Gateway for AI agents and MCP tools: Observe traffic, Control owner budgets, Admit paid outside agents. Every allow or deny comes with a signed receipt.
- ✓Open-source license (Apache-2.0)
- ✓Actively maintained (<30d)
- ✓Clear description
- ✓Topics declared
- ✓Documented (README)
claude mcp add satgate -- python -m satgate{
"mcpServers": {
"satgate": {
"command": "python",
"args": ["-m", "satgate"],
"env": {
"ADMIN_TOKEN": "<admin_token>"
}
}
}
}ADMIN_TOKENResumen de MCP Servers
<p align="center">
<img src="docs/assets/logo.png" alt="SatGate" width="120" />
</p>
<h1 align="center">SatGate</h1>
<p align="center">
<strong>Observe, control and admit AI agent traffic</strong><br/>
<em>Every allow or deny comes with a signed receipt</em>
</p>
<p align="center">
<a href="https://github.com/satgate-io/satgate/actions"><img src="https://github.com/satgate-io/satgate/workflows/CI/badge.svg" alt="CI Status"></a>
<a href="https://goreportcard.com/report/github.com/satgate-io/satgate"><img src="https://goreportcard.com/badge/github.com/satgate-io/satgate" alt="Go Report Card"></a>
<a href="https://pkg.go.dev/github.com/satgate-io/satgate"><img src="https://pkg.go.dev/badge/github.com/satgate-io/satgate.svg" alt="Go Reference"></a>
<a href="LICENSE"><img src="https://img.shields.io/badge/License-Apache%202.0-blue.svg" alt="License"></a>
</p>
<p align="center">
<a href="#the-problem">Why</a> •
<a href="#build-agents-with-satgate">Build</a> •
<a href="#features">Features</a> •
<a href="#quick-start">Quick Start</a> •
<a href="#documentation">Docs</a> •
<a href="https://satgate.io">Website</a> •
<a href="https://satgate.io/blog/why-routing-isnt-governance">Blog</a>
</p>
---
SatGate is a gateway in front of APIs and MCP tools. It meters agent and MCP traffic (**Observe**), enforces owner budgets before work runs (**Control**), and charges outside agents on the routes you choose (**Admit**; the Charge policy in the dashboard). Every allow or deny comes with a signed receipt.
Try it as an agent. This hosted route costs 10 sats:
```bash
curl -i -H "X-SatGate-Tenant: satgate-demo" https://api.satgate.io/paid/agent-demo
```
The unpaid call returns HTTP 402 with a Lightning invoice and terms. Agent instructions are in [llms.txt](https://satgate.io/llms.txt).
## Build Agents with SatGate
SatGate's developer primitive is three calls: `issue()`, `pay()`, and `verify()`.
```python
import os
from satgate import SatGate
satgate = SatGate(api_key=os.getenv("SATGATE_API_KEY"))
capability = satgate.issue(
task="research market prices",
agent="research-agent",
allow=["mcp:web.search", "api:prices.read"],
budget_usd=25,
expires_in="1h",
)
receipt = satgate.pay(
upstream="https://api.example.com/search",
capability=capability,
max_usd=4.20,
)
verified = satgate.verify(receipt)
print(verified.decision, verified.evidence_pack_id)
```
Install today:
```bash
pip install satgate
npm install @satgate/sdk
```
The public packages install today; the `issue/pay/verify` API namespace is in private beta. Calls without private-beta access raise a structured error instead of returning fake receipts:
```text
SatGateAuthError: This API namespace requires private beta access. Visit cloud.satgate.io/docs to request access.
```
Runnable examples:
- `examples/python/issue_pay_verify.py`
- `examples/node/issue-pay-verify.mjs`
Works with: MCP · OpenAI tools · Anthropic tools · LangChain · CrewAI · Raw HTTP
---
<div align="center">
### 🎬 See SatGate in Action
<a href="https://satgate.io#explainer"><img src="https://img.shields.io/badge/▶_Explainer-30s-purple?style=for-the-badge" alt="Watch Explainer"></a> <a href="https://satgate.io#delegation"><img src="https://img.shields.io/badge/▶_Token_Delegation-45s-blue?style=for-the-badge" alt="Watch Delegation"></a>
</div>
---
<div align="center">
### ☁️ Don't want to self-host? Try SatGate Cloud
**Managed SaaS — zero setup, multi-tenant isolation, enterprise dashboard.**<br/>
Free Observe tier. No credit card required.
<a href="https://cloud.satgate.io"><img src="https://img.shields.io/badge/🚀_Try_SatGate_Cloud-Free-blue?style=for-the-badge" alt="Try SatGate Cloud"></a>
</div>
---
## The Problem
AI agents are making API calls autonomously. They spawn sub-agents, call MCP tools, and run overnight while you sleep.
Your existing stack answers: *"Is this request authenticated?"*
Nobody answers: **"Should this agent have authority to spend, delegate, or invoke this paid resource?"**
```
✓ Network Firewall → "Can this packet enter?"
✓ Application Firewall → "Is this request safe?"
? Economic Firewall → "Should this agent act, spend, or pay?"
```
That's the gap. SatGate fills it.
## What is SatGate?
SatGate is an **Economic Firewall** for AI agent requests. Drop it in front of your APIs and MCP tools to enforce scoped authority, budgets, paid-rail context, and Evidence Pack receipts before agents act.
**Not another routing layer.** Routing gateways (Bifrost, LiteLLM, Portkey) optimize *which provider* handles a call. SatGate governs *whether the call should happen at all* based on authority, policy, budget, and paid-rail context.
Use them together:
```
Agent → SatGate (economic governance) → Routing Gateway → LLM Providers
```
## Features
- 🛡️ **Capability Tokens (Macaroons)** — Cryptographic credentials with built-in caveats, delegation, and next-request revocation. Not API keys — tokens that agents can safely sub-delegate.
- 🎯 **MCP-Aware** — Parses MCP JSON-RPC tool calls. Know that Agent X spent $47 on `search_database` and $12 on `send_email` — not just "1,000 requests."
- 💰 **Budget Enforcement** — Hard stops per agent, team, or API. When the budget hits zero, requests are *blocked*. Not logged. Not alerted. Blocked.
- ⚡ **Paid-Rail Governance** — Govern paid API access across L402, x402, API-key billing, and enterprise ledgers without making any one rail the control plane.
- 🔒 **Default-Deny** — All routes require valid credentials unless explicitly public. Zero Trust by design.
- 🚀 **<50ms Overhead** — Lightweight Go proxy. Adds governance without adding latency.
- 📦 **Self-Hosted** — Your infrastructure, your rules. Single binary, Docker, or Kubernetes.
- 🔌 **Drop-in** — Works with any HTTP backend. REST, GraphQL, MCP servers. No code changes.
## Quick Start
### 60-Second Demo
```bash
# Download the binary (macOS Apple Silicon — see Releases for other platforms)
curl -L https://github.com/satgate-io/satgate/releases/latest/download/satgate-darwin-arm64 -o satgate
chmod +x satgate
# Start with example config (mock Lightning, auto-generated keys)
export ADMIN_TOKEN=my-secret-token
export LIGHTNING_BACKEND=mock
./satgate --config examples/gateway.yaml
```
**Try the three policies:**
```bash
# 1. Public — no auth needed
curl http://localhost:8080/health
# 2. Protected — mint a capability token, then use it
curl -X POST http://localhost:8080/api/capability/mint \
-H "X-Admin-Token: my-secret-token" \
-H "Content-Type: application/json" \
-d '{"scope": "api:read", "duration": "1h"}'
# Use the token:
curl -H "Authorization: Bearer YOUR_CAPABILITY_TOKEN" \
http://localhost:8080/api/capability/ping
# 3. Paid — get a payment challenge (L402 today; x402/other rails as governed context)
curl http://localhost:8080/api/micro
```
Public → Protected → Paid. Three policies, one gateway; paid rails are governed context, not the product boundary.
Hosted paid demo (Admit; Charge in the dashboard). No local Lightning node:
```bash
curl -i -H "X-SatGate-Tenant: satgate-demo" https://api.satgate.io/paid/agent-demo
```
Unpaid calls return 402. Price is 10 sats. Show the invoice to the owner, poll payment status, then retry. Poll rules are in [llms.txt](https://satgate.io/llms.txt).
📖 **[Full Quick Start Guide →](docs/getting-started/quickstart.md)**
### Other Install Methods
```bash
# Docker
docker run -v $(pwd)/gateway.yaml:/etc/satgate/gateway.yaml \
-e ADMIN_TOKEN=my-secret-token -e LIGHTNING_BACKEND=mock \
-p 8080:8080 ghcr.io/satgate-io/satgate:latest
# Build from source
git clone https://github.com/satgate-io/satgate.git
cd satgate && go build -o satgate ./cmd/satgate
```
## Configuration
```yaml
version: 1
server:
listen: ":8080"
admin:
capabilityRootKey: "${CAPABILITY_ROOT_KEY}"
lightning:
provider: "${LIGHTNING_BACKEND}"
config:
connectionString: "${NWC_CONNECTION_STRING}"
upstreams:
api:
url: "http://localhost:3000"
routes:
- name: public-health
match:
pathPrefix: /health
upstream: api
policy:
kind: public
- name: protected-api
match:
pathPrefix: /api/
upstream: api
policy:
kind: capability
scope: "api:read"
- name: premium-api
match:
pathPrefix: /premium/
upstream: api
policy:
kind: l402 # paid-rail policy; use payment_context to preserve L402/x402/ledger evidence
priceSats: 100
```
## Policy Types
| Policy | Description | Use Case |
|--------|-------------|----------|
| `public` | No authentication | Health checks, docs, webhooks |
| `capability` | Requires valid Macaroon | Protected API endpoints |
| `l402` | Requires Lightning payment and records paid-rail context | Monetized endpoints; x402/ledger context can be preserved in Evidence Packs |
## How It's Different
| | SatGate | Routing Gateways | Traditional API Gateways |
|---|---|---|---|
| **Primary concern** | Economic governance | Provider routing | Traffic management |
| **Budget enforcement** | Hard caps (blocked at limit) | Soft alerts only | ❌ |
| **MCP cost attribution** | Per-tool granularity | ❌ | ❌ |
| **Credential model** | Macaroons (delegatable) | API keys | API keys / OAuth |
| **Agent delegation** | Sub-tokens with reduced budgets | ❌ | ❌ |
| **Paid-rail governance** | L402, x402, API-key billing, enterprise ledgers | ❌ | ❌ |
| **Works alongside** | — | ✅ Use together | ✅ Use together |
## Architecture
```
┌──────────────────────────────────────────────────┐
│ SatGate │
│ │
│ Request → Route Match → Policy Check → Proxy │
│ │ │
│ ┌──────────────┼──────────────┐ │
│ │ │ │ │
│ [public] [capability] [paid rail] │
│ pass verifyLo que la gente pregunta sobre satgate
¿Qué es SatGate-io/satgate?
+
SatGate-io/satgate es mcp servers para el ecosistema de Claude AI. Gateway for AI agents and MCP tools: Observe traffic, Control owner budgets, Admit paid outside agents. Every allow or deny comes with a signed receipt. Tiene 11 estrellas en GitHub y su última actualización registrada es del 2026-09-29.
¿Cómo se instala satgate?
+
Puedes instalar satgate clonando el repositorio (https://github.com/SatGate-io/satgate) o siguiendo las instrucciones del README en GitHub. ClaudeWave también te ofrece bloques de instalación rápida en esta misma página.
¿Es seguro usar SatGate-io/satgate?
+
Nuestro agente de seguridad ha analizado SatGate-io/satgate y le ha asignado un Trust Score de 95/100 (tier: Verified). Revisa el desglose completo de comprobaciones superadas y flags en esta página.
¿Quién mantiene SatGate-io/satgate?
+
SatGate-io/satgate es mantenido por SatGate-io. La última actividad registrada en GitHub es del 2026-09-29, con 15 issues abiertos.
¿Hay alternativas a satgate?
+
Sí. En ClaudeWave puedes explorar mcp servers similares en /categories/mcp, ordenados por popularidad o actividad reciente.
Despliega satgate en tu cloud
Lleva este repo a producción en minutos. Cada plataforma genera su propio entorno con variables de entorno editables.
¿Mantienes este repo? Añade un badge a tu README
Pega el badge en tu README de GitHub para mostrar que está auditado por ClaudeWave. Cada badge enlaza de vuelta a esta página y muestra el Trust Score actual.
[](https://claudewave.com/repo/satgate-io-satgate)<a href="https://claudewave.com/repo/satgate-io-satgate"><img src="https://claudewave.com/api/badge/satgate-io-satgate" alt="Featured on ClaudeWave: SatGate-io/satgate" width="320" height="64" /></a>Más MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
The fastest path to AI-powered full stack observability, even for lean teams.