PluginBench
MCP Server
Active
MIT

ScopeGate MCP Server

io.github.alifanov/scopegate

Permission gateway for AI agents: scoped MCP endpoints over 27 services, audited and revocable.

What is the ScopeGate MCP server?

ScopeGate is a permission gateway that sits between AI agents and external services, allowing you to grant fine-grained per-action permissions instead of full OAuth scopes. It exposes MCP endpoints with specific capabilities (e.g., `gmail:read_emails` without `gmail:send_email`), logs every call, and supports one-click revocation without disconnecting the underlying service.

ScopeGate lets you safely delegate service access to AI agents by creating scoped MCP endpoints with granular permissions across 27 providers (Google Workspace, Meta, LinkedIn, Slack, Notion, Jira, Salesforce, Stripe, and more). Every request is audited, tokens are encrypted at rest and never exposed to agents, and you can revoke access instantly. Run it yourself with Docker or use the hosted cloud version.

How to install ScopeGate

Copy-paste configuration for popular MCP clients.

transport: http
Config generated by PluginBench — verify against the source before use.
~/.cursor/mcp.json
{
  "mcpServers": {
    "scopegate": {
      "url": "https://scopegate.dev/api/mcp/{api_key}"
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • Gmail — Read emails, send email, list labels, search emails
  • Google Calendar — List events, create event, update event, delete event
  • Google Drive — List files, read file, create file, delete file
  • Service Connection Management — Connect OAuth services, manage credentials, refresh tokens automatically
  • MCP Endpoint Management — Create scoped MCP endpoints, assign per-action permissions, manage API keys
  • Audit Logging — Track all requests with action, status, duration, and error details

Use cases

  • Grant an AI agent read-only Gmail access without send permissions for email analysis
  • Create a scoped Slack endpoint that can post messages but not delete channels
  • Set up a Google Drive endpoint for an agent to read files only, preventing accidental deletions
  • Audit all API calls made by agents across multiple services in a centralized dashboard
  • Revoke agent access to a service instantly without re-authenticating the underlying connection

ScopeGate MCP server FAQ

What is ScopeGate?

ScopeGate is a permission gateway that lets you grant AI agents fine-grained access to external services via MCP endpoints. Instead of handing over full OAuth scopes, you specify exactly which actions (e.g., `gmail:read_emails`) each agent can perform, with full audit logging and one-click revocation.

Is ScopeGate free?

ScopeGate is open-source and free to self-host with Docker. A hosted cloud version is also available at scopegate.dev.

How do I install ScopeGate in Cursor or Claude?

After setting up ScopeGate (self-hosted or cloud), create an MCP endpoint in the dashboard with your desired permissions. Copy the endpoint URL (e.g., `https://scopegate.dev/api/mcp/{api_key}`) and add it to your MCP client configuration as a remote Streamable HTTP server.

What services does ScopeGate support?

ScopeGate supports 27 providers including Google Workspace (Gmail, Calendar, Drive, Sheets), Google Ads & Search Console, Meta, LinkedIn, Twitter, Slack, Notion, Jira, HubSpot, Salesforce, Stripe, Airtable, and more.

Do I need to provide my service credentials to ScopeGate?

Yes, you authenticate each service once via OAuth in the ScopeGate dashboard. Tokens are encrypted at rest with AES-256-GCM and refreshed automatically. Agents only ever see the scoped MCP endpoint key (`sg_…`), never the actual credentials.

Can I revoke agent access without disconnecting the service?

Yes. You can regenerate an MCP endpoint key with one click, which instantly revokes the agent's access while keeping the underlying service connection active for other endpoints.

README (reference)

Source of truth, from the repository.

ScopeGate

Never hand an AI agent a full OAuth scope again.

ScopeGate sits between your agents and the accounts they reach — yours or your clients'. You connect a service once, tick the exact actions an agent may call, and hand it an MCP endpoint that can do nothing else. Every call is logged; one click kills the key without touching the connection.

  • Per-action permissions — gmail:read_emails yes, gmail:send_email no. Finer than any provider's OAuth scopes.
  • Audit trail — who, which tool, what outcome, how long. Per project, exportable.
  • One-click revocation — regenerate an endpoint key; the service connection stays.
  • Tokens never leave — AES-256-GCM at rest, refreshed automatically, agents only ever see sg_….

Run it yourself in one command:

docker compose --profile local up

Open http://localhost:3000 — the admin login is printed in the container logs on first boot. Details in Quick Start.

Tech Stack

  • Framework: Next.js 16 (App Router)
  • Language: TypeScript
  • Database: PostgreSQL + Prisma 7
  • UI: Tailwind CSS v4, shadcn/ui
  • Auth: Better Auth (database-backed sessions, Prisma adapter)
  • MCP: @modelcontextprotocol/sdk (Streamable HTTP)
  • Package Manager: pnpm

Quick Start (self-hosted)

Full feature parity with the hosted cloud version — nothing is cut for self-host.

git clone https://github.com/alifanov/scopegate.git
cd scopegate
docker compose --profile local up

Open http://localhost:3000. No .env file needed: a local Postgres and a fresh BETTER_AUTH_SECRET are provisioned automatically, and the generated admin login is printed once in the app container logs on first boot (look for Generated admin login) — search it with docker compose logs app | grep -A4 "First run". The password is also saved to the app_data volume so it survives restarts.

To connect real services (Gmail, LinkedIn, GitHub, …), copy .env.example to .env and fill in the OAuth client id/secret for the providers you want — every block is independent and optional, a provider without credentials simply doesn't show up.

Development Setup

Prerequisites

  • Node.js 20.19+, 22.12+ or 24+ (required by Prisma 7)
  • pnpm
  • PostgreSQL

Setup

  1. Clone the repository and install dependencies:
pnpm install
  1. Copy the environment file and fill in your values:
cp .env.example .env
VariableDescription
DATABASE_URLPostgreSQL connection string
BETTER_AUTH_SECRETSecret key for session signing
BETTER_AUTH_URLApp base URL (e.g. http://localhost:3000)
ADMIN_EMAILBootstrap admin email
ADMIN_PASSWORDBootstrap admin password
  1. Run database migrations:
pnpm prisma migrate dev
  1. Start the development server:
pnpm dev

Open http://localhost:3000.

Project Structure

src/
├── app/
│   ├── (auth)/              # Login & register pages
│   ├── (dashboard)/         # Protected dashboard pages
│   │   └── projects/        # Project management, endpoints, audit, settings
│   ├── api/
│   │   ├── auth/[...all]/    # Better Auth catch-all handler
│   │   ├── projects/        # Projects CRUD, endpoints, services, audit
│   │   └── mcp/[apiKey]/    # MCP Streamable HTTP handler
│   ├── layout.tsx
│   └── page.tsx             # Landing page
├── components/
│   ├── ui/                  # shadcn/ui components
│   ├── layout/              # Sidebar, header
│   └── shared/              # Reusable app components
├── lib/
│   ├── db.ts                # Prisma client singleton
│   ├── auth.ts              # Better Auth server instance
│   ├── auth-client.ts       # Better Auth client SDK
│   ├── auth-middleware.ts   # getCurrentUser() helper
│   ├── bootstrap.ts         # Admin user bootstrap on empty DB
│   ├── provider-registry.ts # Every supported provider — the one file to edit
│   └── mcp/
│       ├── permissions.ts   # Permission groups (derived from the registry)
│       ├── tools/           # One file per service, aggregated in index.ts
│       ├── service-fetch.ts # Unified, SSRF-safe transport for all providers
│       └── handler.ts       # MCP server factory + audit logging
├── generated/prisma/        # Generated Prisma client
└── middleware.ts             # Route protection

Available Scripts

pnpm dev              # Start development server
pnpm build            # Production build
pnpm start            # Start production server
pnpm lint             # Run ESLint
pnpm prisma generate  # Regenerate Prisma client
pnpm prisma migrate dev  # Create and apply migrations
pnpm prisma studio    # Open Prisma Studio (DB browser)

How It Works

  1. Login — sign in with admin credentials (bootstrapped from env vars on first run)
  2. Create a Project — organize endpoints and services by project
  3. Connect a Service — add a service connection to the project
  4. Create an MCP Endpoint — select a service connection and pick specific permissions (e.g. gmail:read_emails, calendar:create_event)
  5. Use the MCP URL — plug the endpoint URL into any MCP-compatible AI agent; only the allowed actions are exposed
  6. Monitor — track every request in the audit log

Permissions

A permission is a single action, not a service — gmail:read_emails can be granted without gmail:send_email. Groups are derived from src/lib/provider-registry.ts (27 providers: Google Workspace, Google Ads & Search Console, Meta, LinkedIn, Twitter, Slack, Notion, Jira, HubSpot, Salesforce, Stripe, Airtable, …) and listed in src/lib/mcp/permissions.ts. Adding a provider means editing the registry — transport, token strategy and permission groups are all derived from it.

A few Google examples:

GroupActions
Gmailgmail:read_emails, gmail:send_email, gmail:list_labels, gmail:search_emails
Google Calendarcalendar:list_events, calendar:create_event, calendar:update_event, calendar:delete_event
Google Drivedrive:list_files, drive:read_file, drive:create_file, drive:delete_file

Database Schema

  • User — authentication, team membership
  • Session — database-backed auth sessions
  • Account — auth provider credentials (email/password)
  • Project — logical grouping for services and endpoints
  • TeamMember — user-project relationship with roles (owner/member)
  • ServiceConnection — OAuth tokens for connected services
  • McpEndpoint — MCP endpoint with API key, rate limit, active status
  • EndpointPermission — allowed actions per endpoint
  • AuditLog — request log with action, status, duration, errors

License

See LICENSE.

Related MCP servers

Cross-tool decision memory for AI coding agents: search your decision graph, check changes over MCP.

2
TypeScript
MIT
View repository →

Remove watermarks and overlays from images the user owns or has permission to edit.

ALALM X++ MCP Server logo

D365 F&O: 90 AI tools over 200K+ objects, 25M+ cross-refs, 24M+ label translations.

2
View repository →

Coordination memory with verification: reconcile-against-GitHub, verdict freshness, provenance.

0
Python
View repository →

MCP server for managing Docker containers, images, networks, volumes, and registries

2
TypeScript
View repository →

Production MCP server for The Noun Project — search & download icons in Cursor/Claude with OAuth…

3
TypeScript
MIT
View repository →