One governed hop between your agents and everything they touch
Bring your own model keys, your own identity provider, your own monitoring. Praesidia sits between them and governs the connection — it does not replace either end.
Where your agents run15 ecosystems
Praesidia control plane
A non-human identity for every agent, guardrails on every hop, spend caps that hold, and a tamper-evident record of what happened.
- Agent identity
- Content guardrails
- Spend caps
- Tamper-evident audit
- Policy decisions
What they connect toyou own both ends
What we govern, and at which version
Every entry is pinned to the exact version we accepted, the tool path that is covered, and the evidence that path earned. Reviewed 2026-09-07.
- A Evidence grade A
- The governed path passed acceptance with a separate human reviewer, distinct native processes and an independently verified target receipt. 8 of 10 runtimes.
- — No grade recorded yet
- Listed so you can prepare a workspace and evaluate it. Treat compatibility as unverified until you have tested it against your own targets.
- Governed path
- Only the named path is covered. Unrelated native tools, other transports and other versions of that runtime sit outside the profile and are not intercepted.
| Runtime | Languages | Accepted at | Governed path | Evidence | Setup |
|---|---|---|---|---|---|
| Agent runtimesgoverned natively in your runtime | |||||
| OpenClaw Native managed tool, owner-context checks and strict before-tool blocking pass pinned plugin acceptance. | TypeScript | 2026.9.2; Node 24.19.0 | Native plugin and managed HTTP tool | A | Set up |
| Hermes Agent Python managed HTTP tool is implemented with durable approval and exact-request recovery. | Python | 0390ace8179f4cf75bd3941e590dd74e638672b6 | Python managed HTTP tool | A | Set up |
| ZeroClaw Authenticated instance management, durable delivery and a native restricted MCP tool profile are implemented. | Rust, Python | 0.8.40.8.4; bridge Python 3.12.14 / requests 2.32.3ZeroClaw 0.8.4 (a56c345d51dd8ab562e9351e0d4ab83f6a741db9) | Authenticated instance lifecycle · Authenticated delivery and durable polling bridge · Native restricted agent and managed MCP action | — | Set up |
| NemoClaw / OpenShell A version-matched native tool gate and managed MCP recipe are implemented; full NVIDIA sandbox acceptance is pending. | — | NemoClaw 0.0.120 (2444537f5a77c7b2789de4d59430e228328b8279); OpenShell 0.0.106NemoClaw0.0.120; OpenShell0.0.106; OpenClaw2026.7.1; mcporter0.7.3 | Native MCP registration planner · Pinned OpenClaw tool gate with native OpenShell managed MCP | — | Set up |
| LangGraph / LangChain / Deep Agents Python managed HTTP tool is implemented with durable approval and exact-request recovery. | Python | core 1.2.11; SQLite checkpoint 3.1.1 | Python managed HTTP tool | A | Set up |
| CrewAI Managed tool passes functional fixtures; release is blocked by unresolved upstream Chroma dependency advisories. | Python | 1.15.20 | Python managed HTTP tool | A | Set up |
| OpenAI Agents SDK Separately versioned Python and TypeScript managed tools with native approval callbacks and durable restart handling. | Python, TypeScript | Python 0.20.0TypeScript 0.17.0 | Python managed HTTP tool · TypeScript managed HTTP tool | A | Set up |
| Google ADK Python managed HTTP tool is implemented with durable approval and exact-request recovery. | Python | Python 2.8.0 | Python managed HTTP tool | A | Set up |
| Microsoft Agent Framework Python managed HTTP tool is implemented with durable approval and exact-request recovery. | Python, .NET | Python core 1.17.0 | Python managed HTTP tool | A | Set up |
| Agno AgentOS Python managed HTTP tool is implemented with durable approval and exact-request recovery. | Python | 3.0.6 | Python managed HTTP tool | A | Set up |
| Coding and low-code clientsgoverned through the managed MCP companion | |||||
| OpenCode OpenCode 1.18.29 authenticates and discovers the runnable managed MCP companion. Explicit prepare, owned checkpoint and approved resume pass transport and durable-restart acceptance. | — | Managed MCP companion | — | Set up | |
| Claude Code Claude Code 2.1.202 authenticates and discovers the runnable managed MCP companion. Explicit prepare, owned checkpoint and approved resume pass transport and durable-restart acceptance. | — | Managed MCP companion | — | Set up | |
| n8n Installable n8n node 0.1.0 executes authenticated managed MCP prepare, checkpoint and explicit approved resume against an independently signed inert target. | — | Managed MCP companion | — | Set up | |
| Dify The installable tool plugin passes actual Dify Plugin SDK 0.10.2 loading and authenticated managed MCP prepare, checkpoint and approved resume. Official CLI 0.6.10 produces its local package. | — | Managed MCP companion | — | Set up | |
| Langflow The runnable component passes actual lfx 1.12.0 invocation over authenticated managed MCP, including prepare, owned checkpoint and explicit approved resume with independent target-receipt verification. | — | Managed MCP companion | — | Set up | |
No ecosystem matches that filter.
What Praesidia connects to, and what it leaves alone
Model providers
Praesidia governs the agent, not the model, and you bring your own API keys. Through the gateway's one base URL: OpenAI, Anthropic, DeepSeek, Qwen, Moonshot and a self-hosted Ollama. As an agent's configured model: OpenAI, Anthropic, Google Gemini, Mistral, Cohere, Ollama, or any OpenAI-compatible API. Switch or mix providers without re-platforming. How BYOK works →
Protocols
Native support for the Model Context Protocol (MCP) and agent-to-agent (A2A) communication, plus OAuth 2.1 and a versioned REST API described by OpenAPI.
Identity providers (human admins)
Agents carry their own non-human identities inside the platform; your IdP governs the people who manage them — SAML/OIDC single sign-on, SCIM 2.0 user lifecycle, and passkeys / WebAuthn.
Observability
Send your OpenTelemetry (OTLP) GenAI traces to Praesidia and the agents in them join your inventory; scrape your organization's metrics in Prometheus format into the monitoring stack you already operate — no proprietary agent to install.
Alerting, events & issue tracking
Route notifications to Slack, web push, and email; create a tracked issue in Jira or Linear directly from a finding; stream signed webhooks. On the Advanced plan, forward security events to Splunk, Datadog or Microsoft Sentinel, and push incidents, approvals and CMDB links to ServiceNow.
Billing & deploy targets
When self-serve billing opens, Stripe will manage subscriptions, invoices, and metered usage, with reliable reconciliation and dunning. The agents you deploy through Praesidia can ship to Heroku, Render, Hetzner, or Scalingo out of the box; where Praesidia itself runs is stated in the Trust Center.
Anything in the UI, available over the API
Every action in the dashboard is an API call against the same published, OpenAPI-described surface — so you can automate agent registration, governance configuration, and reporting from your own tooling and CI/CD. Scoped API keys let you grant least-privilege access without sharing full-admin credentials. Learn more in the API surface overview and API keys and scopes.
Connect your stack in minutes
Get started for free. No credit card required.