Skip to main content
Forge secures coding agents through their network traffic rather than by instrumenting each agent. Supported requests are routed through the LLM Gateway or MCP Gateway, where Forge applies identity, access, content, tool, and response policies and records normalized sessions.
Claude Code session using a governed tool through Forge

Forge policy enforcement for coding-agent traffic

Support

Support is capability-specific. Inventory coverage does not imply that every model API, MCP transport, or response format is available for content-aware enforcement.

Routing

Use one or both routing paths: Agentless network routing uses managed TLS inspection for the supported content-aware destination set. Forge for devices provides the same gateway path without modifying the coding agent or installing a Forge adapter inside it.

Sessions

Forge reconstructs coding-agent sessions from routed model and MCP traffic. A session preserves the user or workload identity, device or network source, client and provider, native request identifiers, policy decisions, latency, and upstream outcome. Content visibility follows the selected privacy mode and the capability of the protocol being routed. Forge records metadata-only traffic as metadata-only; it does not present it as inspected content.

Policies

The gateway evaluates the same Forge policy model used across other controlled AI surfaces: Access policies govern which agents, models, providers, destinations, MCP servers, and tools an identity may use. Content policies govern the data and actions inside an allowed interaction.

Inventory

Device, repository, SaaS, and cloud collectors can discover coding-agent configuration independently of routed activity: Hooks in Inventory are customer or product artifacts Forge discovered. Forge does not install them to secure the agent.

Configuration

Forge can manage supported native configuration for Claude Code, Claude Cowork, Codex, and Cursor. Targets can be scoped by organization, team, device, system, user, project, or session. Managed settings can include tool permissions, filesystem scope, model and provider selection, MCP connections, extensions, instruction files, telemetry, and update behavior. Device Agent materializes the intended configuration, records its generation, and reports drift or apply errors.

Deployment

For agentless coverage, configure a supported Network integration and enable content-aware routing for the coding-agent destinations in scope. For endpoint coverage, deploy Forge for devices directly, through MDM, CrowdStrike RTR, or SentinelOne. Confirm enrollment, transparent-proxy health, managed CA trust, and a routed test request. Fleet operations include installing or updating Device Agent, validating and repairing the routing stack, refreshing credentials, removing managed coverage, and offboarding a device.