Skip to main content
ClaudeWave

Gateway for AI agents and MCP tools: Observe traffic, Control owner budgets, Admit paid outside agents. Every allow or deny comes with a signed receipt.

MCP ServersOfficial Registry11 stars3 forks● TypeScriptApache-2.0Updated today
ClaudeWave Trust Score
95/100
✓ Verified
Passed
  • ✓Open-source license (Apache-2.0)
  • ✓Actively maintained (<30d)
  • ✓Clear description
  • ✓Topics declared
  • ✓Documented (README)
Last scanned: 9/29/2026
Install in Claude Code / Claude Desktop
Method: pip / Python · satgate
Claude Code CLI
claude mcp add satgate -- python -m satgate
claude_desktop_config.json (Claude Desktop)
{
  "mcpServers": {
    "satgate": {
      "command": "python",
      "args": ["-m", "satgate"],
      "env": {
        "ADMIN_TOKEN": "<admin_token>"
      }
    }
  }
}
1. Run the command above in your terminal (Claude Code), or paste the JSON config into claude_desktop_config.json (Claude Desktop).
2. Replace any <placeholder> values with your API keys or paths.
3. Restart Claude. The MCP server and its tools appear automatically.
💡 Install first: pip install satgate
Detected environment variables
ADMIN_TOKEN
Use cases

MCP Servers overview

<p align="center">
  <img src="docs/assets/logo.png" alt="SatGate" width="120" />
</p>

<h1 align="center">SatGate</h1>

<p align="center">
  <strong>Observe, control and admit AI agent traffic</strong><br/>
  <em>Every allow or deny comes with a signed receipt</em>
</p>

<p align="center">
  <a href="https://github.com/satgate-io/satgate/actions"><img src="https://github.com/satgate-io/satgate/workflows/CI/badge.svg" alt="CI Status"></a>
  <a href="https://goreportcard.com/report/github.com/satgate-io/satgate"><img src="https://goreportcard.com/badge/github.com/satgate-io/satgate" alt="Go Report Card"></a>
  <a href="https://pkg.go.dev/github.com/satgate-io/satgate"><img src="https://pkg.go.dev/badge/github.com/satgate-io/satgate.svg" alt="Go Reference"></a>
  <a href="LICENSE"><img src="https://img.shields.io/badge/License-Apache%202.0-blue.svg" alt="License"></a>
</p>

<p align="center">
  <a href="#the-problem">Why</a> •
  <a href="#build-agents-with-satgate">Build</a> •
  <a href="#features">Features</a> •
  <a href="#quick-start">Quick Start</a> •
  <a href="#documentation">Docs</a> •
  <a href="https://satgate.io">Website</a> •
  <a href="https://satgate.io/blog/why-routing-isnt-governance">Blog</a>
</p>

---

SatGate is a gateway in front of APIs and MCP tools. It meters agent and MCP traffic (**Observe**), enforces owner budgets before work runs (**Control**), and charges outside agents on the routes you choose (**Admit**; the Charge policy in the dashboard). Every allow or deny comes with a signed receipt.

Try it as an agent. This hosted route costs 10 sats:

```bash
curl -i -H "X-SatGate-Tenant: satgate-demo" https://api.satgate.io/paid/agent-demo
```

The unpaid call returns HTTP 402 with a Lightning invoice and terms. Agent instructions are in [llms.txt](https://satgate.io/llms.txt).

## Build Agents with SatGate

SatGate's developer primitive is three calls: `issue()`, `pay()`, and `verify()`.

```python
import os
from satgate import SatGate

satgate = SatGate(api_key=os.getenv("SATGATE_API_KEY"))

capability = satgate.issue(
    task="research market prices",
    agent="research-agent",
    allow=["mcp:web.search", "api:prices.read"],
    budget_usd=25,
    expires_in="1h",
)

receipt = satgate.pay(
    upstream="https://api.example.com/search",
    capability=capability,
    max_usd=4.20,
)

verified = satgate.verify(receipt)
print(verified.decision, verified.evidence_pack_id)
```

Install today:

```bash
pip install satgate
npm install @satgate/sdk
```

The public packages install today; the `issue/pay/verify` API namespace is in private beta. Calls without private-beta access raise a structured error instead of returning fake receipts:

```text
SatGateAuthError: This API namespace requires private beta access. Visit cloud.satgate.io/docs to request access.
```

Runnable examples:

- `examples/python/issue_pay_verify.py`
- `examples/node/issue-pay-verify.mjs`

Works with: MCP · OpenAI tools · Anthropic tools · LangChain · CrewAI · Raw HTTP

---

<div align="center">

### 🎬 See SatGate in Action

<a href="https://satgate.io#explainer"><img src="https://img.shields.io/badge/▶_Explainer-30s-purple?style=for-the-badge" alt="Watch Explainer"></a>&nbsp;&nbsp;<a href="https://satgate.io#delegation"><img src="https://img.shields.io/badge/▶_Token_Delegation-45s-blue?style=for-the-badge" alt="Watch Delegation"></a>

</div>

---

<div align="center">

### ☁️ Don't want to self-host? Try SatGate Cloud

**Managed SaaS — zero setup, multi-tenant isolation, enterprise dashboard.**<br/>
Free Observe tier. No credit card required.

<a href="https://cloud.satgate.io"><img src="https://img.shields.io/badge/🚀_Try_SatGate_Cloud-Free-blue?style=for-the-badge" alt="Try SatGate Cloud"></a>

</div>

---

## The Problem

AI agents are making API calls autonomously. They spawn sub-agents, call MCP tools, and run overnight while you sleep.

Your existing stack answers: *"Is this request authenticated?"*

Nobody answers: **"Should this agent have authority to spend, delegate, or invoke this paid resource?"**

```
✓ Network Firewall    → "Can this packet enter?"
✓ Application Firewall → "Is this request safe?"
? Economic Firewall    → "Should this agent act, spend, or pay?"
```

That's the gap. SatGate fills it.

## What is SatGate?

SatGate is an **Economic Firewall** for AI agent requests. Drop it in front of your APIs and MCP tools to enforce scoped authority, budgets, paid-rail context, and Evidence Pack receipts before agents act.

**Not another routing layer.** Routing gateways (Bifrost, LiteLLM, Portkey) optimize *which provider* handles a call. SatGate governs *whether the call should happen at all* based on authority, policy, budget, and paid-rail context.

Use them together:

```
Agent → SatGate (economic governance) → Routing Gateway → LLM Providers
```

## Features

- 🛡️ **Capability Tokens (Macaroons)** — Cryptographic credentials with built-in caveats, delegation, and next-request revocation. Not API keys — tokens that agents can safely sub-delegate.
- 🎯 **MCP-Aware** — Parses MCP JSON-RPC tool calls. Know that Agent X spent $47 on `search_database` and $12 on `send_email` — not just "1,000 requests."
- 💰 **Budget Enforcement** — Hard stops per agent, team, or API. When the budget hits zero, requests are *blocked*. Not logged. Not alerted. Blocked.
- ⚡ **Paid-Rail Governance** — Govern paid API access across L402, x402, API-key billing, and enterprise ledgers without making any one rail the control plane.
- 🔒 **Default-Deny** — All routes require valid credentials unless explicitly public. Zero Trust by design.
- 🚀 **<50ms Overhead** — Lightweight Go proxy. Adds governance without adding latency.
- 📦 **Self-Hosted** — Your infrastructure, your rules. Single binary, Docker, or Kubernetes.
- 🔌 **Drop-in** — Works with any HTTP backend. REST, GraphQL, MCP servers. No code changes.

## Quick Start

### 60-Second Demo

```bash
# Download the binary (macOS Apple Silicon — see Releases for other platforms)
curl -L https://github.com/satgate-io/satgate/releases/latest/download/satgate-darwin-arm64 -o satgate
chmod +x satgate

# Start with example config (mock Lightning, auto-generated keys)
export ADMIN_TOKEN=my-secret-token
export LIGHTNING_BACKEND=mock
./satgate --config examples/gateway.yaml
```

**Try the three policies:**

```bash
# 1. Public — no auth needed
curl http://localhost:8080/health

# 2. Protected — mint a capability token, then use it
curl -X POST http://localhost:8080/api/capability/mint \
  -H "X-Admin-Token: my-secret-token" \
  -H "Content-Type: application/json" \
  -d '{"scope": "api:read", "duration": "1h"}'

# Use the token:
curl -H "Authorization: Bearer YOUR_CAPABILITY_TOKEN" \
  http://localhost:8080/api/capability/ping

# 3. Paid — get a payment challenge (L402 today; x402/other rails as governed context)
curl http://localhost:8080/api/micro
```

Public → Protected → Paid. Three policies, one gateway; paid rails are governed context, not the product boundary.

Hosted paid demo (Admit; Charge in the dashboard). No local Lightning node:

```bash
curl -i -H "X-SatGate-Tenant: satgate-demo" https://api.satgate.io/paid/agent-demo
```

Unpaid calls return 402. Price is 10 sats. Show the invoice to the owner, poll payment status, then retry. Poll rules are in [llms.txt](https://satgate.io/llms.txt).

📖 **[Full Quick Start Guide →](docs/getting-started/quickstart.md)**

### Other Install Methods

```bash
# Docker
docker run -v $(pwd)/gateway.yaml:/etc/satgate/gateway.yaml \
  -e ADMIN_TOKEN=my-secret-token -e LIGHTNING_BACKEND=mock \
  -p 8080:8080 ghcr.io/satgate-io/satgate:latest

# Build from source
git clone https://github.com/satgate-io/satgate.git
cd satgate && go build -o satgate ./cmd/satgate
```

## Configuration

```yaml
version: 1

server:
  listen: ":8080"

admin:
  capabilityRootKey: "${CAPABILITY_ROOT_KEY}"

lightning:
  provider: "${LIGHTNING_BACKEND}"
  config:
    connectionString: "${NWC_CONNECTION_STRING}"

upstreams:
  api:
    url: "http://localhost:3000"

routes:
  - name: public-health
    match:
      pathPrefix: /health
    upstream: api
    policy:
      kind: public

  - name: protected-api
    match:
      pathPrefix: /api/
    upstream: api
    policy:
      kind: capability
      scope: "api:read"

  - name: premium-api
    match:
      pathPrefix: /premium/
    upstream: api
    policy:
      kind: l402  # paid-rail policy; use payment_context to preserve L402/x402/ledger evidence
      priceSats: 100
```

## Policy Types

| Policy | Description | Use Case |
|--------|-------------|----------|
| `public` | No authentication | Health checks, docs, webhooks |
| `capability` | Requires valid Macaroon | Protected API endpoints |
| `l402` | Requires Lightning payment and records paid-rail context | Monetized endpoints; x402/ledger context can be preserved in Evidence Packs |

## How It's Different

| | SatGate | Routing Gateways | Traditional API Gateways |
|---|---|---|---|
| **Primary concern** | Economic governance | Provider routing | Traffic management |
| **Budget enforcement** | Hard caps (blocked at limit) | Soft alerts only | ❌ |
| **MCP cost attribution** | Per-tool granularity | ❌ | ❌ |
| **Credential model** | Macaroons (delegatable) | API keys | API keys / OAuth |
| **Agent delegation** | Sub-tokens with reduced budgets | ❌ | ❌ |
| **Paid-rail governance** | L402, x402, API-key billing, enterprise ledgers | ❌ | ❌ |
| **Works alongside** | — | ✅ Use together | ✅ Use together |

## Architecture

```
┌──────────────────────────────────────────────────┐
│                    SatGate                        │
│                                                   │
│  Request → Route Match → Policy Check → Proxy    │
│                             │                     │
│              ┌──────────────┼──────────────┐     │
│              │              │              │      │
│          [public]    [capability]   [paid rail]  │
│          pass        verify
aiagentsapiapi-gatewaybitcoinl402langchainlightningmcpmcp-gatewaymcp-servermicropayments

What people ask about satgate

What is SatGate-io/satgate?

+

SatGate-io/satgate is mcp servers for the Claude AI ecosystem. Gateway for AI agents and MCP tools: Observe traffic, Control owner budgets, Admit paid outside agents. Every allow or deny comes with a signed receipt. It has 11 GitHub stars and its last recorded update is dated 2026-09-29.

How do I install satgate?

+

You can install satgate by cloning the repository (https://github.com/SatGate-io/satgate) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.

Is SatGate-io/satgate safe to use?

+

Our security agent has analyzed SatGate-io/satgate and assigned a Trust Score of 95/100 (tier: Verified). See the full breakdown of passed checks and flags on this page.

Who maintains SatGate-io/satgate?

+

SatGate-io/satgate is maintained by SatGate-io. The last recorded GitHub activity is dated 2026-09-29, with 15 open issues.

Are there alternatives to satgate?

+

Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.

Deploy satgate to your cloud

Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.

Maintain this repo? Add a badge to your README

Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.

Featured on ClaudeWave: SatGate-io/satgate
[![Featured on ClaudeWave](https://claudewave.com/api/badge/satgate-io-satgate)](https://claudewave.com/repo/satgate-io-satgate)
<a href="https://claudewave.com/repo/satgate-io-satgate"><img src="https://claudewave.com/api/badge/satgate-io-satgate" alt="Featured on ClaudeWave: SatGate-io/satgate" width="320" height="64" /></a>

More MCP Servers

satgate alternatives