PluginBench
MCP Server
Active
Apache-2.0

SatGate – Economic Firewall for AI Agents MCP Server

io.github.SatGate-io/satgate

Economic firewall for AI agents: enforce budgets, delegate authority, and govern paid API access with cryptographic capability tokens.

What is the SatGate – Economic Firewall for AI Agents MCP server?

SatGate is an economic firewall that sits in front of APIs and MCP tools to meter agent traffic, enforce budgets, and govern paid-rail access. It uses cryptographic capability tokens (Macaroons) to enable scoped delegation and provides hard budget enforcement, MCP-aware cost attribution, and signed receipts for every allow or deny decision.

SatGate fills the gap between network/application firewalls and economic governance for autonomous AI agents. It lets you control whether agents should act, spend, or delegate based on authority, budget, and paid-rail context. Works with MCP, OpenAI tools, Anthropic tools, LangChain, CrewAI, and raw HTTP—adding <50ms overhead with zero code changes to your backend.

How to install SatGate – Economic Firewall for AI Agents

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • SATGATE_URL
    required

    SatGate Cloud MCP URL

  • SATGATE_TOKEN
    required
    secret

    Agent token minted in SatGate Cloud (MCP Setup)

  • Authorization
    required
    secret

    Bearer token minted in SatGate Cloud (MCP Setup)

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "satgate": {
      "command": "npx",
      "args": [
        "-y",
        "satgate-mcp-bridge"
      ],
      "env": {
        "SATGATE_URL": "<YOUR_SATGATE_URL>",
        "SATGATE_TOKEN": "<YOUR_SATGATE_TOKEN>",
        "Authorization": "<YOUR_AUTHORIZATION>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Capability Token Minting (issue) — Cryptographically mint scoped Macaroon tokens with embedded caveats (expiry, scope, budget, IP) that agents can safely sub-delegate without server roundtrips.
  • Payment Processing (pay) — Process payments across L402 (Lightning), x402 (USDC-on-Base), API-key billing, and enterprise ledgers while preserving paid-rail context in Evidence Packs.
  • Receipt Verification (verify) — Verify signed receipts and Evidence Packs to confirm allow/deny decisions and audit which agent spent what on which tool.
  • MCP JSON-RPC Parsing — Parse MCP tool calls to attribute costs per-tool (e.g., $47 on search_database, $12 on send_email) rather than just HTTP endpoints.
  • Budget Enforcement — Hard-stop request blocking when agent, team, or API budgets hit zero—not alerts, not logs, but immediate 402 rejection.
  • MCP Proxy — Native MCP proxy with stdio (local sidecar) or SSE/HTTP (remote multi-agent) transports, per-tool cost configuration, and three auth modes (none, static token, macaroon).
  • Route Matching & Policy Enforcement — Three policy types (public, capability, l402) with path-prefix matching and upstream proxying to any HTTP backend.

Use cases

  • Enforce hard spending caps on autonomous agents before they call expensive APIs or spawn sub-agents overnight.
  • Delegate authority to sub-agents with carved budgets (e.g., Agent A gives Agent B a $50 token) without escalation risk.
  • Attribute costs per MCP tool call and audit which agent spent what, enabling cost center tagging and chargeback.
  • Govern paid API access (Lightning, USDC, API-key billing) without making any one rail the control plane.
  • Protect internal APIs and MCP tools with cryptographic capability tokens that support delegation and next-request revocation.

SatGate – Economic Firewall for AI Agents MCP server FAQ

What is SatGate?

SatGate is an economic firewall for AI agents. It sits in front of APIs and MCP tools to enforce budgets, delegate authority via cryptographic tokens, and govern paid-rail access. Every allow or deny comes with a signed receipt.

Is SatGate free?

The open-source gateway is Apache 2.0 licensed and free to self-host. SatGate Cloud (managed SaaS) offers a free Observe tier (dashboards and usage tracking) with no credit card required; Pro tier adds enforcement and delegation.

How do I install SatGate in Cursor or Claude?

SatGate is not a Cursor/Claude plugin. It's a gateway you self-host or run via SatGate Cloud. You integrate it by pointing your agent's API calls through the SatGate proxy (npm: satgate-mcp-bridge, or remote SSE at https://satgate-mcp-saas.fly.dev/sse). The MCP proxy then enforces budgets and policies.

Does SatGate require authentication?

SatGate supports three policy types: public (no auth), capability (Macaroon tokens with embedded caveats), and l402 (Lightning/USDC payment). Routes default to deny unless explicitly public. You control which routes require which auth.

What payment methods does SatGate support?

SatGate governs L402 (Lightning), x402 (USDC-on-Base), API-key billing, and enterprise ledgers. It treats these as rails to govern around, not the product boundary, so you can mix them without making one the control plane.

Can I self-host SatGate?

Yes. SatGate is a single Go binary available for macOS, Linux, and Windows. It runs standalone, in Docker, or on Kubernetes. See the Quick Start guide for 60-second setup with mock Lightning.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="docs/assets/logo.png" alt="SatGate" width="120" /> </p> <h1 align="center">SatGate</h1> <p align="center"> <strong>Observe, control and admit AI agent traffic</strong><br/> <em>Every allow or deny comes with a signed receipt</em> </p> <p align="center"> <a href="https://github.com/satgate-io/satgate/actions"><img src="https://github.com/satgate-io/satgate/workflows/CI/badge.svg" alt="CI Status"></a> <a href="https://goreportcard.com/report/github.com/satgate-io/satgate"><img src="https://goreportcard.com/badge/github.com/satgate-io/satgate" alt="Go Report Card"></a> <a href="https://pkg.go.dev/github.com/satgate-io/satgate"><img src="https://pkg.go.dev/badge/github.com/satgate-io/satgate.svg" alt="Go Reference"></a> <a href="LICENSE"><img src="https://img.shields.io/badge/License-Apache%202.0-blue.svg" alt="License"></a> </p> <p align="center"> <a href="#the-problem">Why</a> • <a href="#build-agents-with-satgate">Build</a> • <a href="#features">Features</a> • <a href="#quick-start">Quick Start</a> • <a href="#documentation">Docs</a> • <a href="https://satgate.io">Website</a> • <a href="https://satgate.io/blog/why-routing-isnt-governance">Blog</a> </p>

SatGate is a gateway in front of APIs and MCP tools. It meters agent and MCP traffic (Observe), enforces owner budgets before work runs (Control), and charges external agents on the routes you choose (Admit; the Charge policy in the dashboard). Every allow or deny comes with a signed receipt.

Try it as an agent. This hosted route costs 10 sats or 0.01 USDC, and each payment buys one request:

curl -i https://mcp-prod-final.satgate.cloud/paid/premium

The unpaid call returns HTTP 402 with a Lightning invoice, a USDC-on-Base (x402) offer and the terms. Agent instructions are in llms.txt.

Build Agents with SatGate

SatGate's developer primitive is three calls: issue(), pay(), and verify().

import os
from satgate import SatGate

satgate = SatGate(api_key=os.getenv("SATGATE_API_KEY"))

capability = satgate.issue(
    task="research market prices",
    agent="research-agent",
    allow=["mcp:web.search", "api:prices.read"],
    budget_usd=25,
    expires_in="1h",
)

receipt = satgate.pay(
    upstream="https://api.example.com/search",
    capability=capability,
    max_usd=4.20,
)

verified = satgate.verify(receipt)
print(verified.decision, verified.evidence_pack_id)

Install today:

pip install satgate
npm install @satgate/sdk

The public packages install today; the issue/pay/verify API namespace is in private beta. Calls without private-beta access raise a structured error instead of returning fake receipts:

SatGateAuthError: This API namespace requires private beta access. Visit cloud.satgate.io/docs to request access.

Runnable examples:

  • examples/python/issue_pay_verify.py
  • examples/node/issue-pay-verify.mjs

Works with: MCP · OpenAI tools · Anthropic tools · LangChain · CrewAI · Raw HTTP


<div align="center">

🎬 See SatGate in Action

<a href="https://satgate.io#explainer"><img src="https://img.shields.io/badge/▶_Explainer-30s-purple?style=for-the-badge" alt="Watch Explainer"></a>  <a href="https://satgate.io#delegation"><img src="https://img.shields.io/badge/▶_Token_Delegation-45s-blue?style=for-the-badge" alt="Watch Delegation"></a>

</div>
<div align="center">

☁️ Don't want to self-host? Try SatGate Cloud

Managed SaaS — zero setup, multi-tenant isolation, enterprise dashboard.<br/> Free Observe tier. No credit card required.

<a href="https://cloud.satgate.io"><img src="https://img.shields.io/badge/🚀_Try_SatGate_Cloud-Free-blue?style=for-the-badge" alt="Try SatGate Cloud"></a>

</div>

The Problem

AI agents are making API calls autonomously. They spawn sub-agents, call MCP tools, and run overnight while you sleep.

Your existing stack answers: "Is this request authenticated?"

Nobody answers: "Should this agent have authority to spend, delegate, or invoke this paid resource?"

✓ Network Firewall    → "Can this packet enter?"
✓ Application Firewall → "Is this request safe?"
? Economic Firewall    → "Should this agent act, spend, or pay?"

That's the gap. SatGate fills it.

What is SatGate?

SatGate is an Economic Firewall for AI agent requests. Drop it in front of your APIs and MCP tools to enforce scoped authority, budgets, paid-rail context, and Evidence Pack receipts before agents act.

Not another routing layer. Routing gateways (Bifrost, LiteLLM, Portkey) optimize which provider handles a call. SatGate governs whether the call should happen at all based on authority, policy, budget, and paid-rail context.

Use them together:

Agent → SatGate (economic governance) → Routing Gateway → LLM Providers

Features

  • 🛡️ Capability Tokens (Macaroons) — Cryptographic credentials with built-in caveats, delegation, and next-request revocation. Not API keys — tokens that agents can safely sub-delegate.
  • 🎯 MCP-Aware — Parses MCP JSON-RPC tool calls. Know that Agent X spent $47 on search_database and $12 on send_email — not just "1,000 requests."
  • 💰 Budget Enforcement — Hard stops per agent, team, or API. When the budget hits zero, requests are blocked. Not logged. Not alerted. Blocked.
  • ⚡ Paid-Rail Governance — Govern paid API access across L402, x402, API-key billing, and enterprise ledgers without making any one rail the control plane.
  • 🔒 Default-Deny — All routes require valid credentials unless explicitly public. Zero Trust by design.
  • 🚀 <50ms Overhead — Lightweight Go proxy. Adds governance without adding latency.
  • 📦 Self-Hosted — Your infrastructure, your rules. Single binary, Docker, or Kubernetes.
  • 🔌 Drop-in — Works with any HTTP backend. REST, GraphQL, MCP servers. No code changes.

Quick Start

60-Second Demo

# Download the binary (macOS Apple Silicon — see Releases for other platforms)
curl -L https://github.com/satgate-io/satgate/releases/latest/download/satgate-darwin-arm64 -o satgate
chmod +x satgate

# Start with example config (mock Lightning, auto-generated keys)
export ADMIN_TOKEN=my-secret-token
export LIGHTNING_BACKEND=mock
./satgate --config examples/gateway.yaml

Try the three policies:

# 1. Public — no auth needed
curl http://localhost:8080/health

# 2. Protected — mint a capability token, then use it
curl -X POST http://localhost:8080/api/capability/mint \
  -H "X-Admin-Token: my-secret-token" \
  -H "Content-Type: application/json" \
  -d '{"scope": "api:read", "duration": "1h"}'

# Use the token:
curl -H "Authorization: Bearer YOUR_CAPABILITY_TOKEN" \
  http://localhost:8080/api/capability/ping

# 3. Paid — get a payment challenge (L402 today; x402/other rails as governed context)
curl http://localhost:8080/api/micro

Public → Protected → Paid. Three policies, one gateway; paid rails are governed context, not the product boundary.

Hosted paid demo (Admit; Charge in the dashboard). No local Lightning node:

curl -i https://mcp-prod-final.satgate.cloud/paid/premium

Unpaid calls return 402. Price is 10 sats, or 0.01 USDC on Base, for one request. For Lightning, show the invoice to the owner, poll payment status, then retry. Poll rules and the USDC steps are in llms.txt.

📖 Full Quick Start Guide →

Other Install Methods

# Docker
docker run -v $(pwd)/gateway.yaml:/etc/satgate/gateway.yaml \
  -e ADMIN_TOKEN=my-secret-token -e LIGHTNING_BACKEND=mock \
  -p 8080:8080 ghcr.io/satgate-io/satgate:latest

# Build from source
git clone https://github.com/satgate-io/satgate.git
cd satgate && go build -o satgate ./cmd/satgate

Configuration

version: 1

server:
  listen: ":8080"

admin:
  capabilityRootKey: "${CAPABILITY_ROOT_KEY}"

lightning:
  provider: "${LIGHTNING_BACKEND}"
  config:
    connectionString: "${NWC_CONNECTION_STRING}"

upstreams:
  api:
    url: "http://localhost:3000"

routes:
  - name: public-health
    match:
      pathPrefix: /health
    upstream: api
    policy:
      kind: public

  - name: protected-api
    match:
      pathPrefix: /api/
    upstream: api
    policy:
      kind: capability
      scope: "api:read"

  - name: premium-api
    match:
      pathPrefix: /premium/
    upstream: api
    policy:
      kind: l402  # paid-rail policy; use payment_context to preserve L402/x402/ledger evidence
      priceSats: 100

Policy Types

PolicyDescriptionUse Case
publicNo authenticationHealth checks, docs, webhooks
capabilityRequires valid MacaroonProtected API endpoints
l402Requires Lightning payment and records paid-rail contextMonetized endpoints; x402/ledger context can be preserved in Evidence Packs

How It's Different

SatGateRouting GatewaysTraditional API Gateways
Primary concernEconomic governanceProvider routingTraffic management
Budget enforcementHard caps (blocked at limit)Soft alerts only❌
MCP cost attributionPer-tool granularity❌❌
Credential modelMacaroons (delegatable)API keysAPI keys / OAuth
Agent delegationSub-tokens with reduced budgets❌❌
Paid-rail governanceL402, x402, API-key billing, enterprise ledgers❌❌
Works alongside—✅ Use together✅ Use together

Architecture

┌──────────────────────────────────────────────────┐
│                    SatGate                        │
│                                                   │
│  Request → Route Match → Policy Check → Proxy    │
│                             │                     │
│              ┌──────────────┼──────────────┐     │
│              │              │              │      │
│          [public]    [capability]   [paid rail]  │
│          pass        verify token     verify     │
│                      check budget     payment    │
│                      log MCP tool     context    │
└──────────────────────────────────────────────────┘

Key Concepts:

  • Macaroons: Bearer tokens with embedded caveats (expiry, scope, budget, IP). Not API keys — they support delegation without server roundtrips.
  • Delegation: Agent A gives Agent B a sub-token with reduced permissions and a $50 budget cap. B can't escalate.
  • MCP Parsing: SatGate reads MCP JSON-RPC payloads to attribute costs to specific tool calls, not just HTTP endpoints.
  • Paid-rail context: SatGate treats L402, x402, API-key billing, and enterprise ledgers as rails to govern around. Evidence Packs preserve which rail was involved without making the rail the product.

SDKs

LanguagePackageDocs
Pythonpip install satgateREADME
JavaScriptnpm install @satgate/sdkREADME

MCP Proxy (NEW)

SatGate now includes a native MCP proxy that governs tool calls for any MCP-compatible agent:

# Run MCP proxy with 1000-credit budget
satgate-mcp --config satgate-mcp.yaml
  • Budget enforcement: Hard 402 when agents exhaust their allocation
  • Delegation: Parent agents mint sub-agent tokens with carved budgets
  • Per-tool costs: web_search: 5, dalle_generate: 50 (wildcard patterns supported)
  • Two transports: stdio (local sidecar) or SSE/HTTP (remote multi-agent)
  • Three auth modes: none, static token, macaroon (HMAC chain)

See pkg/mcpserver/README.md for full documentation.

Documentation

☁️ SatGate Cloud & Enterprise

Self-hosting not your thing? SatGate Cloud is the fully managed version — same gateway, zero ops.

The open-source gateway handles protection, budgets, and paid-rail enforcement. SatGate Cloud adds the control plane:

  • 📊 Observe — Real-time dashboards, usage attribution, cost center tagging
  • 🎚️ Control — Budget and policy enforcement before agent requests execute
  • 🤖 SatGate Mint — Zero-touch agent provisioning (K8s, AWS, OIDC)
  • 🏢 Multi-tenant — Team isolation, RBAC, SSO/SCIM
  • 📝 Audit — Tamper-evident logging, compliance exports

<a href="https://cloud.satgate.io"><strong>Start Free →</strong></a> (Observe mode is free, unlimited, forever)

Contributing

We welcome contributions! See CONTRIBUTING.md for guidelines.

git clone https://github.com/satgate-io/satgate.git
cd satgate
go mod download
go test ./...
go build -o satgate ./cmd/satgate

License

Apache License 2.0 — see LICENSE for details.

Links


<p align="center"> <sub>Built with ⚡ by <a href="https://satgate.io">SatGate</a> — The Economic Firewall</sub> </p>

Related MCP servers

Developer tools for files, git, ports, processes and more, the same on Windows, Linux and macOS

View repository →
GRGraph-Mem logo

Graph-Mem

Active

Persistent knowledge-graph memory for AI agents, with local semantic search. No API keys.

1
Python
MIT
View repository →

L402 Lightning-paid Bitcoin data: price, fees, blocks, sentiment, DCA signals.

View repository →

Manage your Savanto store from your AI: catalog, content, prompts, and analytics, by chat.

0
TypeScript
MIT
View repository →

The match graph for AI. Search 100K+ capabilities across 13K+ AI artifacts.

View repository →

MCP server and Firefox add-on that let an AI agent drive your real, logged-in browser. Free tier.

0
JavaScript
View repository →