Menu
Protected Agent Gateway
The gateway is the enforcement boundary between a protected agent and consequential tools or resources.
Implementation checklist
Complete these steps in the customer-owned server or agent runtime.
- Authenticate every protected agent request.
- Verify timestamp, nonce, body digest and HMAC signature.
- Evaluate the registered agent authority scope.
- Record tamper-evident authorization evidence.
- Return allow, deny or require-approval decisions before execution.
Security boundary
Keep the credential server-side. Never expose it in browser code.
The public guide explains the integration contract without exposing Nodra's private control-plane implementation.
Reference implementation
Use this as the server-side starting point.
POST /api/gateway/authorize
x-nodra-credential: <server-side secret>
x-nodra-timestamp: <unix seconds>
x-nodra-nonce: <unique nonce>
x-nodra-signature: v1=<hmac-sha256>Ready to validate a real workflow?
Use the Demo Lab for a self-guided sandbox, or review the 7-day technical validation for a real design-partner workflow.