OpenPort Protocol: A Security Governance Specification for AI Agent Tool Access
Genliang Zhu, Chu Wang, Ziyuan Wang, Zhida Li, Qiang Li

TL;DR
OpenPort Protocol (OPP) is a comprehensive security governance specification for AI agent tool access, enabling secure, auditable, and controlled interactions with application data and actions through a model-neutral, runtime-neutral gateway.
Contribution
The paper introduces OpenPort Protocol, a novel governance-first specification that addresses authorization, risk management, and auditability for AI agent tool access in production environments.
Findings
Defined a secure, model-neutral gateway for AI tools
Implemented risk-gated write operation lifecycle with human review
Validated core profile with artifact-based external testing
Abstract
AI agents increasingly require direct, structured access to application data and actions, but production deployments still struggle to express and verify the governance properties that matter in practice: least-privilege authorization, controlled write execution, predictable failure handling, abuse resistance, and auditability. This paper introduces OpenPort Protocol (OPP), a governance-first specification for exposing application tools through a secure server-side gateway that is model- and runtime-neutral and can bind to existing tool ecosystems. OpenPort defines authorization-dependent discovery, stable response envelopes with machine-actionable \texttt{agent.*} reason codes, and an authorization model combining integration credentials, scoped permissions, and ABAC-style policy constraints. For write operations, OpenPort specifies a risk-gated lifecycle that defaults to draft…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsAccess Control and Trust · Security and Verification in Computing · Blockchain Technology Applications and Security
