Cloud and BYOC for Orca Agent Engine are in Private Preview — request an invite
Docs

Glossary

Definitions for the configuration sections and concepts in Orca AI Gateway, with the canonical spelling of each term.

The terms these docs use, and how each one is written. Most map directly to a section of the gateway configuration document, and the entry links to the page that covers it.

Where an entry lists kinds, it lists the kinds the shipped binary supports.

audit sink
Where authorization and guardrail decisions are written. Kinds are noop, stdout, file, kafka, and ext_proc.
auth validator
Verifies the caller's credential and maps trusted identity data onto scope dimensions. Kinds are jwt and api_key.
authorizer
Decides whether an authenticated request may proceed. Kinds are yaml_acl, opa_http, ext_proc, and allow_all.
cost model
Resolves model token prices for usage records, spend admission, and budget enforcement.
destination
An upstream the gateway forwards to - a model provider or an MCP server - with its credentials, model map, and pricing.
MCP server
An external Model Context Protocol endpoint whose tools an agent can call. Declared inline on the agent, never a standalone registry resource.
payload guardrail
A payload inspection step that can block or rewrite a request or buffered response. Configured under plugins.guardrails[].
policy guardrail
An Agent Engine guardrail, or a rule from a local file bundle, evaluated against model and MCP tool traffic with optional state.
rate limiter
Caps requests, tokens, or calendar spend per scope. token_bucket_local keeps counters in one process; redis_window shares them across replicas.
route
A match rule that selects a destination by path, model, header, or scope, and carries retry and fallback behavior.
scope
The tenancy dimensions a request carries, derived from JWT claims and used to match routes and apply limits.
tape
A recorded request and response pair, captured for replay and debugging.
usage sink
Where per-request token and cost records are written. Kinds are stdout, kafka, postgres, and registry.
vault
Workspace-scoped credential storage. A session passes vault IDs, and the gateway injects the matching credential into MCP calls. Not "Vault".
vault resolver
Fetches a secret for a destination. Kinds are env, static_file, and http.
Workspace
The StreamNative Cloud resource that hosts Orca and is the isolation unit for tenancy, identity, and quotas. Capitalized: it names a specific platform resource. Not "workspace".

What's next

On this page