An AI gateway often holds more authority than the application calling it. It may possess provider credentials, reach internal networks and invoke tools. The useful procurement question is whether an ordinary caller can use any of that authority outside its approved purpose.

Start with an interface inventory. List the inference API, dashboard, management API, tool registration, model configuration and health endpoints. Record which identity may reach each one, which permissions it carries and where those permissions are checked. Network placement and application authorisation support each other; neither replaces the other.

Separate application access from administration

The Bifrost management-API case illustrates why tool registration and native-plugin loading belong to an administrative boundary. Its advisories depend on reachable management APIs with authentication disabled, and the remote-plugin outcome differs between dynamic builds and static Docker images.

The GitLab template case has a different prerequisite: an authenticated Duo Agent Platform user submits a crafted flow template. Treat workflow authoring as a capability with execution consequences. Ask which secrets, filesystem paths and outbound services the runtime can access.

A useful demonstration starts with an ordinary application's credential. It should show successful approved inference and rejection of route changes, credential reads, tool installation and administrative exports. Keep the identity and endpoint list with the result.

Follow the request to its real destination

A provider label is not an outbound firewall. Headers, base URLs, redirects, DNS and fallback can change where the request goes. In the Portkey custom-host case, the scope is the open-source gateway and custom-host routing; it does not establish exposure in every managed service.

Document an approved destination set and the point where it is enforced. Decide what happens when a host resolves to a private address, a redirect changes the destination or the approved provider becomes unavailable. The fallback should satisfy the same disclosure and network policy as the original route.

Preserve the meaning of a tool request

The Envoy MCP parsing case concerns different interpretations of the same protocol message. A policy decision is useful only when it describes the action the destination will actually execute.

Ask how ambiguous fields, unsupported content parts and malformed tool arguments are handled. A successful demonstration should connect the parsed request, policy result and forwarded message through a shared request identifier. Rejection behaviour matters alongside compatibility with valid clients.

Technical detail: release and configuration evidence

The agentgateway namespace case requires both the patched release and AGW_BACKEND_REF_GRANT_MODE=route-and-policy. The vendor describes control-plane authoring permissions, not an unauthenticated internet attack. Record the installed version, effective environment, route and policy reference grants, and the administrative role used for the check.

An endpoint matrix should distinguish unauthenticated rejection, authenticated-but-forbidden access and permitted operations. Avoid publishing credentials or exploit payloads as evidence. Preserve enough configuration context for an operator to repeat the relevant check safely.

Questions for your evaluation

Use the security page of the evaluation worksheet. Assign an owner to each boundary and attach the installed version, permission matrix, outbound policy and focused regression result. A feature name or certification logo does not establish the behaviour of your particular route.

Applying this to OneVir

OneVir documents application keys, model grants and policy controls. Our implementation evidence record identifies the credential-normalisation test in src/api/mod.rs: conflicting credentials are rejected and supported credential forms are normalised. That is evidence for a specific parser behaviour, not a complete authentication audit.

For an evaluation, request the installed release, enabled application-key scopes and an endpoint access demonstration. A gateway credential parser does not establish the safety of a separately deployed inference engine, plugin or tool runtime.