Contact Us 1-800-596-4880

Get Started with Agent Fabric

Agent Fabric is the AI control plane for agents, MCP servers, and APIs across platforms. You can’t apply governance, security, or cost controls to agents you don’t know about. Catalog your assets first. Then complete only the jobs you need.

Before You Begin

Complete these checks with your administrator before you rely on Agent Fabric in production. Requirements vary by entry point and by which jobs you do.

Access and Credentials

Confirm that you have an Anypoint Platform user account and valid credentials for your organization’s entry path.

Platform and Product Access

Confirm these platform settings with your administrator:

Permissions

Confirm how your administrator maps jobs to roles:

  • Agent Fabric uses Anypoint Platform access management. Your administrator maps jobs to roles and permissions in Access Management, and exact permission names differ by organization.

  • Use the permission tables in each job section together with your internal access guide. For the enhanced experience permissions table, see Enhanced Experience Permissions.

  • If you can’t complete an action or a page shows an authorization error, ask your organization administrator for the matching permission or role.

These apply to more than one job:

  • Omni Gateway (managed or self-managed) puts authentication, monitoring, and policy in the request path. It’s required for managed instances, A2A bridges, model proxies, and rogue-agent containment. Model Proxy requires an Omni Gateway running in Connected Mode.

  • An identity provider (IdP) that issues JSON Web Tokens (JWTs) is required for model wallets and rogue-agent detection.

  • A connected provider scanner is required before you apply policies to, or govern, third-party gateway APIs.

Catalog Agents, MCP Servers, and APIs

The registry is a single inventory of agents, MCP servers, APIs, and related services, regardless of which platform built them.

Register Services

Register assets so other teams can find and reuse them instead of rebuilding the same agents and tools.

Before you register services, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • Gateways created in Anypoint Platform and opened from Agent Fabric.

You also need these permissions:

To do this You need

View catalogs and services

One of: Exchange Viewer, Exchange Contributor, or Exchange Administrator

Register agents, APIs, and LLMs

One of: Exchange Contributor, Exchange Administrator, or Exchange Creator

Discover Services with Scanners

Use scanners when agents run on more than one platform and manual registration can’t keep the registry current.

Before you create scanners, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • Access to, and active context in, the business group where you want to add the scanner.

  • A connected cloud provider under Platform > Providers for each source you scan.

  • Provider-specific credentials, roles, and permission scopes for that scanner. For example, writing policies to a third-party gateway requires connection credentials that carry the provider’s write scope, and the Microsoft Copilot Studio scanner can require a pre-configured OAuth app. See Scanner Prerequisites by Provider.

  • The Akamai API Security scanner, available only when your administrator turns on that feature for your organization.

You also need these permissions:

To do this You need

Create scanners

Exchange Administrator

View Providers

Exchange Administrator, or the required scanner entitlements for API, MCP, or agent scanners

Expose Existing APIs as MCP Servers

Agents can’t call APIs as tools until you expose those APIs as MCP servers.

Use MCP Bridge

MCP Bridge turns an existing API or SaaS system into an MCP server without custom code.

Before you create an MCP server with MCP Bridge, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • An existing API or SaaS system to expose, including the credentials the MCP server uses to call that source.

You also need these permissions:

To do this You need

Create an MCP server

One of: Exchange Contributor, Exchange Administrator, or Exchange Creator, plus API Manager: Manage APIs Configuration on at least one environment

Build a Custom MCP Server in Mule

Use MCP Connector when the tools don’t map to a single existing API and you need custom Mule logic. The resulting MCP server or client runs in Mule.

Before you add MCP Connector to a Mule application, confirm you have:

  • Familiarity with Anypoint Connectors, Mule runtime engine (Mule), and how to create a Mule app and configure global elements in Anypoint Code Builder.

  • Java 17 and Apache Maven.

  • An Anypoint Platform account.

  • The latest version of Anypoint Code Builder.

  • Credentials to connect with the target resource the MCP server or client calls.

You also need these permissions:

To do this You need

Download and publish assets

Exchange Viewer and Exchange Creator

Deploy applications

Runtime Manager: Read Applications, Create Applications, and Delete Applications

View and create APIs

Design Center Developer

Learn more: MCP Connector.

Present Non-A2A Agents as A2A-Compliant

Many enterprise agents, including Agentforce agents, aren’t A2A-compliant on their own. Register Amazon Bedrock AgentCore and Google Vertex AI directly.

Create an A2A Bridge

An A2A bridge presents a non-A2A agent as A2A-compliant without changing the source agent. Salesforce Agentforce is the supported source platform.

Before you create an A2A bridge, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • A source agent that’s registered in Portfolio and that isn’t already A2A-compliant.

  • A managed or self-managed Omni Gateway in the target environment.

  • Credentials for the source agent’s platform, such as the Salesforce org URL, OAuth token URL, client ID, and client secret for an Agentforce source agent.

You also need these permissions:

To do this You need

Create an A2A bridge

One of: Exchange Contributor, Exchange Administrator, or Exchange Creator, plus API Manager: Manage APIs Configuration on the target environment

Add A2A Support to a Mule Application

Use A2A Connector when an existing Mule application must participate as an A2A-compliant agent. The connector implements the A2A protocol so the app can act as an A2A server, an A2A client, or both.

Before you add A2A Connector to a Mule application, confirm you have:

  • Familiarity with Anypoint Connectors, Mule runtime engine (Mule), and how to create a Mule app and configure global elements in Anypoint Code Builder.

  • Java 17 and Apache Maven.

  • An Anypoint Platform account.

  • The latest version of Anypoint Code Builder.

  • Credentials to connect with the target resource.

  • An existing Mule application that must act as an A2A server, an A2A client, or both.

You also need these permissions:

To do this You need

Download and publish assets

Exchange Viewer and Exchange Creator

Deploy applications

Runtime Manager: Read Applications, Create Applications, and Delete Applications

View and create APIs

Design Center Developer

Learn more: A2A Connector.

Coordinate Work Across Specialized Agents

A broker is an intelligent router that orchestrates work across specialized A2A-compliant agents. You define the broker and its nodes in Agent Script.

Before you create an agent network, confirm you have:

  • Your Anypoint Platform credentials.

  • Anypoint Code Builder, with the Anypoint Code Builder URLs allowlisted. See Allow URLs for Anypoint Code Builder.

  • At least one Managed Omni Gateway in the target environment. A single gateway can handle both ingress and egress traffic.

  • A2A-compliant agents in the network. Create an A2A bridge first for agents that aren’t A2A-compliant.

  • A deployment target such as a CloudHub 2.0 shared or private space, or a Runtime Fabric target. Every Anypoint Platform organization includes a CloudHub 2.0 shared space. A private space requires CloudHub Network Administrator to create and manage it, and you must associate that space with the business groups and environments where you deploy.

  • Generative AI turned on for your organization if you use MuleSoft Vibes. See Enabling or Disabling Generative AI for Anypoint Platform. For Vibes, also install Node.js 20 LTS or later and the latest version of jq, and connect your Anypoint Platform organization to a Salesforce organization that has generative AI enabled.

  • For the Anypoint CLI (optional): Node 20 (v20.19.4) or later, Java 17 or later with JAVA_HOME set, and the Anypoint CLI Agent Fabric Plugin.

You also need these permissions:

To do this You need

Use Anypoint Code Builder

Anypoint Code Builder Developer

Use AI features in Anypoint Code Builder, including MuleSoft Vibes

Anypoint Code Builder: Mule Developer Generative AI User

Create and read applications and servers

Runtime Manager: Manage Servers, Create Applications, and Read Servers

View and create APIs

Design Center Developer

Deploy API proxies and manage policies

API Manager: Deploy API Proxies and Manage Policies

Publish agent network assets

Exchange Contributor

View usage

Usage Viewer

Deploy to a CloudHub 2.0 private space

CloudHub Network Administrator, plus Runtime Manager: Create Applications and Read Applications

View applications on Runtime Fabric or CloudHub 2.0

Runtime Manager: Read Applications for the environment, and Read Runtime Fabrics for the business group

Enforce the Same Policies on Live Traffic

Omni Gateway sits in front of your agents, APIs, MCP servers, and LLM traffic, regardless of the platform that built them.

Create Instances of Services and Apply Policies

Instances represent how a service runs in a specific environment. APIs, agents, MCP servers, and model proxies can include instances. A managed instance of an API, agent, or MCP server puts Omni Gateway in the request path so authentication, monitoring, and policy apply to live traffic.

Before you create instances of services or apply policies, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • An Omni Gateway for each managed instance.

  • A connected provider scanner whose credentials carry the provider’s write scope, required to apply policies to third-party gateway APIs (Azure API Management, Google Apigee, or Kong Gateway). See Policy Write Prerequisites.

You also need these permissions:

To do this You need

Create instances

API Manager: API Creator

View instances

API Manager: View APIs Configuration

Edit instances

API Manager: Edit APIs Configuration

View policies

API Manager: View Policies

Apply, edit, enable, disable, or remove policies

API Manager: Manage Policies

Create Governance Strategies

A governance strategy defines access, data privacy, performance, cost, and compliance rules once and applies them across the services in scope.

Before you create governance strategies, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • Governance available for your tenant.

  • For third-party API governance: a connected third-party gateway scanner and control rules authored as a governance ruleset.

You also need these permissions:

To do this You need

Create governance strategies

API Governance: Governance Administrator for Control types, or API Manager: Manage Policies for Automated Policy types

View governance reports

One of: API Governance: Governance Viewer or Governance Administrator (You also need Exchange Viewer for the conformance badge)

See LLM Spend, Cap It, and Reduce Token Use

A model proxy, deployed to Omni Gateway, is one governed endpoint for multiple LLM providers.

Create a Model Proxy

Deploy the proxy to Omni Gateway so routing, caching, and policy run in front of every LLM call.

Before you create a model proxy, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • A deployed Omni Gateway version 1.11.4 or later, running in Connected Mode. Model Proxy runs only on Omni Gateway.

  • Up to 50 model proxies on each Large Omni Gateway.

  • API keys to authenticate with your LLM providers.

  • A configured semantic routing service if you want to use semantic routing. See Configuring Semantic Routing Services.

  • A configured semantic caching service if you want to enable semantic caching. See Configuring Semantic Caching Services.

  • A connection to an external vault (AWS Secrets Manager, Microsoft Azure Key Vault, or HashiCorp Vault) under Platform > Providers if you want to authenticate a route with a secret from your vault.

You also need these permissions:

To do this You need

Create a model proxy

API Manager: API Creator

Set Model Costs and Cap Spend with Wallets

Set a cost for each model so token counts read as dollars. A model wallet caps a caller’s token or dollar spend against a provider.

Before you set model costs or manage wallets, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • At least one configured model proxy.

  • A configured IdP that issues JWTs for callers. Organizations without an IdP can’t use model wallets.

  • JWT Validation applied on each model proxy that callers reach through the wallet, with DataWeave Headers Transformation and Client ID Enforcement turned off.

You also need these permissions:

To do this You need

Set model costs

One of: API Manager: API Creator, View APIs Configuration, or Edit APIs Configuration

Manage model wallets

API Manager: API Creator, View APIs Configuration, Edit APIs Configuration, and Manage Policies

Use the Cost Management experience

API Manager: Manage Policies, View APIs Configuration, and View Policies; Anypoint Monitoring: Monitoring Viewer; and Exchange: Exchange Viewer. Anypoint Code Builder: Mule Developer Generative AI User is optional and required only to enable AI features.

Route and Cache Model Calls

Semantic routing sends each request to the best-matching model. Semantic caching reuses a response when a new request is similar to an earlier one.

Before you configure semantic routing or caching, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • A model proxy on Omni Gateway.

  • For semantic routing: credentials for an embedding service (OpenAI, Hugging Face, or Azure OpenAI). Advanced Scale also requires a dedicated external vector database (Qdrant, Pinecone, or Azure AI Search).

  • For semantic caching: an OpenAI embedding service, an Azure AI Search vector database, and object store connection values (client ID, client secret, URL, and store name).

You also need these permissions:

To do this You need

Configure semantic routing

One of: Exchange Contributor, Exchange Administrator, or Exchange Creator

Configure semantic caching

One of: Exchange Contributor, Exchange Administrator, or Exchange Creator

Detect and Contain Rogue Agents

A compromised or misconfigured agent can leak data, take unauthorized actions, or drive unexpected cost. Detection flags risky behavior for your review. The Kill Switch policy blocks that agent’s access to the model proxy when you quarantine it.

Before you detect and contain rogue agents, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • Omni Gateway 1.13.5 or later.

  • Each monitored agent registered with a unique instance name and ID, and linked to its model proxies.

  • Agents set up as service identities in your IdP, with tokens that include the agent’s identifier and the identity of the person the agent is acting for.

  • JWT Validation policy applied to each protected model proxy.

You also need these permissions:

To do this You need

Detect and contain rogue agents

API Manager: API Creator, View APIs Configuration, Edit APIs Configuration, View API Alerts, and Manage API Alerts

Keep Credentials in an External Vault

Register an external vault so credentials stay in AWS Secrets Manager, Azure Key Vault, or HashiCorp Vault. Only metadata is stored.

Before you register an external vault, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • Access to the external secrets manager, including its endpoint URL and credentials.

  • A supported vault: AWS Secrets Manager, Microsoft Azure Key Vault, or HashiCorp Vault. You can’t change a vault’s name after you create it.

You also need these permissions:

To do this You need

View vaults

One of: Secrets Manager: View Vault Integrations or Manage Vault Integrations

Manage vaults

Secrets Manager: Manage Vault Integrations, Exchange Administrator, Exchange Contributor, API Manager: API Creator, and API Manager: Manage Policies

Correlate Akamai Risk to Discovered Services

Correlate security findings to APIs and MCP services in the portfolio so you can triage risk before it becomes an incident.

Before you set up Akamai risk correlation, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • Akamai Security base URL, client ID, and client secret from an Akamai service account.

  • A MuleSoft connected app that acts on its own behalf, with the Exchange Viewer or Asset Viewer scope, so Akamai can read API asset and instance information.

  • Access to apply the Akamai correlation policy in the environments you scan.

  • Existing APIs and MCP services in Portfolio to correlate against.

  • The Akamai API Security feature turned on for your organization.

You also need these permissions:

To do this You need

Set up Akamai risk correlation

Exchange Administrator in the target business group, plus write access to apply the correlation policy in the environments you scan

Monitor Latency, Errors, and Volume

Monitoring shows latency, error rates, and request volume. Agent Visualizer maps how agents, brokers, and MCP servers connect.

Before you monitor services or open Agent Visualizer, confirm you have:

  • An Anypoint Platform account with the required product access for Agent Fabric. See Before You Begin.

  • Managed paths on Omni Gateway for the metrics that the experience surfaces.

  • A connected and approved observability backend for organization-wide dashboards when your tenant includes Observability.

  • For alert delivery: the MuleSoft Slack app installed in your workspace, or the MuleSoft for Teams app installed in your Microsoft Teams tenant.

You also need these permissions:

To do this You need

View monitoring

One of: Anypoint Monitoring: Monitoring Viewer or Monitoring Administrator

View agentic assets in Agent Visualizer

Exchange: Exchange Viewer

View API nodes and relationships in Agent Visualizer

API Manager: View APIs Configuration

View policies for assets in Agent Visualizer

API Manager: View Policies

View alerts

One of: API Manager: View API Alerts or Runtime Manager: Read Alerts

Manage alerts

One of: API Manager: Manage API Alerts or Runtime Manager: Manage Alerts