Oct 7, 2026 · 2 min read

Open-Source AI Agent Gateway Keeps Credentials Secure

Tuskira has released an open-source AI Agent Gateway that separates agents from sensitive credentials while controlling access to MCP tools and model providers.

By @nomulagangothri

Source: https://www.helpnetsecurity.com/2026/10/07/open-source-ai-agent-gateway/

Open-Source AI Agent Gateway Keeps Credentials Secure

Open-source gateway aims to keep AI agent credentials away from agents

As AI agents become more capable, they are increasingly being connected to tools, APIs, databases and business systems. That creates a new security problem: the more access an agent receives, the more important it becomes to control the credentials behind that access.

Tuskira has released an open-source AI Agent Gateway designed to address this problem.

The gateway sits between an AI agent and the tools or model providers that the agent uses. Instead of putting sensitive credentials directly into every agent configuration, the gateway can store the real credentials separately and provide them only when an authorized request is made. Help Net Security

The basic architecture is:

AI Agent → Gateway + Policy → MCP Tools → External Systems

For example, an AI coding agent might need access to GitHub. In a traditional setup, the GitHub token could be stored in the agent's configuration. If that configuration is leaked, the token could potentially be misused.

With the gateway approach, the agent sends a gateway key and profile information. The gateway checks whether that profile is permitted to use the requested tool. If the request is allowed, the gateway retrieves the actual credential from encrypted storage and attaches it when communicating with the backend. The agent itself never receives the GitHub token. Help Net Security

The gateway also checks permissions at the time of each tool call. That means an agent cannot simply request a tool it was never authorized to use. Denied requests are blocked and logged instead of being passed to the backend. Help Net Security

Tuskira says the gateway can work with MCP infrastructure as well as several model providers, including Anthropic, OpenAI and Gemini. It also records token usage and estimated costs for model calls. The project is available as open source and can run in a team's own environment. Help Net Security

The security idea is straightforward:

Don't give the agent the keys. Give the agent controlled access through a security layer.

This becomes particularly important as AI agents move from answering questions to taking actions. An agent connected to GitHub, Jira, databases, cloud infrastructure or internal company systems can potentially make changes without a person manually approving every step.

There are still important deployment considerations. Tuskira's documentation warns that profiles should be properly bound to gateway keys and that some demo configurations need to be changed before being used in shared or production environments. Help Net Security

The bigger trend is that AI agent security is becoming its own infrastructure layer.

As agents gain more capabilities, organizations will need to control not only what an agent can do, but also which identity and credentials it can use, which tools it can access, and whether each individual action is authorized.

  • – views
  • – likes
  • – saves
  • – shares

Comments (0)

Sign in to leave a comment.