AI Agent Allowlist
Home Page-Types Database Agent Guardrails 2026 Incidents API Docs Pricing
Resources
Use Cases (15) Industries & Buyers (12) Learn: Core Concepts (12) Implementation Guides (15) Comparisons (8) Schema & Data Reference (6) FAQ Glossary
Why It Matters
2026 Agent Incidents Category Targeting Database Refreshes Contact Customer Login
Download Free Sample
AI gateway market map for buyers and product teams

AI Gateway Vendors: What Each Category Controls

An AI gateway sits between your apps and the model APIs they call. This page sorts the vendors into five categories and shows the one layer most of them leave open.

That layer is web navigation: which pages an AI agent may open. It is what an AI agent allow list covers.

5Gateway categories
7Control layers compared
28Page types per domain
40M+Domains classified
Definition

What counts as an AI gateway

The term is used loosely. Vendors with very different products all call themselves AI gateways.

Working definition

An AI gateway is a proxy that every call to a large language model passes through.

It adds routing, keys, cost limits, logging and safety checks without changing each app.

01

It is not an API gateway

A classic API gateway manages your own APIs. An AI gateway manages outbound calls to model providers.

02

It is not an LLM firewall

Some gateways include prompt and response filters. Others leave that to a separate security product.

03

It sees model traffic

The gateway sees prompts, completions, tokens and tool call payloads as they pass.

04

It rarely sees the web

When an agent's browser tool opens a page, that request often goes out on a different path.

05

It is becoming the agent control point

As agents take actions, buyers expect the gateway to decide what those actions may touch, including web pages and MCP tools.

For how the terms relate, see LLM gateway vs AI gateway vs MCP gateway.

The market

Five categories of AI gateway vendors

Names below are examples that buyers commonly shortlist. They are grouped by where the product came from, which shapes what it controls.

CATEGORY 01

API management platforms with AI features

Examples: Kong, Azure API Management, Google Apigee, IBM API Connect
  • Mature policy engines, auth and rate limits
  • Token quotas and model routing added as plugins
  • Fits teams that already run the platform
  • Web pages an agent opens are out of scope
CATEGORY 02

Edge and CDN networks

Examples: Cloudflare AI Gateway, Vercel AI Gateway
  • Caching, analytics and retries at the network edge
  • Quick to switch on for apps already on the platform
  • Strong on cost visibility per model
  • Tracks model calls, not agent browsing targets
CATEGORY 03

LLM ops and developer gateways

Examples: Portkey, LiteLLM (open source), Helicone, TrueFoundry
  • One API across many model providers
  • Fallbacks, budgets, prompt logs and evaluations
  • Popular with product engineering teams
  • Guardrails focus on prompt and response text
CATEGORY 04

Data and ML platforms

Examples: Databricks Mosaic AI Gateway, AWS Bedrock features
  • Governance tied to the data catalog
  • Usage tracking and access by workspace
  • Fits teams building inside one data platform
  • Outbound agent web traffic is not the focus
CATEGORY 05

Cloud-native and open-source proxies

Examples: Envoy AI Gateway, Gloo AI Gateway (Solo.io), Traefik, Apache APISIX
  • Runs inside Kubernetes next to your services
  • Extensible filters and plugin chains
  • Full control for platform teams
  • Policy content, such as which URLs are risky, is yours to supply
WHAT IS MISSING

A data layer for agent navigation

Where this site fits
  • Knows where the login, checkout and upload pages are on 40M+ domains
  • Answers allow or deny per URL in one lookup
  • Plugs into any gateway above as a policy source

Vendor names are listed as examples of each category, based on how the vendors describe their products. Check current capabilities with each vendor before buying.

Control layers

Seven things an AI gateway could control

Most buyers compare gateways on the first four rows. Agent deployments add the last three.

Model routing

Send each call to the right provider, with fallbacks when one fails.

Common
Keys and access

One place for provider keys, with per-team virtual keys.

Common
Cost and quotas

Token budgets, rate limits and spend alerts per app.

Common
Prompt and output filters

PII masking, toxicity checks, prompt-injection detection on text.

Varies
Tool call inspection

Read which tool the model asked for, and with which arguments.

Varies
MCP server access

Which MCP servers and tools an agent may connect to.

Emerging
Web page policy

Whether the URL an agent is about to open is a login, checkout or upload page.

Usually missing
Why the last row is hard

A gateway can read "open https://example.com/account/new" in a tool call.

It cannot tell that this path is a signup page unless something has already mapped that site.

Side by side

How the categories compare for agent deployments

CategoryBest atTypical buyerAgent web controlWhere page data plugs in
API managementPolicy engine, auth, quotasPlatform and API teamsNeeds a custom pluginPlugin calls the lookup before egress
Edge and CDNCaching, analytics, simple setupWeb and app teamsNot in the model pathWorker or function checks tool URLs
LLM ops gatewaysMulti-model routing, budgetsProduct engineeringText guardrails onlyCustom guardrail on tool calls
Data platformsGovernance tied to dataData and ML teamsLimitedPolicy table in the catalog
Open-source proxiesFull control, extensibilityPlatform engineeringYou build itFilter or sidecar with local database

The pattern holds across all five. Gateways own the model path, and navigation needs its own data source.

The gap in practice

Two ways an agent reaches a web page

Path A: tool call through the gateway

  • The model asks for a fetch or browse tool with a URL
  • The gateway sees the tool call payload
  • A guardrail can check the URL before the tool runs
  • This is where a page-type lookup belongs

Path B: browser session outside the gateway

  • A computer-use or browser agent clicks links itself
  • Each page load goes straight to the internet
  • The gateway only sees screenshots and text
  • Control must sit at the egress proxy or browser

Most enterprises need both. See how to build an agent policy engine for the proxy side.

The data layer

What an AI agent allow list adds to any gateway

A lookup that says which part of a site a URL points to, before the request leaves.

40M+Domains classified
28Page types
~40Egress URL rules
~60High-risk hosts
# Gateway guardrail on a browse tool call (pseudocode) on tool_call(name="browse", url): verdict = lookup("https://www.aiagentallowlist.com/api/check?url=" + url) if verdict.result == "deny": return tool_error("blocked: " + verdict.id) # e.g. login, checkout, upload return run_tool(url)

The same check works as a plugin, a sidecar or an on-premise table. Details are in the API docs.

Buyer checklist

Eight questions to ask any AI gateway vendor

01

Do you see tool call arguments?

If not, URLs requested by agents are invisible to your policies.

02

Can a guardrail block a tool call?

Logging alone is not control. Ask for a pre-execution deny.

03

Can you call an external policy source?

You will want to plug in URL data you did not build.

04

What is the added latency?

A navigation check should stay in the low milliseconds.

05

What happens when a check fails?

Fail-closed should be the default for agent traffic.

06

Do you cover MCP connections?

Agents increasingly reach tools through MCP servers.

07

Is every decision logged?

Auditors will ask which agent tried which URL, and why it was denied.

08

Can it run on-premise?

Regulated teams often need the policy data inside their network.

Vendor snapshots

Twelve gateways buyers shortlist, in one line each

Short orientation notes, not reviews. Each vendor's own documentation is the source of truth.

Kong AI Gateway

AI plugins on the Kong API gateway, including model proxying and prompt guard plugins. Category 01.

Azure API Management

AI gateway policies such as token limits and load balancing across model deployments. Category 01.

Google Apigee

API management used as a front door for model APIs, with Google Cloud identity. Category 01.

IBM API Connect

API management with AI gateway features for IBM-centred estates. Category 01.

Cloudflare AI Gateway

Analytics, caching, rate limits and logging for model calls at the edge. Category 02.

Vercel AI Gateway

One API to many models for apps built on the Vercel platform. Category 02.

Portkey

Gateway with routing, fallbacks and guardrails, popular with product teams. Category 03.

LiteLLM

Open-source proxy that exposes many model providers behind one compatible API. Category 03.

Helicone

Open-source observability and gateway focused on logs, costs and caching. Category 03.

Databricks Mosaic AI Gateway

Usage tracking, rate limits and guardrails governed inside Databricks. Category 04.

Envoy AI Gateway

Open-source project built on Envoy for model traffic in Kubernetes. Category 05.

Gloo AI Gateway

Solo.io's cloud-native gateway with AI traffic policies. Category 05.

None of these notes claims that a vendor lacks a feature. Ask each one the eight questions above.

Rollout plan

Adding agent page control in four steps

1

Log first

Record every URL your agents request for two weeks. Tag each with its page type from the lookup.

2

Read the log

Count how often agents hit login, signup, checkout and upload pages. That is your real exposure.

3

Deny the action types

Block the 8 action types by default. Keep read pages such as docs, pricing and blog open.

4

Default-deny the unknown

Deny unclassified destinations, then add approved exceptions per agent role.

The 8 action types

signup, password_reset, cart, checkout, upload, post_create, comment and subscribe.

These are pages where an agent does something rather than reads. See page types explained.

Selection by situation

Which category fits which team

Your situationStart withAdd for agents
You already run Kong, Apigee or Azure APIMTheir AI pluginsA pre-egress plugin calling the page-type lookup
Your apps sit on Cloudflare or VercelTheir AI gateway for model callsURL checks in the browse tool or a worker
Many models, many teams, fast product workAn LLM ops gatewayA custom guardrail on fetch and browse tools
Everything lives in one data platformThe platform's AI gatewayAn on-premise page-type table in the catalog
Strict network control, Kubernetes everywhereEnvoy or another open proxyA filter with the full database licensed locally
Browser and computer-use agentsAny of the above for model callsAn egress proxy or enterprise browser with page rules
For gateway vendors

Shipping navigation control inside your gateway

If you build a gateway, your customers will soon ask what their agents may browse.

OPTION A

API lookup

  • From $99/month self-serve
  • Up to 2M lookups a month at $1,997
  • Fastest way to prototype
OPTION B

On-premise database

  • 10M domains, $14,999 one-time
  • 15M $24,999, 30M $49,999
  • No calls back to us
OPTION C

OEM license

  • Ship page rules to your customers
  • Rules library and host list included
  • Terms agreed per product

See pricing, or the AI gateway integration page for the product view.

Buying mistakes

Five mistakes teams make when choosing a gateway for agents

MISTAKE 1

Treating prompt filters as navigation control

  • A clean prompt can still lead to a checkout click
  • Text filters never see the page type
  • Test with a URL, not a sentence
MISTAKE 2

Blocking whole domains

  • Blocking amazon.com also blocks its product pages
  • Agents need the read pages to do their job
  • Block the page, not the site
MISTAKE 3

Guessing paths like /login

  • Real login pages sit on subdomains and locales
  • Guessed patterns miss many of them
  • Use verified URLs per domain
MISTAKE 4

Forgetting browser agents

  • Computer-use agents load pages directly
  • The model gateway never sees those loads
  • Put a check at the egress proxy too
MISTAKE 5

Fail-open defaults

  • A timeout should mean deny for agents
  • Fail-open turns an outage into a gap
  • Ask the vendor how to set fail-closed

The 2026 agent incidents went through the web, not the model API

  • Agents edited wikis, installed plugins and uploaded datasets.
  • Each step was an outbound web request that a model gateway does not inspect.
  • In our replay, the database plus egress rules would have stopped almost all of them.
Would your agents have been stopped? Check the incident analysis The Artifactory plugin case

The honest fine print — the same two assumptions we publish, plus two operational ones

  1. The policy engine must see every request — an agent with raw socket access or a second network path bypasses everything; enforcement belongs at the egress proxy/network layer, not only in an SDK hook.
  2. Default-deny must be on. In flag-only mode these become alerts within minutes rather than prevention — still a large improvement on a timeline measured in weeks (the DseWiki edits ran from late May to late June 2026, per the researchers), but not a block.
  3. For full URL+method matching on HTTPS you need to be the proxy or in-process hook — SNI alone shows only the host, which still catches the entire host-list layer.
  4. Policy can’t read intent inside a legitimately allowed action: an agent whose job is publishing packages keeps registry access. In our replay of the 2026 incidents, no crossing fits any plausible allowlist for the agents’ documented tasks.
Related

Keep reading

FAQ

AI gateway vendor questions

Which AI gateway vendors are there?
Buyers usually shortlist from five groups: API management platforms (Kong, Azure API Management, Apigee), edge networks (Cloudflare, Vercel), LLM ops gateways (Portkey, LiteLLM, Helicone), data platforms (Databricks) and open-source proxies (Envoy AI Gateway, Gloo, Traefik, APISIX).
Does an AI gateway stop agents from opening login or checkout pages?
Not by itself. A gateway can read a URL in a tool call, but it needs page-type data to know that the URL is a login or checkout page. An AI agent allow list supplies that data.
Is an AI gateway the same as an LLM gateway?
The terms overlap and vendors use both. "LLM gateway" usually means model routing only, while "AI gateway" often adds guardrails and tool traffic. See the comparison page.
Can I plug page-type data into an open-source gateway?
Yes. Call the lookup API from a filter, or license the database and query it locally so no request leaves your network.
What does the page-type data cost?
The lookup API starts at $99 a month. On-premise licenses start at $14,999 one-time for 10M domains. OEM terms for gateway vendors are agreed per product. See pricing.
Do AI gateways cover MCP servers?
Some are adding MCP features, such as approved server lists and tool call logging. MCP access control decides which tools an agent may use. Page-type data decides which web pages those tools may open, so the two work together.
Can I test it before buying?
The free sample CSV has 100 real domains with their page-type URLs.

Add navigation control to the gateway you already run

Test the data on 100 real domains, then choose API, on-premise or OEM.

Download the sample