Tokens are issued per product instance. TrustGate and TrustGuard are separate
console objects, so a Hybrid install that runs both must create both and
collect two token sets — one per product.
What the console issues
When you create a Private TrustGate or TrustGuard, the console generates two credentials for that instance:
Both are JWTs scoped to the specific gateway or TrustGuard instance. The enrollment
JWT already carries the tenant and instance identifiers — you do not set them
separately.
Create a private TrustGate
- Open app.neuraltrust.ai and go to TrustGate → Agent Gateway → Getting started.
- Choose New Gateway, enter a name, and select Private (High stakes — fixed capacity, no cold starts).
- Under Where do you want to run your gateway? choose Kubernetes (recommended for production). Creating the gateway issues its config-sync token and DataAgent enrollment token.
- Copy the two tokens from the generated
values.yaml. Treat the whole file as a secret — see Secrets. - Leave the wizard open. After the data plane is running you return here to set the Dataplane URL (see Overview).
Create a private TrustGuard
- Go to TrustGuard → Agent Runtime → Getting started.
- Choose New TrustGuard, enter a name, and select Private.
- Choose Kubernetes. Creating the TrustGuard issues its own config-sync token and DataAgent enrollment token — distinct from TrustGate’s.
- Copy both tokens.
The TrustGuard wizard offers Kubernetes and Manual only (no Docker). In a
combined install, TrustGate and TrustGuard each keep independent tokens; never
reuse one product’s token for the other.
Map tokens to chart Secrets
For a production Kubernetes install, pre-create the Secrets below and reference them from values — keep the raw tokens out ofvalues.yaml and source control.
The config-sync Secret also needs a CONFIG_SYNC_LKG_KEY: an operator-generated
base64 32-byte key that encrypts the last-known-good configuration snapshot
(openssl rand -base64 32).
Reference them from the maintained
neuraltrust-platform chart. Select the
products you run with global.products, then point each config-sync and
enrollment block at its Secret:
existingSecret; do not restate enabled: true. For local or evaluation
installs you may inline the raw values with configSync.token and
dataagent.enrolment.token instead of an existingSecret, but those values
enter Helm release history.
Regenerate tokens
Issue fresh tokens any time from Settings → Agent Gateway → Deployment (TrustGate) or the equivalent TrustGuard deployment settings. Regenerating invalidates the previous install credentials, so update the corresponding Secret and roll the runtime pods.Next steps
Overview
See the full private-gateway setup flow and network requirements.
Secrets
Handle config-sync, enrollment, and LKG credentials safely.
Feature flags
Chart switches that shape the Hybrid data plane.
Configuration
Managed stores, ingress, and generated setup.