Source available · built to self-host

Give AI agents tools.
Keep control.

Wardn is the control plane for governed AI tool access—one place to approve MCP servers, protect credentials, run agents, and account for every action.

Built for platform engineering, security, and AI teams

Platform/Run trace
Runtime healthy
AGENT RUN

Prepare release notes

Completed
Triggered by Scheduled taskAgent Release stewardDuration 18.4s
Execution trace4 steps
  1. Request received

    Summarize merged changes since the last release.

  2. Policy evaluated

    github.list_pull_requests allowed

    Passed
  3. Tool called

    GitHub MCP · 14 pull requests returned

  4. Response delivered

    Posted to #product-releases

Govern tools across your stack

GitHubSlackPostgresLinearKubernetesYour APIs
01 The control layer

The last mile of agent adoption isn’t intelligence. It’s control.

Local configs and one-off bots work—until every agent carries a different set of credentials, policies, and blind spots. Wardn turns that sprawl into an operating model.

01

Unknown tools

Know which MCP servers are approved, which version is installed, and which tools each agent can reach.

02

Scattered credentials

Keep secrets behind managed handles and bind access to workspaces—outside prompts, scripts, and local config files.

03

Invisible actions

Trace prompts, tool calls, approvals, errors, token use, and cost without stitching together another observability stack.

02 One governed path

From discovery to execution,
the guardrails stay attached.

Wardn keeps trust decisions in the path of every run—whether an agent starts in chat, on a schedule, or from a connected channel.

TRUSTED CATALOG Workspace: Platform
Step 01

Curate what enters your stack.

Review server metadata, versions, transport, and tools before a workspace can install them.

  • Organization-owned catalog
  • Endpoint and tool validation
  • Version-aware installations
03 The whole operating layer

Everything between
the model and the action.

A compact control plane for the parts that become fragmented when agent programs move beyond a proof of concept.

MCP CATALOG + RUNTIME

Approve once.
Deploy with confidence.

Curate server metadata, install into scoped workspaces, validate real tools, and run with local or Kubernetes-oriented isolation.

GUARDRAILS

Policy before execution.

Restrict tool use, require a human decision, and bind approval to the exact action and arguments.

AGENTS + SCHEDULES

One agent, many ways to work.

Run through chat, recurring tasks, Slack, Telegram, or WhatsApp—with the same tools and policy path.

SECRETS + MODELS

Credentials stay out of the prompt.

Connect model providers and managed secret handles without handing raw credentials to every agent.

OBSERVABILITY + USAGE

Every run tells the whole story.

Follow tool calls, approvals, failures, model use, token volume, and cost from organization health down to one execution.

04 One shared system

Engineering gets velocity.
Security gets control.

FOR PLATFORM + AI TEAMS

Build the useful thing.

Give teams approved tools and reusable agents without rebuilding auth, runtime management, scheduling, and traces for every project.

  • 01Validated MCP installations
  • 02Reusable agents and skills
  • 03Multiple models and channels
FOR SECURITY + OPERATIONS

Know what it can do.

Keep trust, credentials, limits, and approval decisions centrally managed while preserving a complete record of agent activity.

  • 01Tool-level access rules
  • 02Human approval routes
  • 03Usage and audit visibility
05 Your infrastructure

Own the control plane.
Keep your boundaries.

Run Wardn where your tools and data already live. Start locally, connect PostgreSQL and your model providers, then move MCP execution into Kubernetes when you need stronger isolation.

✓Local or OIDC authentication✓OpenBao secret backends✓Kubernetes-oriented runtime✓Source-available deployment
Read the deployment guide →
Quick start
BOOTSTRAP
$git clone https://github.com/abhi1693/wardn-ai.git
$cd wardn-ai
$cp wardn/backend/.env.example wardn/backend/.env
#Configure PostgreSQL and required WARDN_* settings
$(cd wardn/backend && uv sync --extra dev && uv run alembic upgrade head)
$npm install
RUN IN THREE TERMINALS
1cd wardn/backend && uv run uvicorn app.main:app --port 8000 --reload
2cd wardn/backend && uv run python -m app.manage runmcpjobs
3npm run web:dev
API MCP worker frontendThree required processes
CONTROL WITHOUT THE BOTTLENECK

Your agents can move fast.
Your standards can keep up.

Bring tools, policy, execution, and evidence into one governed path.