VPN Works Exit live demo vpnw.com

Fixed exit addresses, with the policy checked again

Two AI agents reach a partner's API through exits in two countries, each from a fixed address the partner allows. Every request is checked by the agent's own policy, then again at the exit, and both ends keep a record that joins up. Partway through, one exit fails, and a client with a stolen token tries the exit directly. Everything below was recorded in a real run in a private test network; the decisions you try yourself run the exit's own code in this page.

Loading Exit's engine

Clients

agent-1research agent, vpnw guard
agent-2CI job, vpnw guard
tampered clientagent-2's token, no Agent

Exits

DEexit-deFrankfurt
NLexit-nlAmsterdam

Destinations

The partnerapi, files and www.partner.testallows the agents' 4 addresses
Off limitsattacker.test, the intranet, cloud metadata

Step 1 of 6

Two agents, two exits

A partner lets in traffic only from addresses it knows. Two agents need to reach it: a research agent and a CI job. Each runs under vpnw guard, sealed, so its only way out is the Agent, and the Agent's only way out is a list of two exits: exit-de first, exit-nl if exit-de stops answering. The agent's policy is a file. The exits read the same file for that client.

ClientPolicy (the same file at the Agent and at the exits)From exit-deFrom exit-nl

The exits know each client by a token and keep only its SHA-256. The Agent reaches them over TLS and checks their certificates, and it sends its run's ID and each connection's number with every request.

What is real here

Recorded

  • The run: vpnw 0.2.0 for both agents and vpnw-exit 0.1.0 for both exits, the real binaries with real TLS, on October 5, 2026. Steps 2 to 6 replay it from the four records they wrote and the test's own log. The replay is slower than the run, which took a few seconds.
  • The private test network: Linux network namespaces on one machine. The two "countries" are two namespaces with addresses from documentation ranges.

Running in this page

  • Exit's own Go code, compiled to WebAssembly: it reads the exits' configuration in step 1, decides your requests in step 4, decides the recorded exit requests again and joins the records in step 6.

Stand-ins

  • The partner's servers and the DNS server are small programs written for the test, and the tampered client is a test script holding a copy of agent-2's token. The tokens were made for the run.
  • No network: this page makes no requests.