The authorization layerfor AI agents.
Before every action, one answer: allow, review, or block.
API, SDKs, and an MCP gateway
Every action, one verdict
What Vulnify does.
It sits in front of the sensitive tool call and sees who acts, which action, where it goes, and how many records. Not the records.
Use it from Node, Python, LangChain, MCP or straight from your {code}.
npm install @vulnify/sdkpip install vulnify
One call. Three answers.
Wrap the sensitive tool call. The agent already knows what to do with the answer.
await vulnify.guard(
{
agent: 'support-agent',
action: 'READ_RECORD',
resource: 'orders',
recordsAffected: 1,
},
() => readOrder(4812),
);
{
"decision": "ALLOW",
"riskScore": 12,
"reasons": [
"Single record read inside the policy"
]
}
The secret stays
in the vault.
Through the beta gateway, the call goes through Vulnify. The credential is injected only on ALLOW and never stays on the agent.
The agent holds no credential. It only says what it wants to do.
Encrypted vault
Third-party credentials live in the vault, not in the agent or the prompt.
Fail closed
If Vulnify is unreachable, the action does not run, unless you choose fail open.
Monitor mode
Start by watching. The verdict is recorded and nothing stops yet.
Simple pricing.
Start free.
List prices in USD. No annual plan and no overage charge.
Common questions.
Agents that act.
Companies that decide.
The Developer plan is free. Design partners get three months at no charge, for weekly feedback.
