Reference

Field-level reference for Agent Gateway surfaces, gateways, trust registries, settings, and operations.

This section provides field-level reference material for every configurable component in the Agent Gateway. Each page covers exact field names, types, defaults, and accepted values.

For step-by-step configuration tasks, see How-to Guides. For conceptual explanations, see Concepts.

Surfaces

ReferenceWhat it covers
Surface referenceTop-level AgentSurface panel fields, protocol options, gateway DID injection settings, and the canvas element index.
Access PointInbound listener: panel settings (listen address, channel prefix, custom path) and canvas elements (policy, rate limit, caller context, identity, trust check, extension validation, metadata).
Managed AgentUpstream destination: endpoint routing and authentication.
Transit PointsAgent-initiated outbound routes: transit point panel settings and canvas elements for per-destination policy, rate limiting, and payment.
VariantsNamed surface snapshots: alias grammar, canvas configuration, and default variant promotion.
Caller ContextAuthentication method selection and per-method credential extraction configuration.
IdentityAgent DID extraction at inbound, protected, external, or outbound pipeline edges.
NetworkingRequest control: timeouts, automatic retry, circuit breaking, traffic mirroring, and the Rate Limit canvas element.
MCP ToolsPer-tool RBAC policy bindings for MCP surfaces.
Paymentx402 paywall configuration for MCP and A2A surfaces.
Trust elementsTrust Check and Trust Recorder elements: TRQP queries, template syntax, result wire shape, error codes, and trust registry writes.
OPA policiesThe Policy element and the complete input field reference for gateway, surface, and MCP tool policy scopes.
Protocol extensionsExtension Validation and Extension Rules elements for A2A and AP2 surfaces.
Metadata elementsMetadata Injection and Metadata Extraction elements: header manipulation and protocol metadata normalisation.
Outbound bindingCredential Delegation and Workload Binding elements: outbound credential injection and VP binding.

Proxies

ReferenceWhat it covers
MCP ProxyMCP Proxy fields, tool generation, sandbox, and how to target a proxy from a surface.

Authentication

ReferenceWhat it covers
SecretsSecret fields, types, and lifecycle operations (create, update, delete).
API keysAPI key fields, key states, and lifecycle operations (create, revoke, rotate, delete).
JWT Verification StrategiesStrategy fields, token validation sequence, and audience configuration.

Gateways

ReferenceWhat it covers
Gateway objectGateway fields, status, and Publishing tab settings.
Connection point objectConnection point fields and metadata.
MediatorMediator fields, status values, and metadata.

Trust registries

ReferenceWhat it covers
Trust registry objectTrust registry fields, verification modes, and mediator configuration.
Issuer objectIssuer fields, TR Registration Status values, and actions.

Observability

ReferenceWhat it covers
TasksRuntime status of surface listeners, connection point tasks, and MCP proxy registrations. Use it to confirm that listeners are up before diagnosing call failures.
NotificationsNotification fields, statuses, and the difference between inbox notifications and integration deliveries.
MetricsField-level reference for ConnectionMetric records exported via OTLP, CloudWatch, or file. Use to interpret fields in your metrics receiver or export files.

Payments

ReferenceWhat it covers
PaymentsTransaction table columns, processing modes, status values, and actions in the Payments view.

Configuration

ReferenceWhat it covers
IntegrationsFields for email, Slack, webhook, and streaming platform integrations.
SettingsDashboard settings: system settings, user preferences, network and mTLS configuration, admin operations, and user management.
Echo serverDependency-free local HTTP echo server. Prints incoming requests to stdout and echoes them as JSON. Supports passive echo and active relay modes for Transit Point testing.