diff --git a/agent-network/README.md b/agent-network/README.md index f370d644d..457872f08 100644 --- a/agent-network/README.md +++ b/agent-network/README.md @@ -3,9 +3,9 @@ Agent Network is NetBird's access control layer for AI agents and the people who run them. It gives every agent a real identity, tied to an identity provider (IdP), and governs what it can reach: LLM APIs and AI gateways it can call, and the internal resources it can access. Traffic flows only over the encrypted NetBird tunnel, -scoped by policy, with no API keys or other credentials to leak. +scoped by policy, with no API keys or other credentials to leak. It also gives you control over cost and token usage. -It also gives you control over cost and token usage. Because every LLM request passes through an +Because every LLM request passes through an identity-aware proxy, you can: - **Set spending and rate limits** per agent, per user, or per team — with hard caps @@ -18,7 +18,7 @@ identity-aware proxy, you can: keeping its routing and config in place while it adds identity on top, so you skip API key distribution. -https://github.com/user-attachments/assets/f76d549f-6ea8-45a2-b069-380037aff36a +https://github.com/user-attachments/assets/44d18286-d8ab-49f8-a457-98ccd66f3268 > **Beta.** Agent Network is in beta, but it's stable and already running in > production environments. It's fully open source and can be self-hosted on your own @@ -26,6 +26,17 @@ https://github.com/user-attachments/assets/f76d549f-6ea8-45a2-b069-380037aff36a ## How it works +Say you have a simple use case: your Engineering or IT team needs access to Claude Code or Codex, and you want visibility into usage plus the ability to enforce budgets. +How can you do that without creating a dedicated API key for every team? + +With Agent Network you get a private endpoint inside your network, for example: https://mirror.netbird.ai +Teams configure their agents to point to that endpoint instead of using individual API keys directly. + +This endpoint is only reachable when users are connected to your NetBird network and authenticated through your IdP. Otherwise, it is not accessible from the public internet. +You can then use this private endpoint to configure your AI agents, whether that is Claude Code, Codex, or another tool. + +## Architecture + Agent Network is built on two existing NetBird capabilities: - **Overlay network** — the encrypted WireGuard mesh between peers. @@ -37,6 +48,9 @@ LLM traffic is routed through the proxy's identity-aware pipeline, while interna resources (databases, internal APIs, self-hosted models) are reached directly over peer-to-peer WireGuard tunnels, governed by the same identities and access policies. +image + + ## Where the code lives There is no separate "agent-network" service — it reuses the reverse-proxy and management