One Control Layer to Secure, Govern, and Run APIs, MCPs, and IDE-Driven AI Agents
AI Agents → SuperContracts MCP Gateway → APIs & MCPs
Cursor/Claude Code/Copilot → IDE Hooks + Runtime Enforcement → Terminal Actions
Gateway · Policy · Guardrails · Approval · Execution · Evidence
Let agents act autonomously — without giving them unrestricted power.
An MCP Gateway with executable SuperContract guardrails for APIs and MCPs. Secure Cursor™, Claude Code™, and production AI agents with policy-driven execution, runtime enforcement, approvals, webhooks, and MCP triggers.
IDE Hooks and eBPF Runtime monitoring.
Deterministic Guardrails · Policy driven Human-in-the Loop · Auditability
Define executable policies in SuperContracts that govern what APIs and MCPs an AI agent can call, with schema validation, rate limits, and data constraints.
IDE hooks and eBPF-powered monitoring review and block terminal commands in real time before they reach production systems.
Human-in-the-loop approvals for sensitive operations. Every execution is logged, versioned, and tied to an auditable contract.
Works inside Cursor™, Claude Code™, Copilot™, and VS Code™. Agents get guardrails without leaving the editor.
One executable contract. One source of truth.
Define, test, execute, document, and debug APIs and MCPs without switching between OpenAPI, Swagger, Postman™, scripts, and logs.
Govern insecure MCP actions before they reach production
Cursor™ and Claude Code™ can route MCP actions through the apiLabs.ai Super Contracts MCP Gateway, where policy-driven guardrails govern what agents are allowed to do — for example, controlling Stripe™ refunds, protecting PII in Supabase™, and enforcing PR-only changes to GitHub™ main.
MCP Gateway policy controls what refunds an AI agent can execute in Stripe™.
Secure Cursor™ and Claude Code™ at the point of action. Intercept agent-initiated terminal commands with hooks and enforce deterministic ALLOW, DENY, or Human Approval guardrails before execution. Govern high-risk actions across git, curl, ssh, kubectl, terraform, cloud CLIs, package installs, credentials, and sensitive files — while preserving a complete audit trail of what the agent attempted and why it was allowed or blocked.
Cursor™ Pre-Shell Hook Guardrails in Action
Pre-shell hook intercepts agent git commands in Cursor™ and enforces PR-only guardrails.
See what AI agents actually do in the terminal — and turn that activity into actionable security findings.
Capture terminal activity through Cursor™ IDE post-shell hooks or an eBPF-monitored runtime environment. Observe commands, processes, network connections, file access, and child-process behavior, including actions hidden behind Python, SDKs, scripts, or other tools.
Automatically identify risky behavior such as credential exposure, sensitive file access, unauthorized network connections, dangerous commands, unexpected processes, and policy bypass attempts.
Turn observations into prioritized findings with severity, agent and session attribution, evidence, affected resources, and remediation guidance.
Post-shell observations → Security findings
Kernel-level observations → Security findings → Enforcement
Cursor™ Post-Shell Observability & Findings in Action
The Cursor™ IDE plugin captures post-shell observations of agent-initiated commands, processes, files, and network calls.