Govern traffic
The controls Orca AI Gateway applies to every call - who is calling, what they may do, how much they may spend, and what content is allowed through.
Governance in Orca AI Gateway is a pipeline. Every request passes the same stages in the same order, whether it is a chat completion or an MCP tool call, and each stage is a named plugin instance you configure rather than code you write.
client
-> auth validator who is this, and what scope are they in
-> authorizer may this principal make this call
-> route + limiter select an upstream, then reserve rate and spend headroom
-> payload guardrail is the request content allowed, and does it need redacting
-> policy guardrail is this model or tool action allowed
-> destination
-> response policies record model usage or suppress a denied tool result
-> payload guardrail inspect a non-streaming response
-> clientIdentity
Scope dimensions and the validators that mint a principal from a credential.
Authorization
Decide whether a principal may make a call, with static ACLs or OPA.
Rate limits
Enforce request and token windows per verified scope and principal.
Spend controls
Price model calls, reserve worst-case cost, and enforce calendar budgets.
Payload guardrails
Redact sensitive data and block unsafe content in requests and buffered responses.
Policy guardrails
Evaluate action, model, token, and spend policy from a file or the Agent Engine registry on model and MCP traffic.
Vaults
Resolve upstream credentials at call time so callers never hold them.
Security model
Trust boundaries, what is in and out of scope, and how secrets are handled.
Failing open and failing closed
Every plugin instance carries a failure_mode that decides what a runtime error means - as
distinct from an intentional deny:
failure_mode | On plugin error | Use for |
|---|---|---|
deny (default) | The request is refused | Authorization and compliance guardrails |
allow | The request proceeds; an audit event records the failure | Non-critical heuristics where availability matters more |
log_only | Same as allow, logged at warning level | Telemetry sinks |
The related required flag is present in configuration, but initialization errors currently fail
gateway boot regardless of its value. /readyz becomes healthy after AppState construction and
does not aggregate ongoing plugin health.
Scope is yours to define
Nothing in the gateway hard-codes what a tenant is. A principal carries a scope: a map of
dimensions you declare in identity.scope_dims. Routes, rate limits, authorizers, and sinks all
match on those dimensions, so the same binary serves a single-tenant deployment with no dimensions
and a multi-tenant one keyed on workspace_id and env.