Platform API · MCP
Operate the AI you secure
Burgus is controlled programmatically on your deployment — operator MCP and REST for keys, access, policies, alerts, and audit exports. Built for platform teams, CI, and automation.
Operator MCP
Configure your MCP client with a burgus_* API key issued on your deployment
(Authorization: Bearer burgus_…). Automate key management, pull audit events, run policy workflows,
and generate combined multi-agent security reports.
REST API
The same capabilities are available via REST on your deployment — suitable for CI/CD pipelines, internal tooling, and SIEM/GRC integrations.
Dual data plane — one control plane
Production traffic runs on securellm (LLM) and mcpdata (MCP sources) hostnames on your deployment. The operator API manages keys, access, policy, and reports for both planes. Both feed the same audit and alert pipelines — integration guide.
Typical workflow
- Deploy Burgus in your environment
- Create a
burgus_*operator API key - Register upstream LLM keys and copy
base_urlhostnames - Activate MCP sources, register client credentials, set Access policies
- Route production agent traffic through assigned hostnames
- Configure blocking policies and review blocks, alerts, and exports via operator MCP or REST
What the operator API covers
- Tenant & keys — profile, Burgus API keys, upstream keys, secure endpoints
- Access — MCP credentials, connection access config, agent/workflow allowlists
- Policies & alerts — content policy, delivery settings, platform and behavioral reports
- Audit — events, sessions, workflows, multi-agent graphs, export bundles
Full reference: llms-full.txt