Works with what you already run.
Every connection is read-only unless you ask for more, and each one changes what NoFly can tell you. This page explains what each one does, and lists only what ships.
Every connector does one of three jobs.

J1It adds a fact
Something NoFly could not see alone: who owns an agent, whose bucket a command touched, whether a person still works here.
J2It supplies the denominator
The “out of how many” behind every percentage. Without a fleet or network count, zero findings says nothing.
J3It opens a door outward
A ticket, an approval in chat, an event in the SIEM, a pull request with the fix.
One command, four connectors deep
With nothing connected the gate still decides, it just decides with less, and says which questions it could not answer.
The pieces that put NoFly in the path.
Connectors tell NoFly what exists. These are the parts that sit between an agent and what it touches, so a decision can happen before the action does.
P1Hooks inside coding agents
Claude Code, Cursor, Windsurf, Gemini CLI, Codex CLI, Copilot CLI and Cline
One command puts the gate inside each coding agent on a machine. Shell commands and tool calls are sent to it before they run, and the agent is told the decision and the reason.
- Critical moves refused on the machine, even offline
- Risky ones held for a person
- A selftest proves each hook is really in the path
- Prompts screened before they are sent, in Claude Code and Cursor
npx @shomra/agent protectOpen source · No account neededP2MCP shim
Local MCP servers in Claude Code, Cursor, Windsurf and Gemini CLI
Wraps each local MCP server so it starts through NoFly. Tool calls are checked before they reach the server, and results are screened before the model sees them.
- Poisoned or denied tools removed from the tool list
- Runs fully local, or asks your policy when enrolled
- One command to wrap, one to undo
shomra mcp guardOpen source · No account neededP3MCP gateway
Any MCP client: Claude Code, Cursor, Windsurf, VS Code and more
Gives each agent one endpoint for every MCP server it is allowed to use. Tool lists, calls and results are screened in one place, and the agent signs in with its own credential.
- Poisoned tool descriptions withheld and recorded
- Server credentials kept by the gateway, never by the agent
- Denied, revoked or quarantined servers refused
PlatformP4Model proxy
Apps and agents that call model providers directly
A local proxy for nine model providers applies the same rules to model traffic with no code changes, and covers tools such as Aider that have no hooks.
- Model calls screened for injection, secrets and personal data
- Covers agents with no hook, such as Aider
- Budgets that refuse the call over the limit
PlatformP5Gateway plugins
Kong, Envoy with Istio and Gloo, Traefik, LiteLLM, Portkey, Cloudflare Workers, Azure API Management and AWS API Gateway
Adds NoFly to the API gateway you already run. Prompts and completions are screened and blocked there, and tool calls inside model traffic are withheld when policy says so.
- APISIX and NGINX block prompts and record completions
- An agentgateway plugin screens MCP tool calls and lists
- Fail-closed available where you need it
CustomersP6SDKs for the agents you build
TypeScript and Python, with adapters for OpenAI, Anthropic, OpenAI Agents, MCP, LangGraph, LangChain, Vercel AI SDK, LlamaIndex, CrewAI, AutoGen, Semantic Kernel, Pydantic AI and Google ADK
Puts the same gate inside your own code. Screen prompts and completions, check a tool call before it runs, screen tool results and retrieved documents, and verify hand-offs between agents.
- guard(), checkToolCall(), screenToolResult() and handoff()
- A tool call can be held for a person
- Zero dependencies in either language
- Runs you never instrumented joined in from Langfuse, Helicone or OpenTelemetry traces
npm install @shomra/sdk · pip install shomraCustomersP7IDE extension
VS Code and Cursor
Checks AI config files as you open and save them, such as MCP configs, skills, CLAUDE.md, AGENTS.md and rules files, and shows each finding on the line that causes it.
- Flags known-vulnerable models loaded in Python, notebooks and JavaScript
- Gate status in the status bar
- Explain a finding, or harden a model load, in one step
No account neededP8Browser extension
Chrome, on ChatGPT, Claude, Gemini, Copilot and other AI sites
Screens prompts before they leave the browser, shows which account is used on each AI site, and lists the extensions installed alongside it.
- Observe, warn or enforce
- Personal and company accounts told apart
- Feeds shadow AI in Discover
Customers
The CLI, hooks and MCP shim are open source under Apache-2.0 and run with no account. The SDKs, gateway plugins and browser extension are available to customers. Streamed completions are screened on LiteLLM and Portkey; on other gateways they pass unscreened.
What each connection adds.
C1Identity providers
A read-only app registration with directory permissions
Your directory tells NoFly who people are, which non-human identities exist and which AI apps people granted access to. Service principals become agent identities, groups decide who may use an agent, and departed people are told apart from current ones.
- Service principals seeded into the agent registry, monitored before they are enforced
- AI apps people consented to with their work account, and the option to revoke them
- Agents sign in without stored keys, using tokens from your identity provider or CI
- SAML single sign-on and SCIM for your own team
- Microsoft Entra ID
- Okta
- Google Workspace
- OneLogin
- Keycloak
- Slack workspace
C2Endpoints and device management
Read-only API credentials for your EDR and MDM
Your EDR already records which programs run on every laptop. NoFly searches that telemetry for AI tools and configs, so it finds coding agents and MCP servers on machines it was never installed on. MDM gives the true size of the fleet, and can push the scan on a schedule.
- AI found on machines without installing anything
- The real number of machines behind every percentage
- Scheduled scans rolled out through MDM
- CrowdStrike Falcon
- Microsoft Defender
- SentinelOne
- Intune
- Jamf
- Kandji
C3Network and proxies
Log exports or API access from your secure web gateway
Your proxy sees which AI services are reached and by whom. NoFly turns that into shadow AI by vendor and person, and checks whether the proxy’s own AI policy actually blocks or only watches.
- Shadow AI by vendor, person and account type
- The traffic denominator behind every count
- Your proxy graded on the Control Ledger
- Netskope
- Zscaler
- Chrome, Edge, Brave, Firefox
C4Hosted agent platforms
An admin connection, plus callbacks where the platform supports them
Agents built in business tools are imported by name as governed identities, starting in monitor mode so nothing breaks. Where the platform allows it, each tool call is sent to NoFly before it runs.
- Every console-built agent in one registry
- Inline blocking on Copilot Studio, Agentforce, Bedrock Agents, Azure AI Foundry and n8n
- After-the-fact or log-based monitoring for the rest, labelled as such
- Copilot Studio
- Agentforce
- Bedrock Agents
- Azure AI Foundry
- n8n
- Microsoft 365 Copilot
- Glean
- Make
- Gemini for Workspace
- ServiceNow Now Assist
C5Cloud and AI providers
Read-only keys or roles, never write access
Model endpoints, deployed agents and AI keys land in the inventory with what each key can reach. When an agent runs a cloud command, NoFly can tell whether the account is yours, somebody else’s, or unknown.
- Models, endpoints and keys with their real reach
- Every cloud command an agent runs tied to an account
- Served models and registries from your ML platforms
- AWS
- Google Cloud
- Azure
- OpenAI
- Anthropic
- Amazon Bedrock
- Azure OpenAI
- Hugging Face
- Databricks
- SageMaker
- Vertex AI
- MLflow
- Snowflake
C6Secrets managers
A read-only connection that lists secret names
Knowing which values are real secrets lets NoFly follow them from where an agent read them to where it tried to send them. The credential broker can also hand agents short-lived access instead of long-lived keys.
- Real secrets tracked as they move through a run
- Short-lived, scoped credentials at the moment of use
- Keys found on laptops matched to what they open
- HashiCorp Vault
- Azure Key Vault
- Doppler
C7Code hosts and CI
A GitHub App, a token, or the GitHub Action
Repositories become a scan source for agent configs, skills, MCP servers and model files. A proposed fix becomes a pull request in one click, and the build gate refuses a dangerous change before it merges.
- Risky AI config caught in the pull request
- Fixes opened as pull requests and re-checked
- Builds failed when an agent regresses under attack
- GitHub
- GitHub Actions
- GitLab
- Bitbucket
- Gitea
- Azure DevOps
- Jenkins
- CircleCI
C8Ticketing
OAuth or an API token for your tracker
A finding becomes a ticket with its evidence attached, and the ticket stays linked to the finding in both directions. Work is never routed to someone who has left.
- Two-way sync between findings and tickets
- Owners resolved from the inventory
- Closed tickets re-checked before the finding closes
- Jira
- ServiceNow
- Linear
- Asana
- Trello
- ClickUp
- monday.com
C9Chat, paging and SIEM
A chat app, a webhook, or your SIEM’s collector
Approvals and alerts go where people already are, and every decision ships to the system your security team already watches.
- Approve or deny held actions from Slack or Teams
- Pages for the things that cannot wait
- Every event in Splunk, Datadog or Microsoft Sentinel
- Slack
- Microsoft Teams
- Discord
- PagerDuty
- Splunk
- Datadog
- Microsoft Sentinel
- Email and webhooks
Don’t see yours?
Most integrations take a read-only key and a few minutes. Tell us what you run and we will tell you honestly whether it is covered.