Compare
Agent frameworks vs an agent runtime.
Frameworks like LangGraph, LangChain, CrewAI, the OpenAI Agents SDK and the Claude Agent SDK are how you build an agent. A runtime is where it runs and what it is allowed to do. You need both, and they do different jobs.
In short
- A framework decides what the agent tries to do: planning, tool selection, memory, multi-agent orchestration.
- A runtime decides what the agent is allowed to do, and enforces it outside the agent's process, where the model cannot reach.
- They work together. MAQPNA's SDKs have adapters for the common frameworks, so you keep your agent code.
Different layers, different jobs
| Agent framework | Agent runtime (MAQPNA) | |
|---|---|---|
| Main job | Build the agent: prompts, planning, tools, memory, orchestration | Run the agent: isolation, identity, policy, approval, audit |
| Where it runs | Inside the agent's process | Around the agent: a sandbox per session and a gateway in front of every tool |
| Guardrails | Checks in the same process as the model's decisions, so they are only as strong as that process | Enforced at the gateway, outside the agent; the agent cannot skip them |
| Human approval | Many frameworks can pause for human input within the application | A policy rule holds the call at the gateway; separation of duties and four-eyes; recorded in the ledger |
| Credentials | Usually the application's API keys, available to the agent | A short-lived identity per session; upstream keys injected at the gateway, never seen by the agent |
| Evidence | Application logs and tracing | A hash-chained, verifiable audit ledger, plus OpenTelemetry traces |
| Isolation | Not in scope | gVisor, microVM or confidential VM per session, default-deny networking |
Why the layer matters
A manipulated agent should not be able to switch off its own guardrails.
Prompt injection works by getting the model to do something it should not. If the check that should stop it lives in the same process, steered by the same model, a clever enough injection, a bug or a malicious dependency can route around it.
A runtime moves the decision out of the agent's reach. The agent can ask for anything; the gateway decides with your policy, the session's identity and the data involved, and records the decision either way. That is also what lets a security team approve an agent they did not write.
Use them together
Keep your framework.
The MAQPNA SDKs for Python, TypeScript and Go call tools through the gateway, with adapters for LangGraph, LangChain, the OpenAI Agents SDK, the Claude Agent SDK and CrewAI.
pip install "maqpna[langgraph]"
maqpna dev up
maqpna dev run -- python my_langgraph_agent.py
maqpna dev timeline --lastFAQ
Common questions
Is MAQPNA an agent framework?
No. MAQPNA does not plan, prompt or orchestrate. It runs agents built with any framework, and governs every tool, model and agent-to-agent call they make.
Do I have to rewrite my agent?
No. Use the SDK adapter for your framework, or point your MCP client at the gateway. The same code runs on a laptop under maqpna dev and in a cluster sandbox.
Can I keep my framework's own guardrails?
Yes. They are useful for quality and user experience. MAQPNA adds enforcement the agent cannot bypass, and the evidence an auditor can verify.
Keep your framework. Add a runtime.
Run your existing agent under a local MAQPNA with one command and see every call it makes.
curl -fsSL https://maqpna.com/install.sh | shbrew install azmxai/maqpna/maqpnairm https://maqpna.com/install.ps1 | iexNo Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.