Cloud and BYOC for Orca Agent Engine are in Private Preview — request an invite
Docs

Govern traffic

The controls Orca AI Gateway applies to every call - who is calling, what they may do, how much they may spend, and what content is allowed through.

Governance in Orca AI Gateway is a pipeline. Every request passes the same stages in the same order, whether it is a chat completion or an MCP tool call, and each stage is a named plugin instance you configure rather than code you write.

client
  -> auth validator      who is this, and what scope are they in
  -> authorizer          may this principal make this call
  -> route + limiter     select an upstream, then reserve rate and spend headroom
  -> payload guardrail   is the request content allowed, and does it need redacting
  -> policy guardrail    is this model or tool action allowed
  -> destination
  -> response policies   record model usage or suppress a denied tool result
  -> payload guardrail   inspect a non-streaming response
  -> client

Failing open and failing closed

Every plugin instance carries a failure_mode that decides what a runtime error means - as distinct from an intentional deny:

failure_modeOn plugin errorUse for
deny (default)The request is refusedAuthorization and compliance guardrails
allowThe request proceeds; an audit event records the failureNon-critical heuristics where availability matters more
log_onlySame as allow, logged at warning levelTelemetry sinks

The related required flag is present in configuration, but initialization errors currently fail gateway boot regardless of its value. /readyz becomes healthy after AppState construction and does not aggregate ongoing plugin health.

Scope is yours to define

Nothing in the gateway hard-codes what a tenant is. A principal carries a scope: a map of dimensions you declare in identity.scope_dims. Routes, rate limits, authorizers, and sinks all match on those dimensions, so the same binary serves a single-tenant deployment with no dimensions and a multi-tenant one keyed on workspace_id and env.

On this page