Kastra
Runtime authorization layer for AI coding agents — Claude Code, Cursor, Codex, OpenClaw.
Kastra is a runtime authorization layer for AI agents. It decides what agents can and cannot do before actions execute, enforcing policies with sub-1 ms latency across tools, prompts, inputs, and outputs. Use one control plane to govern agents and policies across Claude Code, Cursor, Codex, OpenClaw, Anthropic SDK, OpenAI SDK, and more. Prevent unauthorized tool use, prompt injection, and exposure of sensitive data.
What is Kastra?
Kastra is a runtime authorization layer for AI coding agents that enforces policies with sub-1ms latency before any tool or API call executes. It covers Claude Code, Cursor, Codex, OpenClaw, and major SDKs through a single control plane.
Key features
- Sub-1ms policy enforcement on every tool call
- Covers Claude Code, Cursor, Codex, OpenClaw, Anthropic SDK, OpenAI SDK
- Prevents unauthorized tool use and prompt injection in real time
- Open-source runtime and policy pack library
- Single control plane for multi-agent governance
- Fine-grained controls over prompts, inputs, and outputs
Who it's for
- Teams running Claude Code or Cursor on shared/sensitive repositories
- Agentic workflows that call external APIs or execute system commands
- CI/CD pipelines where agent actions must stay within policy boundaries
- Solo founders managing multiple coding agents across projects
When not to use it
Not needed if you only use a single coding agent on your own machine with no sensitive data. The control plane adds architecture complexity best suited for teams or shared environments.
FAQ
Is Kastra open source?
The runtime and policy pack library are open source. The enterprise control plane is commercial.
Does it slow down my agent?
Policy enforcement happens in sub-1ms, so the latency overhead is negligible.
Which coding agents does it support?
Claude Code, Cursor, Codex, OpenClaw, Anthropic SDK, and OpenAI SDK.
Share this launch
Embed this badge
<a href="https://orangebot.ai/product/kastra" target="_blank" rel="noopener noreferrer"> <img src="https://orangebot.ai/api/badge/kastra.svg" alt="Featured on OrangeBot" width="200" height="54" /> </a>