# Kastra documentation

Understand Kastra’s security boundary, prove a workflow, and run it with clear ownership.

Start with the decision your team needs to control. Security leaders can review architecture and assurance; engineers can connect a supported integration; operators can plan rollout and response.

## Choose your path

- [Security leaders](https://docs.kastra.ai/security/overview.md): Assess coverage, data exposure, access, and vendor assurance.
- [Implementation teams](https://docs.kastra.ai/start/first-workflow.md): Connect one workflow and verify allow, block, and approval outcomes.
- [Self-hosted enterprise](https://docs.kastra.ai/reference/self-hosted.md): Review implemented appliance capabilities and the roadmap to an assisted pilot.
- [Platform operators](https://docs.kastra.ai/security/operations.md): Plan rollout, monitoring, failure response, and recovery.

Review Kastra’s SOC 2 assurance and GDPR documentation in the Trust Center, alongside the product behavior described in these guides.

[Open the Kastra Trust Center](https://trust.oneleet.com/kastra)

## Connect an integration

- [Coding agents](https://docs.kastra.ai/edge/install.md): Install Edge and connect a supported coding-agent hook.
- [Applications](https://docs.kastra.ai/proxy/overview.md): Govern supported OpenAI or Anthropic traffic through the proxy.
- [MCP tools](https://docs.kastra.ai/mcp/local-gateway.md): Wrap a local stdio server and test its tool permissions.

## Start here

- [How Kastra works](https://docs.kastra.ai/start/overview.md): Choose the integration that can see and govern the action you care about.
- [Core concepts and decision states](https://docs.kastra.ai/start/concepts.md): Understand the vocabulary used in setup, policy, approval, and evidence guides.
- [Your first governed workflow](https://docs.kastra.ai/start/first-workflow.md): Connect, observe, test a block, and resolve an approval in a test environment.
- [Authentication and environments](https://docs.kastra.ai/start/authentication.md): Use the credential and environment contract for the surface you are connecting.
- [Platform and integration support](https://docs.kastra.ai/start/platform-support.md): Distinguish available artifacts from combinations validated on real machines.
- [Find your way around the console](https://docs.kastra.ai/start/console.md): Navigate the current application from setup to policy, review, evidence, and administration.

## Security review

- [Evaluate Kastra for your security program](https://docs.kastra.ai/security/overview.md): A CISO's guide to the controls, evidence, and operating decisions needed to evaluate Kastra.
- [Architecture and enforcement coverage](https://docs.kastra.ai/security/architecture.md): Trace each action through its enforcement point, policy service, and evidence path.
- [Data protection and privacy review](https://docs.kastra.ai/security/data-protection.md): Map the data each integration processes and the privacy evidence needed before a rollout.
- [Access control and shared responsibilities](https://docs.kastra.ai/security/access-control.md): Assign policy owners, approvers, and credential responsibilities before connecting sensitive workflows.
- [Pilot plan and acceptance criteria](https://docs.kastra.ai/security/evaluation.md): Run a bounded evaluation with observable control outcomes and a clear rollout decision.
- [Rollout, monitoring, and incident response](https://docs.kastra.ai/security/operations.md): Operate the integration, respond to non-enforcement, and preserve a practical recovery and exit path.
- [SOC 2, GDPR, and the Trust Center](https://docs.kastra.ai/security/assurance.md): Find Kastra's vendor assurance material and connect it to your security and privacy review.

## Coding agents

- [Install Kastra Edge](https://docs.kastra.ai/edge/install.md): Install the correct platform build, sign in, and connect your agent hook.
- [Claude Code](https://docs.kastra.ai/edge/claude-code.md): Connect Claude Code to Kastra policies and verify the hook boundary.
- [Codex CLI](https://docs.kastra.ai/edge/codex.md): Connect Codex CLI to Kastra policies and verify the hook boundary.
- [Cursor](https://docs.kastra.ai/edge/cursor.md): Connect Cursor to Kastra policies and verify the hook boundary.
- [OpenClaw](https://docs.kastra.ai/edge/openclaw.md): Install the Kastra plugin and govern supported OpenClaw tool calls.
- [Hermes Agent](https://docs.kastra.ai/edge/hermes.md): Connect native and MCP tool hooks, including Hermes first-use consent.
- [Desktop app and device management](https://docs.kastra.ai/edge/desktop.md): Use desktop approvals and manage devices without confusing the daemon with hook enforcement.
- [Usage telemetry and collection](https://docs.kastra.ai/edge/telemetry.md): Understand Claude Code and Codex telemetry installed alongside hooks and its reporting limits.
- [Troubleshoot Edge](https://docs.kastra.ai/edge/troubleshooting.md): Find missing hooks, wrong binaries, environment mismatches, and fail-open events.

## Applications & proxy

- [Proxy setup](https://docs.kastra.ai/proxy/overview.md): Route supported OpenAI or Anthropic traffic through Kastra with both credentials.
- [OpenAI Chat Completions](https://docs.kastra.ai/proxy/openai.md): Send a server-side Chat Completions request with explicit Kastra and upstream credentials.
- [Anthropic Messages](https://docs.kastra.ai/proxy/anthropic.md): Connect the Messages protocol through Kastra and handle policy outcomes.
- [Streaming and model output](https://docs.kastra.ai/proxy/streaming.md): Handle filtered output, tool-call decisions, and failures after a stream has started.
- [Proxy HOLD and resubmission](https://docs.kastra.ai/proxy/approvals.md): Use the correct approval contract for held requests and generated tool calls.
- [Content scanning and redaction](https://docs.kastra.ai/proxy/content-guardrails.md): Apply supported secret and PII detectors to proxy traffic with visible scope.

## MCP

- [Choose the right MCP connection](https://docs.kastra.ai/mcp/overview.md): Separate downstream tool governance, account inspection, and onboarding.
- [Local MCP gateway](https://docs.kastra.ai/mcp/local-gateway.md): Wrap an existing stdio server and verify discovery, deny, and approval behavior.
- [Tool catalogs and permissions](https://docs.kastra.ai/mcp/catalog.md): Use real tool names in policies and enforce restrictions at discovery and call time.
- [Account MCP connector](https://docs.kastra.ai/mcp/account.md): Read governance state through OAuth or the local read-only server.
- [Onboarding MCP](https://docs.kastra.ai/mcp/onboarding.md): Let an assistant start a signup handoff while the user completes account creation.
- [Claude Code plugin](https://docs.kastra.ai/mcp/claude-plugin.md): Install read-only governance skills and follow the separate Edge enforcement setup.
- [Hosted MCP availability](https://docs.kastra.ai/mcp/hosted-status.md): Understand the separate release boundary for remote third-party MCP connections.

## Policies

- [Author and test policies](https://docs.kastra.ai/policies/authoring.md): Create a rule that matches the real integration surface and activate it deliberately.
- [Policy as code](https://docs.kastra.ai/policies/policy-as-code.md): Validate, apply, version, and promote .kastra policies with the operator CLI.
- [Safety packs](https://docs.kastra.ai/policies/safety-packs.md): Start from curated rules while preserving surface scope and exemptions.
- [AI policy drafting](https://docs.kastra.ai/policies/ai-drafting.md): Describe a rule, review catalog matches and tests, and install the result yourself.
- [Recon history scanning](https://docs.kastra.ai/policies/recon.md): Turn supported Claude Code and Cursor history into reviewable policy recommendations.
- [Shadow mode and replay](https://docs.kastra.ai/policies/shadow-replay.md): Evaluate policy impact before enforcement and understand historical coverage.

## Approvals

- [Approval lifecycle](https://docs.kastra.ai/approvals/overview.md): Understand pending checkpoints, human resolution, expiry, and effective decisions.
- [Smart Holds](https://docs.kastra.ai/approvals/smart-holds.md): Flag false positives and review proposed policy refinements without automatic changes.
- [Slack approvals](https://docs.kastra.ai/approvals/slack.md): Connect a workspace, choose notification channels, and link each human approver.
- [Signed webhooks and notifications](https://docs.kastra.ai/approvals/webhooks.md): Receive governance events, verify authenticity, and handle retries.
- [Notifications and alert rules](https://docs.kastra.ai/approvals/notifications.md): Set personal notification preferences and administrator alert rules.

## Evidence & usage

- [Decision history and verification](https://docs.kastra.ai/evidence/decisions.md): Inspect the exact action, policy, and outcome, then verify the recorded chain.
- [Framework evidence exports](https://docs.kastra.ai/evidence/exports.md): Generate scoped reports, verify their seals, and give reviewers a clear account of coverage.
- [Data handling and masking](https://docs.kastra.ai/evidence/data-handling.md): Separate evaluation payloads, stored evidence, Recon uploads, and usage reporting.
- [Usage and cost provenance](https://docs.kastra.ai/evidence/usage.md): Read metered and reported usage without treating missing data as zero or estimates as invoices.
- [Rate limits and spend caps](https://docs.kastra.ai/evidence/limits.md): Apply windowed controls on supported paths and understand identity and concurrency limits.
- [Governance audit log](https://docs.kastra.ai/evidence/audit.md): Inspect administrative changes separately from runtime decisions and notification delivery.

## Administration

- [Workspaces, roles, and environments](https://docs.kastra.ai/admin/workspaces.md): Keep membership, policy scope, and environment identity explicit.
- [Agent inventory and identity](https://docs.kastra.ai/admin/agents.md): Define matchable selectors and tool scope without implying attested workload identity.
- [SAML SSO and SCIM](https://docs.kastra.ai/admin/sso-scim.md): Configure Enterprise identity with explicit protocol and provisioning boundaries.
- [Plans and observe-only behavior](https://docs.kastra.ai/admin/billing.md): Understand the Pro trial, feature entitlements, and what changes when billing lapses.
- [API keys and identity binding](https://docs.kastra.ai/admin/api-keys.md): Create a scoped runtime credential and manage its binding and revocation.
- [Devices and operator tokens](https://docs.kastra.ai/admin/devices.md): Review workspace connections and revoke credentials you no longer use.
- [Account security and MFA](https://docs.kastra.ai/admin/account-security.md): Enroll an authenticator and distinguish account security from workspace identity settings.

## Reference

- [Operator CLI reference](https://docs.kastra.ai/reference/cli.md): Manage policies, evidence, environments, keys, and checkpoints from a terminal or CI.
- [Evaluation API](https://docs.kastra.ai/reference/evaluate.md): Submit an action, decode ALLOW or DENY, and negotiate a supported HOLD response.
- [Policy attributes and effects](https://docs.kastra.ai/reference/policy-attributes.md): Match the context the integration actually sends, with explicit surface and trigger scope.
- [Failure behavior](https://docs.kastra.ai/reference/failure-behavior.md): Distinguish policy denial, unavailable evaluation, billing observe-only, and host timeouts.
- [TypeScript SDK status](https://docs.kastra.ai/reference/sdk.md): Understand the alpha implementation and its cooperative enforcement boundary.
- [Self-hosted deployment and availability](https://docs.kastra.ai/reference/self-hosted.md): Implemented appliance capabilities, offline licenses, access recovery, and the requirements for a customer-operated deployment.
- [API reference and contracts](https://docs.kastra.ai/reference/api.md): Find the reviewed runtime endpoints and navigate the full implementation schema.

The TypeScript SDK is in alpha; public package installation is not verified. Use the evaluation API for a custom integration and review the SDK status before planning adoption.

[SDK status and integration boundary](https://docs.kastra.ai/reference/sdk.md)
