The authorization layer for AI systems
Kastra is the authorization layer for AI systems. It sits in the execution path of every prompt, tool call, shell command, database operation, API request, and agent workflow. Before an action runs, Kastra evaluates attribute-based policy in under one millisecond and returns allow, deny, redact, or hold. Recorded decisions form a cryptographically chained audit trail so operators, auditors, and agents can explain why something was permitted.
What Kastra does
Use the Kastra HTTP API from production agents, install Kastra Edge on developer machines to govern Claude Code, Cursor, and Codex, or connect an MCP client to read governance data. A no-signup sandbox lives at /sandbox. A 15-day self-serve trial starts at https://app.kastra.ai/signup — API keys are created in the console with no sales call.
When to use Kastra
Reach for Kastra when an agent can take a real-world action and you need a deterministic allow, deny, redact, or hold before that action executes. Kastra is the wrong tool if you only need to filter model prose, route between model vendors, or replace your identity provider.