Skip to main content
A Resource is a private API, database, or cache that Forge can identify, authenticate to, and protect with protocol-aware policy. People, agents, and services use their Forge identity; the destination credential stays at the customer-deployed Resource gateway. Resources have their own policy family. Existing Access Policies continue to control AI products, applications, processes, domains, and routes. Existing Content Policies continue to control prompts, model responses, tools, and MCP activity. Resource Policies control Resource connections, requests, commands, and supported data transformations.

Supported protocols

See Protocols for client behavior and explicit limits.

Two access paths

Both paths use the same Resource definition, identity resolution, destination credential, Resource Policies, approval grants, and activity records. Automatic routing changes the network path before a connection opens. Forge cannot govern one SQL command on a database connection that otherwise bypasses Forge; the entire connection must first use one of these paths.

How the pieces fit

  1. A Resource defines the protocol and destination.
  2. A Resource gateway runs in a customer network that can reach it.
  3. A credential assignment determines how Forge authenticates upstream for the caller.
  4. A Resource Policy evaluates the connection and each supported operation.
  5. Live → Resources records safe evidence and policy outcomes.
  6. Responses handles approval requests, decisions, and short-lived grants.
Forge’s control plane distributes encrypted configuration, coordinates approvals, and receives bounded health and activity events. Request and response bodies, raw SQL, database result values, and destination secrets do not transit the control plane during normal Resource traffic. Start with the Resource quickstart, or continue to Configure Resources and routing.