Agent gateway · MCP

Give your AI agents the tools. Never the keys.

Your teams already run Claude, ChatGPT, Cursor and their own LangChain agents. Integral puts one governed MCP endpoint between those agents and your ERP, email, tickets and databases: the credentials stay in our vault, every agent acts as a named person, risky actions wait for approval, and every call is on the record.

ConnectWorkApproveRevokeOne endpoint, four controls.
1
MCP endpoint for every agent and every system
0
system passwords or tokens handed to an agent
19
systems ready to connect — cloud and on-prem
15 min
lifetime of a single-use approval link

01

Shadow AI already has the keys to your systems.

Nobody decided it. Every team that wired an agent into the ERP, a mailbox or a database made one small, reasonable exception — and the exceptions add up.

API keys in .env files

Every agent that touches the ERP needed a key, so someone pasted one into a config file, a notebook, a prompt. Nobody knows how many copies exist, and most of them never expire.

No record of what an agent did

Which records did it read? Did it actually send that email? The only log is the agent’s own chat history — and that belongs to whoever happened to run it.

No moment to say “not that one”

An agent with write access posts, sends and deletes at machine speed. There is no step where a person sees the change before it happens.

A gateway it can walk around

An LLM proxy watches model traffic. It cannot stop an agent that holds the database password from connecting straight to the database.

02

One agent, four moments you control.

Connect it, let it work, stop it at the risky step, switch it off — the same agent, all four. The screens are mock-ups of the real ones: the same endpoint, the same consent screen, the same approval card.

An animation in four steps. A coding agent in a terminal connects to the Integral gateway and a person approves the consent screen; the agent reads overdue invoices from the ERP through the gateway, which logs each call; it tries to send three reminder emails and the gateway asks a person to approve them; finally an admin revokes the agent in the console and its next call is refused.
  1. Runs on its own. Click a word to jump straight to it.

claude — ~/finance-agent
Integralintegral.meteorit.rs/oauth/authorize

03

Four decisions in Integral. One address in the agent.

Nothing is installed on the agent’s side beyond the MCP endpoint. What an agent may reach, and what it must ask before doing, is a setting — not a code change and not a new password.

  1. 1

    Connect your systems once

    ERP, email, tickets, chat, file shares and databases — 19 connectors, plus a small on-premise agent for systems that must not face the internet. Their credentials go into our vault, never into an agent.

  2. 2

    Give every agent its own identity

    Apps with a Connect button — Claude, ChatGPT, Cursor — sign in over OAuth 2.1 with PKCE, and a person approves the consent screen. Scripts and custom agents get an API key bound to one member. There is no workspace-wide key.

  3. 3

    Decide what each one may do

    Permissions per credential, never wider than that member’s own access. Reads from your systems run under that person’s rights; anything consequential — a workflow run, a changed connection, a deleted record — comes back as an approval; changes to access, people and money always need a person.

  4. 4

    Watch it, limit it, switch it off

    One list of every key and app that can reach your systems, with who each acts as and when it was last used. Rate limits per credential, hard spend caps for the workspace, and revocation that takes effect on the next request.

The whole client-side setup
# Claude Code, Cursor, Claude — OAuth
$ claude mcp add --transport http integral \
    https://integral.meteorit.rs/api/mcp

# scripts, CI, LangChain — an API key
Authorization: Bearer mk_…

OAuth for apps with a Connect button. An API key for scripts, CI and custom agents — same endpoint, same rules.

Read the MCP documentation

04

Works with the agents your teams already use.

Anything that speaks the Model Context Protocol over HTTP, and plain REST for scripts that do not.

  • Claude — web & desktop
  • Claude Code
  • ChatGPT
  • Cursor
  • Windsurf
  • LangChain & LangGraph
  • Any MCP client
  • REST API

Behind the gateway

Balans ERP · Dezkom · Gmail · Outlook · Teams · Slack · Jira · Freshdesk · Airtable · SQL databases · Google Drive · OneDrive · Dropbox · S3 · SFTP · WebDAV · your own MCP servers

See all 19 connectors

05

What holds for every agent, on every call.

These are properties of the platform, enforced in code and in the database — not lines in a policy nobody reads.

Credentials never leave the vault

System passwords and tokens are stored encrypted and added on the server, per call. An agent holds a gateway credential that opens nothing on its own.

Every agent is a named person

Each credential acts as one member and can never do more than that member can in the app. There is no service account to over-provision.

Source permissions still apply

If a person cannot open a file in Google Drive, their agent cannot read it either. Access comes from the source system, not from a copy of it.

People approve the risky steps

Workflow runs, deletions and connection changes return a single-use approval link, valid for 15 minutes. Changes to access, membership and money always need a person, even for a trusted app.

Hard limits, not soft ones

Requests per minute for every key and app, and workspace spend caps. Over the limit, the call is refused — not quietly billed.

Revocation that takes effect now

No sessions to wait out: every request re-checks its credential. A revoked key, or a person who left the company, is locked out on the next call.

Every connection on the record

Who connected which app, every system call it made, and who approved what — in your workspace’s audit trail, under GDPR and Serbia’s ZZPL.

On-premise stays on-premise

For databases and ERPs that must not face the internet, a small agent on your server dials out. No inbound port, and the password never reaches us.

06

An LLM gateway watches traffic. An agent gateway holds the keys.

Both are useful, and they solve different problems. Only one of them can stop an agent that decides to go around it.

  • Holds the credentials to your systems

    LLM gateway or proxy
    No — the agent keeps them
    Integral agent gateway
    Yes, in an encrypted vault
  • Gives each agent its own revocable identity

    LLM gateway or proxy
    Usually one shared key
    Integral agent gateway
    Yes — OAuth per app, API key per member
  • Applies the person’s own permissions to every call

    LLM gateway or proxy
    No
    Integral agent gateway
    Yes
  • Stops consequential actions for a human decision

    LLM gateway or proxy
    No
    Integral agent gateway
    Yes — single-use approval links
  • Records which systems were called, and by whom

    LLM gateway or proxy
    Only prompts and tokens
    Integral agent gateway
    Yes — every tool call and approval
  • Can be bypassed by an agent that holds a password

    LLM gateway or proxy
    Yes
    Integral agent gateway
    No — the agent never gets one
  • Routes and meters model calls

    LLM gateway or proxy
    Yes — that is its job
    Integral agent gateway
    Coming next

Close the network side too: allow agent hosts to reach integral.meteorit.rs and block direct calls to model providers and SaaS APIs. We publish the one hostname; your firewall enforces it.

07

Where teams start.

The first agent through the gateway is usually one that already exists and already has too much access.

Engineering agents

Claude Code and Cursor read Jira, the runbook and the database — through a key that expires, not a production password in .env.

“Which tickets block the release, and what changed in orders last week?”

Finance & operations

Answers straight from the ERP without anyone exporting a spreadsheet — read with that person’s own rights, never a shared admin login.

“Which customers are over 60 days past due, and how much is that?”

Support & service

An agent reads ticket history and the knowledge base and drafts the reply. Sending it to the customer stays with a person.

“Summarise #4471 and draft a reply with the fix article.”

Your own agents

LangChain and LangGraph workers get scoped keys with their own rate limit, and show up in the same inventory as everyone else.

“Every night, flag invoices that do not match a purchase order.”

08

What CTOs ask before they switch it on.

01

What is an agent gateway?

An agent gateway is a single, governed entry point between AI agents and the systems they use. Instead of giving each agent passwords to your ERP, email or database, the agent connects to the gateway with its own credential. The gateway checks who the agent acts for, applies that person’s permissions, asks a human before anything consequential, calls the system with credentials it keeps, and records the call. Integral’s agent gateway does this over the Model Context Protocol (MCP).

02

How is an agent gateway different from an LLM gateway?

An LLM gateway sits between an application and model providers: it routes, meters and logs model calls. An agent gateway sits between agents and your systems: it holds the credentials, decides what each agent may touch and records what it did. An agent that still holds a database password can walk around an LLM gateway. It cannot walk around a gateway that holds the password instead.

03

Which agents and clients work with it?

Anything that speaks MCP over HTTP: Claude on the web and desktop, Claude Code, ChatGPT with custom connectors, Cursor, Windsurf, and agents built with LangChain or LangGraph through an MCP adapter. Scripts without an MCP client can use the REST endpoint with an API key.

04

Can an agent bypass the gateway?

Not to reach the systems the gateway governs, because the agent never receives their credentials — the gateway adds them on the server, call by call. What we cannot control is your network: if an agent host also holds other keys, close those routes on your side by allowing integral.meteorit.rs and blocking direct calls to model providers and SaaS APIs.

05

What happens when an agent tries something risky?

Nothing, until a person says so. Over the gateway an agent reads your connected systems; anything consequential — running a workflow, changing a connection, deleting a record — returns a single-use approval link instead of acting. A person opens it, sees exactly what will change, and applies or discards it; the link expires after 15 minutes. Changes to access, membership and money always need a person, even for an app the owner has marked as trusted.

06

Is it GDPR-compliant, and is our data used for training?

Integral acts as your processor under GDPR and Serbia’s ZZPL, with a data processing agreement on request and a published list of sub-processors. Encryption covers data in transit and at rest, tenant isolation is enforced in the database, and your content is never used to train models.

07

Do we have to build MCP servers for our own systems?

No. The 19 connectors and the on-premise agent are the MCP surface — the gateway exposes their tools under the rules above. If you already run an MCP server of your own, connect it too and it is governed the same way.

Put every agent on one governed path.

Tell us which agents your teams run and which systems they touch. In a 30-minute call we will show one of them working through the gateway — with your systems in the picture, not a slide deck.