Secure, govern, and run APIs, MCPs, and IDE-driven AI agents.
AI Agents → SuperContracts MCP Gateway → APIs & MCPs
Cursor/Claude Code/Copilot → IDE Hooks + Runtime Enforcement → Terminal Actions
Gateway · Policy · Guardrails · Approval · Execution · Evidence
Let agents act autonomously — without giving them unrestricted power.
An MCP Gateway with executable SuperContract guardrails for APIs and MCPs. Secure Cursor, Claude Code, and production AI agents with policy-driven execution, runtime enforcement, approvals, webhooks, and MCP triggers.
IDE Hooks and eBPF Runtime monitoring .
Deterministic Guardrails · Policy driven Human-in-the Loop · Auditability
One executable contract. One source of truth.
Define, test, execute, document, and debug APIs and MCPs without switching between OpenAPI, Swagger, Postman, scripts, and logs.
Debug chained API and MCP workflows end-to-end from one place.
Get answers from APIs without becoming an API engineer.
An AI-powered Request Studio for REST, GraphQL, and MCPs. Ask questions, get answers, and act on APIs — without writing code.
MCP Gateway with Guardrails to govern insecure MCP actions
Cursor™ and Claude Code™ can route MCP actions through the apiLabs.ai Super Contracts MCP Gateway, where policy-driven guardrails govern what agents are allowed to do—for example, controlling Stripe™ refunds, protecting PII in Supabase™, and enforcing PR-only changes to GitHub™ main.
MCP Gateway policy controls what refunds an AI agent can execute in Stripe™.
Secure Cursor™ and Claude Code™ at the point of action. Intercept agent-initiated terminal commands with hooks and enforce deterministic ALLOW, DENY, or Human Approval guardrails before execution. Govern high-risk actions across git, curl, ssh, kubectl, terraform, cloud CLIs, package installs, credentials, and sensitive files—while preserving a complete audit trail of what the agent attempted and why it was allowed or blocked.
Cursor™ Pre-Shell Hook Guardrails in Action
Pre-shell hook intercepts agent git commands in Cursor™ and enforces PR-only guardrails.
See what AI agents actually do in the terminal — and turn that activity into actionable security findings.
Capture terminal activity through Cursor™ IDE post-shell hooks or an eBPF-monitored runtime environment. Observe commands, processes, network connections, file access, and child-process behavior, including actions hidden behind Python, SDKs, scripts, or other tools.
Automatically identify risky behavior such as credential exposure, sensitive file access, unauthorized network connections, dangerous commands, unexpected processes, and policy bypass attempts.
Turn observations into prioritized findings with severity, agent and session attribution, evidence, affected resources, and remediation guidance.
Post-shell observations → Security findings
Kernel-level observations → Security findings → Enforcement
Cursor™ Post-Shell Observability & Findings in Action
The Cursor™ IDE plugin captures post-shell observations of agent-initiated commands, processes, files, and network calls.
Stop Context Switching Between AI IDEs, API Tools, and MCPs
Developers using Cursor™ or Claude Code™ shouldn’t have to jump between the IDE, Swagger/OpenAPI specs, Postman™ collections, scripts, dashboards, and approval workflows just to build, test, or troubleshoot an agentic workflow. SuperContracts replaces this fragmented toolchain with one executable contract for APIs, MCP tools, workflows, guardrails, execution, and evidence—so developers can build, test, debug, govern, and run directly from their AI development environment without needing Postman™ or separate API tooling.
Connect ApiLabs.ai directly to APIs running on your laptop, inside a VPC, or behind a private network. Dev Mode uses secure ngrok™ and Cloudflare Tunnel™ connections to make localhost and private IP endpoints safely accessible for testing, debugging, and agent workflows—without staging deployments, VPN gymnastics, or manual proxy setup.
Build locally. Test securely. Connect instantly.
Cursor™ / Claude Code™ → SuperContracts MCP Gateway → APIs & MCPs
One executable contract. One workflow. No tool-hopping.
SuperContracts™ DSL Contract Spec (YAML) — Define API workflows, MCP actions, guardrails, approvals, tests, and runtime policies in a single executable YAML contract.
Explore YAML code samples and example SuperContracts™ in the apilabs.ai Super Contracts™ GitHub.
Supercontracts Youtube Video Playlist
API Contract Testing DSL — apilabs.ai Super Contracts™
AI-powered API studio to build, test, and call REST, GraphQL, and MCP endpoints
Watch how our AI-powered studio makes API and MCP endpoint testing effortless
Turn intent into SaaS Actions
Example: How many sales came from Google Ads, Events from my Google Calendar, Read unread Gmail etc.

| The Problem | How does apilabs.ai solve? | |
|---|---|---|
| Security Teams | Uncontrolled, non-deterministic agent actions across IDEs, terminals, MCPs, and APIs. | Agentic Security — MCP Gateway + SuperContracts™ guardrails, IDE hooks, eBPF runtime enforcement, approvals, and audit trails. |
| Developers | Context switching across OpenAPI, Swagger, Postman™, scripts, dashboards, and logs. | One executable SuperContracts™ DSL — build, test, execute, document, debug, and govern APIs and MCPs from Cursor™ / Claude Code™. |
| Business Teams | Dependence on engineering for API workflows, data, and SaaS answers. | AI Chat Core and Request Studio — ask, run, and act on APIs & MCPs using natural language. |
One control layer to secure, govern, and run APIs, MCPs, and IDE-driven AI agents.
| Traditional approach | API Labs |
|---|---|
| OpenAPI / Swagger for definition | Executable SuperContracts™ (YAML DSL) |
| Postman™ for testing | Built-in Request Studio + execution & testing |
| MCP server for connectivity | MCP Gateway + policy-driven guardrails |
| IAM / static RBAC for access | Runtime policy & action controls |
| Separate approval systems | Deterministic ALLOW / DENY / Human Approval |
| Scripts for API / MCP chaining | Visual / API / MCP workflows + Agent Flow |
| Logs scattered across systems | Execution Evidence & audit trails |
| Agent framework-specific security | Works across Cursor™, Claude Code™, Copilot, and production agents |
| Manual localhost / private API setup | Dev Mode with ngrok™ / Cloudflare Tunnel™ |
Build, Govern, and Run Agentic Workflows
Start Anywhere. Everything Connects.
Secure AI agent actions across MCP gateways, IDEs, terminals, and runtime environments. Apply deterministic controls, monitor agent behavior, surface findings, and enforce guardrails before high-risk actions reach APIs, infrastructure, credentials, or sensitive systems.
Define reusable API and MCP behavior in YAML using executable contracts, skills, policies, tests, and guardrails. SuperContracts™ gives developers and AI agents a shared way to understand what actions are allowed, how they should execute, and when approval is required.
Ask questions about APIs, workflows, and datasets using natural language. Chat helps explore data, invoke approved actions, inspect responses, troubleshoot issues, and interact with connected services without switching between multiple tools.
Build, test, and troubleshoot API requests in an interactive workspace similar to Postman™. Configure authentication, headers, parameters, and payloads, inspect responses, and turn successful requests into reusable workflows or SuperContracts™.
Organize and navigate generated content, files, folders, outputs, and other workspace artifacts in one place. Explorer gives users a persistent view of what agents and workflows create, making it easier to find, reuse, and manage results.
Turn API data into usable insights. Pipeline syncs and prepares data from APIs and connected systems, Analytics enables analysis using SQL, Pandas, and AI-assisted queries, and Charts transforms results into visualizations that are easier to understand and share.
Automate multi-step workflows across APIs, MCP tools, agents, data, and approvals. Similar to Zapier™ or n8n™, Flow connects triggers, actions, conditions, and human approvals while keeping execution governed and auditable.
Everything you need to know about the apilabs.ai One Control Layer
| Capability | OpenAPI | Postman™ | AI Agent Platforms | Zapier™/n8n™ | Security tools | apilabs.ai |
|---|---|---|---|---|---|---|
| API specification | ✓ | ✓ | — | Partial | — | ✓ |
| REST API client | — | ✓ | — | — | — | ✓ |
| API testing | — | ✓ | — | — | — | ✓ |
| API documentation | ✓ | ✓ | — | Partial | — | ✓ |
| API mocking | — | ✓ | — | — | — | ✓ |
| API monitoring | — | ✓ | — | Limited | Limited | ✓ |
| SaaS connectors | — | ✓ | ✓ | CORE | — | ✓ |
| MCP support | — | ✓ | ✓ | — | — | ✓ |
| MCP Gateway | — | Partial | Partial | — | — | CORE |
| Agent tool registry | — | ✓ | ✓ | Partial | — | ✓ |
| Agent guardrails | — | Partial | ✓ | — | Partial | CORE |
| Runtime authorization | — | Limited | Partial | — | Limited | CORE |
| Policy-as-code | Schema | Partial | ✓ | — | Partial | SuperContracts |
| Risk-based action evaluation | — | Limited | Partial | — | ✓ | CORE |
| Human approval | — | — | ✓ | ✓ | — | CORE |
| Approval before API action | — | — | Partial | ✓ | — | CORE |
| Evidence per action | — | Limited | Tracing | Limited | ✓ | CORE |
| Agent audit trail | — | ✓ | ✓ | ✓ | ✓ | ✓ |
| API + MCP unified execution | — | Partial | ✓ | — | — | CORE |
| Agent → API execution | — | — | ✓ | Partial | — | CORE |
| Agent → API → approval → API | — | — | Partial | ✓ | — | CORE |
| Action simulation | — | Partial | ✓ | — | — | ✓ |
| CLI execution | — | ✓ | ✓ | — | Limited | apirun |
| Natural language API & MCP chat | — | — | ✓ | — | — | AI Chat Core |
| Executable API + MCP contracts | Schema | Partial | ✓ | — | — | SuperContracts™ |
| Dev Mode — localhost & private APIs | — | — | — | — | — | CORE |
| Terminal agent security (eBPF runtime) | — | — | Partial | — | Limited | Agentic Security |
| Security findings & observability | — | Limited | Tracing | — | ✓ | CORE |
| BI Pipeline / Analytics / Charts | — | — | — | Limited | — | ✓ |
| Visual workflow automation | — | — | ✓ | ✓ | — | ✓ |
| Workspace explorer (files, outputs, artifacts) | — | Limited | — | — | — | ✓ |
Disclaimer: Claude™ is a trademark of Anthropic, PBC. Zapier™ is a trademark of Zapier, Inc. n8n™ is a trademark of n8n GmbH. Postman™ is a trademark of Postman, Inc. Google™, Google Ads™, and Google Drive™ are trademarks of Google LLC. Stripe™ is a trademark of Stripe, Inc. HubSpot™ is a trademark of HubSpot, Inc. Salesforce™ is a trademark of Salesforce, Inc. Shopify™ is a trademark of Shopify Inc. Slack™ is a trademark of Salesforce, Inc. Snowflake™ is a trademark of Snowflake Inc. apilabs.ai is not affiliated with, endorsed by, or sponsored by any of these companies. All trademarks are the property of their respective owners.