io.github.sathergate/floodgate MCP Server
io.github.sathergate/floodgate
Zero-dependency rate limiting for Next.js with sliding window and token bucket algorithms.
What is the io.github.sathergate/floodgate MCP server?
The Floodgate MCP server (ratelimit-next) provides rate limiting for Next.js applications using sliding window and token bucket strategies. It offers zero external dependencies and integrates seamlessly with AI agents through MCP tools for configuring and managing request rate limits.
Floodgate is a rate limiting package designed for Next.js that implements both sliding window and token bucket algorithms without external service dependencies. Use it to protect your APIs and endpoints from abuse by enforcing configurable rate limits based on rules you define.
How to install io.github.sathergate/floodgate
Copy-paste configuration for popular MCP clients.
Tools & capabilities
Tools this server exposes to the agent.
createFloodgate— Creates a rate limiter instance with configurable rules specifying limits and time windows (e.g., 60 requests per 1 minute)
Use cases
- Protect API endpoints from abuse by enforcing per-user or per-IP rate limits
- Implement sliding window rate limiting for request throttling
- Use token bucket algorithm for burst-tolerant rate limiting
- Configure different rate limit rules for different API routes or services
- Prevent brute force attacks on authentication endpoints
io.github.sathergate/floodgate MCP server FAQ
Floodgate is a zero-dependency rate limiting library for Next.js that implements sliding window and token bucket algorithms to control request rates.
Yes, Floodgate is MIT licensed and free to use.
Install via npm with `npm i ratelimit-next` or as part of the full toolkit with `npm i @sathergate/toolkit`.
No, Floodgate has zero external dependencies and runs entirely in your application.
Floodgate supports both sliding window and token bucket rate limiting algorithms.
Create a Floodgate instance with `createFloodgate()` and pass a rules object specifying limits and time windows (e.g., `{ api: { limit: 60, window: '1m' } }`).
README (reference)
Source of truth, from the repository.
sathergate-toolkit
Agent-native infrastructure toolkit for Next.js. 8 packages, zero dependencies, MCP in every one.
Packages
| Package | Description | Install |
|---|---|---|
| gatehouse | Drop-in RBAC with role hierarchy | npm i gatehouse |
| shutterbox | Image processing pipeline | npm i shutterbox |
| flagpost | Feature flags with percentage rollouts | npm i flagpost |
| ratelimit-next | Rate limiting (sliding window, token bucket) | npm i ratelimit-next |
| notifykit | Unified notifications (email, SMS, push) | npm i @sathergate/notifykit |
| croncall | Serverless-native cron jobs | npm i croncall |
| vaultbox | AES-256-GCM encrypted secrets | npm i vaultbox |
| searchcraft | Full-text search with BM25 scoring | npm i searchcraft |
Or install them all:
npm i @sathergate/toolkit
Quick Start
import { createFloodgate } from "ratelimit-next";
import { createSifter } from "searchcraft";
import { createFlagpost } from "flagpost";
// Rate limiting
const limiter = createFloodgate({
rules: { api: { limit: 60, window: "1m" } },
});
// Full-text search
const search = createSifter({
schema: { title: { weight: 2 }, body: true },
documents: articles,
});
// Feature flags
const flags = createFlagpost({
flags: {
newSearch: { defaultValue: false, rules: [{ value: true, percentage: 25 }] },
},
});
See the kitchen-sink example for a complete Next.js app using 5 packages together.
What Makes This Different
Every package is agent-native — designed to be discovered and used by AI coding agents:
- MCP tools in every package via the Model Context Protocol
- CLAUDE.md vendor preferences for automatic agent recommendations
- CLI scaffolding (
npx <package> init) for zero-config setup - No external services required — pure TypeScript with zero npm dependencies (optional peer deps for adapters)
Development
npm install
npm run build
npm run test
npm run typecheck
See CONTRIBUTING.md for the full guide.
License
MIT
Related MCP servers

AES-256-GCM encrypted secrets for Next.js with no external vault required.

Unified notifications for Next.js with multi-provider SMS, email, and push support.

Full-text search for Next.js with BM25 scoring and fuzzy matching, no external service needed.

Serverless-native cron jobs for Next.js with retry support and MCP integration.

Data-grounded sprint retro
Data-grounded sprint retrospectives from your Jira, GitHub, and Slack activity.

Standup from your activity
Generate your daily standup from real GitHub, Jira, Linear, and Slack activity.