What is Forgebench?
Forgebench is a governed chokepoint for LLM calls and agent tool use. Every call an agent makes to a model, every tool it invokes, goes through one path: authenticate, gate the budget, inject the provider credential, forward the call, meter it, write the audit row. There is no other path: a call that skips a step is not a supported one.
Every call is recorded with its model, tokens, cost, latency and full request/response, queryable, not grepped out of logs.
Budgets are checked before the call leaves, not reconciled after. Over the cap, the call is refused with a 402 and costs nothing.
The audit log is hash-chained: each entry commits to the one before it, so any edit or deletion breaks the chain and is detectable.
An agent can only call tools you allowed it. Anything else is blocked at the chokepoint, regardless of what the model asked for.
Provider keys live encrypted in the platform and are injected at call time. Agents never hold them, so revoking one is a single action.
A post-fact scanner checks completed traces for PII, secrets and denylisted terms, and can auto-pause an agent once findings pass a threshold you set.
What you work with
| Concept | What it is |
|---|---|
| Workspace | An isolated tenant. Agents, keys, budgets and audit records belong to exactly one, and never leak across. |
| Agent | The unit you author: a name, the models it may use, the tools it may call, and the policy it runs under. |
| API key | How your code authenticates. Each key carries its own scopes, model allowlist and daily/monthly spend caps. |
| Budget | A spend ceiling enforced before the call, at workspace and per-key level. |
| Guardrail | A content check run over completed traces, producing findings you review per agent. |
Full definitions in Core concepts.

