Pangolin’s maintainers claim their released AI gateway replaces provider API-key distribution with SSO-authenticated WireGuard connections, potentially reducing credential exposure and centralizing identity-based access to team LLM services.
state: expiredheat: lowuncertainty: mediumknownscott: mediumllm-gateways agentic-security zero-trustPangolin
What is this?
Pangolin is an open-source zero-trust remote-access platform whose version 1.22 adds an AI Gateway for cloud and self-hosted models. The gateway acts as an identity-aware proxy: coding agents and other AI clients connect through SSO-authenticated WireGuard tunnels, while provider credentials remain centralized rather than being distributed to users. The supplied material supports the architecture and access-control claims, but does not independently demonstrate that it reduces overall credential risk; centralizing provider keys may also concentrate security impact at the gateway.
Why it matters to Scott
Scott already holds this architecture in Company AI Gateway and operates its component patterns through LiteLLM and WireGuard-based Tailscale, so the core position is known rather than new convergence. Pangolin is still practically relevant as a packaged implementation of identity-based, secret-centralized LLM access that could inform his gateway stack, though the supplied evidence does not establish a net reduction in risk or address the gateway’s concentrated blast radius.
ip:concept.company-ai-gatewaydev:technology.litellmdev:technology.tailscaleradar:concept.agent-authenticationradar:concept.credential-isolation
queries asked of Scott's wikis
- secretless LLM access and API-key distribution
- identity-aware gateways for coding agents
- zero-trust access to team AI services
- centralized AI credentials and blast radius
- WireGuard tunnels as agent authentication
- LLM gateway control-plane architecture
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-09T16:30:16Z
The announcement has become a static tooling-comparison reference rather than a developing story: repeated reviews have added no deployment, integration, or security evidence, and no concrete follow-up is expected. Expiring monitoring does not dispute the release or its architectural relevance; independent operational findings would justify reopening it.
2026-09-07T16:27:25Z
This remains a released implementation to compare with Scott’s existing gateway stack, not new validation of the architecture’s security benefits. The staleness review adds no evidence beyond the original maintainer line; further attention should depend on deployment experience, integration details, or security findings rather than the surrounding agent-security activity.
2026-09-05T15:31:59Z
Pangolin remains a packaged implementation worth comparing with Scott’s existing gateway stack, not evidence that network-identity authentication delivers a net security improvement. No independent deployment or security evidence has arrived; the release announcement and reconstructed maintainer testimony remain one evidentiary line.
2026-09-03T14:40:32Z
The forced re-evaluation adds no new evidence or adoption signal; this remains a first-party packaged implementation of an architecture Scott already knows, with its claimed net security benefit still unvalidated.
2026-09-03T14:29:50Z
grounded: known/medium — Scott already holds this architecture in Company AI Gateway and operates its component patterns through LiteLLM and WireGuard-based Tailscale, so the core posit
2026-09-03T14:27:42Z
case created — The released gateway applies a concrete network-identity security model to shared LLM access rather than offering only general security guidance.
Decision trace
- 09-10 02:30expireThe announcement has become a static tooling-comparison reference rather than a developing story: repeated reviews have added no deployment, integration, or security evidence, and no concrete follow-u
- 09-10 02:30alert_silentThere is no new consequential delta to surface. The existing implementation remains relevant to a future gateway comparison, but nothing changes Scott’s decisions today or makes the next briefing too
- 09-10 02:30alert_routeThere is no new consequential delta to surface. The existing implementation remains relevant to a future gateway comparison, but nothing changes Scott’s decisions today or makes the next briefing too
- 09-08 02:27repriceThis remains a released implementation to compare with Scott’s existing gateway stack, not new validation of the architecture’s security benefits. The staleness review adds no evidence beyond the orig
- 09-08 02:27alert_silentThere is no new release, access change, or implementation finding that changes Scott’s decisions today. The existing announcement can remain a tooling-comparison reference without interrupting him.
- 09-08 02:27alert_routeThere is no new release, access change, or implementation finding that changes Scott’s decisions today. The existing announcement can remain a tooling-comparison reference without interrupting him.
- 09-06 01:31repricePangolin remains a packaged implementation worth comparing with Scott’s existing gateway stack, not evidence that network-identity authentication delivers a net security improvement. No independent de
- 09-06 01:31alert_silentThe announced release remains established, but this review adds no consequential change in access, implementation, or security findings. A later tooling comparison is sufficient; nothing new makes the
- 09-06 01:31alert_routeThe announced release remains established, but this review adds no consequential change in access, implementation, or security findings. A later tooling comparison is sufficient; nothing new makes the
- 09-04 00:40repriceThe forced re-evaluation adds no new evidence or adoption signal; this remains a first-party packaged implementation of an architecture Scott already knows, with its claimed net security benefit still
- 09-04 00:40alert_silentThere is no new consequential delta since the prior review, and unchanged engagement supplies neither independent validation nor an implementation reason Scott needs today.
- 09-04 00:40alert_routeThere is no new consequential delta since the prior review, and unchanged engagement supplies neither independent validation nor an implementation reason Scott needs today.
- 09-04 00:34alert_silentPangolin’s maintainers have announced a packaged SSO-and-WireGuard AI gateway, but the architecture largely matches Scott’s existing gateway direction and the supplied evidence adds no implementation
- 09-04 00:34surface_candidatePangolin’s maintainers have announced a packaged SSO-and-WireGuard AI gateway, but the architecture largely matches Scott’s existing gateway direction and the supplied evidence adds no implementation
- 09-04 00:34alert_routePangolin’s maintainers have announced a packaged SSO-and-WireGuard AI gateway, but the architecture largely matches Scott’s existing gateway direction and the supplied evidence adds no implementation
- 09-04 00:29groundScott already holds this architecture in Company AI Gateway and operates its component patterns through LiteLLM and WireGuard-based Tailscale, so the core position is known rather than new convergence
- 09-04 00:27createThe released gateway applies a concrete network-identity security model to shared LLM access rather than offering only general security guidance.