Agent Action Passport Runtime

Passport-gated actions for coding and devops agents.

dexgate is the product implementation of Decision Execution Governance for coding and devops agents. For supported integrations and configured execution surfaces, it evaluates covered shell, patch, and deploy-class proposals before execution and returns an allow, constrain, deny, or escalation result. A model may propose; a protected executor acts only with scoped authority where the paid path is enabled.

Start free with local hard gates. Move to paid dexgate when production-bound actions need Dexgate policy decisions, Action Passport policy evaluation, and reviewable outcome evidence. The product model is broader than today’s implemented coverage—see the compatibility matrix for which adapters and surfaces are available now (including Codex host-path limits).

Start Free Interactive demo See Pricing How Passports work

Purchase

Current availability

Free adapters: available now on npm

Paid governed workflows: early-access pilot

Coverage last validated: July 30, 2026

Validated free packages: @dexgate/openclaw-trusted-mode@1.0.18, @dexgate/codex-trusted-mode@0.1.16

See the compatibility matrix for coverage, limitations, and current versions.

Choose the operating mode that fits your rollout

Free local hard gate

Best for: adapter evaluation and safer local defaults

Protection: local adapter-specific hard gates with conservative read-only defaults; high-consequence actions blocked. Exact allowed tools vary by adapter—see Compatibility.

Outcome: no passport, no governed decision record

Paid dexgate runtime

Best for: production-bound coding/devops agents in a controlled pilot

Protection: Dexgate policy decision plus Action Passport authority

Outcome: reviewable policy decision, authorization, execution verification, and outcome record

What it does

Stops risky covered actions before execution

On supported adapters, dexgate evaluates covered shell, patch, and deploy-class agent proposals before execution—not every host capability in every mode.

Creates passport records your team can review

Security, audit, and engineering teams can see what was requested, which policy applied, what scope was authorized, and why execution was allowed or refused.

Takes you from safe defaults to governed control

Free local hardening helps you start safely. Paid dexgate adds the pilot policy runtime and Action Passport path for production-bound allow-with-proof when entitled.

How it works

Agent Execution Governance is Decision Execution Governance applied to AI agents. The primary use case is governed production change: shell commands, code patches, and deploy-class actions.

Where the runtime exposes a pre-execution hook, the adapter intercepts covered actions before they execute.

Free mode applies local hard gates.

Paid dexgate checks important actions against policy and Action Passport rules.

Allowed protected actions carry passport evidence for review.

Technical details

Technical details: free mode uses local hardening only (no passport). Paid dexgate uses Dexgate policy decisions, Ed25519-verified policy packs at load, Action Passport policy evaluation, and governed evidence records. Adapter package “integrity” files are local checksums—not the same as runtime policy-pack or decision signing. OpenClaw is the recommended free path; Codex has controlled host coverage (some host paths may report governance gaps).

What dexgate adds

Governed action decisions

Allow, deny, constrain, acquire more evidence, simulate, or escalate sensitive runtime actions with clear policy outcomes.

Scoped action passports

On the paid path, bind allowed actions to an authorization type, target, environment, expiry, and proof fields for review. When outcome signing is enabled in the licensed runtime, those proof fields can carry Ed25519 signatures.

Reviewable outcome records

Keep clear evidence for troubleshooting, internal controls, and security review after execution succeeds or is refused. Free local hard gates do not mint passports.

What is an Action Passport?

An Action Passport is a scoped, single-use authorization record for one supported agent action, issued only after policy decides, and re-checked before protected execution so production side effects stay allow-with-proof. When cryptographic signing is enabled, the record can be independently verified.

It is not a login session, API key, or travel document.

Free path

No Passport

Local hard gates on the agent host with conservative read-only defaults (adapter-specific allowlists). High-consequence actions stay blocked. See Compatibility for exact free-mode surfaces.

  • Host-local only
  • No shared Dexgate policy decide / issue / verify path
  • No org-wide decision or Action Passport stream
  • Free mode: local allowlist only (no Passport); assess may still report separate env fields

Paid path

Full Passport pipeline

Customer-hosted licensed runtime when the adapter is entitled and configured for paid mode—not free mode with audit logging added after execution.

  • Shared Dexgate policy decisions
  • Action Passport issue + executor verification
  • Fail-closed without valid proof
  • Evidence: policy decision, authorization, execution verification, and outcome record in the customer console when enabled

Paid path: how a Passport is used

Every step below is the paid pilot path. Free mode can intercept tools (PROPOSE) but does not run DECIDE → ISSUE → VERIFY → ACT-with-proof → RECORD on the Dexgate policy runtime.

1 · PROPOSE

Agent wants a tool action (patch, shell, deploy-class). Free adapters can intercept here; paid path continues below.

2 · DECIDE

Dexgate policy runtime: allow, deny, constrain, escalate. Free mode has no shared policy runtime.

3 · ISSUE

Allow-with-proof mints an Action Passport (authorization type, scope, env, expiry, proof). Free never mints.

4 · VERIFY

Protected executor re-checks the Action Passport; fail-closed if missing or invalid.

5 · ACT

Execute only if verification passes; otherwise refuse the side effect.

6 · RECORD

Policy decision, authorization, execution verification, and outcome record in the customer console when enabled.

Host adapters and entitlement determine how fully each paid-path step is enforced on a given runtime. Coverage details: compatibility matrix.

Supported today

OpenClaw adapter

Available free on npm · recommended free path.

Start with local hardening.

Move to paid pilot dexgate when you need policy decisions, passport evidence, and environment-level controls.

Start Free Interactive demo Read Docs

Codex adapter

Available free on npm · controlled host coverage.

Start with a conservative free posture: read-only shell allowlist; apply_patch and mutations blocked by default.

Use the paid pilot path when Codex actions need policy decisions, passport evidence, and readonly governance-gap detection on current builds.

Start Free Interactive demo Read Docs

What dexgate does not replace

dexgate works alongside existing identity, sandboxing, and monitoring controls. It does not replace them.

dexgate fits customer-controlled deployments and licenses by protected deployment and environment.

Protected deployment: one governed deployment boundary, usually one runtime integration serving a specific team, application path, or environment set. (Technical configure fields may still use names such as gatewayId.)

Public tiers are Production at 1 protected deployment / 2 environments, Team at 3 protected deployments / 3 environments, Business at 10 protected deployments / 5 environments, and Enterprise by custom annual agreement.

Deployment, licensing, and validation details

dexgate runs with customer-controlled deployment boundaries.

dexgate supports licensing by protected deployment and environment rather than seat counting.

Customers can map their own environment labels to named policy profiles and edit those profile definitions in the delivered runtime bundle.

Validation, evidence, and compatibility statements on this site describe first-party Dexgate testing for declared configurations. They do not constitute government approval, legal advice, or a guarantee that all customer environments will achieve the same outcome.

Get Started Interactive demo See Pricing

Purchase