New · Policies as code in the CLI

The authorization layerfor AI agents.

Before every action, one answer: allow, review, or block.

Start free

API, SDKs, and an MCP gateway

Every action, one verdict

What Vulnify does.

It sits in front of the sensitive tool call and sees who acts, which action, where it goes, and how many records. Not the records.

Use it from Node, Python, LangChain, MCP or straight from your {code}.

npm install @vulnify/sdkpip install vulnify

One call. Three answers.

Wrap the sensitive tool call. The agent already knows what to do with the answer.

agent.ts
await vulnify.guard(
  {
    agent: 'support-agent',
    action: 'READ_RECORD',
    resource: 'orders',
    recordsAffected: 1,
  },
  () => readOrder(4812),
);
ResponseThe order was read.
{
  "decision": "ALLOW",
  "riskScore": 12,
  "reasons": [
    "Single record read inside the policy"
  ]
}

The secret stays
in the vault.

Through the beta gateway, the call goes through Vulnify. The credential is injected only on ALLOW and never stays on the agent.

support-agent · tool call
GET /orders/4812
Authorization: —

The agent holds no credential. It only says what it wants to do.

1 of 4Gateway · beta

Encrypted vault

Third-party credentials live in the vault, not in the agent or the prompt.

Fail closed

If Vulnify is unreachable, the action does not run, unless you choose fail open.

Monitor mode

Start by watching. The verdict is recorded and nothing stops yet.

Simple pricing.
Start free.

List prices in USD. No annual plan and no overage charge.

Common questions.

Agents that act.
Companies that decide.

The Developer plan is free. Design partners get three months at no charge, for weekly feedback.