DVARA 1.8.0 is available.
An Open Source foundation for LLM traffic, enforced API scopes, clearer PII actions, safer streaming, and one governed path across models, MCP tools, and agent handoffs.
https://t.co/dz9XIwz5eo
@MajorOcelot45 Good to have a shared baseline. Worth pairing it with one thing: the benchmark checks how a server is configured, but the risk shows up at runtime. Logging every tool call, with who asked and what came back, is what proves the config actually held.
@thibauld@fairmint@tryramp For the API side (OpenRouter, Codex, Cursor on your own key): put one gateway in front, give each person their own key, and set budgets per team. That covers every model, not just OpenAI and Anthropic.
Seat plans like ChatGPT and Claude stay blind without Enterprise, sadly.
See which team, app and model drives your AI bill.
Every call is recorded against its workspace, model and provider. A soft threshold warns; a hard limit stops the next request before it goes out.
How do you track AI spend per team today?
@arunimastwt Nice, testing agents the way an attacker would is overdue. One request: tag each finding with the tool call and arguments that triggered it. That turns a failed test into a rule you can enforce at the call, and lets you re-run to prove the fix holds.
Personal data, handled before it reaches the model.
DVARA checks each request for the patterns you configure, then logs it, blocks the call, redacts the value or replaces it with a token. Every decision is recorded.
What happens today when a prompt contains customer data?
@PadraigOraghail@2whazzuup Fair reaction! The confusing part isn't the expired token, it's being told everything's fine while it isn't. Any luck since the fresh login, or is it still dropping?
@scottychain The workable answer is to not rely on the agent knowing the law. Put the rules outside it: every action it can take passes a check first, anything binding (filing, sending, signing) waits for an attorney's OK, and every decision is logged. Which steps would she want to approve?
@PadraigOraghail@2whazzuup That fits. If Cloudflare's own agent was also saying the token had expired, it's probably one shared login session timing out, so every Cloudflare MCP failed together while still showing "connected". One fresh login should reset them all. Hope tomorrow is smoother!
@PadraigOraghail@2whazzuup That pattern usually means the connection is up but the token behind it expired or lost a scope, so the client says "connected" while each tool call is denied. Revoking and re-granting access (not just reconnecting) often clears it. Have you seen it with one server or several?
Write your AI rules once. Every model call is checked against them.
An app asks for a model you haven't approved: the gateway stops it before it reaches the provider, says which model to use instead, and records the decision.
Which AI rule would you write first?
@_Creation22 This is the core gap. The fix taking shape: the agent gets its own identity and acts on your behalf, so the app sees both who asked and who acted. Until then, every log line says it was you, even when it wasn't.
@adbertram Good walkthrough. One gap worth adding: this covers what people paste into AI apps, but not the calls your own apps make to model APIs. Those need the same check on the server side, before the data reaches the model.
@goyalshaliniuk Great list. One thing we see in production: #9 (guardrails) and #10 (observability) work best in the same place, on the path every model and tool call takes. Then the rule that stopped an action and the record of what the agent did are one log.