August 2026 product release

AI Gateway platform updates

AgentProfile to end reliance on human credentials and hidden costs

Earlier this month, Barndoor announced a new capability that ties each agent’s profile, credentials, and spend to a single governed record. This is the first step for organizations toward governing the entire agent lifecycle from provisioning to deprovisioning access. 

August’s release now adds owner and contact fields, secrets rotation, and an activity view that breaks down each agent’s LLM traffic and error rate on its own page. By giving each agent its own profile instead of inheriting a human’s credentials and permissions, you can control exactly what an agent is allowed to access, see what it’s spending, regardless of who built it. 

These latest updates brings more operational control:

  • If an agent’s client secret is compromised, you can rebuild without needing to start over with the agent itself
  • Barndoor will now block binding the same LLM key to two agents by mistake
  • The agent’s LLM audit history will persist, even after an agent’s LLM key is unbound or rotated
  • The agent’s own detail page now shows 24 hours of activity, as well as traffic and error-rate breakdowns

Real-time alerts and notifications for events that need your attention 

Barndoor now provides real-time, in product alerts for events across the Barndoor AI Gateway. A bell icon in the header opens an inbox of events. For example, an LLM budget exceeded threshold, an MCP tool change, a policy update, and more – these are tagged by severity, with actionable alert links that then allow you to drill into the alerted issue. Admins can also configure these alerts to be sent to a specific email address, Slack channel, Microsoft Teams channel, or a generic webhook, depending on your team’s uses. 

Set up real-time, in product events across the Barndoor AI Gateway

MCP Governance updates

Barndoor Terraform provider

Barndoor now ships an official Terraform provider. This way, infrastructure teams can configure Barndoor as code, applying policies, MCP connectors, agent configurations, and log export settings. Now, policies and configuration can be version controlled instead of living in the UI. 

Install from the Terraform Registry (barndoor-ai/barndoor) and start with the guides at docs.barndoor.ai/terraform.

Control localhost MCPs in early access

An engineer using an MCP server locally on their own laptop could be shadow AI that gateway solutions can’t see or help make safe to use. Barndoor Bridge solves this by running as a background agent on the engineer’s machine, deployed through your MDM. This background agent sits between the local MCP server and what it’s about to do. It evaluates those actions against Barndroor access policies you can control. Instead of worrying about engineers using ungoverned MCP servers, Barndoor Bridge ensures that governance exists by default. 

Are you managing local agents? Or concerned about shadow AI? Co-founder and CTO Tim Stacey demonstrated how to bring these agents under centralized controls with an AI Gateway. Watch the replay here

Barndoor Bridge is in the early access program. If interested, reach out to Barndoor.

Policy revision history shows what changed, when, and who changed it

Barndoor retains a full revision history of every MCP policy. Now, the policy revision history is visible directly in the access control center. This means that when a policy changes, admins can see the full historical record. Each revision captures what, when, and who changed a policy. 

Historical capture of policy revisions that shows what changed, when, and who changed it

Granular confirmations in access control center

Previously, confirmations, the approval step before an agent takes an action, could only be configured for an entire agent at once, the same for every user and tool.

Now, an admin can configure this per tool, and scope it by user group or role. Each action can be set to Always Allow, Needs Approval, or Blocked, so the same agent can behave differently for different people (eg. automation users get Always Allow, everyone else gets Needs Approval).

Admins can also set quick defaults for all Read or Write/Delete tools, then override individual tools or groups as needed.

Admins can configure confirmations per tool, and scope it by user group or role

New MCPs for Cloud66 and DigitalOcean

Barndoor now includes Cloud66 and the DigitalOcean stack. Agents that provision infrastructure or manage networking through these tools are now under the same policies, confirmations, and audit trail as governed connectors within your organization.

The new connectors include

LLM Gateway updates

Deeper agent reporting in LLM Gateway

While AgentProfile is scoped to one agent, each with its own detail page, the LLM Gateway usage dashboard provides a wider view of traffic, cost, and error rate broken down per agent, user, organization, group, and API key. 

The LLM Gateway usage dashboard provides a wider view of traffic, cost, and error rate broken down per agent, user, organization, group, and API key

Instead of guessing spend from a bill at the end of the month, admins can see which agent or model is driving cost or errors in real time, and combine that visibility with budget caps and automatic fallbacks.

Sign up for a demo

Ready to empower your knowledge workers with governed AI at scale? Book a demo or start a free trial to see Barndoor in action.

Note to customers: If any of the features above aren’t visible in your account yet, reach out to your account executive and we’ll get them turned on for you.