Features

Endpoint Governance

Source

Endpoint governance is the shared control layer for every Eden endpoint. It covers how callers are authenticated, how endpoint access is granted, how backend credentials are isolated, how requests are routed through Gateway, and what audit evidence is recorded.

Provider-specific pages document the controls that apply to a particular endpoint kind. The baseline governance model applies across databases, LLMs, applications, servers and APIs, platforms, agents, and Gateway native gateway listeners.

Shared Controls

ControlWhat it doesPrimary surface
Endpoint registryStores endpoint identity, kind, description, backend profile, and provider-specific connection config./api/v1/endpoints
Control-plane RBACControls who can view, configure, promote, grant, audit, or destroy endpoint configuration./api/v1/iam/control/endpoints/{endpoint}
Data-plane RBACControls who can use the endpoint at runtime through shared read/write/execute permissions./api/v1/iam/data/endpoints/{endpoint}
Resource-specific grantsAllows endpoint, template, workflow, and API access to be granted without broad organization-wide rights.RBAC APIs
Credential isolationKeeps backend credentials in endpoint config or endpoint-level security assignments instead of clients.Endpoint config, ELS
TemplatesDefine approved read/write/transaction shapes instead of arbitrary backend access./api/v1/templates
APIsPublish governed endpoint-backed operations as stable API and tool surfaces./api/v1/apis
WorkflowsOrchestrate endpoint, template, and API steps with policy, run state, and audit evidence./api/v1/workflows, /api/v1/workflow-runs
Native gateway runtimeRoutes native protocol traffic through Gateway-managed interlay listeners with RBAC, masking, mirror, and telemetry controls in the path.Gateway, /api/v1/interlays
MaskingRedacts or blocks configured request fields, arguments, or command surfaces before backend egress.interlays.settings.masking
Backend profilesSeparates production and development backend lanes, credentials, routes, and pool budgets.backend_profile, backend_pool_limits
Mirror modeSends eligible traffic asynchronously to secondary endpoints for comparison, migration, or validation.interlays.settings.mirror
VPN transportAllows WireGuard peers to reach selected Gateway native gateway listeners while Eden remains in the path./api/v1/vpn/*
Telemetry and auditRecords safe request, endpoint, policy, latency, and route evidence for operations and review.Analytics and audit APIs

Endpoint Families

FamilyExamplesCommon governance notes
DatabasesPostgreSQL, MongoDB, Redis, ClickHouse, Snowflake, PineconeRBAC, templates, APIs, workflows, database-appropriate masking, native gateway listeners where supported, and audit evidence.
LLMsOpenAI, Anthropic, Ollama, OpenRouter, Azure OpenAIGateway keys, routing, PII governance, content profiles, access boundaries, and cost/route evidence.
ApplicationsGoogle Workspace, GitHub, GitLab, Datadog, PostHog, Salesforce, Tavily, EraserRBAC, templates, APIs, workflows, credential isolation, safe tool exposure, and audit evidence.
Servers, storage, and APIsHTTP, S3, LambdaRBAC, narrow operation shapes, credential isolation, templates, APIs, workflows, and audit evidence.
PlatformsAWS, Azure, DatabricksRBAC, provider-specific authentication, credential isolation, templates, APIs, workflows, and provider-specific controls where available.
AgentsCodex, Claude Code, Hermes, and compatible clientsGateway key or native protocol configuration, safe work attribution, model policy, tool authorization, and promptless evidence.

Request Lifecycle

  1. The caller authenticates through local Eden auth or a configured external identity provider.
  2. Eden resolves the organization, subject, endpoint, and requested action.
  3. Control-plane or data-plane RBAC is checked for the concrete endpoint or resource.
  4. Endpoint-level security, backend profile, native gateway listener, VPN, masking, mirror, template, API, or workflow policy is applied when configured.
  5. Gateway forwards the request using the endpoint's backend credentials, not client-held backend credentials.
  6. Eden records safe telemetry, audit, policy, route, and latency evidence.

Provider-Specific Governance

Some endpoint kinds add controls that are not meaningful for every backend. For example, cloud-platform endpoints can require provider-specific authentication and signing behavior, while agent endpoints can require a native protocol or OpenAI-compatible gateway configuration.

Those provider-specific controls build on the same endpoint governance layer rather than replacing it.

Native Gateway Runtime

Interlay listeners are part of the Gateway capability. They are the native protocol runtime Gateway uses when a client must speak the backend protocol directly while Eden still owns identity, endpoint policy, credential isolation, masking, mirror behavior, migration evidence, and telemetry.

Endpoint governance documents the controls Gateway applies through that runtime. It does not treat interlay listeners as a separate feature or product from Gateway.

Help improve Eden Docs

Find something unclear or incomplete? Review the source and propose an update.

View on GitLab Updated August 2, 2026