Agent Action Passport Runtime
Passport-gated actions for coding and devops agents.
dexgate is the product implementation of Decision Execution Governance for coding and devops agents. For supported integrations and configured execution surfaces, it evaluates covered shell, patch, and deploy-class proposals before execution and returns an allow, constrain, deny, or escalation result. A model may propose; a protected executor acts only with scoped authority where the paid path is enabled.
Start free with local hard gates. Move to paid dexgate when production-bound actions need Dexgate policy decisions, Action Passport policy evaluation, and reviewable outcome evidence. The product model is broader than today’s implemented coverage—see the compatibility matrix for which adapters and surfaces are available now (including Codex host-path limits).
Current availability
Free adapters: available now on npm
Paid governed workflows: early-access pilot
Coverage last validated: July 30, 2026
Validated free packages:
@dexgate/openclaw-trusted-mode@1.0.18,
@dexgate/codex-trusted-mode@0.1.16
See the compatibility matrix for coverage, limitations, and current versions.
Choose the operating mode that fits your rollout
What it does
How it works
Agent Execution Governance is Decision Execution Governance applied to AI agents. The primary use case is governed production change: shell commands, code patches, and deploy-class actions.
Technical details
Technical details: free mode uses local hardening only (no passport). Paid dexgate uses Dexgate policy decisions, Ed25519-verified policy packs at load, Action Passport policy evaluation, and governed evidence records. Adapter package “integrity” files are local checksums—not the same as runtime policy-pack or decision signing. OpenClaw is the recommended free path; Codex has controlled host coverage (some host paths may report governance gaps).
What dexgate adds
What is an Action Passport?
An Action Passport is a scoped, single-use authorization record for one supported agent action, issued only after policy decides, and re-checked before protected execution so production side effects stay allow-with-proof. When cryptographic signing is enabled, the record can be independently verified.
It is not a login session, API key, or travel document.
Paid path: how a Passport is used
Every step below is the paid pilot path. Free mode can intercept tools (PROPOSE) but does not run DECIDE → ISSUE → VERIFY → ACT-with-proof → RECORD on the Dexgate policy runtime.
Host adapters and entitlement determine how fully each paid-path step is enforced on a given runtime. Coverage details: compatibility matrix.
Supported today
What dexgate does not replace
dexgate works alongside existing identity, sandboxing, and monitoring controls. It does not replace them.
- Not malware scanning.
- Not a DLP suite.
- Not surveillance tooling.
- Not OpenClaw or Codex themselves.
- Not a fork of OpenClaw or Codex.
dexgate fits customer-controlled deployments and licenses by protected deployment and environment.
Protected deployment: one governed deployment boundary, usually one runtime integration serving a specific team, application path, or environment set. (Technical configure fields may still use names such as gatewayId.)
Public tiers are Production at 1 protected deployment / 2 environments, Team at 3 protected deployments / 3 environments, Business at 10 protected deployments / 5 environments, and Enterprise by custom annual agreement.
Deployment, licensing, and validation details
dexgate runs with customer-controlled deployment boundaries.
dexgate supports licensing by protected deployment and environment rather than seat counting.
Customers can map their own environment labels to named policy profiles and edit those profile definitions in the delivered runtime bundle.
Validation, evidence, and compatibility statements on this site describe first-party Dexgate testing for declared configurations. They do not constitute government approval, legal advice, or a guarantee that all customer environments will achieve the same outcome.