command (**script**). An app that arrived as a setup program is still removed with the uninstaller it registered. Everything else is a download from its vendor's page.

## Features

- **[Is the API behind that key what it was sold as?](https://github.com/apache/casbin-gateway#the-killer-feature-is-the-api-behind-that-key-what-it-was-sold-as)** β€” a reseller can quietly swap in a cheaper model or fake a cache hit, and none of it shows up in the traffic. Authenticity asks the upstream directly and grades it A–F.
- **[Switch every agent's provider from one place](https://github.com/apache/casbin-gateway#send-an-agents-traffic-through-gateway)** β€” change an API key or base URL once, and every agent pointed at Gateway picks it up.
- **[Add a provider, an MCP server, a prompt or a skill from a link](https://github.com/apache/casbin-gateway#import-from-a-link)** β€” click a vendor's "add this" button on the web and Gateway opens with what the link carries, before any of it is written.
- **[Run several instances of one agent side by side](https://github.com/apache/casbin-gateway#what-to-do-next)** β€” e.g. multiple Claude Desktop instances, each signed in to a different account.
- **[Install, upgrade and roll back the agents themselves](https://github.com/apache/casbin-gateway#what-to-do-next)** β€” which build each agent is on against what its package manager publishes, and back to an older release when an update broke something. One click whichever way it was installed, with the command shown
jhan66730
🟧 echo.githubThe gateway manages local coding agents and compiles permission switches into Casbin policies enforced on requests it relays; monitoring aloCasbin Gateway maintainersβ€”β€”

Interpretation history

Decision trace