dhvati ProductConnectSecurityPricingDocs
Book a demo
IAM for the agent era

Identity, authorization, and audit for AI agents.

Govern every tool call your agents make — on the harnesses you already use. Credentials stay in the vault, policy decides each call, everything is audited. Nothing to bypass.

Book a demo Request access
Works with Claude Desktop, claude.ai, Claude Code, Cursor & any MCP client → · OIDC / SAML / SCIM · Cedar policy
Claude — maya@acme
Post the standup summary to #eng-daily.
I can't — dhvati blocked it:
slack.post_message DENY · requires your approval
I hold no Slack credential, so there's no way around it. I can request access for you — want me to?
Yes, request it.
Requested — I sent your admin the reason. request pending
Approved by Deepa (admin) — 24 hours · audited via dhvati
Posted to #eng-daily. ALLOW · credential injected from vault · logged
09:41:22 maya@acme slack.post_message ALLOW · grant 24h (Deepa)
Blocked → requested → approved → allowed. Every step audited.
console.dhvati.ai
dhvati Console — admin dashboard with pending access requests, posture stats, active grants
Built on open standards OIDCSAML / SCIMCedarMCPOAuth 2.1 100% of decisions audited0 credentials held by agentsdeny by default
The platform

Authenticate. Authorize. Audit.

Authenticate
Every agent action is tied to a verified person — your IdP (OIDC, SAML, SCIM) for orgs, dhvati-issued identity for individuals. No anonymous automation.
Authorize
Per-role, per-action policy in Cedar, with resource scope and conditions. Allow the read, deny the post — decided on every call, before it reaches the vendor.
Audit
Every decision logged — who, what, when, allow or deny, and why — in a stream your SIEM can read. Answers, not forensics.
Policy

The most confident table an admin has ever used.

Roles × actions, default-deny. Allow the read and deny the post in one click, simulate "would Carol be allowed?" before you save, and review every change as a diff. Compiles to Cedar; the Gateway enforces it within seconds.

Explore policy
Roles & Policies — the roles-by-tools allow/deny matrix with the Would-Carol simulator
Audit log — every Gateway decision with allow/deny, reason, and volume over time
Audit

Answers, not forensics.

Every decision the Gateway makes — who, what, when, allow or deny, and the exact policy path that decided it. A deny links to the request it created and the grant that resolved it. Export today; SIEM streaming is on the near-term roadmap.

Explore audit
How it works

Credential custody, not honor system.

The Gateway holds your vendor credentials. It verifies the acting employee, evaluates Cedar policy, then injects the credential and forwards — or blocks.

Step 1 · Agent
Claude Code, Cursor, or a custom harness makes a tool call — with no credential of its own.
Step 2 · dhvati Gateway
Verifies the employee via your IdP, checks Cedar policy, audits the decision — then injects the vault credential and forwards, or blocks with a precise reason.
Step 3 · Vendor
Slack, GitHub, internal APIs, MCP servers — reached only through the Gateway, only with an allowed call.
"Bypass the Gateway and you get no credential — so there's nothing to bypass."
Connect your agent

Two minutes to your first governed call.

One endpoint for every agent. Paste it into Claude Desktop, claude.ai, Claude Code, or Cursor, sign in when the browser opens — and every call after that is verified, decided by policy, and audited.

Connect your agent Book a demo
Terminal — or any connector menu
# your endpoint — same URL for everyone
https://mcp.dhvati.ai/mcp
# e.g. Claude Code
claude mcp add --transport http dhvati https://mcp.dhvati.ai/mcp
✓ sign in once → every call governed & audited
Why dhvati

Built for how enterprises actually run agents.

Harness-agnostic
Claude Code, Cursor, custom harnesses. Govern the agents you already use — no switch required.
Un-bypassable by design
Credential custody means the Gateway is the only place credentials exist. Going around it yields nothing.
Sovereign & on-prem
Run it in your datacenter or cloud of choice. Start hosted, self-host when you need to.
Standards-based
Cedar for policy, OIDC / SAML / SCIM for identity. Nothing proprietary, nothing exotic to learn.

Put your agents under governance.

See dhvati govern a live agent's tool calls in a 30-minute walkthrough — or request access to run it yourself.

Book a demo Request access
dhvati
Sovereign identity, authorization & audit for the agent era. Run it hosted, or entirely on your own infrastructure.
ProductPlatformGatewayPolicy & CedarAudit & SIEM
CompanyDocsPricingContactTrust centerTerms
DeployHosted — book a demoSelf-hosted / on-premClaude Code setupCursor setup
© 2026 dhvati · a product of Adiyogi Technologies · Made for security-first teams. Cedar · OIDC / SAML / SCIM · MCP