Popular articles
59 articlesRolling out fail-closed mode safely
Moving from fail-open to fail-closed is worth doing carefully: the whole point is to block…
Fail-open vs fail-closed: enabling fail-closed mode
"Fail-open" and "fail-closed" decide what happens when analysis can't finish in time —…
Connect your first API key
Getting traffic flowing through G8KEPR takes three steps. Your dashboard's Overview page…
How rug-pull detection works
A "rug pull" is when an MCP server quietly changes a tool's definition after you've…
Deploy G8KEPR in your VPC
G8KEPR runs where your traffic and data already live. You can start on our hosted…
Choosing an LLM Routing Strategy
The AI Gateway sits in front of your model providers and decides which model handles each request. Your routing strategy…
Inside the 7-Step Tool-Call Security Pipeline
Every time one of your AI agents invokes a tool over MCP, G8KEPR intercepts that tools/call and runs it through a seven-…
The four verification layers explained
Every response G8KEPR checks passes through four independent verification layers. Each layer answers a different questio…
Reading your detection numbers
Your dashboard shows how many requests were analyzed, flagged, and blocked. Here is what…
Upgrading your plan and seats
Plans scale with how much you run through G8KEPR and the support guarantees you need —…
Managing payment methods
Your payment methods are the cards G8KEPR charges for your subscription and any usage overages. From the Payment Methods…
Creating custom roles
Custom roles let you define exactly what each teammate can see and do in G8KEPR by toggling individual permissions in a …
Plan-based model and feature limits
Your subscription plan determines which LLM models the AI Gateway will route to and which security features are switched…
Viewing and downloading invoices
Every charge on your G8KEPR subscription generates an invoice, and each one is saved to your account so you can view it,…
Inviting and Managing Team Members
Everyone who uses G8KEPR does so as a member of your organization. From the Team page you can invite new people, control…
Understanding roles and permissions (RBAC)
G8KEPR uses role-based access control (RBAC) to decide who on your team can see and change what. Every member is assigne…
Generate and use your first API key
API keys let your applications and scripts authenticate with G8KEPR programmatically. This guide walks you through creat…
Understanding your security score
Your security score is the at-a-glance indicator at the top of your dashboard that summarizes how well-protected your AI…
How a request flows through G8KEPR
Every call your AI apps, APIs, and MCP tools make can pass through G8KEPR's four protection pillars, and related events …
Configuring API rate limits
Rate limits protect your G8KEPR endpoints from abuse and runaway traffic by capping how many requests are accepted in a …
Understanding Rate-Limit Response Headers
G8KEPR API responses include headers that tell you how much of your rate limit remains and, if you've been throttled, ho…
Adding Custom WAF Rules for Your Org
G8KEPR lets you extend the managed Web Application Firewall (WAF) with rules specific to your organization, so you can b…
What is a shadow API?
A shadow API is any API endpoint that is serving live traffic but isn't part of your official, documented, or governed A…
What G8KEPR is: the four security pillars
G8KEPR is a security platform for AI-powered applications. It protects every layer an AI request touches — your APIs, yo…
Auto-classifying sensitive data fields
G8KEPR inspects the requests and responses flowing through your APIs, MCP servers, and AI tools, and automatically flags…
A tour of the Command Center dashboard
The Command Center is your primary security operations view in G8KEPR. It brings together your live security score, bloc…
How the web application firewall works
The G8KEPR web application firewall (WAF) inspects incoming API and MCP requests and can block or flag requests that mat…
Understanding rug-pull detection
A "rug-pull" is when an MCP server presents a safe, approved tool when you first connect, then quietly swaps in a differ…
Setting Tool Permissions, Approvals, and MFA
G8KEPR lets you control exactly which MCP tools an AI agent can call, which calls require a human approval, and which se…
Finding and archiving zombie APIs
A zombie API is an endpoint that still lives in your OpenAPI specs but no longer receives real traffic. G8KEPR surfaces …
Demo Mode vs. Live Data Explained
When your dashboard shows a demo-data banner, it means the page is displaying sample data instead of your live account a…
Bot and scraper detection explained
G8KEPR can classify requests reaching your APIs as human or automated, then lets you decide what happens next. It does t…
Completing the onboarding activation checklist
The Start Here page is the first thing you see when you open your G8KEPR dashboard. It walks you through a 4-step activa…
Replaying MCP Sessions for Investigation
G8KEPR records every MCP session an AI agent runs through your gateway, so you can replay it later to see exactly which …
Quickstart: Send Your First Protected Request
This guide takes you from a new account to your first protected API call in a few minutes, using the ready-made curl sni…
Blocking prompt injection in tool output
When an AI agent calls a tool, the response can carry hidden instructions that try to hijack the agent — a technique cal…
Bring Your Own API Keys (BYOK)
Bring Your Own Key (BYOK) lets you connect your own provider API keys to the G8KEPR AI Gateway, so requests run on your …
What is the AI Gateway?
The AI Gateway is a single, secured endpoint that sits between your applications and the large language model (LLM) prov…
Configuring AI Guardrail Policies
AI guardrail policies let you screen the prompts and responses flowing through the AI Gateway for unsafe or unwanted con…
Creating output constraints
Output constraints are rules the Verification Engine checks every model, API, or MCP response against before it reaches …
What is source grounding (hallucination detection)?
Source grounding checks whether the factual claims in an AI response are actually supported by the source material the m…
How the MCP Sandbox Isolates Tool Execution
When an AI agent calls a tool through G8KEPR, that tool doesn't run loose on the host. It runs inside a sandbox that cap…
Constraint actions: warn, suggest, and block
When you attach constraints to a policy, each one declares an action that decides what happens if it fires on a response…
What MCP security protects against
MCP lets your AI agents call external tools to fetch data and take actions — but those tools can carry hidden instructio…
Reading verification analytics and pass rates
The Verification analytics dashboard shows how effectively G8KEPR is inspecting traffic to and from your AI, API, and MC…
Reading your usage meters and limits
Your billing page shows three usage meters that track your account against your plan's limits: API calls, team members, …
What the Verification Engine does
The Verification Engine is a final checkpoint that inspects AI-generated responses before they reach your users or downs…
Which LLM Providers Are Supported
The G8KEPR AI Gateway routes your inference traffic across 14 built-in LLM providers, plus a Custom option for your own …
Tracking and budgeting LLM costs
G8KEPR meters every LLM request that passes through the AI Gateway, so you always know what you're spending and by whom.…
Comparing plans: Free, Starter, Pro, and Enterprise
G8KEPR offers four plans — Free, Starter, Pro, and Enterprise — that scale from a single project to organization-wide se…
Filtering PII before it reaches the LLM
The AI Gateway can scan outbound prompts for personally identifiable information (PII) before they are forwarded to an L…
Monitoring Conversation Drift and Coherence
Multi-turn AI conversations can gradually wander off topic, contradict earlier turns, or be steered somewhere they were …
What counts toward your API-call limit
Your plan includes a monthly allowance of API calls. In short: every request your workloads send through the G8KEPR gate…
Upgrading or downgrading your plan
You can change your G8KEPR subscription tier at any time from the Compare Plans page in your dashboard. Upgrades take ef…
Setting Budget Alert Thresholds
Budget alerts can notify you by email or Slack when your AI Gateway spend crosses a threshold you define, so rising cost…
Reading the EU AI Act risk-class header on gateway completions
Every completion returned by the AI Gateway includes an X-AI-Risk-Class response header. It tells you the EU AI Act risk…
Setting up two-factor authentication
Two-factor authentication (2FA) adds a second step to sign-in, so your G8KEPR account stays protected even if your passw…
Registering and monitoring MCP servers
Registering an MCP server puts it under G8KEPR's watch: every tool it exposes is inventoried, pinned, and checked on eac…
Block vs. detect: fail-open and fail-closed paths
The Verification Engine can either block a bad model response before it reaches your caller (fail-closed) or log it whil…
Still can't find what you need?
Open a ticket and our team will follow up — tracked against your plan SLA.