Barndoor website screenshot

Barndoor

Barndoor AI is the control plane for agentic AI, providing secure access and governance for AI agents and Model Context Protocol (MCP) servers. Founded in 2024 by Oren Michels (founder of Mashery), Barndoor enables enterprise IT, security, and developer teams to register agents, govern MCP server access through policy, broker OAuth connections to backend SaaS, and proxy MCP traffic with runtime policy enforcement and full audit trails. The Barndoor Platform REST API manages servers, connections, policies, agents, and MCP / SSE request proxying. Python, TypeScript, and Go SDKs are published on GitHub alongside Rust SDKs (Cerbos, official MCP, MCP OAuth compliance suite) and a Crew AI example. Deployment options include SaaS (trial), private cloud, and on-premises (Enterprise).

Barndoor publishes 6 APIs on the APIs.io network, including Agents API, Connections API, MCP Proxy API, and 3 more. Tagged areas include AI Agents, AI Governance, Agentic AI, MCP, and Model Context Protocol.

The Barndoor catalog on APIs.io includes 1 JSON-LD context and 2 Spectral governance rulesets.

Barndoor’s developer surface includes authentication, engineering blog, documentation, API reference, developer portal, signup flow, pricing, and 24 more developer resources.

61.4/100 strong ▬ flat Agent 41/100 agent ready Full breakdown ↓
scored 2026-07-28 · rubric v0.6
AccessFreemiumSelf serveFree trial⚡ Free to try
13 APIs 14 Features 7 Use Cases
AI AgentsAI GovernanceAgentic AIMCPModel Context ProtocolPolicy EnforcementOAuthIdentitySecurityAuditControl Plane

Kin Score

Kin Score Kin Score How this is scored →
scored 2026-07-28 · rubric v0.6
Composite quality — 61.4/100 · strong
Contract Quality 16.9 / 25
Developer Ergonomics 9.6 / 20
Commercial Clarity 13.2 / 20
Operational Transparency 6.2 / 13
Governance 8.3 / 12
Discoverability 7.4 / 10
Agent readiness — 41/100 · agent ready
Machine-Readable Contract 18 / 18
Agentic Access Contract 10 / 10
MCP Server 0 / 12
Machine-Readable Auth 10 / 10
Idempotency 0 / 9
Stable Error Semantics 8 / 8
Request/Response Examples 7 / 7
Rate-Limit Signaling 7 / 7
Typed Event Surface 0 / 6
Agent Skills 0 / 5
Well-Known Catalog 0 / 4
Consent & Bot Identity 0 / 3
A2A Agent Card 0 / 8
Dry-Run / Simulate Mode 0 / 4
Improve this rating by publishing the missing artifacts — every area above can be raised, and the full rubric is at apis.io/rating/. This rating is computed from github.com/api-evangelist/barndoor: open an issue to ask a question, or submit a pull request to add artifacts. Want it done for you? Prioritized profiling — $2,500 →

APIs 13

Individual APIs this provider publishes, each with its own machine-readable definition.

Barndoor Python SDK

Python SDK for the Barndoor AI Platform. Wraps the Platform REST API, handles Auth0 PKCE login (`loginInteractive()`), discovers governed MCP tools, brokers OAuth connections to...

Barndoor TypeScript SDK

TypeScript SDK for the Barndoor AI Platform. Browser- and Node-friendly client for Auth0 PKCE login, governed MCP tool discovery, OAuth connection initiation, and proxying MCP /...

Barndoor Go SDK

Go SDK for the Barndoor AI Platform. Server-side client for registering agents, managing MCP servers and policies, brokering OAuth connections, and proxying MCP requests from Go...

Official MCP Rust SDK

The official Rust SDK for the Model Context Protocol. Maintained under the Barndoor AI GitHub organization; provides primitives to build MCP clients and servers in Rust.

Cerbos Rust SDK

Rust SDK for Cerbos, the policy-decision-point used by Barndoor for attribute-based access control. Lets Rust services request policy decisions from a Cerbos PDP.

MCP OAuth Compliance Suite

Rust test suite that validates remote MCP servers against the MCP authorization specification - RFC 9728 (Protected Resource Metadata), RFC 8414 (Authorization Server Metadata),...

Barndoor + Crew AI Example

Reference Python demo application showing how to plug Barndoor-governed MCP tools into a Crew AI multi-agent workflow.

Barndoor Agents API

Manage AI agent registrations

Barndoor Connections API

Manage OAuth connections to MCP servers

Barndoor MCP Proxy API

Proxy requests to MCP servers

Barndoor Policies API

Manage access control policies for agents and servers

Barndoor Policy API

The Policy API from Barndoor — 1 operation(s) for policy.

Barndoor Servers API

Manage MCP server instances

Scroll for all 13

Postman Collections 6

Ready-to-run Postman collections for exercising this provider's APIs.

Open Collections 1

Open, tool-agnostic API collections (OpenAPI-derived and Bruno).

Barndoor Platform API

OPEN COLLECTION

Pricing Plans 1

Published pricing tiers and plan structures.

Rate Limits 1

Documented rate limits and quota policies.

Barndoor Rate Limits

6 limits

RATE LIMITS

FinOps 1

Cost, billing, and metering signals for API financial operations.

Features 14

Notable capabilities this provider offers.

MCP Governance

Secure access control and policy enforcement for Model Context Protocol servers.

Runtime Policy Enforcement

Continuous governance applied at the moment AI agents act, not just at login.

Right-Sized Permissions

Precise, scoped access for agents - not broad human-level permissions.

Context Filtering

Dynamically surface only policy-compliant MCP tools, optimizing the context window.

AI Agent Registry

Register internal and external agents, group them, and track activity.

OAuth Connection Brokering

Initiate and manage OAuth 2.0 connections from agents to backend SaaS.

MCP / SSE Proxying

Streaming proxy that injects credentials and enforces policy on every MCP and SSE request.

Policy Authoring (RBAC/ABAC)

Create, clone, version, validate, and apply Cerbos-based RBAC and ABAC policies.

Audit Dashboards and Activity Logs

Complete audit trails for every AI action, applied policy, and outcome.

Audit Log Export

Stream audit events as gzipped JSON Lines to S3 / GCS / MinIO / SeaweedFS buckets.

Shadow AI Discovery

Centralized visibility into unauthorized AI apps and agents in the environment.

Identity Provider Integration

Connect to existing enterprise IdPs (Keycloak-based) for SSO and identity.

Static Egress IPs

Five dedicated outbound IPs for whitelisting Barndoor traffic at MCP servers.

Private and On-Prem Deployment

SaaS, private cloud, and on-premises deployment options for sensitive environments.

Scroll for all 14

Semantic Vocabularies 1

JSON-LD contexts and semantic vocabularies used across these APIs.

Barndoor Context

3 classes · 14 properties

JSON-LD

Spectral Rules 2

Spectral governance rulesets for linting and validating these APIs.

Barndoor API Rules

5 rules · 4 warnings 1 info

SPECTRAL

Barndoor API Rules

21 rules · 10 errors 10 warnings 1 info

SPECTRAL

JSON Schema 24

Standalone JSON Schema definitions for this provider's data models.

AgentCounts

3 properties

JSON SCHEMA

AgentDirectoryBase

11 properties

JSON SCHEMA

AgentPayload

1 properties

JSON SCHEMA

AgentResponse

7 properties

JSON SCHEMA

Agent

5 properties

JSON SCHEMA

ConnectionInitiationResponse

1 properties

JSON SCHEMA

ConnectionStatusResponse

1 properties

JSON SCHEMA

Error

3 properties

JSON SCHEMA

FilterCategory

3 properties

JSON SCHEMA

FilterOption

2 properties

JSON SCHEMA

PaginationMeta

6 properties

JSON SCHEMA

PolicyDetail

14 properties

JSON SCHEMA

PolicyRevisionSummary

7 properties

JSON SCHEMA

PolicyRuleCondition

1 properties

JSON SCHEMA

PolicyRule

5 properties

JSON SCHEMA

PolicySummary

13 properties

JSON SCHEMA

ServerCreateRequest

6 properties

JSON SCHEMA

ServerCreateResponse

3 properties

JSON SCHEMA

ServerDetail

0 properties

JSON SCHEMA

ServerSummary

5 properties

JSON SCHEMA

ServerUpdateRequest

5 properties

JSON SCHEMA

UpdatePolicy

7 properties

JSON SCHEMA

ValidatePolicyRequest

4 properties

JSON SCHEMA

ValidatePolicyResponse

3 properties

JSON SCHEMA

Scroll for all 24

JSON Structure 24

JSON Structure definitions describing this provider's data shapes.

Barndoor Agent Counts Structure

3 properties

JSON STRUCTURE

Barndoor Agent Directory Base Structure

10 properties

JSON STRUCTURE

Barndoor Agent Payload Structure

1 properties

JSON STRUCTURE

Barndoor Agent Response Structure

7 properties

JSON STRUCTURE

Barndoor Agent Structure

5 properties

JSON STRUCTURE

Barndoor Error Structure

3 properties

JSON STRUCTURE

Barndoor Filter Category Structure

3 properties

JSON STRUCTURE

Barndoor Filter Option Structure

2 properties

JSON STRUCTURE

Barndoor Pagination Meta Structure

6 properties

JSON STRUCTURE

Barndoor Policy Detail Structure

13 properties

JSON STRUCTURE

Barndoor Policy Revision Summary Structure

7 properties

JSON STRUCTURE

Barndoor Policy Rule Condition Structure

1 properties

JSON STRUCTURE

Barndoor Policy Rule Structure

5 properties

JSON STRUCTURE

Barndoor Policy Summary Structure

12 properties

JSON STRUCTURE

Barndoor Server Create Request Structure

6 properties

JSON STRUCTURE

Barndoor Server Create Response Structure

3 properties

JSON STRUCTURE

Barndoor Server Detail Structure

0 properties

JSON STRUCTURE

Barndoor Server Summary Structure

5 properties

JSON STRUCTURE

Barndoor Server Update Request Structure

5 properties

JSON STRUCTURE

Barndoor Update Policy Structure

6 properties

JSON STRUCTURE

Barndoor Validate Policy Request Structure

4 properties

JSON STRUCTURE

Scroll for all 24

Examples 48

Example request and response payloads for these APIs.

Barndoor Agent Example

5 fields

EXAMPLE

Barndoor Error Example

3 fields

EXAMPLE

Scroll for all 48

Security Posture 3

Authentication, domain security, vulnerability disclosure, and trust-center signals.

Barndoor Authentication

http · 1 scheme

SECURITY

Barndoor Domain Security

TLSv1.3 · HSTS · DMARC

SECURITY

Barndoor Vulnerability Disclosure

security.txt · contact published

SECURITY

Agentic Access 1

Recommended x-agentic-access execution contracts for AI agents.

Barndoor Agentic Access

26 operations · 13 acting · 1 human-in-the-loop

26 operations · 13 acting

AGENTIC

Use Cases 7

What developers build with this provider.

Enterprise AI Governance

Apply access policies and governance to AI agents across the organization.

MCP Server Management

Centrally register, secure, and manage MCP server deployments for AI agents.

Agentic Workflow Orchestration

Coordinate multi-agent workflows with security and accountability controls.

AI Security and Data Exfiltration Prevention

Prevent unauthorized AI agent actions and limit data exfiltration.

Shadow AI Discovery

Surface unauthorized AI apps and agents already running in the environment.

Developer Tooling for Governed Agents

Build agents safely with end-to-end policy enforcement via SDKs.

Microsoft 365 Agent Governance

Govern agents that work across Microsoft 365 (Excel, Outlook, Teams, OneDrive).

Scroll for all 7

Solutions 2

Packaged solutions this provider offers.

IT & Security Teams

Centralize AI governance, manage shadow AI, and enforce real-time access controls at scale.

Developers

Deploy agents safely without custom security logic, with end-to-end policy across dev, staging, and prod.

Resources

Get Started 2

Portal, sign-up, and the first successful call

Documentation 3

Reference material describing how the API behaves

Agent Surfaces 3

MCP servers, agent skills, and machine-readable catalogs

Design & Contract 3

Pagination, idempotency, versioning, errors, and events

Build 3

SDKs, sample code, and the tooling you integrate with

Access & Security 8

Authentication, authorization, and security posture

Scroll for all 8

Operate 1

Status, limits, changes, and where to get help

Commercial 3

Pricing, plans, and the legal terms of use

Company 4

The organization behind the API

Other 2

Properties that don't map to a standard resource type

Source (apis.yml)

apis.yml Raw ↑
aid: barndoor
url: https://raw.githubusercontent.com/api-evangelist/barndoor/refs/heads/main/apis.yml
name: Barndoor
kind: company
description: Barndoor AI is the control plane for agentic AI, providing secure access and governance for AI agents and Model
  Context Protocol (MCP) servers. Founded in 2024 by Oren Michels (founder of Mashery), Barndoor enables enterprise IT, security,
  and developer teams to register agents, govern MCP server access through policy, broker OAuth connections to backend SaaS,
  and proxy MCP traffic with runtime policy enforcement and full audit trails. The Barndoor Platform REST API manages servers,
  connections, policies, agents, and MCP / SSE request proxying. Python, TypeScript, and Go SDKs are published on GitHub alongside
  Rust SDKs (Cerbos, official MCP, MCP OAuth compliance suite) and a Crew AI example. Deployment options include SaaS (trial),
  private cloud, and on-premises (Enterprise).
accessModel:
  pricing: freemium
  onboarding: self-serve
  trial: true
  try_now: true
  public: false
  label: Freemium (free trial) · Self-serve signup
  confidence: high
  source:
  - plans
  - authentication
  generated: '2026-07-22'
  method: derived
image: https://kinlane-images.s3.amazonaws.com/shared/apis-json/icons/barndoor.png
tags:
- AI Agents
- AI Governance
- Agentic AI
- MCP
- Model Context Protocol
- Policy Enforcement
- OAuth
- Identity
- Security
- Audit
- Control Plane
created: '2026-03-16'
modified: '2026-05-19'
specificationVersion: '0.19'
apis:
- aid: barndoor:python-sdk
  name: Barndoor Python SDK
  description: Python SDK for the Barndoor AI Platform. Wraps the Platform REST API, handles Auth0 PKCE login (`loginInteractive()`),
    discovers governed MCP tools, brokers OAuth connections to backend SaaS, and exposes the catalog through Pythonic helpers
    compatible with OpenAI tool-calling and frameworks such as Crew AI.
  humanURL: https://docs.barndoor.ai/sdks/python
  baseURL: https://github.com/barndoor-ai/barndoor-python-sdk
  tags:
  - Python SDK
  - SDK
  - MCP
  properties:
  - type: Documentation
    url: https://docs.barndoor.ai/sdks/python
  - type: Repository
    url: https://github.com/barndoor-ai/barndoor-python-sdk
- aid: barndoor:typescript-sdk
  name: Barndoor TypeScript SDK
  description: TypeScript SDK for the Barndoor AI Platform. Browser- and Node-friendly client for Auth0 PKCE login, governed
    MCP tool discovery, OAuth connection initiation, and proxying MCP / SSE requests through Barndoor.
  humanURL: https://docs.barndoor.ai/sdks/typescript
  baseURL: https://github.com/barndoor-ai/barndoor-ts-sdk
  tags:
  - TypeScript SDK
  - SDK
  - MCP
  properties:
  - type: Documentation
    url: https://docs.barndoor.ai/sdks/typescript
  - type: Repository
    url: https://github.com/barndoor-ai/barndoor-ts-sdk
- aid: barndoor:go-sdk
  name: Barndoor Go SDK
  description: Go SDK for the Barndoor AI Platform. Server-side client for registering agents, managing MCP servers and policies,
    brokering OAuth connections, and proxying MCP requests from Go services.
  humanURL: https://github.com/barndoor-ai/barndoor-go-sdk
  baseURL: https://github.com/barndoor-ai/barndoor-go-sdk
  tags:
  - Go SDK
  - SDK
  - MCP
  properties:
  - type: Repository
    url: https://github.com/barndoor-ai/barndoor-go-sdk
- aid: barndoor:official-mcp-rust-sdk
  name: Official MCP Rust SDK
  description: The official Rust SDK for the Model Context Protocol. Maintained under the Barndoor AI GitHub organization;
    provides primitives to build MCP clients and servers in Rust.
  humanURL: https://github.com/barndoor-ai/official-mcp-rust-sdk
  baseURL: https://github.com/barndoor-ai/official-mcp-rust-sdk
  tags:
  - MCP
  - Rust
  - SDK
  properties:
  - type: Repository
    url: https://github.com/barndoor-ai/official-mcp-rust-sdk
- aid: barndoor:cerbos-sdk-rust
  name: Cerbos Rust SDK
  description: Rust SDK for Cerbos, the policy-decision-point used by Barndoor for attribute-based access control. Lets Rust
    services request policy decisions from a Cerbos PDP.
  humanURL: https://github.com/barndoor-ai/cerbos-sdk-rust
  baseURL: https://github.com/barndoor-ai/cerbos-sdk-rust
  tags:
  - Cerbos
  - ABAC
  - Policy
  - Rust
  - SDK
  properties:
  - type: Repository
    url: https://github.com/barndoor-ai/cerbos-sdk-rust
- aid: barndoor:mcp-auth-compliance
  name: MCP OAuth Compliance Suite
  description: Rust test suite that validates remote MCP servers against the MCP authorization specification - RFC 9728 (Protected
    Resource Metadata), RFC 8414 (Authorization Server Metadata), RFC 7591 (Dynamic Client Registration), and OAuth 2.1. Useful
    for vendors and customers verifying MCP server conformance before onboarding to Barndoor.
  humanURL: https://github.com/barndoor-ai/mcp-auth-compliance
  baseURL: https://github.com/barndoor-ai/mcp-auth-compliance
  tags:
  - MCP
  - OAuth
  - Compliance
  - Rust
  - Conformance
  properties:
  - type: Repository
    url: https://github.com/barndoor-ai/mcp-auth-compliance
- aid: barndoor:crew-ai-example
  name: Barndoor + Crew AI Example
  description: Reference Python demo application showing how to plug Barndoor-governed MCP tools into a Crew AI multi-agent
    workflow.
  humanURL: https://github.com/barndoor-ai/barndoor-ai-crew-ai-python-example
  baseURL: https://github.com/barndoor-ai/barndoor-ai-crew-ai-python-example
  tags:
  - Crew AI
  - Python
  - Example
  - MCP
  properties:
  - type: Repository
    url: https://github.com/barndoor-ai/barndoor-ai-crew-ai-python-example
- aid: barndoor:barndoor-agents-api
  name: Barndoor Agents API
  description: Manage AI agent registrations
  humanURL: https://docs.barndoor.ai/api-reference/introduction
  baseURL: https://{organization_id}.platform.barndoor.ai
  tags:
  - Agents
  properties:
  - type: OpenAPI
    url: openapi/barndoor-agents-api-openapi.yml
  - type: Documentation
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: Authentication
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: SDKs
    url: https://docs.barndoor.ai/sdks/introduction
- aid: barndoor:barndoor-connections-api
  name: Barndoor Connections API
  description: Manage OAuth connections to MCP servers
  humanURL: https://docs.barndoor.ai/api-reference/introduction
  baseURL: https://{organization_id}.platform.barndoor.ai
  tags:
  - Connections
  properties:
  - type: OpenAPI
    url: openapi/barndoor-connections-api-openapi.yml
  - type: Documentation
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: Authentication
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: SDKs
    url: https://docs.barndoor.ai/sdks/introduction
- aid: barndoor:barndoor-mcp-proxy-api
  name: Barndoor MCP Proxy API
  description: Proxy requests to MCP servers
  humanURL: https://docs.barndoor.ai/api-reference/introduction
  baseURL: https://{organization_id}.platform.barndoor.ai
  tags:
  - MCP Proxy
  properties:
  - type: OpenAPI
    url: openapi/barndoor-mcp-proxy-api-openapi.yml
  - type: Documentation
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: Authentication
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: SDKs
    url: https://docs.barndoor.ai/sdks/introduction
- aid: barndoor:barndoor-policies-api
  name: Barndoor Policies API
  description: Manage access control policies for agents and servers
  humanURL: https://docs.barndoor.ai/api-reference/introduction
  baseURL: https://{organization_id}.platform.barndoor.ai
  tags:
  - Policies
  properties:
  - type: OpenAPI
    url: openapi/barndoor-policies-api-openapi.yml
  - type: Documentation
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: Authentication
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: SDKs
    url: https://docs.barndoor.ai/sdks/introduction
- aid: barndoor:barndoor-policy-api
  name: Barndoor Policy API
  description: The Policy API from Barndoor — 1 operation(s) for policy.
  humanURL: https://docs.barndoor.ai/api-reference/introduction
  baseURL: https://{organization_id}.platform.barndoor.ai
  tags:
  - Policy
  properties:
  - type: OpenAPI
    url: openapi/barndoor-policy-api-openapi.yml
  - type: Documentation
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: Authentication
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: SDKs
    url: https://docs.barndoor.ai/sdks/introduction
- aid: barndoor:barndoor-servers-api
  name: Barndoor Servers API
  description: Manage MCP server instances
  humanURL: https://docs.barndoor.ai/api-reference/introduction
  baseURL: https://{organization_id}.platform.barndoor.ai
  tags:
  - Servers
  properties:
  - type: OpenAPI
    url: openapi/barndoor-servers-api-openapi.yml
  - type: Documentation
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: Authentication
    url: https://docs.barndoor.ai/api-reference/introduction
  - type: SDKs
    url: https://docs.barndoor.ai/sdks/introduction
common:
- type: PostmanWorkspace
  url: https://www.postman.com/kinlaneapi/barndoor/overview
- type: AgenticAccess
  url: agentic-access/barndoor-agentic-access.yml
- type: VulnerabilityDisclosure
  url: security/barndoor-vulnerability-disclosure.yml
- type: DomainSecurity
  url: security/barndoor-domain-security.yml
- type: Authentication
  url: authentication/barndoor-authentication.yml
- url: http://barndoor.ai/feed/
  type: Blog
- type: LinkedIn
  url: https://www.linkedin.com/company/barndoor-ai
- type: Website
  url: https://barndoor.ai/
  name: Barndoor AI
- type: Documentation
  url: https://docs.barndoor.ai/
  name: Barndoor Developer Documentation
- type: APIReference
  url: https://docs.barndoor.ai/api-reference/introduction
  name: Barndoor API Reference
- type: OpenAPI
  url: openapi/barndoor-openapi.yml
  name: Barndoor Platform API OpenAPI
- type: Authentication
  url: https://docs.barndoor.ai/api-reference/introduction
  name: Authentication (Auth0 OAuth 2.0 with PKCE)
- type: SDKs
  url: https://docs.barndoor.ai/sdks/introduction
  name: Barndoor SDKs (Python, TypeScript, Go)
- type: Portal
  url: https://app.barndoor.ai/
  name: Barndoor App
- type: Signup
  url: https://app.barndoor.ai/auth/signup/trial
  name: Barndoor Free Trial Signup
- type: TokensManagement
  url: https://app.barndoor.ai/settings/tokens
  name: Platform API Tokens
- type: Pricing
  url: https://barndoor.ai/pricing
  name: Barndoor Pricing
- type: Plans
  url: plans/barndoor-plans-pricing.yml
  name: Barndoor Plans (API Commons)
- type: RateLimits
  url: rate-limits/barndoor-rate-limits.yml
  name: Barndoor Rate Limits (API Commons)
- type: FinOps
  url: finops/barndoor-finops.yml
  name: Barndoor FinOps (FOCUS 1.3)
- type: GitHub
  url: https://github.com/barndoor-ai
  name: Barndoor AI GitHub Org
- type: Security
  url: https://barndoor.ai/security/
  name: Barndoor Security
- type: TrustCenter
  url: https://trust.barndoor.ai
  name: Barndoor Trust Center
- type: About
  url: https://barndoor.ai/about-us/
  name: About Barndoor AI
- type: MCPCatalog
  url: https://docs.barndoor.ai/mcp-servers/servers
  name: Barndoor MCP Catalog (60+ servers)
- type: IPAllowlist
  url: https://docs.barndoor.ai/how-tos/ip-whitelisting
  name: Static Egress IPs for MCP Servers
- type: LogExport
  url: https://docs.barndoor.ai/how-tos/log-export
  name: Audit Log Export to S3-Compatible Storage
- type: SpectralRules
  url: rules/barndoor-spectral-rules.yml
  name: Spectral Ruleset
- type: Vocabulary
  url: vocabulary/barndoor-vocabulary.yaml
  name: Barndoor Vocabulary
- type: JSONLD
  url: json-ld/barndoor-context.jsonld
  name: Barndoor JSON-LD Context
- name: Features
  type: Features
  data:
  - name: MCP Governance
    description: Secure access control and policy enforcement for Model Context Protocol servers.
  - name: Runtime Policy Enforcement
    description: Continuous governance applied at the moment AI agents act, not just at login.
  - name: Right-Sized Permissions
    description: Precise, scoped access for agents - not broad human-level permissions.
  - name: Context Filtering
    description: Dynamically surface only policy-compliant MCP tools, optimizing the context window.
  - name: AI Agent Registry
    description: Register internal and external agents, group them, and track activity.
  - name: OAuth Connection Brokering
    description: Initiate and manage OAuth 2.0 connections from agents to backend SaaS.
  - name: MCP / SSE Proxying
    description: Streaming proxy that injects credentials and enforces policy on every MCP and SSE request.
  - name: Policy Authoring (RBAC/ABAC)
    description: Create, clone, version, validate, and apply Cerbos-based RBAC and ABAC policies.
  - name: Audit Dashboards and Activity Logs
    description: Complete audit trails for every AI action, applied policy, and outcome.
  - name: Audit Log Export
    description: Stream audit events as gzipped JSON Lines to S3 / GCS / MinIO / SeaweedFS buckets.
  - name: Shadow AI Discovery
    description: Centralized visibility into unauthorized AI apps and agents in the environment.
  - name: Identity Provider Integration
    description: Connect to existing enterprise IdPs (Keycloak-based) for SSO and identity.
  - name: Static Egress IPs
    description: Five dedicated outbound IPs for whitelisting Barndoor traffic at MCP servers.
  - name: Private and On-Prem Deployment
    description: SaaS, private cloud, and on-premises deployment options for sensitive environments.
- name: Use Cases
  type: UseCases
  data:
  - name: Enterprise AI Governance
    description: Apply access policies and governance to AI agents across the organization.
  - name: MCP Server Management
    description: Centrally register, secure, and manage MCP server deployments for AI agents.
  - name: Agentic Workflow Orchestration
    description: Coordinate multi-agent workflows with security and accountability controls.
  - name: AI Security and Data Exfiltration Prevention
    description: Prevent unauthorized AI agent actions and limit data exfiltration.
  - name: Shadow AI Discovery
    description: Surface unauthorized AI apps and agents already running in the environment.
  - name: Developer Tooling for Governed Agents
    description: Build agents safely with end-to-end policy enforcement via SDKs.
  - name: Microsoft 365 Agent Governance
    description: Govern agents that work across Microsoft 365 (Excel, Outlook, Teams, OneDrive).
- name: Solutions
  type: Solutions
  data:
  - name: IT & Security Teams
    description: Centralize AI governance, manage shadow AI, and enforce real-time access controls at scale.
  - name: Developers
    description: Deploy agents safely without custom security logic, with end-to-end policy across dev, staging, and prod.
- name: Compliance
  type: Compliance
  data:
  - name: SOC 2 Type II
    description: Barndoor holds a SOC 2 Type II attestation for security controls effectiveness over time.
- type: LlmsText
  url: https://docs.barndoor.ai/llms.txt
integrations:
- name: Salesforce
- name: Notion
- name: GitHub
- name: GitLab
- name: Slack
- name: HubSpot
- name: Microsoft 365
- name: Microsoft Teams
- name: Microsoft Excel
- name: Microsoft Word
- name: OneDrive
- name: OneNote
- name: PowerPoint
- name: Outlook Mail
- name: Outlook Calendar
- name: Microsoft Planner
- name: Microsoft Dynamics
- name: SharePoint
- name: Gmail
- name: Google Calendar
- name: Google Docs
- name: Google Sheets
- name: Google Slides
- name: Google Drive
- name: Atlassian
- name: Linear
- name: Asana
- name: Monday
- name: Basecamp
- name: Aha!
- name: Box
- name: Dropbox
- name: Figma
- name: Airtable
- name: Snowflake
- name: Hex
- name: Amplitude
- name: SonarQube
- name: Datadog
- name: Grafana
- name: Sentry
- name: Harness
- name: Finch
- name: ServiceNow
- name: Zendesk
- name: Freshdesk
- name: Intercom
- name: Zoom
- name: Fireflies.ai
- name: Granola
- name: Otter
- name: Apollo
- name: Attio
- name: Close
- name: Gong
- name: Shopify
- name: Zoho CRM
- name: Stripe
- name: Plaid
- name: QuickBooks
- name: Xero
- name: Octagon
- name: Crew AI
- name: Auth0
- name: Keycloak
- name: Cerbos
maintainers:
- FN: Kin Lane
  email: kin@apievangelist.com