Request access
DocsSDK & ExamplesAPI Reference
Products / Governance

Gateway kill switch

Fail-closed controls for RaksHex-routed traffic, with durable PostgreSQL state and Redis propagation.

Workspace, identity, project and agent scoped kill-switch state can be evaluated before a RaksHex-routed provider request. The gateway reconciles low-latency Redis state with durable PostgreSQL state so a cache miss must not silently clear an active durable switch.

Budgets

Hard gateway budgets apply to traffic routed through the RaksHex gateway. monitor_only budgets are visibility/alerting and must not be described as blocks. provider_native enforcement is attempted only for provider capabilities that genuinely support it.

Critical boundary

A RaksHex gateway kill switch cannot truthfully be described as disabling direct provider traffic that bypasses RaksHex. Provider-side revocation/limits require a supported, authorised provider-native control.

Runtime authorization of consequential agent actions is the separate Agent Firewall path.