An agent represents an LLM endpoint registered with Orithos. Agents are the target of all security scans.
Register an agent by providing its endpoint URL and optional API key. No instrumentation, sidecars, or code changes required.
Agent API keys are encrypted at rest using Fernet symmetric encryption before being stored in the database. The encryption key is derived from the server's secret key. Keys are never logged or exposed in API responses.
Before creating a scan, Orithos verifies the agent endpoint is reachable and returns valid JSON. This prevents scans against unreachable or misconfigured endpoints.
Orithos ships with provider presets for OpenAI, Anthropic, Google, Groq, Together, Mistral, and more. Each preset includes the default endpoint URL, supported models, and endpoint type.