Overview
Your gateway, active controls and recent traffic.
Connect your workspace
Connect your workspace to inspect the active configuration and manage policies.
Connect your identity
Use a management credential to view and change policies. Add an agent credential to send requests.
Set your policy
Describe a rule or configure controls directly. Review changes before activating them.
Verify a request
Send your own input through the gateway and inspect the decision in Activity.
Top denial reasons
Recent loaded activity onlyConnect a management identity to inspect recent denials.
Active controls
Policy —Connect a management identity to inspect active controls.
Configuration status
Configuration status is available after connecting a management identity.
Changes apply to new requests. Requests already in progress finish using their original policy version.
Resource usage
Per identity · UTC dayConnect a management identity to view resource usage.
Budgets and retained audit records are local to this process and reset when it restarts.
Policies
Define what can enter and leave your models and tools.
Active configuration
Source not loadedYour current rules and privacy settings will appear here.
Text analysis uses Laya to assess meaning and your written guidelines. Fast rules use exact local matches. Review every change before activation. Rule editors also test your samples; settings changes show an exact configuration diff.
Rules and privacy
Connect your management identity to view existing rules and edit them.
How configuration updates work
Changes made here are validated and saved to the configured policy source. You do not need to restart the gateway. Each activation increments the policy version.
If configuration comes from a remote source, this console is read-only. Publish a newer version at that source; the gateway validates it before switching. Invalid updates retain the last valid version.
Test requests
Send a real request through the active policy. See what was allowed, changed or blocked.
Request
Response privacy
Requires reversible anonymization, complete recovery tokens and restoration permission in every matched rule. Other controls still apply.
Requests use your active policy and consume configured budgets.
Decision
Your decision, policy version and returned content will appear here.
Input blocks prevent execution. Output blocks prevent delivery after the upstream has already run.
Documents
Extract text locally, apply your policy, then download protected Markdown or send it to a model.
Process a document
PNG · JPEG · PDFMulti-page PDFs are processed in page order. The original document is never sent to the model. This produces Markdown, not an edited image or PDF.
OCR setup
Install the local OCR runtime once in your project directory, then restart the gateway:
sh scripts/setup-ocr.sh uv run fastfence doctor --full
Protected output
Only content approved by the active policy is displayed here.
Activity
Inspect security decisions and configuration changes without storing request bodies.
| Time | Identity | Destination | Decision | Reason | Policy | Latency | |
|---|---|---|---|---|---|---|---|
| No activity loaded. | |||||||
Shows the latest 200 loaded events. Export includes the retained history. In-memory retention and resource counters reset when this gateway restarts.
Connection
Connect your identity, then route your application through this gateway.
Workspace access
Management credentials view activity and change policies. Agent credentials execute protected requests. Tokens stay in this tab's memory and are cleared on reload.
Where do I get credentials?
Start FastFence from your chosen working directory:
uv tool run fastfence
New installations store credentials in state/credentials.json. Existing installations retain their original credential file; startup prints its location. Never put these credentials in Git or share a management credential with an agent.
Gateway endpoints
Authenticate with your agent bearer token. Model IDs must be present in the policy allowlist.
Integration guide ↗Local runtime setup
Start the gateway with uv run fastfence serve. Use uv run fastfence doctor --full to check local Laya, Qwen and OCR prerequisites.
Policy changes activate without a restart. Changes to process settings, model-server addresses or installed integrations require restarting the gateway.
Update this installation
From the repository directory, stop the running gateway, update the checkout and dependencies, then verify and start it again. Keep your private state and review configuration changes.
git pull --ff-only uv sync --locked uv run fastfence doctor --full uv run fastfence serve