API-to-AI action conversion
Convert existing APIs and OpenAPI definitions into agent-ready actions and manifests.
From governed API execution to the enterprise control plane for AI agents.
Discover agents, understand what they can access, authorize and execute actions safely, observe outcomes and spend, continuously optimize permissions, and revoke risky capabilities in real time.
Filter delivery commitments by status, priority, ownership area, and window.
Available to qualified teams through the KeyRunner early access program.
Convert existing APIs and OpenAPI definitions into agent-ready actions and manifests.
Apply governance controls before actions are exposed or executed.
Keep credentials out of agents and inject them only at execution time.
Redact PII, PHI, PCI, secrets, keys, and other sensitive data before it reaches a model.
Require human approval for sensitive or high-risk actions.
Maintain execution history and governance evidence for actions and policy decisions.
Map agents, identities, policies, tools, APIs, and governed relationships.
Provide central visibility and operational control across enterprise agents.
Track and govern AI usage and costs.
Provide governance insights, evidence, and operational analytics.
Immediately disable an agent, capability, tool, or execution path.
Official SDK to integrate KeyRunner into Node.js applications.
Forward audit and access logs to Datadog for observability.
Conditions, loops, scripts, test-result export, and enhanced request-flow testing.
Export enterprise audit events to SIEM tools such as Splunk and Elastic.
First-class Kafka connections, message production and consumption, topic handling, SASL authentication, AWS MSK IAM, and SSL support.
Credential-management integration for smoother secret retrieval and use.
Publish private and public mock servers with explicit access tokens, rotation, and revocation.
Compare actual responses with expected schemas and generate typed definitions across supported languages.
Secure credential and key access across AWS KMS, HashiCorp Vault, 1Password, AWS Secrets Manager, and Google Cloud KMS.
Run and identify Kubernetes-based agents and workloads as governed identities within KeyRunner.
Discover unmanaged agents, MCP servers, tools, OAuth grants, service identities, and AI workloads. Show governed, unmanaged, and drifting capabilities.
Create a complete identity chain from the initiating human through agent and workload identity to policy, tool, target system, and result.
Show human, agent, identity, tool, API, and system relationships in a single governed graph.
Add explicit governed, unmanaged, and high-risk status across Agent Fleet.
Expose agent and capability revocation directly from Agent Graph and Agent Fleet.
Control Plane capability that brings policy blocks, approvals, risky actions, spend, and sensitive-data events into one analytics view.
Control Plane capability that recommends removal of unused tools, stale permissions, excessive scopes, and unnecessary write capabilities from observed behavior.
Govern model access with provider and model allowlists, routing policy, data rules, budgets, prompt and response controls, and fallback policy.
Attribute model and tool spend by agent, user, team, workflow, provider, and model.
Apply budgets and automated enforcement actions to agent, team, workflow, model, and tool usage.
Score agents using identity strength, privilege, data access, environment, blast radius, external connectivity, spend, and behavior.
Inventory MCP servers and tools, attach policy, identify capability drift, isolate credentials, and support risk and kill-switch controls.
Preview which agents and workflows a policy change affects before enforcement and identify who can perform sensitive actions.
Generate auditor-ready evidence for identity, policy, tools, credential source, approvals, data exposure, history, spend, and kill-switch state.
Revoke agent access when identity, employment, permission, ownership, or risk context changes.
Use workforce and permission context from an identity platform as live agent-governance signals.
Package enterprise governance templates for healthcare, finance, and other regulated environments.
Integrate systems such as Rippling, Okta, Microsoft Entra ID, and Workday for employment, role, ownership, app-access, and permission context.
Connect Splunk, Datadog, Microsoft Sentinel, and Elastic for discovery signals, analytics, and audit export.
Use AWS IAM, Azure Managed Identity, and GCP IAM as agent, workload, and environment signals.
Connect OpenAI, Anthropic, Azure OpenAI, and Google Vertex AI for model routing, spend, and data controls.
Support MCP servers, LangGraph, CrewAI, AutoGen, and similar runtimes with inventory, policy, audit, and kill-switch controls.
Provide local help for API exploration, request generation, and testing without a cloud dependency.
Enterprise-ready Java SDK with KeyRunner support.
Lightweight Python SDK for secure KeyRunner integration.
Send alerts and governance events to Amazon SQS queues.
Connect governance context with OAuth controls for Apigee-managed APIs.
Find out about our latest product changes as we continue improving KeyRunner to enable your team to collaborate better.