Skip to content
Back to the index

CapFence

capfence.devInfrastructure

PulseGate's liveness check found it on 14 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 17 Jun 2026. How this is checked

CapFence is an authorization gateway for AI agent side effects. It sits between agents and real-world tools so that shell, database, filesystem, payment, API, and MCP calls are evaluated before they run. The page states that agents do not authorize themselves and that CapFence removes the LLM from the authorization path before execution.

Inferred · not functionally tested

Open SourceMITCLISelf-hosted
CapFence preview
Visit capfence.dev

Overview

5 features

Purpose: Prevents unauthorized or risky actions by AI agents by enforcing policy-based authorization for side effects.

Inferred · not functionally tested

Audience: AI infrastructure engineers and security teams

Inferred · not functionally tested

Functions: agents, monitoring

Inferred · not functionally tested

Interfaces: API: unknown · MCP: indicated (inferred, not tested) · CLI: indicated (inferred, not tested) · Self-hosting: indicated (inferred, not tested)

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli, self_hosted

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: capfence.dev · github.com. These links do not verify the individual claims.

CapFence is an AI security & guardrails project. Inferred · not functionally tested: It prevents unauthorized or risky actions by AI agents by enforcing policy-based authorization for side effects. Inferred · not functionally tested: CapFence is an open-source project aimed at AI infrastructure engineers and security teams. Basis unknown · not verified: CapFence is open source under the MIT license. Basis unknown · not verified: It ships for the command line, and it can be self-hosted.

CapFence first shipped in 2026. Inferred · not functionally tested: Key capabilities include policy enforcement, shell command authorization, and database write control. Basis unknown · not verified: Catalogued interfaces include an MCP server. CapFence is currently in beta.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Policy enforcement
  • Shell command authorization
  • Database write control
  • API access gating
  • Replayable decisions

Topics: Inferred · not functionally tested

Tags
agent-authorizationside-effect-gatewaypolicy-enforcementmcp-integrationai-security

JSON profile · Text profile · Access guide

Built with & integrations

Framework
Next.js
Connectors
MCP
Runs on
CLISelf-hosted
Detected from
Next.js
/_next/static/ in the HTML · __next_f in the HTML

Trust & compliance

License
MIT
Public signals

Indexing history

What PulseGate has recorded for this listing

Nothing recorded for this listing in this window.

Frequently asked questions about CapFence

What is CapFence?
Inferred · not functionally tested: CapFence prevents unauthorized or risky actions by AI agents by enforcing policy-based authorization for side effects. It is catalogued under AI security & guardrails on PulseGate.
Who should use CapFence?
Inferred · not functionally tested: CapFence is an open-source project built for AI infrastructure engineers and security teams.
Is CapFence free?
Basis unknown · not verified: Yes — CapFence is open source under the MIT license and free to use.
What platforms does CapFence run on?
Basis unknown · not verified: CapFence runs on the command line. It can also be self-hosted.
Is CapFence still active?
PulseGate's liveness check found it on 14 Sep 2026.
How long has CapFence been around?
CapFence first shipped in 2026.
Is CapFence open source?
Basis unknown · not verified: Yes — CapFence is open source under the MIT license, developed on GitHub.
Does CapFence have an API or integrations?
Basis unknown · not verified: Yes — CapFence exposes an MCP server.

Similar projects

Closest matches by what these projects do