Rhys Sullivan watched AI agents multiply across the enterprise landscape, each one theoretically capable of calling thousands of tools, and noticed something missing: hardly any of them could do so safely. His answer arrived this month in the form of Executor, an open-source gateway that attempts to untangle one of the messier problems in AI infrastructure—how to let agents act without handing them the keys to everything.
The product consolidates Model Context Protocol servers, OpenAPI specifications, and GraphQL endpoints into a unified catalog, then layers on shared authentication and granular permissions. Sullivan's company argues that the real bottleneck isn't capability but control. Thousands of integrations exist; production-grade access policies do not.
"MCP shipped before anyone knew how to wire tools to agents, and it caught the blame for it," Sullivan wrote in a blog post published in late June. The observation cuts to a broader tension: the Model Context Protocol, which Anthropic introduced to standardize how AI systems access external data and actions, arrived with technical elegance but little guidance on securing the connections it enabled. Executor's pitch is straightforward—move credentials and approval workflows to the gateway itself, where neither the language model nor the downstream agent ever handles raw tokens.
Architecture Built on Distrust
The mechanics reflect that philosophy. Developers register integrations (MCP servers, OpenAPI files, GraphQL schemas), attach OAuth flows or API keys, then assign policies at the individual tool level: always permitted, gated behind human approval, or blocked outright. Agents see only a single MCP endpoint. When a tool call arrives, Executor injects the necessary credentials on the fly and runs the code inside a QuickJS sandbox.
The gateway preserves semantic hints embedded in the protocols it translates. HTTP verbs matter; a DELETE carries different implications than a GET. MCP's destructive flags and GraphQL mutations trigger approval pathways automatically, a design choice that suggests the founders have debugged enough runaway agent behaviors to know where guardrails belong.
There's also a claim about efficiency. Instead of bloating prompts with metadata for hundreds or thousands of tools, Executor exposes a single "execute" function that discovers others on demand. The company offers a comparison: a hypothetical catalog of 1,640 tools consuming roughly 278,800 tokens versus Executor's streamlined interface at approximately 1,044 tokens. The math is appealing, though the underlying model and tokenizer that produced those figures remain unspecified.
Deployment Reflects Developer Realities

Executor ships in forms that suggest the team understands where developers actually work. There's a local command-line tool requiring Node.js 20 or later, desktop apps for macOS, Windows, and Linux, a self-contained Docker image running atop SQLite (via libSQL), and a Cloudflare Worker variant backed by D1 storage. The Docker package bundles API, MCP server, authentication, code execution, and a web console into a single container with no external dependencies—a choice that signals impatience with complex orchestration.
The Cloudflare deployment leans into that platform's access-control primitives and supports either managed OAuth or service tokens for MCP clients, according to documentation reviewed recently.
Pricing follows a familiar SaaS progression. The free tier accommodates up to three team members and 10,000 monthly executions with unlimited integrations. A $150-per-month Team plan raises the ceiling to 250,000 executions, adds unlimited seats, and extends execution timeouts to five minutes. Enterprise contracts unlock SSO, SAML, SCIM provisioning, audit trails for every tool invocation, and deployment assistance at negotiated rates. Overage across all tiers runs $0.20 per 1,000 additional executions.
The codebase carries an MIT license and lives on GitHub under UsefulSoftwareCo/executor, where it had accumulated approximately 3,000 stars as of early checks. Recent activity includes version 1.5.40, tagged in early August, with a steady drumbeat of releases throughout the summer.
A Crowded Field Gets More Crowded

Executor enters a gateway landscape that has filled quickly. Composio runs a managed MCP gateway anchored by a broad connector library. Permit.io announced an authorization-focused gateway earlier this year, threading fine-grained permissions into the MCP layer. AWS debuted AgentCore Gateway in mid-year with OAuth delegation flows, access controls, and observability hooks tailored for Bedrock agents. Open Connector offers a self-hosted alternative under the AGPL-3.0 license, emphasizing OAuth support and deployment flexibility.
Sullivan demonstrated an early version of Executor at a WorkOS MCP Night event in late May, a gathering that has become something of a regular checkpoint for developers building in this domain. The company lists a San Francisco address on Market Street in its terms of service, though the operational footprint of an infrastructure startup at this stage likely extends as far as its contributors' laptops.
What remains uncertain is whether enterprises struggling to govern AI agents will adopt yet another gateway, or whether consolidation will favor platforms that bundle security alongside the agents themselves. Sullivan's bet appears to be that developers, given tooling that finally makes credential hygiene straightforward, will choose to build rather than wait for vendors to catch up. The early GitHub traction suggests at least some validation, though stars and production deployments occupy different universes.
