> ## Documentation Index
> Fetch the complete documentation index at: https://docs.forge.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Automatic routing

> Route managed-device traffic through Resource Policy without changing client destinations.

Automatic routing lets a person or local agent keep using a Resource's existing
hostname, port, and client. Forge changes the network path on an enrolled
device, sends the connection to the assigned customer-deployed Resource
Gateway, and then connects separately to the original destination.

The managed endpoint also identifies every unambiguous Forge catalog product
in the initiating process ancestry. This lets one Resource policy apply to
traffic from Codex, Claude Code, Cowork, or Cursor without changing the client
command. Nested products are retained as a set: launching Claude Code from
Codex does not hide either product from policy.

It is an access path, not a second proxy or policy system. Direct and automatic
connections use the same Resource, destination credential assignment, Resource
Policies, approval grants, protocol handling, and Resource Activity.

## Prerequisites

* The device is enrolled and shows managed routing as **Active**.
* The organization inspection CA is trusted on the device.
* The Resource uses an exact DNS hostname and a supported protocol.
* The Resource is enabled, assigned to an online Resource Gateway, and has
  **Automatic routing** enabled.
* The Gateway can resolve and reach the destination and verify its certificate.
* The authenticated user or service account resolves to exactly one compatible
  destination credential.

The endpoint route and the destination are separate TLS legs. The managed
device trusts the Forge-issued certificate used for the governed path. The
Gateway independently verifies the destination hostname against public system
roots or the Resource's configured private authority. Forge never offers a
skip-verification mode.

## Enable automatic routing

1. Open the Resource and assign the Resource Gateway that can reach it.
2. Add and test a destination credential.
3. Turn on **Automatic routing** and save.
4. Confirm the intended device has received the current managed-routing
   configuration.
5. Use the Resource's original client command.

```sh theme={"system"}
curl https://service.internal.example/health
psql 'host=db.internal.example port=5432 dbname=app user=app sslmode=require'
mysql --ssl-mode=VERIFY_IDENTITY --host mysql.internal.example --user app --password
redis-cli --tls --host cache.internal.example --user app --pass 'destination-client-value'
```

The examples show normal destination commands, not the direct Gateway syntax.
The endpoint proves the user and device to Forge; the destination credential is
selected and used only by the Gateway.

## Verify the route

Perform one harmless operation, then open **Live → Resources** and filter by
the Resource. Confirm the expected user, device and process when available,
originating product when recognized, protocol operation, outcome, and
responsible policy.

For a policy test, begin with a narrow monitor rule, then enforce a harmless
block such as one test HTTP path or database command in non-production. The
client should receive the policy identifier and configured message; the Live
row should show the same outcome.

## Troubleshoot

| Symptom | Check |
| - | - |
| Traffic reaches the destination | Resource hostname and port, saved routing toggle, device assignment, and routing health |
| TLS trust error on the device | Organization inspection CA installation and the exact Resource hostname |
| Gateway rejects the connection | Gateway status, Resource assignment, configuration freshness, and destination credential |
| Destination TLS failure | Destination hostname, certificate chain, and Resource private authority |
| Policy does not match | Resource, authenticated identity, protocol facts, policy mode, and exceptions |
| Product rule does not match | Use automatic routing; direct gateway access has no trusted endpoint process context |
| Approval repeats | Retry the identical operation before the one-use grant expires; do not change identity |

Automatic routing cannot govern only one SQL command on an otherwise direct
database connection. The entire connection must first follow the Forge route;
the Gateway then evaluates each supported command on that connection.

See [Forge for devices](/integrations/device-agent) for enrollment and routing
health, and [Protocols](/resources/protocols/overview) for protocol limits.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.