AI Endpoint Shield
Overview
Akto's AI Endpoint Shield is the background agent you deploy to your employees' devices to discover and protect local AI activity. It auto-detects the MCP servers configured in your employees' IDEs and CLIs, wraps them with runtime security, installs the guardrail hooks for your AI tooling, and reports everything back to your Akto dashboard, with no changes required to how your employees work.
What It Does
Once installed on an employee's device, AI Endpoint Shield:
Discovers every AI agent, MCP server, skill, and plugin present on the device, including MCP server configs inside clients like Cursor, VS Code, and Claude Desktop.
Protects what it finds by installing the IDE and CLI hooks for the device's AI tools, which enforce guardrails wherever the hook supports it, and by wrapping local (STDIO) and remote (HTTP) MCP servers with runtime security, transparently forwarding safe traffic and blocking unsafe requests or responses with a clear JSON-RPC error.
Covers standalone desktop apps that don't expose hooks, such as Claude Desktop, GitHub Copilot, and the ChatGPT desktop app, through the bundled Akto System Proxy.
Reports everything back to the Endpoint Shield page, so you always have a live view of what's protected.
Stays current on its own, checking a version manifest so one deployment policy handles the initial install and every future update.
How You Deploy It
AI Endpoint Shield supports macOS, Windows, and Linux. Roll it out fleet-wide through whichever MDM you already run, or install it standalone on a single machine:
Linux
Available
Available
Every method runs the same underlying installation script per platform, so behavior is consistent no matter which MDM you deploy it from. These guides walk you through the install steps only; they don't include the installer file itself.
After Deployment
Allowlist AI Endpoint Shield in your antivirus, EDR, and endpoint management tools so it isn't quarantined or blocked.
On macOS, optionally set a custom device name and email for each Mac, instead of the auto-detected hostname and username.
Review every protected device and its MCP servers on the Endpoint Shield page.
Get Support for your Akto setup
There are multiple ways to request support from Akto. We are 24x7 available on the following:
In-app
intercomsupport. Message us with your query on intercom in Akto dashboard and someone will reply.Join our discord channel for community support.
Contact
support@akto.iofor email support.Contact us here.
Last updated