{{ pageTitle }}

{{ greeting }}

{{ overviewSub }}

Gateway healthy. v1.0.0-rc3 · streamable HTTP transport · gVisor runsc sandbox · memguard key isolation.
Get started — three steps to your first verified task
{{ st.mark }}
{{ st.title }}
{{ st.desc }}
{{ k.label }}
{{ k.value }}
{{ k.sub }}

Live delegation pipeline

{{ pipeState }}

{{ pipeSub }}

{{ s.id }}
{{ s.name }}
{{ s.state }}
{{ m.label }}
{{ m.value }}

Recent delegations

Task & target Status Gate C(T) Worker engine AST Δ Latency Saved
{{ r.title }}
{{ r.short }} · {{ r.filesLabel }}
{{ r.status }} {{ r.gate }} {{ r.model }} {{ r.add }} {{ r.del }} {{ r.latency }} {{ r.saved }}

Quickstart

{{ quickstart }}

Delegations & task ledger

{{ tasksSub }}

Task & context Status Stage Gate C(T) Worker engine AST Δ Latency Saved
{{ r.title }}
{{ r.short }} · {{ r.filesLabel }}
{{ r.status }} {{ r.stage }} {{ r.gate }} {{ r.model }} {{ r.add }} {{ r.del }} {{ r.latency }} {{ r.saved }}

No delegations in this state

{{ tasksEmptySub }}

/ {{ d.short }}

{{ d.title }}

{{ d.status }}
{{ d.filesLabel }}
{{ d.test }}
{{ d.breach.code }}
{{ d.breach.desc }}
{{ d.breach.at }} · {{ d.breach.rfc }}
In pipeline · {{ d.stage }}
Guard ceilings from RFC §5.5 are enforced for the remainder of this run.

Conduit inspector

{{ s.id }} {{ s.name }} {{ s.desc }} {{ s.state }}

AST slice & containment

{{ m.label }}
{{ m.value }}
{{ l.text }}
Grammar {{ d.whitelist.grammar }}
{{ p }}
Scope {{ d.containment.scope }}
{{ c.label }} {{ c.state }}

Execution event log

{{ d.logCount }}
{{ l.t }} {{ l.at }}
{{ l.d }}

Task sealed · RFC 8785 canonical JSON Merkle root

The contract, unified patch, and sandbox execution receipt are hashed into one canonical tree. Any byte changed downstream breaks the root.

{{ p.label }}
{{ p.value }}
{{ d.proofJson }}

Structured autopsy

Breach record
{{ a.title }}
{{ a.body }}
{{ a.meta }}

Forensics & evidence ledger

Deterministic, tenant-scoped evidence bundles written to .agents/audit/tenants/acme/. Every bundle re-hashes to the same root on any machine.

{{ k.label }}
{{ k.value }}
{{ k.sub }}
RFC §4.7 PROTOCOL

Cryptographic SHA-256 Merkle root verifier

Leaves are H(contract) ‖ H(patch) ‖ H(receipt) under RFC 8785 canonicalisation; the root R is the pairwise SHA-256 reduction.

{{ auditPath }}
{{ h.n }} {{ h.label }} {{ h.hash }} {{ h.badge }}
RFC 3161 · SPEC §9.4

TSA anchor receipts

{{ anchorsSub }}

{{ anchorsVerdict }}

{{ anchorsEmptyText }}

#{{ a.id }} {{ a.when }} {{ a.head }} {{ a.records }} {{ a.badge }} {{ a.detail }}
SPEC §2.2 · RECOVERY ESCROW

Recovery escrow enrollment

{{ escrowSub }}

{{ escrowServerLabel }}

{{ escrowEmptyText }}

{{ e.fingerprint }} {{ e.when }}
Strict-mode records
{{ escrowStrictCount }}
client-only E2EE · server holds ciphertext
Escrow-mode records
{{ escrowEscrowCount }}
enrolled envelope unwraps server-side
TRUST MODEL · SPEC §2

Flag review — unverified records

{{ flagSub }}

{{ flagEmptyText }}

{{ f.task }} {{ f.when }} {{ f.sev }} {{ f.reason }} {{ f.device }}
Verified records
{{ flagVerifiedCount }}
on the verified chain page
Flagged records
{{ flagFlaggedCount }}
held for review · never silently degraded

Tamper-evident evidence ledger

Sorted by execution time. Each entry lists the manifest as written to disk.

{{ b.nodeText }}
{{ b.title }} {{ b.audit }} {{ b.badgeText }}

{{ b.desc }}

{{ b.path }}
[contract.json, patch.diff, execution.json, proof.json]
{{ m }}

API keys & BYOK enclaves

Keys are stored only as SHA-256 digests. Provider credentials you bring live in locked RAM for the life of a request and are wiped on return.

ENCLAVE ACTIVE

Memguard locked enclave · zero-knowledge RAM isolation

The X-Embassy-Provider-Key header is copied into a memguard-locked buffer on arrival. It is never serialised, logged, or written to disk.

{{ e.title }}
{{ e.body }}
Label & environment Key hash prefix Scope Status Expiry Last used Created Actions
{{ k.label }} {{ k.env }}
{{ k.id }}
{{ k.masked }}
{{ k.scope }} {{ k.state }}
{{ k.expLabel }} expired expiring
{{ k.lastUsed }} {{ k.created }}

No API keys yet

Mint your first key to authenticate the CLI and API calls. The full key is shown exactly once at creation — copy it then.

Usage, quotas & pricing

{{ usageSub }}

{{ k.label }}
{{ k.value }}
{{ k.sub }}

Sliding-window quota meters

{{ m.label }} {{ m.sub }} {{ m.text }} {{ m.pct }}

Budget override

Temporary headroom · base balance untouched

Layer temporary spending headroom on top of the prepaid balance. Use it during an incident or a one-off migration — the base balance and grant history never change.

Base balance
{{ budgetBalanceText }}
credits
Effective balance
{{ budgetEffectiveText }}
with override
Enforcement
{{ budgetEnforcedText }}
quota gate
Active override
{{ budgetOverrideAmountText }} credits {{ budgetOverrideModeText }} · {{ budgetOverrideCyclesLeft }} cycle(s) left · {{ budgetOverrideReason }}
No active override · effective = base.
{{ budgetError }}
Owner/Admin role required to change.
Demo mode · override controls are inert. Sign in or paste a live key to manage the budget.

Cost breakdown

trailing 30 days

Per-call credit attribution from the double-entry ledger, grouped by day, model, or tool. 1 credit = $0.01.

Loading…
Key Calls Amount Unbilled In / Out Proof-linked
{{ g.key }} {{ g.callsText }} {{ g.amountText }} {{ g.unbilledText }} {{ g.tokensText }} {{ g.proofText }}
Total {{ costTotals.callsText }} {{ costTotals.amountText }} {{ costTotals.unbilledText }} {{ costTotals.tokensText }} {{ costTotals.proofText }}
No billed usage in the last 30 days.
Demo mode · cost breakdown is server-side. Sign in or paste a live key to view per-call credit attribution.

Savings calculator

Calibrated ZLDP-v1 rates

Claude Sonnet 5 billed direct against the same workload delegated through the gateway, after AST pruning.

{{ s.display }}
Monthly {{ calc.reduction }} lower
Claude Sonnet 5 direct {{ calc.direct }}
AI Embassy delegated {{ calc.embassy }}
Net cash saved
{{ calc.saved }}
{{ calc.annual }} projected annually
{{ calc.roi }}

Subscription plans

Monthly billing
{{ p.name }} {{ p.tag }}
{{ p.price }} {{ p.period }}
{{ p.cap }}
{{ f }}

Upstream MCP registry

REGISTRY · C1

{{ mcpSub }}

{{ sv.name }} {{ sv.command }}
allowed: {{ sv.allowed }}
Tool catalog
mcp:{{ sv.name }}:{{ t.name }} {{ t.desc }}
{{ mcpEmptyText }}

Register a server

Stdio command line, exactly as the gateway would launch it. Registration is in-memory — it does not survive a restart.

API playground

RUNG 5.4 · OPENAI-COMPATIBLE

Run a real demo call against POST /v1/chat/completions with a console-issued key. The /v1 plane is Bearer-only — exactly what an OpenAI SDK sees. Every response renders verbatim, including refusals: a 403 embassy_byok_required for a BYOK-plan key is the correct answer, not a bug.

Prefilled from the console link when present. Mint one on the API keys screen; it is only used for these direct calls.
GET /v1/models → {{ pgModelsStatus }}{{ pgModelsError }}
HTTP {{ pgStatusTag }} POST /v1/chat/completions
{{ pgResult.content }}
{{ r.label }}{{ r.value }}
proof: {{ pgResult.proof }}
{{ pgResult.errorTag }} — {{ pgResult.errorMessage }}
{{ pgResult.raw }}
{{ pgSnippet }}

System parameters

RFC §5.5 compliant

Guard ceilings are clamped server-side. Values above the ceiling are accepted in the form and reduced on save.

Guard ceilings

Presets apply the three canonical RFC profiles.

{{ g.display }}
{{ g.warn }}
✓ Guard settings active

Tenant tool allowlist

{{ toolsModeText }}

{{ toolsSub }}

Owner/Admin role required to change.
{{ toolsCountText }}

Multi-provider failover cascade

Drafting falls through this cascade; complexity above the sovereign threshold skips it entirely.

{{ p.rank }} {{ p.badge }}
{{ p.name }}
{{ p.endpoint }}
{{ m.label }} {{ m.value }}

Context firewall

Policies applied to every request before it leaves the gateway.

{{ t.title }} Locked
{{ t.body }}

Global delegation search

{{ searchCount }}

{{ searchSub }}

Suggestions
Task & target files Status Stage Gate C(T) Worker model Latency Saved
{{ r.pre }}{{ r.hit }}{{ r.post }}
{{ r.filesLabel }}
{{ r.status }} {{ r.stage }} {{ r.gate }} {{ r.model }} {{ r.latency }} {{ r.saved }}

No matches

Try a file name, a task ID, or a status keyword such as “escalated”.

esc
{{ g.label }}
Nothing matches that.
↑↓ navigate↵ selectesc dismiss
{{ modal.title }}
{{ modal.subtitle }}
This is the only time the full key is shown. Embassy stores just a SHA-256 digest — it cannot be recovered later. Copy it into your secret manager now.
{{ minted.snippet }}
{{ st.mark }}
{{ st.title }}
{{ st.desc }}
{{ st.cmd }}
Executed on your machine, sealed client-side. The server holds only the encrypted payload; the Merkle root binds it into the tenant chain.
{{ r.label }}{{ r.value }}
Programmatic fetch: {{ edge.api }}
{{ reveal.snippet }}
The plaintext is not retained — it was shown exactly once when the key was minted. Revoke and mint a new key if it was lost.
{{ r.label }}{{ r.value }}
This is permanent. Any process still presenting this key receives HTTP 401 on its next call.
{{ r.label }}{{ r.value }}
Set a hard expiry. The server rejects calls presenting the key after this time. Use Never to remove an existing expiry.
Must be in the future. Seconds and timezone are required.
The task runs through the real pipeline — package & prune, complexity gate, draft, static verify, evidence test, commit — and lands in the ledger with its sealed proof receipt.
{{ submitError }}
Parsed as JSON before dispatch; a malformed body is reported verbatim, never silently coerced.
{{ mcpCallData.error }}
{{ mcpCallData.content }}
Evidence receipt
{{ r.label }}{{ r.value }}
{{ t.msg }}