Govern AI agents on infrastructure you control.
Authenticate every AI request, audit every prompt, and contain agents behind a default-deny network.


AI is already in your software development lifecycle. But how do you manage it?
Uncontrolled AI development tools introduce security risk, shadow usage, and rising costs, while blocking AI slows progress and delivery. With Coder, AI agents (bring your own or use Coder Agents) run on self-hosted infrastructure with enforced access controls and centralized audits of every AI interaction.
Visibility and attribution
- Coder authenticates every AI request and ties it to a named user.
- Prompts, token usage, models, and tool invocations are logged centrally.
- Provider API keys never leave the control plane.
Blast radius containment
- Run agents in isolated ephemeral workspaces behind default-deny networks.
- Only approved domains and services are accessible.
- Log every allow and deny centrally.
Self-hosted control
- Deploy Coder on cloud, on-prem, or air-gapped infrastructure.
- Integrate with your IdP via OIDC and SCIM.
- Export audit events from Coder to your SIEM.
We are reliant on Coder right now to roll out Claude Code and Codex since it's the path of least resistance for centralizing model configuration.
Get visibility and control with
Coder

Get visibility and control with Coder
Govern agent interactions with LLM providers for auditing and cost control.

Build with tools you love



Move AI agents into production with Coder. Coder provides a self-hosted control plane for managing model access, agent identity, MCP tools, network egress, and audit visibility across every AI coding agent your developers use.
Bring your own or run Coder Agents
- Run Claude Code, Codex, or any HTTP agent in self-hosted workspaces behind a default-deny network.
- Or use Coder Agents on the control plane with no separate deployment.
- Trigger agents from chat or via API for CI, GitHub Actions, Slack, and Jira.
- Identity, audit, and credentials apply consistently, so teams can switch vendors without re-architecting.

Get centralized visibility and auditability
- Coder's AI Gateway centralizes access for coding agents like Claude Code and Codex.
- Centralize authentication, user-level tracking, cost monitoring, and audit trails across all developer laptops.
- Enable compliant AI adoption without slowing developers down.

Restrict AI agent access by default
- Coder's Agent Firewall enforces default-deny network policies, restricting which domains and HTTP methods agents can access.
- Admins define explicit allow lists in templates controlling access to registries, internal services, and external APIs.
- All policy decisions are logged and streamed to the control plane for centralized auditing.






