Straza docs
Open source runtime governance for AI agents.
Straza is the control plane between your IdM/IGA and your agents. Your identity manager (IdM) or identity governance and administration system (IGA) says who people and agents are and which roles they hold. Straza turns those roles into a decision on each tool call that passes through it, on the agent’s machine and at the gateway in front of your MCP servers. It records every decision.
Start from what you came to do
- Try it on one machineInstall the binaries, then run your first governed session. The server needs nothing else.Install
- Run it for a teamPick a profile, deploy with Docker or Helm, add TLS and back it up.Run Straza
- Connect your identity managermidPoint, Okta or any SCIM client provisions people, agents and roles.Connect identity
- Govern an agent or a coding assistantConnect Claude Code, Codex CLI, Gemini CLI or your own Python agent.Govern agents
- Put MCP servers behind the gatewayAdd a server, store its credential and give a role its tools.Add a server
- Review security and auditThe security model, the known limits, the audit chain and the compliance mapping.Security
- Explore the demo stackmidPoint, Keycloak and working AI agents, wired together on your machine.The demo stack