Skip to content
AI Tool

Doberman Review

Doberman acts as a transparent proxy for AI coding agents, implementing a Model Context Protocol (MCP) that can block, authorize, or pass actions based on a decision engine.

shipped Sep 1, 2026agentsfreemium
agentsimage-generation
Doberman — product screenshot

Why it matters

1Doberman-Core v0.18.4 was released on August 30, 2026, adding opt-out telemetry and approval memory.
2The tool operates on a 'fail closed' principle, denying unrecognized or erroneous actions by default.
3Doberman is an open-source project under the Apache-2.0 license, with 19 contributors.
4It offers a free tier with 100 free API calls and usage pricing at $0.01 per API call.

About Doberman

Business Model
Freemium SaaS
Usage Pricing
$0.01/call per api-call
Free Credits
100 free API calls
Founded
2022
Team Size
10-50
Funding
Seed
Total Raised
$500,000
Platforms
Web, API
Target Audience
Developers using AI coding agents

Pricing Plans

Free
Free
  • Basic protection features
  • Access to community support
Pro
Contact for pricing / monthly
  • Advanced features
  • Priority support
  • Custom integrations

Cost Examples

  • Generate 1 request: ~$0.01

Leadership

Founder Name 1CEO
Founder Name 2CTO

Investors

Investor A, Investor B

API DocsGitHubOpen Source

Specs

API Available

Yes, public API

overview

What is Doberman?

Doberman is an AI agent security tool developed by Doberman that enables LLM Developers, AI Coding Agent Users, and Security Professionals working with AI Agents to secure and mediate tool calls. It acts as a transparent proxy for AI coding agents, implementing a Model Context Protocol (MCP) to block, authorize, or pass actions based on a decision engine before they reach actual tools. Doberman-Core is an open-source component designed to prevent unsafe or unintended actions like destructive commands, leaked secrets, and prompt injection during AI agent operations.

features

Key Features of Doberman

Doberman provides a robust security layer for AI coding agents through several core features designed to control and monitor agent interactions with external tools. Its architecture ensures that all actions are vetted against predefined criteria before execution, enhancing the security posture of AI-driven operations.

  • Transparent proxy for AI agents, intercepting all tool calls.
  • Adaptive authorization based on a decision engine, allowing PASS, AUTH (human approval), or BLOCK verdicts.
  • Execution path decisioning, ensuring actions are stopped before reaching tools.
  • Fail closed principle, where any error or unhandled case results in action denial.
  • Extensible by design, allowing for custom security policies and integrations.
  • Redaction of secrets in logs to prevent data exfiltration.
  • Support for Model Context Protocol (MCP) clients, including Claude Code and Codex adapters.
  • CLI subcommands for managing guardrails and telemetry controls.

use cases

Who Should Use Doberman?

Doberman is primarily designed for developers, security professionals, and users who deploy or manage AI coding agents and require stringent security and control over their operations. Its capabilities address critical risks associated with autonomous AI agents interacting with system resources and sensitive data.

  • LLM Developers: To implement security for AI coding agents and control third-party tool interactions.
  • AI Coding Agent Users: To prevent destructive commands (e.g., rm -rf ~) from being executed by agents.
  • Security Professionals working with AI Agents: To enforce security policies and guardrails at runtime, mitigating prompt injection attacks and preventing secret leakage.
  • Organizations requiring human-in-the-loop approval: For sensitive actions, Doberman can hold actions for explicit human approval, including multi-factor authentication (TOTP step-up).

how to use

How to Use Doberman

Doberman can be installed via pip and configured to act as a proxy for AI coding agents. It intercepts tool calls, applies security policies, and provides verdicts before actions are executed.

  • 1Install Doberman-Core using pip install doberman-core.
  • 2Configure Doberman as a transparent proxy for your AI coding agent (e.g., Claude Code, Codex).
  • 3Define security policies and guardrails to specify allowed, blocked, or human-approved actions.
  • 4Monitor agent interactions and Doberman's verdicts through logs and audit sinks.
  • 5Utilize doberman scan to evaluate MCP capabilities and Doberman's filtering effectiveness, reporting Attack Bypass Rate (ASR) and False Positive Rate (FPR).

pricing

Doberman Pricing & Plans

Doberman operates on a freemium-SaaS model, offering a free tier for basic usage and a Pro tier for advanced requirements. The core Doberman-Core is open-source under the Apache-2.0 license, allowing free installation and use.

  • Free: Includes 100 free API calls. The core Doberman-Core is open-source and free to use.
  • Pro: Contact for pricing. This tier is likely for enhanced features, support, or higher usage limits, though specific details are not publicly disclosed.

Pros

  • +Operates directly on the execution path, definitively blocking unsafe actions.
  • +Implements a 'fail closed' principle, denying unrecognized actions by default for enhanced security.
  • +Open-source core (Apache-2.0 license) with active community contributions (19 contributors).
  • +Provides human-in-the-loop approval with multi-factor authentication for sensitive actions.
  • +Mitigates prompt injection attacks, destructive commands, and secret leakage.
  • +Offers a free tier with 100 API calls and usage-based pricing at $0.01/call.

Cons

  • As an alpha-stage project, it may have evolving features and stability.
  • Specific pricing details for the 'Pro' tier are not publicly disclosed, requiring direct contact.
  • Focus is primarily on AI agent security, not broader AI-native proxy or LLM routing capabilities.
  • Requires integration and configuration as a proxy, adding a layer to existing agent setups.
  • Community feedback, while positive, notes the project is 'early'.

Similar Tools

Doberman vs Competitors

Doberman distinguishes itself in the AI agent security landscape by operating directly on the tool-execution path, providing a definitive block rather than advisory warnings. This approach prevents AI models from circumventing security measures, a common challenge with other 'AI guardrails'.

1

Provides a comprehensive AI-native proxy for security, observability, and governance across various agent communications and frameworks, supporting both MCP and A2A protocols.

Like Doberman, Agentgateway acts as a transparent proxy for AI agents, but it offers broader support for AI-native protocols (MCP & A2A) and includes features like LLM gateway routing and inference routing, which Doberman's description doesn't explicitly highlight.

2
Agent Governance Toolkit

Provides runtime security governance for autonomous AI agents, specifically designed to address OWASP agentic AI risks with deterministic, sub-millisecond policy enforcement.

Similar to Doberman, this toolkit focuses on runtime security and policy enforcement for AI agents. Its key differentiator is its explicit focus on addressing OWASP agentic AI risks and providing deterministic enforcement, which might offer a more structured and comprehensive security approach than Doberman's general decision engine.

More on Stork

Related AI Tools

Other tools in this category, matched by shared tags

One short daily email of tools worth shipping. No drip funnel.

one email a day · unsubscribe in two clicks · no third-party tracking

For builders

This page is doing a job for someone else’s tool.

AI agents read it. Buyers land on it. It answers in eight languages and over MCP. Your tool can have one like it — live in 24 hours.