Security
Control what every agent can reach
Agents accumulate MCP servers quietly, and most setups can't answer the basic questions: which servers are installed, what is actually being called, and which agent is doing the calling. Every call runs through a gate you own, so those answers are always one screen away, and access is a switch you flip rather than a config file you go hunting for.
- Per-agent allow-lists: grant, scope, or revoke a server in one click
- Every tool call attributed to an agent, timed, and logged on your machine
- Server credentials and OAuth tokens stay in Hypergate, never in agent configs
- Each agent gets its own bearer token, so revoking one leaves the rest running