Secure your agents.
The gofl platform gives agents the identity standards your security team already trusts. Connect any framework with one lightweight SDK.
Govern every call
Every model, tool, MCP and database call passes one gateway — under one identity, one audit trail, one policy. Same governance, builder-built or your own code.
Secrets never reach the model
The gateway injects a scoped, short-lived credential at egress. The agent and the LLM never see a standing secret.
Every call attributed
Bound to the signed-in person or a named service account — human or machine. Attributed, never NULL.
One audit trail
Model spend and every tool, MCP and database call in a turn share one trace under one identity.
Govern your own code
Declare models, tools and access as Kubernetes resources. Your engineers’ own agents get the same plane — as code.
The standards we spent a decade building — now for agents
OAuth and OIDC gave enterprise software scopes, resource owners and resource servers. Agents arrived and threw all of it out. gofl brings those same primitives to every agent call — so your security team governs agents with the model they already trust, not a bespoke one.
Bounded permission, per call
An agent can only do what its scope allows — never the user’s full access. The same idea that has bounded API clients for years, now bounding agents.
The person the agent acts for
Every call is tied to the human — or service — on whose behalf it runs. The resource owner is explicit, not lost the moment an agent takes over.
Your models, tools, DBs and APIs
Each destination validates the token and enforces its own access. The gateway never bypasses it — exactly how resource servers have always worked.
On-behalf-of, provably
The agent presents a short-lived token that names both who acted and on whose authority — standard delegation, applied to autonomous agents.
Lightweight SDK
The whole integration is a base URL and an import. Reach any model through your gofl key, and call any tool on a user’s behalf with one GoflAuth — in the framework you already use.
Any model, any provider
Open-weight models on your own GPUs, or a frontier model reached through the provider you already run. One contract for all of them — swap the model, not your code.
Sovereign, on your hardware
Run open-weight models on your own GPUs — in-region, nothing leaving your boundary.
Frontier, through your provider
Reach the latest hosted models through the cloud account you already run. The provider credential never leaves the gateway.
One model contract
Every model — self-hosted or hosted — speaks the same API. Switching is a string.
Deploy where you are comfortable
Self-host on the infrastructure you already run, or let us run it for you — the same platform and the same governance, either way.
gofl installs as an appliance on the infrastructure you already run — any cloud, your own Kubernetes, bare metal, even air-gapped. Nothing phones home. One helm install, one knob: a domain.
$ helm install gofl gofl/gofl \
--set domain=gofl.acme.comBook a demo.
Tell us what you want to build and we’ll get back to you.
Or email me directly — [email protected]