Doberman is an open-source runtime security layer that proxies AI coding agents and decides PASS, AUTH or BLOCK for each tool call.
- for
- Developers using AI coding agents who need runtime protection against rogue actions.
- pricing
- open source
- license
- Apache-2.0
- v0.18.7v0.18.7 — phone approvals and closed bypassesa month ago
- v0.18.6v0.18.6 — security hardening and UX overhaula month ago
- v0.18.5v0.18.5 — decision-log retention, update nudges, dashboard polisha month ago
Key features
- MCP proxy — Intercepts every tool call from an agent and normalizes it into a SecurityObject.
- Three-verdict engine — Deterministic core returns PASS, AUTH (human approval) or BLOCK before execution.
- Raise-only learning — Behavioral baselines can only tighten; weakening requires 2FA-gated approval.
- Mode dial — Four security postures (Light, Balanced, Strict, Paranoid) adjust thresholds and default verdicts.
- Tiered authentication — Local confirmation, TOTP 2FA, and time-limited role elevation for AUTH actions.
- Local audit log — Append-only, redacted log of decisions with reason codes and HMAC fingerprints.
- Extensible plugins — Custom detectors, auth providers, or audit sinks can be added via Python entry points.
- Fail-closed default — Any error, uncertainty or unknown case results in a BLOCK verdict.
Use cases
- Prevent an AI agent from executing destructive commands like `rm -rf ~`.
- Require human approval before an agent writes to sensitive paths such as authentication files.
- Block secret exfiltration by scanning tool arguments and outputs for leaked credentials.
Doberman vs alternatives
Doberman | Claude Code | OpenAI Codex | LangChain | CrewAI | |
|---|---|---|---|---|---|
| Best for | Adaptive authorization for AI coding agents | Agentic coding in the terminal | Code generation with OpenAI models | LLM app development | Multi-agent orchestration |
| Pricing | Open source | Subscription | Subscription | Free | Subscription |
| DevHunt upvotes | 3 | 0 | 0 | 0 | 0 |
| Launched | Sep 2026 | — | — | — | — |
- Doberman vs Claude Code: Claude Code provides an agentic coding environment but lacks a runtime security proxy that enforces PASS/AUTH/BLOCK on tool calls.
- Doberman vs OpenAI Codex: OpenAI Codex offers code generation and execution but does not include a deterministic guardrail layer like Doberman.
- Doberman vs LangChain: LangChain is a framework for building LLM apps; it does not provide a built-in, fail-closed security gate for agents.
- Doberman vs CrewAI: CrewAI orchestrates multiple agents but does not focus on runtime tool-call authorization and local audit logging.
Doberman FAQ
How does Doberman stop an AI coding agent from running dangerous commands?+
It sits between the agent and its tools, reads each call, and the policy engine returns PASS, AUTH or BLOCK; BLOCKed actions never reach the tool.
Which AI agents does it work with?+
Native hooks for Claude Code and Codex; any MCP-speaking client such as Cursor, OpenClaw, or custom agents can point to Doberman as a transparent proxy.
How is this different from built-in permission prompts?+
Built-in prompts only ask the agent; Doberman inspects the actual call (paths, secrets, destinations) and blocks or requires approval only when needed, passing routine work silently.
Is any code or data sent to the cloud?+
No. All policy evaluation, decision making and audit logging run locally on the developer’s machine.
What happens on errors or unknown situations?+
Doberman fails closed – unknown cases or internal errors default to a BLOCK verdict, with a reason code and explanation logged.
Summarized by DevHunt from trydoberman.dev · Oct 4, 2026. Details may change; check the official site.

Claude Code
OpenAI Codex
LangChain
CrewAI.png?width=64)






.png?width=64)



