{"repo":"Garudex-Labs/caracal","free":true,"listed":false,"github":"https://github.com/Garudex-Labs/caracal","clone":"git clone https://github.com/Garudex-Labs/caracal.git","description":"🐾 Authority, not credentials, for AI agents: policy-approved actions, delegation that can only narrow, instant revocation, tamper-evident audit.","language":"TypeScript","stars":171,"topics":["authorization","agent-security","ai-agents","oauth2","zero-trust"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"Authority, not credentials: Policy-checked, attributable, revocable, provable AI agent authorization. Supported By: &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; &nbsp;&nbsp;&nbsp; --- Why Caracal \"Gateway-mediated agents never hold upstream credentials. Every action is policy-approved before it runs, scoped to exactly what was delegated, revocable in one call, and recorded as tamper-evident evidence.\" AI agents are entering production with long-lived API keys in their environment , broader access than any task needs , and no answer to \"which agent did this, under whose authority?\" One prompt injection, leaked key, or runaway loop turns an assistant into an incident. Security reviews block launches. Auditors have nothing to inspect. Existing tools weren't built for this: identity providers register agents but never see their actions, secrets managers hand the credential to the workload, and API gateways route traffic without deciding anything. Caracal is the missing control plane. It decides what an agent may do before every action, proves what it actually did , and shuts it down instantly when something goes wrong. --- How It Works For gateway-mediated calls, agents never receive upstream credentials. They carry mandates : short-lived, signed grants of authority that can only shrink as work is delegated. Caracal's gateway injects the real credential at call time, so the upstream credential never enters the agent process. Capability Outcome for your team -----------------------------","default_branch":null,"files":null,"tree":[],"storefront":"/r/Garudex-Labs","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Garudex-Labs/caracal/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}