Skip to content

bot-marshal documentation

Start here if you are new; each page below stands on its own once you have.

  • Getting started — install it, write a minimal config, generate a CA, put a request through it. Fifteen minutes, no agent required.
  • Concepts — the model the rest of the documentation assumes: how a request travels from capture through identity, the policy chain, and transforms, and where default-deny actually lives.
I want to…Start here
Permit reads but refuse unwanted writesRequest rules
Use API keys without giving them to an agentSecret injection and provider examples
Capture a CLI login and renew tokensOAuth workflows and bootstrap walkthrough
Choose models and providers centrallyLLM routing
Restrict tools and their argumentsMCP tool controls
Detect credentials in outgoing requestsDLP scanning
Give each agent its own access and enforce routingIdentity and Linux containment
Use native decision models to judge or route requestsDecision APIs
Judge requests with an LLMAI judge
Investigate a decision or roll out a policy graduallyAudit log and warn mode
Set or filter request headersHeader transforms
Limit response bodiesResponse size limits
Check service health or reload policyManagement API and reload
Understand streaming and buffering costsStreaming
  • CLI — every subcommand and global flag.
  • Configuration — the config file, and how it splits across profiles/, bundles/ and transforms/ directories.
  • Capture — explicit proxy ingress, DNS resolver limitations and upstream checks.

  • Observability — logs, the audit trail, and what to watch.

  • Operations — the management API, hot reload, and rolling default-deny out with warn mode.

  • Production — running as a dedicated service user under systemd.

  • Troubleshooting — startup, trust, attribution, policy and OAuth failures.

  • Roadmap — what is built, what is deliberately not, and why.
  • Architecture decisions — why the design is the way it is: the constraints that forced each significant choice, and the alternatives rejected.