Agent gateway · MCP
Your teams already run Claude, ChatGPT, Cursor and their own LangChain agents. Integral puts one governed MCP endpoint between those agents and your ERP, email, tickets and databases: the credentials stay in our vault, every agent acts as a named person, risky actions wait for approval, and every call is on the record.
Your agents
Keys stay in the vault
Your systems
01
Nobody decided it. Every team that wired an agent into the ERP, a mailbox or a database made one small, reasonable exception — and the exceptions add up.
Every agent that touches the ERP needed a key, so someone pasted one into a config file, a notebook, a prompt. Nobody knows how many copies exist, and most of them never expire.
Which records did it read? Did it actually send that email? The only log is the agent’s own chat history — and that belongs to whoever happened to run it.
An agent with write access posts, sends and deletes at machine speed. There is no step where a person sees the change before it happens.
An LLM proxy watches model traffic. It cannot stop an agent that holds the database password from connecting straight to the database.
02
Connect it, let it work, stop it at the risky step, switch it off — the same agent, all four. The screens are mock-ups of the real ones: the same endpoint, the same consent screen, the same approval card.
Runs on its own. Click a word to jump straight to it.
03
Nothing is installed on the agent’s side beyond the MCP endpoint. What an agent may reach, and what it must ask before doing, is a setting — not a code change and not a new password.
ERP, email, tickets, chat, file shares and databases — 19 connectors, plus a small on-premise agent for systems that must not face the internet. Their credentials go into our vault, never into an agent.
Apps with a Connect button — Claude, ChatGPT, Cursor — sign in over OAuth 2.1 with PKCE, and a person approves the consent screen. Scripts and custom agents get an API key bound to one member. There is no workspace-wide key.
Permissions per credential, never wider than that member’s own access. Reads from your systems run under that person’s rights; anything consequential — a workflow run, a changed connection, a deleted record — comes back as an approval; changes to access, people and money always need a person.
One list of every key and app that can reach your systems, with who each acts as and when it was last used. Rate limits per credential, hard spend caps for the workspace, and revocation that takes effect on the next request.
# Claude Code, Cursor, Claude — OAuth
$ claude mcp add --transport http integral \
https://integral.meteorit.rs/api/mcp
# scripts, CI, LangChain — an API key
Authorization: Bearer mk_…OAuth for apps with a Connect button. An API key for scripts, CI and custom agents — same endpoint, same rules.
Read the MCP documentation04
Anything that speaks the Model Context Protocol over HTTP, and plain REST for scripts that do not.
Behind the gateway
Balans ERP · Dezkom · Gmail · Outlook · Teams · Slack · Jira · Freshdesk · Airtable · SQL databases · Google Drive · OneDrive · Dropbox · S3 · SFTP · WebDAV · your own MCP servers
See all 19 connectors05
These are properties of the platform, enforced in code and in the database — not lines in a policy nobody reads.
System passwords and tokens are stored encrypted and added on the server, per call. An agent holds a gateway credential that opens nothing on its own.
Each credential acts as one member and can never do more than that member can in the app. There is no service account to over-provision.
If a person cannot open a file in Google Drive, their agent cannot read it either. Access comes from the source system, not from a copy of it.
Workflow runs, deletions and connection changes return a single-use approval link, valid for 15 minutes. Changes to access, membership and money always need a person, even for a trusted app.
Requests per minute for every key and app, and workspace spend caps. Over the limit, the call is refused — not quietly billed.
No sessions to wait out: every request re-checks its credential. A revoked key, or a person who left the company, is locked out on the next call.
Who connected which app, every system call it made, and who approved what — in your workspace’s audit trail, under GDPR and Serbia’s ZZPL.
For databases and ERPs that must not face the internet, a small agent on your server dials out. No inbound port, and the password never reaches us.
06
Both are useful, and they solve different problems. Only one of them can stop an agent that decides to go around it.
Holds the credentials to your systems
Gives each agent its own revocable identity
Applies the person’s own permissions to every call
Stops consequential actions for a human decision
Records which systems were called, and by whom
Can be bypassed by an agent that holds a password
Routes and meters model calls
Close the network side too: allow agent hosts to reach integral.meteorit.rs and block direct calls to model providers and SaaS APIs. We publish the one hostname; your firewall enforces it.
07
The first agent through the gateway is usually one that already exists and already has too much access.
Claude Code and Cursor read Jira, the runbook and the database — through a key that expires, not a production password in .env.
“Which tickets block the release, and what changed in orders last week?”
Answers straight from the ERP without anyone exporting a spreadsheet — read with that person’s own rights, never a shared admin login.
“Which customers are over 60 days past due, and how much is that?”
An agent reads ticket history and the knowledge base and drafts the reply. Sending it to the customer stays with a person.
“Summarise #4471 and draft a reply with the fix article.”
LangChain and LangGraph workers get scoped keys with their own rate limit, and show up in the same inventory as everyone else.
“Every night, flag invoices that do not match a purchase order.”
08
An agent gateway is a single, governed entry point between AI agents and the systems they use. Instead of giving each agent passwords to your ERP, email or database, the agent connects to the gateway with its own credential. The gateway checks who the agent acts for, applies that person’s permissions, asks a human before anything consequential, calls the system with credentials it keeps, and records the call. Integral’s agent gateway does this over the Model Context Protocol (MCP).
An LLM gateway sits between an application and model providers: it routes, meters and logs model calls. An agent gateway sits between agents and your systems: it holds the credentials, decides what each agent may touch and records what it did. An agent that still holds a database password can walk around an LLM gateway. It cannot walk around a gateway that holds the password instead.
Anything that speaks MCP over HTTP: Claude on the web and desktop, Claude Code, ChatGPT with custom connectors, Cursor, Windsurf, and agents built with LangChain or LangGraph through an MCP adapter. Scripts without an MCP client can use the REST endpoint with an API key.
Not to reach the systems the gateway governs, because the agent never receives their credentials — the gateway adds them on the server, call by call. What we cannot control is your network: if an agent host also holds other keys, close those routes on your side by allowing integral.meteorit.rs and blocking direct calls to model providers and SaaS APIs.
Nothing, until a person says so. Over the gateway an agent reads your connected systems; anything consequential — running a workflow, changing a connection, deleting a record — returns a single-use approval link instead of acting. A person opens it, sees exactly what will change, and applies or discards it; the link expires after 15 minutes. Changes to access, membership and money always need a person, even for an app the owner has marked as trusted.
Integral acts as your processor under GDPR and Serbia’s ZZPL, with a data processing agreement on request and a published list of sub-processors. Encryption covers data in transit and at rest, tenant isolation is enforced in the database, and your content is never used to train models.
No. The 19 connectors and the on-premise agent are the MCP surface — the gateway exposes their tools under the rules above. If you already run an MCP server of your own, connect it too and it is governed the same way.
Tell us which agents your teams run and which systems they touch. In a 30-minute call we will show one of them working through the gateway — with your systems in the picture, not a slide deck.