# Run SealGate in Your Centaur Pod | Sealgate

Install the SealGate CLI (sealg) in a Centaur pod with one paste and let the coding agent list and call every governed tool through the gateway, honoring the pod proxy, with policy enforced on the server.

Source: https://sealgate.ai/centaur

---

[Docs](https://sealgate.ai/docs/) [Product](https://sealgate.ai/product)

AI Data Leaks

[Guides](https://sealgate.ai/guides/) [Blog](https://sealgate.ai/blog/) [Pricing](https://sealgate.ai/pricing) [Try for Free](https://dashboard.sealgate.ai) Get Demo

Agent-native

# Give your Centaur agent governed access to every tool

One paste installs the SealGate CLI inside your Centaur pod and points it at your gateway, so the agent can list and call every tool your org has enabled, through the pod's proxy, with SealGate checking each call on the server.

Paste this to the agent in your Centaur pod (Claude Code, Cursor, Codex, and others) and it will set everything up. Or run the steps yourself in the pod shell.

Install the SealGate CLI (sealg) in my Centaur pod and connect it to my gateway.

1. Download the latest sealg release for this pod's OS and CPU from https://github.com/Edison-Watch/cli/releases/latest and put it on my PATH. If Rust is available, "cargo install --git https://github.com/Edison-Watch/cli sealg" also works.
2. Set SEALGATE_URL=https://mcp.sealgate.ai and SEALGATE_API_KEY to the key I give you (I generate it at https://dashboard.sealgate.ai).
3. If any of my tools use encrypted secrets, also set SEALGATE_SECRET_KEY to the secret key I generate at https://dashboard.sealgate.ai/dashboard/settings. Skip this if none of them do.
4. sealg reads the proxy CA from SSL_CERT_FILE, REQUESTS_CA_BUNDLE, or NODE_EXTRA_CA_CERTS, which Centaur already sets. If a call fails TLS verification, point SSL_CERT_FILE at the pod's CA bundle.
5. Run "sealg doctor" to check the connection, then "sealg list" to see the tools my org has authorized, then call any of them, for example "sealg call builtin_whoami".

Every call is checked by SealGate on the server. Source: https://github.com/Edison-Watch/cli

Copy

Runs inside any Centaur pod. Needs a SealGate API key, plus a secret key only if your tools hold encrypted credentials. Both come from dashboard.sealgate.ai.

## Why route your agent through SealGate

One paste sets it up inside the pod, every tool sits behind one command, policy is enforced server-side, and it honors Centaur's proxy and CA out of the box.
- One paste in the pod Hand the prompt to the agent running in Centaur and it installs sealg and sets the gateway environment. There are no config files to edit and no fork to maintain.
- Every tool behind one command sealg list shows every MCP server your org has enabled, aggregated behind the gateway, and sealg call runs any of them from inside the pod.
- Policy stays on the server sealg carries no rules. Access levels, lethal-trifecta blocking, and the audit trail are enforced by the gateway, so the same policy applies whichever interface makes the call.
- Built for the proxied pod One static binary, configured from the environment. It honors Centaur's egress proxy and CA out of the box, and an upstream proxy can inject the API key so the raw key never lands in the sandbox.

## Connect a specific app

Want your agent to reach messaging apps like WhatsApp, iMessage, and Telegram instead? Set those up from the [connections hub](https://sealgate.ai/connect) .

## sealg and coding agents: FAQ

What is sealg? The SealGate command-line interface. It is a thin MCP client that forwards tools/list and tools/call to your per-user gateway endpoint, where SealGate applies access policy and records the session. It holds no policy of its own.

Why run it in a Centaur pod? Centaur pods run coding agents behind a forced egress proxy. sealg is a single static binary that honors that proxy and its CA, so the agent reaches every governed tool through one gateway without any pod-specific build.

Do I configure policy in the CLI? No. Access-control levels, lethal-trifecta blocking, and audit logging live in the gateway. The CLI only carries the call, so the rules an admin sets apply the same way across every interface.

Where does my API key live? Only in the pod environment, as SEALGATE_API_KEY. The binary is stateless and reads it at startup, writing nothing to disk. In Centaur an upstream proxy can inject the credential so the raw key never enters the sandbox.

When do I need a secret key? Only if your tools hold encrypted user or org credentials. Generate SEALGATE_SECRET_KEY from Settings at dashboard.sealgate.ai and set it in the pod. Leave it unset when none of your tools need to decrypt stored secrets.

Is it open source? Yes. sealg ships from the public Edison-Watch/cli repository, so you can read exactly what the client does before you run it.

Read the [open-source CLI](https://github.com/Edison-Watch/cli) or the [documentation](https://docs.sealgate.ai) , or email [hello@sealgate.ai](mailto:hello@sealgate.ai) .

### Contact Us

Sealgate (GPU-EVM LTD)

3rd Floor, 86-90 Paul Street

London EC2A 4NE

Email: hello@sealgate.ai

### Legal

[Terms of Service](https://sealgate.ai/terms-of-service) [Privacy Policy](https://sealgate.ai/privacy-policy) [Subprocessors](https://sealgate.ai/subprocessors) [Data Processing Addendum](https://sealgate.ai/dpa)

### Quick Links

[Home](https://sealgate.ai/) [Product](https://sealgate.ai/product) [Pricing](https://sealgate.ai/pricing) [Self-hosting](https://sealgate.ai/self-hosting) [Security](https://sealgate.ai/security) [About](https://sealgate.ai/about) [Contact](https://sealgate.ai/contact) [Brand](https://sealgate.ai/brand) [Press](https://sealgate.ai/press) [Docs](https://sealgate.ai/docs/) [Guides](https://sealgate.ai/guides/) [Blog](https://sealgate.ai/blog/)

### Connect

[Connect AI to messaging](https://sealgate.ai/connect) [WhatsApp](https://sealgate.ai/connect/whatsapp) [iMessage](https://sealgate.ai/connect/imessage) [Telegram](https://sealgate.ai/connect/telegram) [LinkedIn DMs](https://sealgate.ai/connect/linkedin) [Signal](https://sealgate.ai/connect/signal) [Instagram DMs](https://sealgate.ai/connect/instagram) [Messenger](https://sealgate.ai/connect/messenger) [X DMs](https://sealgate.ai/connect/x) [Discord DMs](https://sealgate.ai/connect/discord) [LINE](https://sealgate.ai/connect/line) [Beeper](https://sealgate.ai/beeper)

### Follow Us
