Control D for AI agents

Control D is a DNS filtering platform that lets a business manage internet access policies and monitor traffic across devices and networks. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

Security and identityAPI keyMCP + RESTcontrold.com
AUDIT LOG · CONTROL DPOLICY: acme-support
09:41:07 · claude · u_8f2read
control_d.get_ip
Get IP✓ allowed · 212ms
09:41:08 · claude · u_8f2read
control_d.get_users
Get Users✓ allowed · 164ms
09:41:09 · claude · u_8f2write
control_d.post_devices
Create Device✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
control_d.delete_devices_device_id
Delete Device by ID✕ blocked · policy: deny
EVERY CONTROL D CALL, ON THE RECORD
01 · USE CASES

What agents do in Control D.

01

Check a profile's analytics

Check a profile's analytics summary to see what traffic has been blocked recently.

02

Look up devices on a profile

List the devices attached to a profile before applying a new filtering rule.

03

Confirm before deleting a profile

Confirm before deleting a profile, since every device and rule tied to it stops working.

02 · ACTIONS

54 Control D actions, graded by risk.

Every Control D action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

33

Look things up. Allowed by default.

  • control_d.get_ip
    Get IP
  • control_d.get_users
    Get Users
  • control_d.get_access
    List Known Access IPs
  • control_d.get_devices
    Get Devices
  • control_d.get_network
    Get Network Stats
  • control_d.get_proxies
    Get Proxies
  • control_d.get_profiles
    Get Profiles
  • control_d.get_devices_types
    Get Device Types
  • control_d.get_analytics_levels
    Get Analytics Levels
  • control_d.get_billing_payments
    Get Billing Payments
  • control_d.get_billing_products
    Get Billing Products
  • control_d.get_profiles_options
    Get Profile Options
  • control_d.get_analytics_endpoints
    Get Analytics Endpoints
  • control_d.get_profiles_profile_id
    Get Profile by ID
  • control_d.get_services_categories
    Get Service Categories
  • control_d.get_organizations_members
    Get Organization Members
+ 17 MORE

write

16

Create and change things. Allow, or ask the user first.

  • control_d.post_devices
    Create Device
  • control_d.post_profiles
    Create Profile
  • control_d.post_profiles_profile_id_rules
    Create Custom DNS Rule
  • control_d.post_profiles_profile_id_schedules
    Create Profile Schedule
  • control_d.post_profiles_profile_id_rules_folder_id
    Create Custom Rules in Profile Folder
  • control_d.put_organizations
    Modify Organization
  • control_d.put_devices_device_id
    Modify Device
  • control_d.put_profiles_profile_id
    Modify Profile
  • control_d.put_profiles_profile_id_rules
    Modify Custom Rule for Profile
  • control_d.put_profiles_profile_id_filters
    Bulk Update Profile Filters
  • control_d.put_profiles_profile_id_rules_rule_id
    Update Custom Rule by Rule ID
  • control_d.put_profiles_profile_id_filters_external
    Update External Filters for Profile
  • control_d.put_profiles_profile_id_services_service
    Modify Service for Profile
  • control_d.put_profiles_profile_id_filters_filter_filter
    Modify Profile Filter
  • control_d.put_profiles_profile_id_schedules_schedule_id
    Update Profile Schedule
  • control_d.put_profiles_profile_id_rules_rule_id_folder_id
    Move Profile Rule to Folder

destructive

5

Delete, cancel or archive. Ask first, or deny outright.

  • control_d.delete_devices_device_id
    Delete Device by ID
  • control_d.delete_profiles_profile_id
    Delete Profile
  • control_d.delete_profiles_profile_id_rules_rule_id
    Delete Profile Rule by Rule ID
  • control_d.delete_profiles_profile_id_schedules_schedule_id
    Delete Profile Schedule
  • control_d.delete_profiles_profile_id_rules_rule_id_folder_id
    Delete Rule from Folder
03 · HOW IT WORKS

Control D in three steps.

  1. 01Your users connect Control DThey add their Control D api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Device” can wait for the user, and “delete Device by ID” can be denied outright.
  3. 03Any agent can actYour agent calls Control D through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('control_d', {
  read: 'allow',
  write: 'ask',        // post_devices
  destructive: 'deny',  // delete_devices_device_id
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How Control D connects.

Users add their Control D api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same Control D connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use Control D from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

Control D and Arc0, answered.

Q01

Can I use Control D with Claude, ChatGPT or Cursor?

Yes. Connect Control D to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Control D actions you allow.

Q02

How do users connect Control D?

Users add their Control D api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which Control D actions can my agent take?

54 in total: 33 read, 16 write and 5 destructive, such as “create Device”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in Control D?

Yes. Actions like “delete Device by ID” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call Control D too?

Yes. The same Control D connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug Control D into your agent.

Your users connect Control D once, under your brand. Your agent gets 54 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan