AGENT CONTROL PLANE · TECHNICAL PREVIEW

Your agents move fast.
Keep your team in control.

Plug your existing agents into Descles. See who called what, enforce budgets, and deny or hold model-proposed tool calls for approval. Your agents. Your providers. One team console.

Descles is an AI agent control plane: an identity-aware LLM gateway with per-request budgets, tool-call policy, human-in-the-loop approvals, and signed audit records — bring your own provider key.

Plug in by endpoint Keep your provider No model markup
EXAMPLE / GOVERNED REQUESTPOLICY IN STREAM
maya@acmeperson group
coding-agentscoped token
REQUEST ENTERS DESCLES
Policy decision
REQUIRE APPROVALterminal → kubectl delete pod checkout-apiBudget checked · actor bound · trace opened
Model I/Oroute
Tool I/Opause
Resource I/Oscope
Tool call removed; approval apr_0042 openedSSE
PLUGS INTO THE STACK YOU ALREADY RUN
OpenAI SDKAnthropic SDKClaude CodeHermesCustom agentsMCP adapterSelf-hosted
01 / PLUG IN

Plug in.
Keep your existing agent.

Store your provider key in the console, issue an agent key, then change the endpoint in your SDK or agent settings. Start with model traffic; add runtime integration for mediated execution.

AFTER SAVING YOUR OPENAI PROVIDER KEY
# Keep your SDK. Change the endpoint and key.
export OPENAI_BASE_URL=https://openai.gw.descles.com/v1
export OPENAI_API_KEY=<agent-descles-key>
BEFOREProvider keys on laptops

Shared credentials, unclear ownership, budgets discovered after spend.

WITH DESCLESOne company control path

Scoped identity, enforced limits, reviewable actions, signed evidence.

02 / TRY THE DECISION

Agents move fast.
You decide where they pause.

Try the interaction below. In your workspace, policy inspects structured tool calls in the model response and can withhold them for review. Resuming execution depends on your runtime integration.

descles / control room INTERACTIVE PREVIEW
ACTION REQUEST / 0042

Review a production command

Awaiting review
OWNERmaya / coding-agent
TOOLterminal
RESOURCEpod/checkout-api · production
Review the intent before the tool call reaches the agent.

This example holds a terminal command for review. Inspect the proposed resource, then approve once or deny it.

Illustrative UI; no real action executes here.EVERY EXCEPTION HAS AN OWNER.

Run the same story against the real policy, approval, resource, and audit APIs.

Open your console
03 / THREE CONTROL PATHS

Control what agents call,
do, and touch.

Model I/O is the hosted entry point. Tool and resource execution become enforceable when the participating runtime uses the mediated Action API or MCP adapter.

LIVE · HOSTED

Control intelligence

Route supported OpenAI and Anthropic traffic through one identity-aware gateway. Keep provider billing in your account, centralize credentials, attribute usage, and reject requests over budget.

CONTROL SURFACEopenai.gw.descles.com/v1
BYOK · routing · budgets · traces

Three paths, different maturity. Model I/O is hosted on AWS. The Tool I/O and Resource I/O policy surfaces work through integrated runtimes; their zero-setup hosted gateway is planned.

04 / THE CONTROL LOOP

From API traffic
to accountability.

Give the team a shared place to answer: which agent requested this, what did policy decide, and who approved it?

01

Identify

Bind every mediated request to an organization, group, agent, and agent-bound key.

02

Decide

Apply budgets and policy in the request path—not after the damage is done.

03

Intervene

Route sensitive actions to a named operator for an explicit decision.

04

Review

Review signed decision records alongside agent traces and approval history.

05 / YOUR KEYS. YOUR PROVIDERS.

Govern the traffic.
Keep the provider relationship.

Choose how each provider credential reaches the gateway. Both paths run through the same identity, budget, policy, approval, trace, and audit controls.

Read the endpoint contract
NO CREDENTIAL STORAGE

Use a key per request

Send the upstream endpoint and credential as headers on each call. Useful for evaluation and strict third-party storage policies.

api.gw.descles.com/v1
Same governed pathattribute → budget → inspect tool calls → deny or hold → trace → audit
Custom endpoints are first-classRouter aggregators (OpenRouter, OneAPI-style), LiteLLM proxies, self-hosted vLLM / SGLang — connect through the supported OpenAI-compatible protocols. The <name>.gw subdomain is just a label you choose; your model string passes through untouched.
06 / PRODUCT PROGRESS

Built to try today.
Clear about what comes next.

Start with one agent and a real workflow. Model routing and response-level tool enforcement are available now; execution integrations and audit hardening are still evolving in this technical preview.

Hosted model gateway

OpenAI Chat Completions, Responses, native Anthropic Messages, and OpenAI-compatible providers.

live

Agent-bound identity

Every data key belongs to an agent inside an isolated organization; header spoofing is rejected.

live

Hosted and per-request BYOK

Store provider credentials encrypted at rest, or send them only on an individual request.

live

Usage, cost, latency, budgets

Attribute calls and reject the next eligible request when a daily limit is reached.

live

Streaming tool-call enforcement

Deny or park tool calls across Chat Completions, Responses, and Anthropic SSE streams.

live

Approval and single-use resume

Create, decide, expire, and consume parameter-bound grants through participating runtimes.

live

Signed decision records

Inspect signed audit records and runtime-reported tool results. Tenant verification and production durability are being hardened.

preview

Hosted MCP / Action Gateway

The APIs and adapter work today; a zero-setup hosted execution path is still planned.

planned

Current boundary. Descles can stop tool intent before the agent receives it. Runtime-reported tool results provide execution evidence, not independent proof of local success. Actions outside the mediated path remain outside Descles control.

07 / TEST LAUNCH · TECHNICAL PREVIEW

Put your first agent
under control today.

Create your workspace, connect a provider, and try one agent with a 30-day test key. Your first 1,000 gateway requests are included. Model usage is billed by your provider; Descles adds no model markup. Activate a policy in the console to try your first deny or approval.

No credit card 1,000 requests Isolated org
Checking your session…
PRICING · ONE-TIME PACK

Start free.
Add requests when they run out.

Your workspace starts with 1,000 governed requests and no card. A request pack adds 25,000 more to the same workspace — spent by any agent in it, never expiring. Model usage stays on your provider account; Descles adds no markup to it.

ONE-TIME · NO SUBSCRIPTION

Descles request pack

$19for 25,000 governed requests
  • Added to your workspace, not to one key
  • Spent by any agent in the workspace, and never expires
  • Model usage stays on your own provider account
Charged in US dollars, excluding any sales tax, which is calculated at checkout. Sold by Waffo Pancake as our Merchant of Record. See terms and refunds.
08 / PLANNED

Help choose what
ships next.

Tell us what would make Descles useful to your team. These are planned capabilities, not included features. Sign in to vote once per item.

SIGNED-IN PRODUCT VOTE

What should we build next?

Checking your session…

ONE AGENT. ONE POLICY. YOUR FIRST GOVERNED REQUEST.

One control plane for
the agents already on your team.

Available as a hosted test path or a self-hosted container.

09 / FEEDBACK

Something broken?
Tell us directly.

Tell us which agent you use and where setup got stuck. Your feedback shapes the test launch.