DataGrout
About
DataGrout - Discovery, governance, and orchestration layer for AI agents working across multiple MCP servers and integrations.
Explore
- Intelligent Interface (on by default) — collapses the entire tool surface into two calls, discover and perform. The agent describes a goal in plain language instead of reasoning over hundreds of tool schemas. Disable with use_intelligent_interface=False to see raw tools.
- Semantic discovery — available standalone too, for searching tools by meaning rather than exact name.
- Cost visibility — every call returns a receipt with credit usage.
- Guided workflows — client.guide(goal=...) walks through a multi-step goal interactively.
- Cognitive Trust Certificates — cryptographic proof a workflow is cycle-free, type-safe, policy-compliant, and within budget, signed by the same CA as agent identities.
Don't have a DataGrout account or endpoint yet? The SDK can provision both for you directly (Python shown; the same call exists in each language's SDK — see the per-language docs linked below for the exact syntax):
from datagrout.conduit import ClientBuilder
from datagrout.conduit.onramp import OnrampOptions
client = await ClientBuilder().bootstrap_onramp(OnrampOptions(
gateway="https://app.datagrout.ai",
agent_name="my-agent",
agent_type="claude-sonnet-4-6",
intended_use="Summarise documents and extract entities.",
))
await client.connect()
Behind that single call: the SDK registers your agent, exchanges a short-lived token for OAuth credentials and a server URL, generates a local key pair, and gets it signed by DataGrout's CA. The private key stays on your machine. Every run after the first reuses the saved identity automatically.
Prefer the terminal to writing code: invariant onboard.
Three methods, identical across all five SDKs:
- Bearer token — simplest option, good for quick testing.
- OAuth 2.1 (client credentials) — the SDK fetches, caches, and refreshes JWTs automatically.
- mTLS — after a one-time bootstrap, the certificate itself authenticates every request; no tokens to manage afterward.
For mTLS, identity is auto-discovered in a fixed search order: an explicit override directory, CONDUIT_MTLS_CERT/CONDUIT_MTLS_KEY env vars, CONDUIT_IDENTITY_DIR, the default ~/.conduit/, then a local .conduit/ relative to the working directory. Running multiple agents on one machine means giving each its own identity directory.
Why a dedicated CA: machine identity has different requirements than browser identity — agents need certificates issued and rotated programmatically, without a human in the loop each time. The signing key lives in an HSM-backed AWS KMS key (FIPS 140-2 Level 2) and never leaves it. The CA certificate is public at ca.datagrout.ai/ca.pem for independent chain verification.
Where this connects to DataGrout's integrations
Conduit is the layer between your agent and any DataGrout server — including the Salesforce, QuickBooks, and Oracle Fusion Cloud integrations. A call_tool("salesforce@1/get_lead@1", ...) call works the same way regardless of which integrations that server has configured; the SDK doesn't need to know about a specific integration in advance.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



