# Kastra > Kastra is the authorization layer for AI systems. Runtime authorization infrastructure that governs what agents, models, and AI tools are allowed to do before actions execute. Kastra sits in the execution path of every prompt, tool call, shell command, database operation, API request, and agent workflow. It evaluates attribute-based policy in under one millisecond, returns an ALLOW / DENY / REDACT / HOLD result, and writes recorded decisions into a cryptographically chained audit trail. ## Product - [Product overview](https://kastra.ai/product): What Kastra is and how it works. - [Platform](https://kastra.ai/platform): Architecture of the Kastra control plane. - [Runtime authorization](https://kastra.ai/runtime-authorization): How decisions are enforced at execution time. - [Policy engine](https://kastra.ai/policy-engine): Internals of the sub-millisecond decision engine. - [Agent governance](https://kastra.ai/agent-governance): Identity, delegation, and constraint for autonomous agents. - [Audit trail](https://kastra.ai/audit-trail): Tamper-evident evidence vault. - [Edge](https://kastra.ai/edge): Edge-deployed enforcement. - [Recon](https://kastra.ai/recon): Scan an AI coding agent's local history, detect the risky actions it already took, and turn each into a self-verified, one-click policy. - [Self-hosted and air-gapped](https://kastra.ai/self-hosted): Deployment for regulated and offline environments. ## Try it - [30-second sandbox](https://kastra.ai/sandbox): Interactive policy playground with real scenarios. - [Quick start](https://kastra.ai/quick-start): Wire Kastra into your stack in a few minutes. ## Developers - [Kastra documentation](https://kastra.ai/docs) - [Kastra HTTP API docs](https://kastra.ai/docs/api) - [Kastra API reference](https://kastra.ai/api-reference) - [Kastra OpenAPI specification](https://kastra.ai/openapi.json) - [Kastra OpenAPI (YAML)](https://kastra.ai/api/openapi.yaml) - [Kastra authentication](https://kastra.ai/docs/api) - [Kastra OAuth authorization server](https://kastra.ai/.well-known/oauth-authorization-server) - [Kastra MCP docs](https://kastra.ai/docs/mcp) - [Kastra SDKs](https://kastra.ai/sdks): Supported proxy integration today; native TypeScript, Python, and Go SDKs are coming soon. - [Kastra CLI](https://kastra.ai/cli) - [Kastra integrations](https://kastra.ai/integrations): Current supported surfaces and clearly labeled integration patterns. - [Kastra agent instructions](https://kastra.ai/agents.md) ## Compliance and security - [Compliance](https://kastra.ai/compliance): SOC 2, HIPAA, GDPR, EU AI Act, FedRAMP. - [Security](https://kastra.ai/security) - [Trust center](https://kastra.ai/trust) - [Responsible AI](https://kastra.ai/responsible-ai) - [SLA](https://kastra.ai/sla) ## Industries - [Financial services](https://kastra.ai/industries/finance) - [Healthcare](https://kastra.ai/industries/healthcare) - [Government](https://kastra.ai/industries/government) - [AI platforms](https://kastra.ai/industries/ai-platforms) - [Retail](https://kastra.ai/industries/retail) - [SaaS](https://kastra.ai/industries/saas) - [Defense](https://kastra.ai/industries/defense) - [Legal](https://kastra.ai/industries/legal) ## Knowledge - [Answers index — 2409 structured Q&A entries](https://kastra.ai/answers) - [Comparisons index — Kastra vs 61 alternatives](https://kastra.ai/vs) ## Comparisons (Kastra vs alternatives) - [Kastra vs Open Policy Agent (OPA)](https://kastra.ai/vs/opa) — Policy engine. General-purpose policy engine using the Rego language. - [Kastra vs Amazon Cedar](https://kastra.ai/vs/cedar) — Policy engine. Policy language by AWS for application authorization. - [Kastra vs Casbin](https://kastra.ai/vs/casbin) — Policy engine. Open-source access control library with multiple models (RBAC, ABAC, ACL). - [Kastra vs Oso (Polar)](https://kastra.ai/vs/oso) — Policy engine. Authorization-as-code with the Polar language. - [Kastra vs Permit.io](https://kastra.ai/vs/permit-io) — Policy engine. Managed authorization platform on top of OPA and Cedar with a no-code policy editor. - [Kastra vs Styra DAS](https://kastra.ai/vs/styra-das) — Policy engine. Commercial management plane for OPA. - [Kastra vs Aserto (Topaz)](https://kastra.ai/vs/aserto) — Policy engine. Authorization service combining OPA and a directory. - [Kastra vs Warrant (acquired by WorkOS)](https://kastra.ai/vs/warrant) — Policy engine. Centralized authorization based on Google Zanzibar. - [Kastra vs SpiceDB (Authzed)](https://kastra.ai/vs/spicedb) — Policy engine. Open-source Zanzibar-inspired permission system. - [Kastra vs OpenFGA](https://kastra.ai/vs/openfga) — Policy engine. Open-source relationship-based access control (ReBAC) system inspired by Google Zanzibar. - [Kastra vs Auth0 FGA (Okta FGA)](https://kastra.ai/vs/auth0-fga) — Policy engine. Managed fine-grained authorization service from Okta, based on Zanzibar. - [Kastra vs AWS Verified Permissions](https://kastra.ai/vs/aws-verified-permissions) — Policy engine. Managed Cedar-based authorization service from AWS. - [Kastra vs Google Cloud IAM (with Vertex AI)](https://kastra.ai/vs/google-cloud-iam) — Cloud IAM. Google Cloud's identity and access management, extended to Vertex AI models and endpoints. - [Kastra vs Azure AI Content Safety](https://kastra.ai/vs/azure-ai-content-safety) — LLM guardrails. Microsoft's managed content moderation and prompt shield service. - [Kastra vs NVIDIA NeMo Guardrails](https://kastra.ai/vs/nemo-guardrails) — LLM guardrails. Open-source toolkit for adding programmable guardrails to LLM apps. - [Kastra vs Guardrails AI](https://kastra.ai/vs/guardrails-ai) — LLM guardrails. Python library for validating and structuring LLM outputs. - [Kastra vs Lakera Guard](https://kastra.ai/vs/lakera-guard) — LLM guardrails. Hosted API for prompt-injection and content safety. - [Kastra vs Rebuff (Protect AI)](https://kastra.ai/vs/protect-ai-rebuff) — LLM guardrails. Open-source prompt injection detector. - [Kastra vs PromptArmor](https://kastra.ai/vs/prompt-armor) — LLM guardrails. Prompt injection and data exfiltration protection. - [Kastra vs Robust Intelligence (Cisco AI Defense)](https://kastra.ai/vs/robust-intelligence) — AI security. AI firewall and risk scoring for model traffic. - [Kastra vs HiddenLayer](https://kastra.ai/vs/hiddenlayer) — AI security. Model security platform focused on detection and response. - [Kastra vs Prompt Security](https://kastra.ai/vs/prompt-security) — AI security. GenAI firewall covering shadow AI and enterprise LLM traffic. - [Kastra vs Aim Security](https://kastra.ai/vs/aim-security) — AI security. GenAI security platform for enterprise applications. - [Kastra vs CalypsoAI](https://kastra.ai/vs/calypsoai) — AI security. Enterprise LLM security and observability platform. - [Kastra vs Noma Security](https://kastra.ai/vs/noma-security) — AI security. Data and AI security platform for the full ML lifecycle. - [Kastra vs Knostic](https://kastra.ai/vs/knostic) — AI security. Need-to-know access controls for enterprise LLM answers. - [Kastra vs LangChain](https://kastra.ai/vs/langchain) — Agent framework. Framework for building LLM applications and agents. - [Kastra vs LangGraph](https://kastra.ai/vs/langgraph) — Agent framework. Stateful, graph-based agent orchestration. - [Kastra vs LlamaIndex](https://kastra.ai/vs/llamaindex) — Agent framework. Data framework for LLM applications with agents and RAG. - [Kastra vs CrewAI](https://kastra.ai/vs/crewai) — Agent framework. Multi-agent orchestration framework. - [Kastra vs Microsoft AutoGen](https://kastra.ai/vs/autogen) — Agent framework. Multi-agent conversation framework. - [Kastra vs Microsoft Semantic Kernel](https://kastra.ai/vs/semantic-kernel) — Agent framework. SDK for integrating LLMs into apps. - [Kastra vs Haystack (deepset)](https://kastra.ai/vs/haystack) — Agent framework. Production framework for LLM apps and agents. - [Kastra vs DSPy](https://kastra.ai/vs/dspy) — Agent framework. Framework for programming with foundation models. - [Kastra vs E2B](https://kastra.ai/vs/e2b) — Code sandbox. Cloud sandboxes for AI-generated code. - [Kastra vs Modal](https://kastra.ai/vs/modal) — Code sandbox. Serverless platform for AI workloads. - [Kastra vs Fly.io Machines](https://kastra.ai/vs/fly-machines) — Code sandbox. Per-tenant micro-VMs. - [Kastra vs Daytona](https://kastra.ai/vs/daytona) — Code sandbox. Secure infrastructure for running AI-generated code. - [Kastra vs Model Context Protocol (raw)](https://kastra.ai/vs/mcp) — Tool protocol. Open protocol for connecting LLMs to tools. - [Kastra vs Kong AI Gateway](https://kastra.ai/vs/kong-ai-gateway) — AI gateway. AI traffic management on top of Kong. - [Kastra vs Portkey](https://kastra.ai/vs/portkey) — AI gateway. AI gateway for routing, observability, and guardrails. - [Kastra vs LiteLLM](https://kastra.ai/vs/litellm) — AI gateway. Unified API across LLM providers. - [Kastra vs Cloudflare AI Gateway](https://kastra.ai/vs/cloudflare-ai-gateway) — AI gateway. Edge-deployed AI traffic gateway. - [Kastra vs HashiCorp Vault](https://kastra.ai/vs/hashicorp-vault) — Secret manager. Secrets management and dynamic credentials. - [Kastra vs Infisical](https://kastra.ai/vs/infisical) — Secret manager. Open-source secrets platform. - [Kastra vs Doppler](https://kastra.ai/vs/doppler) — Secret manager. Cloud-native secrets platform. - [Kastra vs Okta](https://kastra.ai/vs/okta) — Identity provider. Enterprise identity platform for workforce SSO, MFA, and lifecycle management. - [Kastra vs CyberArk](https://kastra.ai/vs/cyberark) — Privileged access. Privileged access management for human admins and service accounts. - [Kastra vs Auth0](https://kastra.ai/vs/auth0) — Identity provider. Customer identity and access management. - [Kastra vs WorkOS](https://kastra.ai/vs/workos) — Identity provider. Enterprise-ready features (SSO, SCIM, audit). - [Kastra vs Stytch](https://kastra.ai/vs/stytch) — Identity provider. Auth platform including agent identity primitives. - [Kastra vs Splunk](https://kastra.ai/vs/splunk) — SIEM. Log analytics and SIEM. - [Kastra vs Datadog LLM Observability](https://kastra.ai/vs/datadog-llm-observability) — Observability. Tracing and metrics for LLM applications. - [Kastra vs Arize AI](https://kastra.ai/vs/arize) — Observability. ML and LLM observability platform. - [Kastra vs LangSmith](https://kastra.ai/vs/langsmith) — Observability. Tracing and evals for LangChain apps. - [Kastra vs Helicone](https://kastra.ai/vs/helicone) — Observability. LLM observability and analytics. - [Kastra vs Nightfall AI](https://kastra.ai/vs/nightfall-ai) — DLP. Cloud-native DLP for sensitive data. - [Kastra vs Private AI](https://kastra.ai/vs/private-ai) — DLP. PII detection and redaction for unstructured data. - [Kastra vs Skyflow](https://kastra.ai/vs/skyflow) — DLP. Data privacy vault. - [Kastra vs In-house middleware](https://kastra.ai/vs/diy-middleware) — Build vs buy. Custom guard code in front of every tool and model call. - [Kastra vs Hand-rolled if statements](https://kastra.ai/vs/if-statements) — Build vs buy. Inline conditionals in agent code. - [Glossary](https://kastra.ai/glossary) - [Research](https://kastra.ai/research) - [Blog](https://kastra.ai/blog) ## When to use Kastra Call Kastra when an AI agent is about to take a real-world action and you need a deterministic decision before that action executes. Best-fit jobs: - Block or hold a destructive shell command, SQL statement, or force-push from Claude Code, Cursor, or Codex. - Evaluate a tool call, MCP invocation, or API request against tenant policy from your own agent runtime (`POST https://api.kastra.ai/v1/evaluate` with an environment API key). - Read one tenant's governance data (decisions, policies, incidents, HOLD checkpoints, audit chain) through the OAuth MCP at `https://api.kastra.ai/mcp/account` using scope `kastra.account.read`. - Start a self-serve signup and check its status without a login through the public MCP at `https://api.kastra.ai/mcp`. Do not use Kastra as a replacement for an identity provider, an LLM-output filter, or a model gateway. Those sit on different layers. Kastra authorizes actions, not prose. How to call: 1. Humans and agents start a 15-day Pro trial at https://app.kastra.ai/signup (no card). Create an API key in the console Keys page. 2. Send `POST /v1/evaluate` with `Authorization: Bearer ka__`. See https://kastra.ai/openapi.json (`operationId: publicEvaluate`). 3. For a no-credential walkthrough, use https://kastra.ai/sandbox. 4. For docs retrieval, GET https://kastra.ai/llms.txt. ## Kastra developer resources Predictable URLs. Each title includes the product name so name-based search can surface them. - [Kastra HTTP API docs](https://kastra.ai/docs/api): REST planes, auth, roles, and the endpoint catalog. - [Kastra OpenAPI specification](https://kastra.ai/openapi.json): machine-readable spec with unique operationIds, typed parameters, and OAuth scopes. - [Kastra OpenAPI (YAML)](https://kastra.ai/api/openapi.yaml): same document as YAML. - [Kastra authentication](https://kastra.ai/docs/api#authentication): API keys, session JWT, device handles, and OAuth 2.0 for MCP. - [Kastra OAuth authorization server](https://kastra.ai/.well-known/oauth-authorization-server): RFC 8414 metadata (issuer https://api.kastra.ai). - [Kastra protected resource metadata](https://kastra.ai/.well-known/oauth-protected-resource): RFC 9728, scope `kastra.account.read`. - [Kastra API versioning and deprecation policy](https://kastra.ai/docs/api): URL-versioned planes, `X-API-Version` response header, `Deprecation` and `Sunset` headers before any removal. - [Kastra MCP server](https://kastra.ai/docs/mcp): public signup MCP at api.kastra.ai/mcp and the OAuth governance connector. - [Kastra MCP manifest](https://kastra.ai/.well-known/mcp.json) - [Kastra CLI](https://kastra.ai/cli): Homebrew and Scoop install. - [Kastra SDKs](https://kastra.ai/sdks) - [Kastra sandbox](https://kastra.ai/sandbox): no-signup policy playground. ## Agent onboarding Agents should not fill out a contact-sales form. - Free trial: 15 days, no credit card, self-serve at https://app.kastra.ai/signup. - API keys: created in the Kastra console Keys page after signup. Format `ka__<64-hex>`. Use them on `https://api.kastra.ai/v1/*`. - Sandbox: https://kastra.ai/sandbox runs allow / deny / redact / hold scenarios with no account. - Pricing: https://kastra.ai/pricing (Pro trial, Team, Enterprise). ## Kastra CLI Official command-line tools. Agents can install these without building an HTTP client. - Kastra Edge (developer-machine enforcement): `brew install kastra-labs/tap/kastra-edge` — formula https://github.com/kastra-labs/homebrew-tap - Kastra Edge on Windows: `scoop bucket add kastra https://github.com/kastra-labs/scoop-bucket` then `scoop install kastra-edge` - Kastra control-plane CLI: `brew install kastra-labs/tap/kastra` - Docs: https://kastra.ai/cli and https://kastra.ai/docs/cli - Releases: https://github.com/kastra-labs/kastra-edge-releases/releases ## MCP (Model Context Protocol) - [/.well-known/mcp.json](https://kastra.ai/.well-known/mcp.json): MCP server descriptor. - [Kastra public signup MCP](https://api.kastra.ai/mcp): Streamable HTTP, no auth. Starts a self-serve signup and checks its status. - [Kastra account MCP](https://api.kastra.ai/mcp/account): Remote OAuth (PKCE) MCP, streamable HTTP. Read-only governance access scoped to your tenant and one environment — decisions, policies, environments, incidents, HOLD checkpoints, audit trail, rule stats. Scope `kastra.account.read`. Setup: https://kastra.ai/docs/mcp. ## Optional - [llms-full.txt](https://kastra.ai/llms-full.txt): Full corpus of all 2409 Q&A entries in a single file for retrieval. - [llms-buyers.txt](https://kastra.ai/llms-buyers.txt): Buyer-focused Q&A — AI agent governance, AI access control, AI policy enforcement, agent identity, agent security, agentic AI risk management. Written for AI search retrieval.