Secure, govern, and run APIs, MCPs, and IDE-driven AI agents.
AI Agents → SuperContracts MCP Gateway → APIs & MCPs
Cursor/Claude Code/Copilot → IDE Hooks + Runtime Enforcement → Terminal Actions
Gateway · Policy · Guardrails · Approval · Execution · Evidence
Let agents act autonomously — without giving them unrestricted power.
An MCP Gateway with executable SuperContract guardrails for APIs and MCPs. Secure Cursor, Claude Code, and production AI agents with policy-driven execution, runtime enforcement, approvals, webhooks, and MCP triggers.
IDE Hooks and eBPF Runtime monitoring .
Deterministic Guardrails · Policy driven Human-in-the Loop · Auditability
One executable contract. One source of truth.
Define, test, execute, document, and debug APIs and MCPs without switching between OpenAPI, Swagger, Postman, scripts, and logs.
Debug chained API and MCP workflows end-to-end from one place.
Get answers from APIs without becoming an API engineer.
An AI-powered Request Studio for REST, GraphQL, and MCPs. Ask questions, get answers, and act on APIs — without writing code.

MCP Gateway with Guardrails to govern insecure MCP actions
Cursor™ and Claude Code™ can route MCP actions through the apiLabs.ai Super Contracts MCP Gateway, where policy-driven guardrails govern what agents are allowed to do—for example, controlling Stripe™ refunds, protecting PII in Supabase™, and enforcing PR-only changes to GitHub™ main.
MCP Gateway policy controls what refunds an AI agent can execute in Stripe™.
Secure Cursor™ and Claude Code™ at the point of action. Intercept agent-initiated terminal commands with hooks and enforce deterministic ALLOW, DENY, or Human Approval guardrails before execution. Govern high-risk actions across git, curl, ssh, kubectl, terraform, cloud CLIs, package installs, credentials, and sensitive files—while preserving a complete audit trail of what the agent attempted and why it was allowed or blocked.
Cursor™ Pre-Shell Hook Guardrails in Action
Pre-shell hook intercepts agent git commands in Cursor™ and enforces PR-only guardrails.
See what AI agents actually do in the terminal — and turn that activity into actionable security findings.
Capture terminal activity through Cursor™ IDE post-shell hooks or an eBPF-monitored runtime environment. Observe commands, processes, network connections, file access, and child-process behavior, including actions hidden behind Python, SDKs, scripts, or other tools.
Automatically identify risky behavior such as credential exposure, sensitive file access, unauthorized network connections, dangerous commands, unexpected processes, and policy bypass attempts.
Turn observations into prioritized findings with severity, agent and session attribution, evidence, affected resources, and remediation guidance.
Post-shell observations → Security findings
Kernel-level observations → Security findings → Enforcement
Cursor™ Post-Shell Observability & Findings in Action
The Cursor™ IDE plugin captures post-shell observations of agent-initiated commands, processes, files, and network calls.
SuperContracts are YAML-based executable guardrails inside the apilabs.ai platform.
Use them for Agentic Security guardrails, multi-step API & MCP testing, agentic skills, approvals, workflow execution, and runtime evidence.
SuperContracts combines APIs, MCPs, tests, workflows, skills, guardrails, approvals, and execution into one executable contract—directly from Cursor™ or Claude Code™.
Build. Test. Govern. Run.
Securely connect localhost, VPC, and private APIs through ngrok™ or Cloudflare Tunnel™—without staging deployments or manual proxy setup.
Cursor™ / Claude Code™ → SuperContracts MCP Gateway → APIs & MCPs
One executable contract. Multiple use cases. One control layer.
SuperContracts DSL Contract Spec (YAML) — Define API workflows, MCP actions, guardrails, approvals, tests, and runtime policies in a single executable YAML contract.
Explore the public SuperContracts GitHub repository for YAML code samples, example contracts, and implementation patterns:
apilabs.ai SuperContracts on GitHub
Watch demos and walkthroughs in the:
SuperContracts YouTube Playlist
API Contract Testing DSL — apilabs.ai Super Contracts
AI-powered API studio to build, test, and call REST, GraphQL, and MCP endpoints
Watch how our AI-powered studio makes API and MCP endpoint testing effortless

| The Problem | How does apilabs.ai solve? | |
|---|---|---|
| Security Teams | Uncontrolled, non-deterministic agent actions across IDEs, terminals, MCPs, and APIs. | Agentic Security — MCP Gateway + SuperContracts guardrails, IDE hooks, eBPF runtime enforcement, approvals, and audit trails. |
| Developers | Context switching across OpenAPI, Swagger, Postman™, scripts, dashboards, and logs. | One executable SuperContracts DSL — build, test, execute, document, debug, and govern APIs and MCPs from Cursor™ / Claude Code™. |
| Business Teams | Dependence on engineering for API workflows, data, and SaaS answers. | AI Chat Core and Request Studio — ask, run, and act on APIs & MCPs using natural language. |
One control layer to secure, govern, and run APIs, MCPs, and IDE-driven AI agents.
| Traditional approach | API Labs |
|---|---|
| OpenAPI / Swagger for definition | Executable SuperContracts (YAML DSL) |
| Postman™ for testing | Built-in Request Studio + execution & testing |
| MCP server for connectivity | MCP Gateway + policy-driven guardrails |
| IAM / static RBAC for access | Runtime policy & action controls |
| Separate approval systems | Deterministic ALLOW / DENY / Human Approval |
| Scripts for API / MCP chaining | Visual / API / MCP workflows + Agents |
| Logs scattered across systems | Execution Evidence & audit trails |
| Agent framework-specific security | Works across Cursor™, Claude Code™, Copilot, and production agents |
| Manual localhost / private API setup | Dev Mode with ngrok™ / Cloudflare Tunnel™ |
Build, Govern, and Run Agentic Workflows
Start Anywhere. Everything Connects.
Secure AI agent actions across MCP gateways, IDEs, terminals, and runtime environments. Apply deterministic controls, monitor agent behavior, surface findings, and enforce guardrails before high-risk actions reach APIs, infrastructure, credentials, or sensitive systems.
Define reusable API and MCP behavior in YAML using executable contracts, skills, policies, tests, and guardrails. SuperContracts gives developers and AI agents a shared way to understand what actions are allowed, how they should execute, and when approval is required.
Ask questions about APIs, workflows, and datasets using natural language. Chat helps explore data, invoke approved actions, inspect responses, troubleshoot issues, and interact with connected services without switching between multiple tools.
Build, test, and troubleshoot API requests in an interactive workspace similar to Postman™. Configure authentication, headers, parameters, and payloads, inspect responses, and turn successful requests into reusable workflows or SuperContracts.
Organize and navigate generated content, files, folders, outputs, and other workspace artifacts in one place. Explorer gives users a persistent view of what agents and workflows create, making it easier to find, reuse, and manage results.
Turn API data into usable insights. Pipeline syncs and prepares data from APIs and connected systems, Analytics enables analysis using SQL, Pandas, and AI-assisted queries, and Charts transforms results into visualizations that are easier to understand and share.
Automate multi-step workflows across APIs, MCP tools, agents, data, and approvals. Similar to Zapier™ or n8n™, Agents connects triggers, actions, conditions, and human approvals while keeping execution governed and auditable.
Everything you need to know about the apilabs.ai One Control Layer
Disclaimer: Claude™ is a trademark of Anthropic, PBC. Zapier™ is a trademark of Zapier, Inc. n8n™ is a trademark of n8n GmbH. Postman™ is a trademark of Postman, Inc. Google™, Google Ads™, and Google Drive™ are trademarks of Google LLC. Stripe™ is a trademark of Stripe, Inc. HubSpot™ is a trademark of HubSpot, Inc. Salesforce™ is a trademark of Salesforce, Inc. Shopify™ is a trademark of Shopify Inc. Slack™ is a trademark of Salesforce, Inc. Snowflake™ is a trademark of Snowflake Inc. apilabs.ai is not affiliated with, endorsed by, or sponsored by any of these companies. All trademarks are the property of their respective owners.