Skip to main content
ClaudeWave

Gateway for AI agents and MCP tools: Observe traffic, Control owner budgets, Admit paid outside agents. Every allow or deny comes with a signed receipt.

MCP ServersRegistry oficial11 estrellas3 forks● TypeScriptApache-2.0Actualizado today
ClaudeWave Trust Score
95/100
✓ Verified
Passed
  • ✓Open-source license (Apache-2.0)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Last scanned: 9/29/2026
Install in Claude Code / Claude Desktop
Method: pip / Python · satgate
Claude Code CLI
claude mcp add satgate -- python -m satgate
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "satgate": {
      "command": "python",
      "args": ["-m", "satgate"],
      "env": {
        "ADMIN_TOKEN": "<admin_token>"
      }
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Install first: pip install satgate
Detected environment variables
ADMIN_TOKEN
Casos de uso

Resumen de MCP Servers

<p align="center">
  <img src="docs/assets/logo.png" alt="SatGate" width="120" />
</p>

<h1 align="center">SatGate</h1>

<p align="center">
  <strong>Observe, control and admit AI agent traffic</strong><br/>
  <em>Every allow or deny comes with a signed receipt</em>
</p>

<p align="center">
  <a href="https://github.com/satgate-io/satgate/actions"><img src="https://github.com/satgate-io/satgate/workflows/CI/badge.svg" alt="CI Status"></a>
  <a href="https://goreportcard.com/report/github.com/satgate-io/satgate"><img src="https://goreportcard.com/badge/github.com/satgate-io/satgate" alt="Go Report Card"></a>
  <a href="https://pkg.go.dev/github.com/satgate-io/satgate"><img src="https://pkg.go.dev/badge/github.com/satgate-io/satgate.svg" alt="Go Reference"></a>
  <a href="LICENSE"><img src="https://img.shields.io/badge/License-Apache%202.0-blue.svg" alt="License"></a>
</p>

<p align="center">
  <a href="#the-problem">Why</a> •
  <a href="#build-agents-with-satgate">Build</a> •
  <a href="#features">Features</a> •
  <a href="#quick-start">Quick Start</a> •
  <a href="#documentation">Docs</a> •
  <a href="https://satgate.io">Website</a> •
  <a href="https://satgate.io/blog/why-routing-isnt-governance">Blog</a>
</p>

---

SatGate is a gateway in front of APIs and MCP tools. It meters agent and MCP traffic (**Observe**), enforces owner budgets before work runs (**Control**), and charges outside agents on the routes you choose (**Admit**; the Charge policy in the dashboard). Every allow or deny comes with a signed receipt.

Try it as an agent. This hosted route costs 10 sats:

```bash
curl -i -H "X-SatGate-Tenant: satgate-demo" https://api.satgate.io/paid/agent-demo
```

The unpaid call returns HTTP 402 with a Lightning invoice and terms. Agent instructions are in [llms.txt](https://satgate.io/llms.txt).

## Build Agents with SatGate

SatGate's developer primitive is three calls: `issue()`, `pay()`, and `verify()`.

```python
import os
from satgate import SatGate

satgate = SatGate(api_key=os.getenv("SATGATE_API_KEY"))

capability = satgate.issue(
    task="research market prices",
    agent="research-agent",
    allow=["mcp:web.search", "api:prices.read"],
    budget_usd=25,
    expires_in="1h",
)

receipt = satgate.pay(
    upstream="https://api.example.com/search",
    capability=capability,
    max_usd=4.20,
)

verified = satgate.verify(receipt)
print(verified.decision, verified.evidence_pack_id)
```

Install today:

```bash
pip install satgate
npm install @satgate/sdk
```

The public packages install today; the `issue/pay/verify` API namespace is in private beta. Calls without private-beta access raise a structured error instead of returning fake receipts:

```text
SatGateAuthError: This API namespace requires private beta access. Visit cloud.satgate.io/docs to request access.
```

Runnable examples:

- `examples/python/issue_pay_verify.py`
- `examples/node/issue-pay-verify.mjs`

Works with: MCP · OpenAI tools · Anthropic tools · LangChain · CrewAI · Raw HTTP

---

<div align="center">

### 🎬 See SatGate in Action

<a href="https://satgate.io#explainer"><img src="https://img.shields.io/badge/▶_Explainer-30s-purple?style=for-the-badge" alt="Watch Explainer"></a>&nbsp;&nbsp;<a href="https://satgate.io#delegation"><img src="https://img.shields.io/badge/▶_Token_Delegation-45s-blue?style=for-the-badge" alt="Watch Delegation"></a>

</div>

---

<div align="center">

### ☁️ Don't want to self-host? Try SatGate Cloud

**Managed SaaS — zero setup, multi-tenant isolation, enterprise dashboard.**<br/>
Free Observe tier. No credit card required.

<a href="https://cloud.satgate.io"><img src="https://img.shields.io/badge/🚀_Try_SatGate_Cloud-Free-blue?style=for-the-badge" alt="Try SatGate Cloud"></a>

</div>

---

## The Problem

AI agents are making API calls autonomously. They spawn sub-agents, call MCP tools, and run overnight while you sleep.

Your existing stack answers: *"Is this request authenticated?"*

Nobody answers: **"Should this agent have authority to spend, delegate, or invoke this paid resource?"**

```
✓ Network Firewall    → "Can this packet enter?"
✓ Application Firewall → "Is this request safe?"
? Economic Firewall    → "Should this agent act, spend, or pay?"
```

That's the gap. SatGate fills it.

## What is SatGate?

SatGate is an **Economic Firewall** for AI agent requests. Drop it in front of your APIs and MCP tools to enforce scoped authority, budgets, paid-rail context, and Evidence Pack receipts before agents act.

**Not another routing layer.** Routing gateways (Bifrost, LiteLLM, Portkey) optimize *which provider* handles a call. SatGate governs *whether the call should happen at all* based on authority, policy, budget, and paid-rail context.

Use them together:

```
Agent → SatGate (economic governance) → Routing Gateway → LLM Providers
```

## Features

- 🛡️ **Capability Tokens (Macaroons)** — Cryptographic credentials with built-in caveats, delegation, and next-request revocation. Not API keys — tokens that agents can safely sub-delegate.
- 🎯 **MCP-Aware** — Parses MCP JSON-RPC tool calls. Know that Agent X spent $47 on `search_database` and $12 on `send_email` — not just "1,000 requests."
- 💰 **Budget Enforcement** — Hard stops per agent, team, or API. When the budget hits zero, requests are *blocked*. Not logged. Not alerted. Blocked.
- ⚡ **Paid-Rail Governance** — Govern paid API access across L402, x402, API-key billing, and enterprise ledgers without making any one rail the control plane.
- 🔒 **Default-Deny** — All routes require valid credentials unless explicitly public. Zero Trust by design.
- 🚀 **<50ms Overhead** — Lightweight Go proxy. Adds governance without adding latency.
- 📦 **Self-Hosted** — Your infrastructure, your rules. Single binary, Docker, or Kubernetes.
- 🔌 **Drop-in** — Works with any HTTP backend. REST, GraphQL, MCP servers. No code changes.

## Quick Start

### 60-Second Demo

```bash
# Download the binary (macOS Apple Silicon — see Releases for other platforms)
curl -L https://github.com/satgate-io/satgate/releases/latest/download/satgate-darwin-arm64 -o satgate
chmod +x satgate

# Start with example config (mock Lightning, auto-generated keys)
export ADMIN_TOKEN=my-secret-token
export LIGHTNING_BACKEND=mock
./satgate --config examples/gateway.yaml
```

**Try the three policies:**

```bash
# 1. Public — no auth needed
curl http://localhost:8080/health

# 2. Protected — mint a capability token, then use it
curl -X POST http://localhost:8080/api/capability/mint \
  -H "X-Admin-Token: my-secret-token" \
  -H "Content-Type: application/json" \
  -d '{"scope": "api:read", "duration": "1h"}'

# Use the token:
curl -H "Authorization: Bearer YOUR_CAPABILITY_TOKEN" \
  http://localhost:8080/api/capability/ping

# 3. Paid — get a payment challenge (L402 today; x402/other rails as governed context)
curl http://localhost:8080/api/micro
```

Public → Protected → Paid. Three policies, one gateway; paid rails are governed context, not the product boundary.

Hosted paid demo (Admit; Charge in the dashboard). No local Lightning node:

```bash
curl -i -H "X-SatGate-Tenant: satgate-demo" https://api.satgate.io/paid/agent-demo
```

Unpaid calls return 402. Price is 10 sats. Show the invoice to the owner, poll payment status, then retry. Poll rules are in [llms.txt](https://satgate.io/llms.txt).

📖 **[Full Quick Start Guide →](docs/getting-started/quickstart.md)**

### Other Install Methods

```bash
# Docker
docker run -v $(pwd)/gateway.yaml:/etc/satgate/gateway.yaml \
  -e ADMIN_TOKEN=my-secret-token -e LIGHTNING_BACKEND=mock \
  -p 8080:8080 ghcr.io/satgate-io/satgate:latest

# Build from source
git clone https://github.com/satgate-io/satgate.git
cd satgate && go build -o satgate ./cmd/satgate
```

## Configuration

```yaml
version: 1

server:
  listen: ":8080"

admin:
  capabilityRootKey: "${CAPABILITY_ROOT_KEY}"

lightning:
  provider: "${LIGHTNING_BACKEND}"
  config:
    connectionString: "${NWC_CONNECTION_STRING}"

upstreams:
  api:
    url: "http://localhost:3000"

routes:
  - name: public-health
    match:
      pathPrefix: /health
    upstream: api
    policy:
      kind: public

  - name: protected-api
    match:
      pathPrefix: /api/
    upstream: api
    policy:
      kind: capability
      scope: "api:read"

  - name: premium-api
    match:
      pathPrefix: /premium/
    upstream: api
    policy:
      kind: l402  # paid-rail policy; use payment_context to preserve L402/x402/ledger evidence
      priceSats: 100
```

## Policy Types

| Policy | Description | Use Case |
|--------|-------------|----------|
| `public` | No authentication | Health checks, docs, webhooks |
| `capability` | Requires valid Macaroon | Protected API endpoints |
| `l402` | Requires Lightning payment and records paid-rail context | Monetized endpoints; x402/ledger context can be preserved in Evidence Packs |

## How It's Different

| | SatGate | Routing Gateways | Traditional API Gateways |
|---|---|---|---|
| **Primary concern** | Economic governance | Provider routing | Traffic management |
| **Budget enforcement** | Hard caps (blocked at limit) | Soft alerts only | ❌ |
| **MCP cost attribution** | Per-tool granularity | ❌ | ❌ |
| **Credential model** | Macaroons (delegatable) | API keys | API keys / OAuth |
| **Agent delegation** | Sub-tokens with reduced budgets | ❌ | ❌ |
| **Paid-rail governance** | L402, x402, API-key billing, enterprise ledgers | ❌ | ❌ |
| **Works alongside** | — | ✅ Use together | ✅ Use together |

## Architecture

```
┌──────────────────────────────────────────────────┐
│                    SatGate                        │
│                                                   │
│  Request → Route Match → Policy Check → Proxy    │
│                             │                     │
│              ┌──────────────┼──────────────┐     │
│              │              │              │      │
│          [public]    [capability]   [paid rail]  │
│          pass        verify
aiagentsapiapi-gatewaybitcoinl402langchainlightningmcpmcp-gatewaymcp-servermicropayments

Lo que la gente pregunta sobre satgate

¿Qué es SatGate-io/satgate?

+

SatGate-io/satgate es mcp servers para el ecosistema de Claude AI. Gateway for AI agents and MCP tools: Observe traffic, Control owner budgets, Admit paid outside agents. Every allow or deny comes with a signed receipt. Tiene 11 estrellas en GitHub y su última actualización registrada es del 2026-09-29.

¿Cómo se instala satgate?

+

Puedes instalar satgate clonando el repositorio (https://github.com/SatGate-io/satgate) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.

¿Es seguro usar SatGate-io/satgate?

+

Nuestro agente de seguridad ha analizado SatGate-io/satgate y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.

¿Quién mantiene SatGate-io/satgate?

+

SatGate-io/satgate es mantenido por SatGate-io. La última actividad registrada en GitHub es del 2026-09-29, con 15 issues abiertos.

¿Hay alternativas a satgate?

+

Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.

Despliega satgate en tu cloud

Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.

¿Mantienes este repo? Añade un badge a tu README

Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.

Featured on ClaudeWave: SatGate-io/satgate
[![Featured on ClaudeWave](https://claudewave.com/api/badge/satgate-io-satgate)](https://claudewave.com/repo/satgate-io-satgate)
<a href="https://claudewave.com/repo/satgate-io-satgate"><img src="https://claudewave.com/api/badge/satgate-io-satgate" alt="Featured on ClaudeWave: SatGate-io/satgate" width="320" height="64" /></a>

Más MCP Servers

Alternativas a satgate