Skip to content
Tool GatewayPrivate previewWorks with Titan

Agents take action. They never hold the keys.

Tool Gateway turns approved actions into real calls to GitHub, Slack, Google Sheets and MCP servers, and releases a scoped credential only for the call Titan granted.

AgentTitan grant · 30sTool Gateway Credential added hereGitHub#SlackGoogle SheetsMCP servers
slack.message.post Succeeded

Checked twice, run once

Tool Gateway only takes calls from Titan, and checks the signed grant again before anything runs. The capability, adapter, arguments, resource and boundaries all have to match.
Authorized executionjust now
Request came from Titanverified
Grant signaturevalid
Grant expiry18s left
Capabilityslack.message.post
Tool versionmatch
Argumentsmatch
Resource and boundariesmatch
StatusSUCCEEDED
ResultMessage posted to #eng-alerts

A vault, not a config file

Connections live in an encrypted vault. A grant releases exactly one credential, for one call, and it is never handed back to the agent.
Connections Encrypted
GitHub · acmeOAuth 2.0 · boundary github.com/acmeConnected
#Slack · acme.slack.comWorkspace verified with auth.testConnected
Google Sheets · finance@acme.comRefreshed on releaseConnected
One credential per callNever returned to the agentRefreshed automatically

Outbound, on a short leash

Every call follows an egress profile: HTTPS only, the exact host, public addresses only, no redirects, and caps on time and size. Anything else is refused.
Egress profile · slack-api
HTTPS onlyrequired
Exact hostslack.com
Public addresses onlyenforced
Redirectsnot followed
Timeout and response sizecapped
Blocked
GET http://169.254.169.254/latest/meta-data
not https · not the profile’s host · private address

Bring your MCP servers

Import tools from any MCP server by URL. Tool descriptions that read like instructions to the model are turned away, and imports refresh every six hours.
Acme CRMhttps://mcp.acme.example/mcpImported
Imported12 tools
Rejected1 · description read like an instruction
Re-importevery 6 hours
crm.contact.get
crm.contact.search
crm.deal.list
crm.deal.update
crm.note.create
sync_all

Connectors

What Tool Gateway can call today, and what’s next. We only list a connector as live once it has run end to end.

  • GitHubIssues, pull requests, repositoriesLive in preview
  • SlackMessages and channelsLive in preview
  • Google SheetsRead and write spreadsheetsLive in preview
  • Any MCP serverImport tools by URLPreview
  • GmailRead mail and threadsComing soon
  • JiraIssues and projectsComing soon
  • WhatsApp BusinessMessages to customersComing soon

Careful by construction.

  • Respects the kill switch

    If Titan has stopped a session or connection, the gateway refuses to act.

  • Recorded attempts

    Every call is recorded, so a retry never runs the same action twice.

  • Catalog lifecycle

    Tools move from draft to published, deprecated and retired.

  • Tenant isolation

    Organization, workspace and environment on every record.

  • Generated from specs

    Toolkits built from published API specs, like Gmail’s.

  • Fresh imports

    MCP toolkits re-import on a schedule, with the same screening.

Let agents act without handing over the keys.

Tool Gateway works with Titan and is in private preview.