The Governance Layer for Safe Agentic Automation
Control what AI agents can do, how much they can spend, and what requires human approval. Audit every action with zero friction.
$ curl -fsSL https://preloop.ai/install/cli | sh
Install the CLI on macOS or Linux. Discovers and onboards your local agents.
OpenClaw
OpenCode
Claude Code
Codex CLI
Gemini CLI
Hermes
Cursor
Windsurf
VSCode
Onboard existing agents with one command
Install the CLI to find local agents on your machine, including OpenClaw, Claude Code, Codex CLI, Cursor, Gemini CLI, Hermes, Windsurf, OpenCode, and other MCP-compatible runtimes, and onboard them into Preloop in seconds. Tool calls are transparently rewritten to go through the Preloop MCP Firewall and model traffic through the Preloop Gateway. No SDK changes, no agent code changes.
MCP Firewall for tool access
Define allow, deny, require-approval, and require-justification rules for any MCP tool or built-in action. Policy-as-code in YAML with CEL expressions, ordered rules with priority, per-parameter conditions, and clear denial messages to the agent. Policies live alongside your infrastructure and version-control like the rest of your stack.
AI model gateway with budgets and attribution
Route model traffic through an OpenAI- and Anthropic-compatible gateway. Control which models each agent, flow, or API key can use, enforce per-account and per-flow budgets, attribute every token to the runtime that spent it, and keep model spend visible before costs run away. Self-hosted - your keys, your infrastructure.
Human approvals that don't kill velocity
When a tool call hits an approval rule, the right people get notified instantly on mobile, watch, Slack, Mattermost, or email with full context, arguments, and agent reasoning. Approve with one tap. Low-risk actions still run at full speed. Optional async mode lets agents poll for status instead of blocking, so long-running reviews don't break transport hooks.
Runtime sessions, audit trails, and AI Act evidence
Every action is logged with attempted tool, inputs, matched policy, decision, approver, model spend, and outcome. Drill from an agent's fleet view into one runtime session timeline. Use the same operational evidence to optimize agents, support internal governance reviews, and build EU AI Act readiness artifacts.
Frequently Asked Questions
What is Preloop?
Preloop is the open-source AI agent control plane. It combines an MCP firewall (tool access control), an AI model gateway (cost and attribution), policy-as-code with human approvals, runtime session observability, and audit trails — in one self-hostable platform. Teams use it to govern OpenClaw, Hermes, Claude Code, Codex CLI, Cursor, Gemini CLI, OpenCode, and any MCP-compatible agent from a single control plane.
How is Preloop different from an AI gateway like Portkey or LiteLLM?
AI gateways route model traffic and track cost. Preloop does that too, but also governs tool calls through an MCP firewall, adds human-in-the-loop approval workflows, and gives you a single view of every runtime session and audit trail.
How does Preloop compare to AWS Bedrock AgentCore?
Preloop covers the same core jobs as AWS Bedrock AgentCore — runtime, gateway, identity, observability, and policy — but is open source, self-hostable, MCP-native, and vendor-neutral.
Is Preloop an MCP firewall? An AI firewall? An AgentOps platform?
Preloop is a control plane that spans all three. The MCP Firewall governs tool access. The Preloop Gateway governs model traffic. Policy and approval workflows govern sensitive actions.
Does Preloop protect against prompt injection?
Preloop provides partial prompt-injection defense today through tool access policies, per-parameter CEL conditions, approval workflows on risky tool calls, and redaction of sensitive fields in logs and notifications.
Who is Preloop for?
Platform, DevEx, security, and operations teams that have rolled out AI agents — OpenClaw, Hermes, Claude Code, Codex CLI, Cursor, Gemini CLI, OpenCode — and now need to control what they can do, how much they spend, and which actions require human approval.
How does onboarding work?
Install the Preloop CLI and run preloop agents discover. Preloop inspects local configurations for OpenClaw, Hermes, Claude Code, Codex CLI, Cursor, Gemini CLI, OpenCode, and other MCP-compatible runtimes, imports representable MCP servers and model metadata into your account.
Which AI agents does Preloop support?
Preloop works with OpenClaw, Hermes, Claude Code, Codex CLI, Cursor, Gemini CLI, Windsurf, Cline, OpenCode, and any other MCP-compatible agent or managed runtime.
What actions can I control?
Any action exposed through MCP or a built-in tool: deployments, shell commands, database operations, secret access, cloud provisioning, billing changes, ticket automation, internal APIs, and more.
Do I need to modify my infrastructure or app code?
No. Preloop fits existing agent workflows without SDKs or invasive changes.
How do approval notifications work?
When a tool call hits an approval rule, Preloop notifies the right people with full context.
Will policies slow down my AI agents?
Only actions requiring approval pause for human input. Allowed actions run at near-zero overhead.
Do I get an audit trail?
Yes. Every action — tool call, model call, policy decision, approval, denial, outcome — is logged with full context, inputs, timestamps, matched rule, and approver.
Is Preloop open source?
Yes. The Preloop core is Apache 2.0 licensed and self-hostable on your own infrastructure.
Can Preloop help with EU AI Act readiness?
Yes. Preloop helps teams build operational controls and evidence for AI governance programs — approval workflows, runtime visibility, policy enforcement, audit trails.
Does Preloop make my company automatically compliant with the EU AI Act?
No. Preloop does not replace legal interpretation, risk classification, conformity assessment, or broader compliance work.