Skip to main content
Automatic routing lets a person or local agent keep using a Resource’s existing hostname, port, and client. Forge changes the network path on an enrolled device, sends the connection to the assigned customer-deployed Resource Gateway, and then connects separately to the original destination. The managed endpoint also identifies every unambiguous Forge catalog product in the initiating process ancestry. This lets one Resource policy apply to traffic from Codex, Claude Code, Cowork, or Cursor without changing the client command. Nested products are retained as a set: launching Claude Code from Codex does not hide either product from policy. It is an access path, not a second proxy or policy system. Direct and automatic connections use the same Resource, destination credential assignment, Resource Policies, approval grants, protocol handling, and Resource Activity.

Prerequisites

  • The device is enrolled and shows managed routing as Active.
  • The organization inspection CA is trusted on the device.
  • The Resource uses an exact DNS hostname and a supported protocol.
  • The Resource is enabled, assigned to an online Resource Gateway, and has Automatic routing enabled.
  • The Gateway can resolve and reach the destination and verify its certificate.
  • The authenticated user or service account resolves to exactly one compatible destination credential.
The endpoint route and the destination are separate TLS legs. The managed device trusts the Forge-issued certificate used for the governed path. The Gateway independently verifies the destination hostname against public system roots or the Resource’s configured private authority. Forge never offers a skip-verification mode.

Enable automatic routing

  1. Open the Resource and assign the Resource Gateway that can reach it.
  2. Add and test a destination credential.
  3. Turn on Automatic routing and save.
  4. Confirm the intended device has received the current managed-routing configuration.
  5. Use the Resource’s original client command.
The examples show normal destination commands, not the direct Gateway syntax. The endpoint proves the user and device to Forge; the destination credential is selected and used only by the Gateway.

Verify the route

Perform one harmless operation, then open Live → Resources and filter by the Resource. Confirm the expected user, device and process when available, originating product when recognized, protocol operation, outcome, and responsible policy. For a policy test, begin with a narrow monitor rule, then enforce a harmless block such as one test HTTP path or database command in non-production. The client should receive the policy identifier and configured message; the Live row should show the same outcome.

Troubleshoot

Automatic routing cannot govern only one SQL command on an otherwise direct database connection. The entire connection must first follow the Forge route; the Gateway then evaluates each supported command on that connection. See Forge for devices for enrollment and routing health, and Protocols for protocol limits.