AgentPort
Open-source Security Gateway For Agents
Details
- External ID
- 47950752
- Source
- HN
- Company
- —
- Product
- AgentPort
- Website domain
- agentport.sh
- Launched
- April 29, 2026
- Cohort
- —
- Upvotes
- 8
- Upvotes percentile
- 0.4813624678663239
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hey HN!I've been wanting to use something like OpenClaw for a while but couldn't get myself to give it access to anything important due to all the risks involved. Prompt injection is still a problem (even though some people seem to ignore it) and so are hallucinations and mishaps that cause agents to do things like delete production data [1].Even harnesses like Claude Code and Codex are subject to this, particularly since we're getting progressively looser about how we run them e.g. Conductor is really popular and runs agents without any sandboxing.That means we're in a bit of an all-or-nothing situation. There are people who just ignore the risks and connect everything to their agents and reap benefits from it while being subject to more risk, and there are others that just don't connect anything because they are mindful of the potential issues.I've been quite cautious but have wanted to run more autonomous agents and so I built the component I needed to enable me to do so: AgentPort.AgentPort is a gateway that connects to any service (e.g. Gmail, GitHub, Stripe, PostHog, Linear) and let's you set granular permissions for what the agent can do automatically, what it needs your approval for, and what it can never do.For example, you can set `list_customers` and `get_customer` on the Stripe integration to "Auto-approve" but `create_refund` to "Ask for approval". The agent will thus be able to do a lot in the background independently but when it comes to a potentially destructive operation it will be blocked and receive an approval link to send to you. You can then approve or deny the call with those exact parameters e.g. `create_refund(customer_id: 1234, amount: 12)`.Agents connect via MCP or CLI and have access to all the integrations you connected without ever getting API keys. Kind of like Composio but with granular permissions and open source.The goal with AgentPort is to specifically address two vulnerabilities that agents are subject to:1. Destructive operations on downstream services: It can't delete a database unless you explicitly approve 2. Credential exfiltration: Your agent never sees API keysAgentPort also helps with sensitive data exfiltration, but that is more nuanced and complicated to defend against if the agent has an internet connection [2].Ultimately, AgentPort was the missing piece for me to start running more autonomous agents that have access to third-party services, and hopefully it can unlock use cases for you too. There's a ton more work needed around securing agents (Claws in particular) and I've both been writing about it [3] and intend to do more in this space, so if you're thinking about similar things let's have a chat.The repo is https://github.com/yakkomajuri/agentport and you can run it locally with docker compose in a minute or use the one-liner install to deploy a prod instance (domain, TLS, etc.) in just a few mins as well.[1] "An AI agent deleted our production database. The agent's confession is below" (https://news.ycombinator.com/item?id=47911524)[2] See my post "On agents dropping production databases": https://yakko.dev/blog/on-agents-dropping-production-dbs[3] https://yakko.dev/blog
Enrichment
- Theme
- AI agent frameworks and developer tools
- Vertical
- Security
- Function
- Compliance & governance
- Audience
- Developer
- AI stance
- AI-native
- Project type
- Hobby / open-source project
- Normalized one-liner
- security gateway for ai agents
- Manually corrected
- False
Could you build this?
Partial Basic API proxying is straightforward, but building a robust security gateway protecting against sophisticated prompt injections, side-channel leaks, and unauthorized tool calls requires deep application security and adversarial ML defense expertise.
What it would actually take: Requires an inline reverse proxy running high-throughput streaming inspection, AST/JSON schema validation for tool calls, credential compartmentalization, and specialized heuristic/ML classifier pipelines to detect jailbreaks and prompt injection without introducing massive latency.
Discussion
3 comments analyzed.
Competitors mentioned: Composio, MCP gateways
Feature requests: Custom tool integrations, Support for custom tools integration
Competitors
Other products that read as similar to this one — 436 launches clear the similarity bar, closest 8 shown.
Attention rank: #259 of 437 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 177 days after the earliest competitor.
- Zeroclawed: Secure Agent Gateway · hn · 2026-04-10 · 8 upvotes · similarity 0.64
- I built a firewall for agents because prompt engineering isn't security · hn · 2026-01-19 · 7 upvotes · similarity 0.52
- FireClaw · hn · 2026-03-17 · 5 upvotes · similarity 0.52
- I built an open-source alternative to Claude Cowork · hn · 2026-07-02 · 39 upvotes · similarity 0.51
- OpenClaw-superpowers · hn · 2026-03-15 · 8 upvotes · similarity 0.51
- Agent Vault · hn · 2026-04-22 · 156 upvotes · similarity 0.51
- ClawShell, Process-Level Isolation for OpenClaw Credentials · hn · 2026-02-19 · 10 upvotes · similarity 0.51
- Running local OpenClaw together with remote agents in an open network · hn · 2026-04-04 · 8 upvotes · similarity 0.50
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a compliance & governance tool for Media & entertainment yet.