Kastra authorization infrastructure for AI systems checks prompts, tool calls, shell commands, API requests, and browser actions before execution.

Kastra

Authorization for AI systems

Kastra is authorization infrastructure for AI systems. Its main job is to decide what an AI is allowed to do before the action runs, rather than recording or analyzing behavior after the fact.

The product checks prompts, tool calls, shell commands, API requests, and browser actions against policy in under a millisecond. The same policy layer can be used across local coding agents, autonomous workflows, and enterprise deployments, with deployment options that include cloud, self-hosted, and air-gapped environments.

Core capabilities

Runtime authorization at the action boundary

Checks prompts, tool calls, shell commands, and API requests before execution, with the site describing sub-millisecond decision latency.

Typed, versioned policy authoring

Lets teams write policies in Kastra Policy Language, a typed DSL that lives in git, is reviewed in pull requests, and can be tested against fixtures.

Deterministic policy decisions

Supports allow, deny, redact, and escalate or approval-based outcomes depending on the policy and surface being evaluated.

Cross-surface runtime enforcement

Runs enforcement on developer laptops, browser agents, backend services, and other AI surfaces using the same policy model.

Signed audit trail and exports

Produces signed, append-only audit traces that can be replayed and exported to SIEM tools such as Datadog, Splunk, and S3.

Retroactive review with Recon

Includes Kastra Recon, which scans historical agent activity, surfaces risky actions already taken, and drafts policies for them.

Practical use cases

  • Local coding-agent governance

    Use Kastra on a developer laptop to gate destructive commands, file edits, and local API calls from coding assistants before they run.

  • Autonomous workflow control

    Apply the same policy layer to autonomous agent workflows so each step is checked and sensitive steps can require human approval.

  • Browser-agent enforcement

    Govern browser-based agents by intercepting clicks, navigation, form fills, and downloads before they fire in the DOM.

  • Retroactive policy setup

    Review historical agent activity with Recon to find risky actions already taken and draft policies before turning on enforcement.

  • Enterprise governance and audit

    Run authorization in enterprise environments where teams want signed evidence, audit exports, and deployment models that include self-hosted or air-gapped setups.

Pros and Cons

Pros

  • Covers multiple AI action types, including prompts, tool calls, shell commands, API requests, and browser actions.
  • Uses a policy language designed for AI actions, with typed rules, git-based versioning, PR review, testing, and signed bundles.
  • Supports both local developer workflows and broader enterprise enforcement patterns.
  • Provides signed, append-only audit evidence with replay and export options.
  • Offers a separate Recon workflow to review past agent activity before enforcement is enabled.

Cons

  • The public pages do not fully document every module, integration, or limit in detail.
  • Pricing and enterprise capabilities are described at a high level, but exact implementation requirements will depend on the deployment model and are not fully spelled out on the marketing pages.

FAQ

What does Kastra do?

Kastra is positioned as authorization infrastructure for AI systems. It sits in the path of prompts, tool calls, shell commands, API requests, browser actions, and other AI-generated actions, then allows, denies, or in some cases requires approval before the action runs.

Can Kastra run outside a hosted cloud setup?

The source describes deployment models including cloud, self-hosted, and air-gapped. The pricing page also says Enterprise can run in self-hosted, BYOC, or air-gapped environments.

Which AI tools and agents are mentioned as supported?

Kastra’s pricing page lists support for Claude Code, Codex CLI, Cursor, OpenClaw, and any OpenAI-compatible runtime, plus custom agents through SDKs.

Can policies be tested before they block actions?

Yes. The pricing page includes Shadow Mode for observing activity before enforcement, and the policy-engine page describes replaying historical actions against policy versions to see what would have changed.

Does Kastra offer exports or SDKs?

The site says decisions and audit records can be streamed to SIEM destinations including Datadog, Splunk, and S3. The policy-engine page also notes first-party SDKs for TypeScript, Python, Go, Rust, Java, and Swift.

Quick Facts

Category
Authorization infrastructure for AI systems
Deployment modes
Cloud, self-hosted, BYOC, and air-gapped
Primary surfaces
Prompts, tool calls, shell commands, API requests, browser actions
Named tools/agents
Claude Code, Codex CLI, Cursor, OpenClaw
Policy language
Kastra Policy Language (typed DSL)
Pricing signal
Free, Pro, Team, and Enterprise tiers are listed

Kastra 분석

트래픽 데이터는 참고용으로만 확인하세요.

트래픽 및 순위

월간 방문 수
2.8천
평균 방문 시간
00:00
방문당 페이지 수
1.07

트래픽 추이

주요 지역

  • 남아프리카: 41.1%
  • 대한민국: 38.8%
  • 인도: 20.1%

트래픽 소스

  • 직접 방문: 0.00%
  • 검색: 0.00%
  • 추천: 0.00%
  • 소셜: 0.00%
  • 메일: 0.00%
  • 디스플레이 광고: 0.00%