Back to dashboard

Agent Tool Gateway

Public-safe gateway calls are limited to registered trusted targets and read-only discovery or MCP introspection methods. Protected execution is guarded by PLATPHORM_API_KEY.

Status
Gateway/proxy execution state
activeactive_for_trusted_discovery_artifacts_and_read_only_mcp_methodsactive_for_trusted_targets_with_PLATPHORM_API_KEY_and_Cloudflare_audit
Trusted Targets
Only registered targets are eligible.
*.platphormnews.commcp.platphormnews.com*.ph3ar.comascii.platphormnews.comdesign.platphormnews.comfiles.platphormnews.compdf.platphormnews.com
Blocked Targets
SSRF and private-target guardrails.
localhostprivate-ip-ranges127.0.0.0/810.0.0.0/8172.16.0.0/12192.168.0.0/16link-localmetadata-servicesmetadata servicesfile://ftp://gopher://URLs with embedded credentialsuntrusted external domainsredirects to blocked targets
auth
Public-safe read calls can be described and validated. Mutating/protected downstream calls require PLATPHORM_API_KEY.
secretHandling
PLATPHORM_API_KEY is forwarded only after local authentication and only to trusted PlatPhormNews MCP endpoints for protected operations; it is never persisted or returned.
durableAudit
active_in_cloudflare.gateway_audit_log
circuitBreaker
three_failures_open_target_for_30_seconds
responseLimitBytes
2000000
tracePropagation
traceparent, tracestate, X-PlatPhorm-Trace-Id, X-PlatPhorm-Span-Id, X-PlatPhorm-Request-Id
ja4Digest
capture when present, hash/redact for public summaries, never expose raw values publicly