See them, govern them, cut their cost.
Install the CLI #get-started Book a Demo https://calendar.app.google/FV95tXZtfGpPk7398curl -fsSL https://preloop.ai/install/cli | sh
macOS, Windows or Linux. Finds your local agents and onboards them. On Windows PowerShell, run: irm https://preloop.ai/install/cli.ps1 | iex
Apache-2.0|Self-hostable|No SDK or agent code changes|Works with any MCP agent
Preloop is the open-source AI agent control plane. It combines an MCP firewall for tool access, an AI model gateway for cost and attribution, policy-as-code with CEL, human-in-the-loop approvals (mobile, watch, Slack, Mattermost), runtime session observability, and audit trails in a single self-hostable platform. The `preloop agents discover` command imports compatible local agent configs and transparently rewrites Claude Code, Codex CLI, Cursor, Gemini CLI, Hermes, OpenClaw, and OpenCode to route through Preloop without SDK changes. Teams use Preloop as an open-source alternative to AWS Bedrock AgentCore, a unified MCP gateway and AI gateway, and a way to collect machine evidence for EU AI Act, Cyber Resilience Act, DORA, and NIS2 programs. Named-instrument pages: /ai-act-readiness, /cra-readiness, /dora, /nis2. Preloop is not a law firm and nothing on the site is legal advice.
gridRoute model traffic through an OpenAI- and Anthropic-compatible gateway. Every token is attributed to the agent, flow, or API key that spent it. Set soft and hard budgets per account and per flow. When the provider reports the actual cost, Preloop records it over the estimate. Usage it cannot price is labelled unpriced, not $0.00. Cursor spend that never touches the gateway can be imported from the Cursor usage CSV. Self-hosted: your keys, your infrastructure.
Install the CLI and run preloop agents discover. It finds Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, Hermes, OpenCode, and other MCP-compatible runtimes on the machine. It backs up each config, then rewrites it to send tool calls through the MCP Firewall and model traffic through the Gateway. No SDK. No agent code changes.
Write rules in YAML with CEL expressions. Rules are ordered, carry a priority, and can inspect arguments, not just tool names. Deny a payment above 2000. Require approval above 100. Allow the rest. Denied calls fail at once with a clear message the agent can act on. Policies live next to your infrastructure and go through version control like the rest of your stack.
Most gateways and MCP proxies observe or block. They cannot pause and ask a person. Preloop can. When a call matches an approval rule, the right people get it on mobile, watch, Slack, Mattermost, email, or a webhook, with the arguments, the context, and the rule that gated it. Approve with one tap. Low-risk actions never wait. An async mode lets the agent poll for the decision instead of blocking.
Every action is logged: tool, inputs, matched rule, decision, approver, model spend, outcome. Drill from the fleet view into one session timeline. Apache flow presets verify a build SBOM, map components to OSV.dev and CISA KEV, and write a versioned result.json. CRA Art. 14 reporting duties apply from 11 September 2026. The same evidence supports EU AI Act Art. 12 and Art. 14 work, DORA ICT-action trails, and NIS2 Art. 21(2) supply-chain questions. It is evidence, not a certification.
Preloop is the open-source AI agent control plane. It combines an AI model gateway for cost and budgets, an MCP firewall for tool access, human approvals, runtime session observability, and audit trails in one self-hostable platform. Teams use it to govern Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, Hermes, OpenCode, and any MCP-compatible agent.
Model traffic goes through an OpenAI- and Anthropic-compatible gateway. Every request is attributed to the agent, flow, or API key that made it. Budgets have a soft and a hard limit, per account and per flow. When a provider reports the actual cost of a request, Preloop records that value over its own estimate. Usage it cannot price is labelled unpriced instead of $0.00. Cursor spend that bypasses the gateway can be imported from the Cursor usage CSV.
AI gateways route model traffic and track cost. Preloop does that too. It also governs tool calls through an MCP firewall, adds human approvals, and keeps one view of every runtime session and its audit trail. Preloop's gateway embeds the LiteLLM library for provider translation. See <a href="/vs/litellm">Preloop vs LiteLLM</a>, <a href="/vs/portkey">Preloop vs Portkey</a>, and <a href="/vs/agentgateway">Preloop vs agentgateway</a>.
Install the Preloop CLI and run <code>preloop agents discover</code>. It inspects local configurations for Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, Hermes, OpenCode, and other MCP-compatible runtimes, read-only, and reports what each one supports. <code>preloop agents onboard</code> then imports the MCP servers and model metadata it can represent, mints a durable credential, backs up the existing config, and rewrites the agent to use Preloop-managed endpoints. No SDK. No agent code changes.
Claude Code, Codex CLI, Cursor, Gemini CLI, OpenClaw, Hermes, Windsurf, Copilot CLI, OpenCode, and any other MCP-compatible agent or managed runtime. Standard MCP clients such as Claude Desktop, Cursor, and VS Code Copilot can also connect to the Preloop MCP server with OAuth 2.1 and PKCE. New agents are added through the MCP standard.
Any action exposed through MCP or a built-in tool: deployments, shell commands, database operations, secret access, cloud provisioning, billing changes, ticket automation, internal APIs. Rules can inspect arguments and context, not just tool names, with CEL expressions.
When a tool call matches an approval rule, Preloop notifies the right people on mobile, watch, Slack, Mattermost, email, or a custom webhook. The request shows the arguments, the context, and the rule that gated it. Approvers can approve, reject, or leave guidance. An async mode lets long reviews finish without blocking the agent's transport.
Allowed actions pass through without a pause. Denied actions fail at once with a message the agent can act on. Actions that need approval wait for a person, or run in async mode so the agent polls for the decision instead of blocking.
Those products govern MCP tool access, and several now add a model gateway too. Preloop puts per-call human approvals, native action gates for coding agents, per-agent budgets, and a hash-chained runtime audit trail in the Apache-2.0 core, not behind an enterprise tier. See <a href="/vs/mintmcp">MintMCP</a>, <a href="/vs/lunar">Lunar.dev</a>, and <a href="/vs/runlayer">Runlayer</a>.
Preloop covers the same core jobs: runtime, gateway, identity, observability, and policy. It is open source, self-hostable, MCP-native, and vendor-neutral. You are not tied to AWS models or infrastructure. Run it in your own VPC or on-prem. See <a href="/vs/aws-agentcore">Preloop vs AWS Bedrock AgentCore</a>.
They do different jobs. A workflow engine runs the agents you build: retries, queues, schedules, and durable waits. Preloop governs the agents you run, including the ones you bought: model spend and budgets, tool policy, human approvals, and the audit trail. A task can route its model calls through the Preloop gateway with an environment variable, and a Preloop approval can complete a wait token through a webhook relay. See <a href="/vs/trigger-dev">Preloop vs Trigger.dev</a>.
Your MDM is the rollout channel: it deploys vendor settings and the Preloop CLI, and keeps users from switching them off. Preloop is the control layer those settings point at: per-call approvals, budgets, session timelines, and one policy across Claude Code, Codex, Cursor, and server-side agents. Discovery can run as an MDM job with a key scoped only to reporting. See <a href="/vs/jamf">Preloop vs Jamf AI Governance</a>.
Varonis protects the data AI can reach: classification, permissions, DLP, and Copilot exposure. Preloop governs what agents do, what they cost, and who approved it, open source and on your own infrastructure. Run them side by side and send Preloop's signed events to the same SIEM. See <a href="/vs/varonis-atlas">Preloop vs Varonis Atlas</a>.
Partly. Tool access policies, per-parameter CEL conditions, approval rules on risky calls, and redaction of sensitive fields in logs and notifications all limit what an injected instruction can do. Model content policies add deterministic prompt-injection heuristics, documented as best-effort; semantic detection is not built in. Content-safety firewalls such as Lakera or Llama Guard can run in front of Preloop. See <a href="/vs/zenity">Preloop vs Zenity</a>.
Yes. The core is Apache-2.0 and self-hostable. A self-hosted OSS instance is one operator per account. Preloop Cloud (hosted) and Preloop Enterprise (self-hosted commercial) add users, teams, and RBAC on one account, plus managed hosting or support plans. The CRA and AI Act evidence presets are Apache presets, not an edition gate. Release assets carry signed SLSA build provenance.
As operational evidence, not as a certification or legal advice. EU AI Act, <a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj">Regulation (EU) 2024/1689</a>: Preloop can pause a tool call for a person (Art. 14-style oversight) and keep session logs (Art. 12-style records). CRA, <a href="https://eur-lex.europa.eu/eli/reg/2024/2847/oj">Regulation (EU) 2024/2847</a>: Art. 14 reporting applies from 11 September 2026; Apache presets verify an SBOM your build produced and write result.json. DORA, <a href="https://eur-lex.europa.eu/eli/reg/2022/2554/oj">Regulation (EU) 2022/2554</a>: an ICT-action trail, not the register of information. NIS2, <a href="https://eur-lex.europa.eu/eli/dir/2022/2555/oj">Directive (EU) 2022/2555</a> Art. 21(2): approvals on agent paths into production and SBOM exploit checks. Details: <a href="/ai-act-readiness">EU AI Act</a>, <a href="/cra-readiness">CRA</a>, <a href="/dora">DORA</a>, <a href="/nis2">NIS2</a>.
On Preloop Cloud, we store your sessions to give you search, audit trails, cost reports and policy enforcement. We use them for nothing else: we do not train models on them, and we do not sell or share them. Self-hosted, your tool calls, model traffic and audit records stay in your network; the only thing sent to us is an optional daily version check, which <code>PRELOOP_DISABLE_TELEMETRY=true</code> or <code>DISABLE_VERSION_CHECK=true</code> turns off. Message content is stored with pattern redaction, or not at all if you turn content capture off, and retention is yours to set. Details: <a href="https://docs.preloop.ai/security/security-privacy/">Security & Privacy</a>.
Preloop is not a law firm. Nothing on this site is legal advice. Every regulation reference names the instrument and the article or date so you can check it against EUR-Lex yourself.
Three commands to onboard your existing agents Read the quickstart https://docs.preloop.ai/guide/quickstart/Per-agent spend and hard budgets on day one. Start with visibility only.
Add deny and approval rules where agents can deploy, touch production data, or spend money.
Keep the session trail and the SBOM evidence packs. Hand them to your reviewer. Not a certification.