Runtime Gateway for AI Agents. 17-phase security pipeline between agents and LLM APIs. Works with OpenClaw, Paperclip, Claude Code, Cursor. Open source, MIT license.
<p align="center"> <img src="docs/assets/banner.png" alt="Orchesis" width="100%"> </p> <p align="center"> <strong>See everything your AI agents do.</strong> </p> <p align="center"> Runtime Gateway for AI Agents — block threats, cut token waste, monitor your fleet. One config change. </p> <p align="center"> <a href="https://pypi.org/project/orchesis/"><img src="https://img.shields.io/pypi/v/orchesis?color=a855f7&style=flat-square" alt="PyPI"></a> <!-- UPDATE: test count on each release --> <a href="https://github.com/poushwell/orchesis/actions"><img src="https://img.shields.io/badge/tests-4%2C912%2B-22c55e?style=flat-square" alt="Tests"></a> <a href="https://github.com/poushwell/orchesis/blob/main/LICENSE"><img src="https://img.shields.io/badge/license-MIT-38bdf8?style=flat-square" alt="License"></a> <a href="https://www.python.org/"><img src="https://img.shields.io/badge/python-3.10%2B-fb923c?style=flat-square" alt="Python"></a> <a href="https://orchesis.ai/scan"><img src="https://img.shields.io/badge/MCP_checks-113-c084fc?style=flat-square" alt="MCP Checks"></a> </p> <p align="center"> <a href="https://orchesis.ai">Website</a> · <a href="https://github.com/poushwell/orchesis/blob/main/QUICK_START.md">Docs</a> · <a href="https://orchesis.ai/scan">MCP Scanner</a> · <a href="https://orchesis.ai/scorecard">Scorecard</a> · <a href="https://orchesis.ai/blog">Blog</a> </p> --- ## What is Orchesis? > Your AI agent made 122 API calls. Its built-in loop detector caught zero. Detection was ON. All thresholds configured. > ([Issue #34574](https://github.com/OpenClaw/OpenClaw/issues/34574)) Orchesis is an open-source HTTP proxy that sits between your AI agents and their LLM providers (OpenAI, Anthropic, Google, Mistral). One config change — set `base_url` to `localhost:8080` — and every request passes through a **17-phase security pipeline**. No SDK integration. No code changes. No vendor lock-in. - **Security** — Injection detection (96% explicit,
Agent that generates comprehensive documentation, API references, architecture diagrams, and developer onboarding guides from existing code.
Agent configuration for systematic bug investigation that traces issues from error logs through the codebase to root cause with suggested fixes.
Agent for integrating third-party APIs including SDK setup, type generation, error handling, retry logic, and rate limit management.
Cursor's built-in autonomous coding agent that can make multi-file edits, run terminal commands, search the codebase, and iteratively build features with minimal human intervention.
Cloud-based autonomous coding agent that runs in the background on remote sandboxed environments, handling complex multi-step tasks while you continue working.
Cursor's multi-file editing agent within Composer mode that can create, edit, and delete files across your entire project in a single conversation.