Skip to main content
A Hybrid data plane runs in your cluster but is configured and observed by the NeuralTrust SaaS control plane. To connect the two, each runtime authenticates to SaaS with tokens issued by the console at app.neuraltrust.ai.
Tokens are issued per product instance. TrustGate and TrustGuard are separate console objects, so a Hybrid install that runs both must create both and collect two token sets — one per product.

What the console issues

When you create a Private TrustGate or TrustGuard, the console generates two credentials for that instance: Both are JWTs scoped to the specific gateway or TrustGuard instance. The enrollment JWT already carries the tenant and instance identifiers — you do not set them separately.

Create a private TrustGate

  1. Open app.neuraltrust.ai and go to TrustGate → Agent Gateway → Getting started.
  2. Choose New Gateway, enter a name, and select Private (High stakes — fixed capacity, no cold starts).
  3. Under Where do you want to run your gateway? choose Kubernetes (recommended for production). Creating the gateway issues its config-sync token and DataAgent enrollment token.
  4. Copy the two tokens from the generated values.yaml. Treat the whole file as a secret — see Secrets.
  5. Leave the wizard open. After the data plane is running you return here to set the Dataplane URL (see Overview).
Docker and Manual are also offered. Docker is for local evaluation of the LLM/proxy path only (no MCP). Manual returns CONTROL_PLANE_JWT and DATA_AGENT_JWT for fully custom manifests. Use Kubernetes for production.

Create a private TrustGuard

  1. Go to TrustGuard → Agent Runtime → Getting started.
  2. Choose New TrustGuard, enter a name, and select Private.
  3. Choose Kubernetes. Creating the TrustGuard issues its own config-sync token and DataAgent enrollment token — distinct from TrustGate’s.
  4. Copy both tokens.
The TrustGuard wizard offers Kubernetes and Manual only (no Docker). In a combined install, TrustGate and TrustGuard each keep independent tokens; never reuse one product’s token for the other.

Map tokens to chart Secrets

For a production Kubernetes install, pre-create the Secrets below and reference them from values — keep the raw tokens out of values.yaml and source control. The config-sync Secret also needs a CONFIG_SYNC_LKG_KEY: an operator-generated base64 32-byte key that encrypts the last-known-good configuration snapshot (openssl rand -base64 32). Reference them from the maintained neuraltrust-platform chart. Select the products you run with global.products, then point each config-sync and enrollment block at its Secret:
Config-sync is on by default in Hybrid (mode-derived) — set only existingSecret; do not restate enabled: true. For local or evaluation installs you may inline the raw values with configSync.token and dataagent.enrolment.token instead of an existingSecret, but those values enter Helm release history.

Regenerate tokens

Issue fresh tokens any time from Settings → Agent Gateway → Deployment (TrustGate) or the equivalent TrustGuard deployment settings. Regenerating invalidates the previous install credentials, so update the corresponding Secret and roll the runtime pods.

Next steps

Overview

See the full private-gateway setup flow and network requirements.

Secrets

Handle config-sync, enrollment, and LKG credentials safely.

Feature flags

Chart switches that shape the Hybrid data plane.

Configuration

Managed stores, ingress, and generated setup.