Nodra
Menu
RUNTIME ENFORCEMENT

Protected Agent Gateway

The gateway is the enforcement boundary between a protected agent and consequential tools or resources.

Documentation Security model

Implementation checklist

Complete these steps in the customer-owned server or agent runtime.

  1. Authenticate every protected agent request.
  2. Verify timestamp, nonce, body digest and HMAC signature.
  3. Evaluate the registered agent authority scope.
  4. Record tamper-evident authorization evidence.
  5. Return allow, deny or require-approval decisions before execution.

Security boundary

Keep the credential server-side. Never expose it in browser code.

The public guide explains the integration contract without exposing Nodra's private control-plane implementation.

Reference implementation

Use this as the server-side starting point.

POST /api/gateway/authorize
x-nodra-credential: <server-side secret>
x-nodra-timestamp: <unix seconds>
x-nodra-nonce: <unique nonce>
x-nodra-signature: v1=<hmac-sha256>

Ready to validate a real workflow?

Use the Demo Lab for a self-guided sandbox, or review the 7-day technical validation for a real design-partner workflow.

Explore safe Demo Lab7-day validation