Glossary
Definitions for the configuration sections and concepts in Orca AI Gateway, with the canonical spelling of each term.
The terms these docs use, and how each one is written. Most map directly to a section of the gateway configuration document, and the entry links to the page that covers it.
Where an entry lists kinds, it lists the kinds the shipped binary supports.
- audit sink
- Where authorization and guardrail decisions are written. Kinds are
noop,stdout,file,kafka, andext_proc. - auth validator
- Verifies the caller's credential and maps trusted identity data onto scope dimensions. Kinds are
jwtandapi_key. - authorizer
- Decides whether an authenticated request may proceed. Kinds are
yaml_acl,opa_http,ext_proc, andallow_all. - cost model
- Resolves model token prices for usage records, spend admission, and budget enforcement.
- destination
- An upstream the gateway forwards to - a model provider or an MCP server - with its credentials, model map, and pricing.
- MCP server
- An external Model Context Protocol endpoint whose tools an agent can call. Declared inline on the agent, never a standalone registry resource.
- payload guardrail
- A payload inspection step that can block or rewrite a request or buffered response. Configured under
plugins.guardrails[]. - policy guardrail
- An Agent Engine guardrail, or a rule from a local file bundle, evaluated against model and MCP tool traffic with optional state.
- rate limiter
- Caps requests, tokens, or calendar spend per scope.
token_bucket_localkeeps counters in one process;redis_windowshares them across replicas. - route
- A match rule that selects a destination by path, model, header, or scope, and carries retry and fallback behavior.
- scope
- The tenancy dimensions a request carries, derived from JWT claims and used to match routes and apply limits.
- tape
- A recorded request and response pair, captured for replay and debugging.
- usage sink
- Where per-request token and cost records are written. Kinds are
stdout,kafka,postgres, andregistry. - vault
- Workspace-scoped credential storage. A session passes vault IDs, and the gateway injects the matching credential into MCP calls. Not "Vault".
- vault resolver
- Fetches a secret for a destination. Kinds are
env,static_file, andhttp. - Workspace
- The StreamNative Cloud resource that hosts Orca and is the isolation unit for tenancy, identity, and quotas. Capitalized: it names a specific platform resource. Not "workspace".