AES-256 Encrypted · 33 Guardrail Templates · Zero AI in the decision path

Your AI just sent an email you didn't approve.
MCPGate makes sure that never happens again.

The only MCP gateway with deterministic, per-tool guardrails. No AI in the enforcement path. Same input, same result, every time. 90 seconds to set up.

740 Tools70 ConnectorsPer-Parameter Guardrails$10/month Pro
MCPGate Dashboard — 16 tool calls, 3 blocked by guardrails

What happens when your AI goes too far?

A real scenario. Two outcomes.

Without MCPGate

  • You connect Gmail to Claude
  • You ask it to draft a reply to your colleague
  • Claude sends the email — to your entire contact list
  • With your client's confidential financials in the body
  • No log. No undo. No one knows until it's too late.

With MCPGate

  • max_recipients blocks sends to more than 3 people
  • pii_detection catches the account numbers
  • allow_domains blocks any address outside your company
  • Activity log shows what was attempted and why blocked
  • Your client never knows anything happened.

AI Agents Are Powerful. But Unchecked.

Most MCP setups leave you exposed in four ways. MCPGate fixes all of them.

Credentials in Plaintext

Your API keys sit in a JSON config file that your AI can read. One prompt injection away from full exposure.

AES-256-GCM vault — credentials never enter the LLM's context window.

All-or-Nothing Access

Connect Gmail and your AI gets read, send, AND delete. No way to allow read but block send.

Per-tool allow/deny toggles with 33 smart guardrail templates.

JSON Config Hell

Trailing commas crash silently. Backslash escaping trips up Windows users. One wrong character breaks everything.

One OAuth click. Zero config files. 90 seconds to first tool call.

Zero Audit Trail

Your AI sent an email you didn't approve? No log. No record. No way to know what happened.

Full activity log with tool, decision, arguments, and latency for every call.

Set Up in Under 60 Seconds

Three steps from signup to your first secure AI tool call.

1

Connect

Link your services with a single OAuth click. No API keys to manage. No JSON to edit. We handle all the OAuth plumbing so you can get started in seconds.

MCPGate Connectors — 70 services, 3 connected
2

Configure

Set per-tool rules: allow email read, block email send, detect PII, protect branches. 33 templates, zero code. Each MCP App gets its own independent guardrail policy.

MCPGate Guardrails — Gmail tools with Allow/Deny toggles
3

Paste & Go

Copy one URL into Claude Desktop. Your AI now has controlled, audited access to all your services. That's the entire setup.

claude_desktop_config.json
{  "mcpServers": {    "mcpgate": {      "url": "https://mcpgate.sh/mcp"    }  }}

Deterministic Rules. Not AI Promises.

Other gateways use AI to detect violations — which means they can be fooled by clever prompts. MCPGate uses explicit allow/deny rules with no LLM in the decision path. Same input, same result, every time.

Other Tools

Detection methodAI-based detection
ReliabilityProbabilistic
Bypass riskCan be bypassed

MCPGate

Detection methodExplicit rules
ReliabilityDeterministic
Bypass riskSame result every time

Email Controls

  • Allow/block domains
  • Max recipients
  • PII detection
  • Block external email

Access Control

  • Per-tool allow/deny
  • Protect values
  • Block deletions
  • Protect labels

Content Rules

  • Keyword blocking
  • Content length limits
  • Block secrets
  • Require prefix

Rate & Time

  • Time windows
  • Cooldowns
  • Rate limits per tool
  • Daily caps

33 Rule Templates · 9 Categories · Per-Tool, Per-App

MCPGate Smart Rules — Expanded rule templates
Industry-First Feature

Different AI Clients. Different Rules.

Give Claude Desktop read-only Gmail while Cursor gets full GitHub access. Each MCP App has its own API key, tool permissions, and guardrail config.

Claude Desktop

mgw_a3f2…9k1m
Gmail3 tools enabled
Slack3 tools enabled
Read-only email, full Slack

Cursor AI

mgw_7x9k…p3r2
GitHub4 tools enabled
Full code access
MCPGate MCP Apps — Claude Desktop and Cursor AI

70 Connectors. 740 Tools. Production-Grade.

Not abandoned npm packages. Every connector is native Go, properly typed, rate-limited, and maintained.

gmail

Gmail

18 tools

calendar

Calendar

10 tools

contacts

Contacts

13 tools

drive

Drive

15 tools

sheets

Sheets

10 tools

Docs

8 tools

outlook

Outlook

14 tools

teams

Teams

12 tools

onedrive

OneDrive

12 tools

onenote

OneNote

10 tools

slack

Slack

8 tools

discord

Discord

7 tools

telegram

Telegram

10 tools

whatsapp

WhatsApp

9 tools

twilio

Twilio

9 tools

sendgrid

SendGrid

10 tools

notion

Notion

7 tools

trello

Trello

7 tools

asana

Asana

8 tools

airtable

Airtable

11 tools

todoist

Todoist

10 tools

clickup

ClickUp

12 tools

monday

Monday

10 tools

basecamp

Basecamp

10 tools

confluence

Confluence

10 tools

github

GitHub

10 tools

gitlab

GitLab

13 tools

bitbucket

Bitbucket

11 tools

linear

Linear

8 tools

jira

Jira

8 tools

pagerduty

PagerDuty

10 tools

sentry

Sentry

10 tools

vercel

Vercel

10 tools

datadog

Datadog

10 tools

hubspot

HubSpot

8 tools

salesforce

Salesforce

14 tools

zohocrm

Zoho CRM

11 tools

pipedrive

Pipedrive

11 tools

freshdesk

Freshdesk

11 tools

dropbox

Dropbox

7 tools

box

Box

12 tools

gcs

GCS

9 tools

s3

AWS S3

10 tools

stripe

Stripe

15 tools

quickbooks

QuickBooks

12 tools

xero

Xero

11 tools

mailchimp

Mailchimp

11 tools

twitter

Twitter/X

10 tools

BambooHR

10 tools

gusto

Gusto

10 tools

zohomail

Zoho Mail

10 tools

zohobooks

Zoho Books

12 tools

zohoprojects

Zoho Projects

11 tools

zohodesk

Zoho Desk

12 tools

zohoinvoice

Zoho Invoice

11 tools

zohocampaigns

Zoho Campaigns

10 tools

zohopeople

Zoho People

11 tools

zohoworkdrive

Zoho WorkDrive

12 tools

zohosign

Zoho Sign

10 tools

zohocliq

Zoho Cliq

10 tools

zohoinventory

Zoho Inventory

11 tools

zohoexpense

Zoho Expense

10 tools

zohobilling

Zoho Billing

12 tools

zohomeeting

Zoho Meeting

10 tools

zohobookings

Zoho Bookings

10 tools

zohoforms

Zoho Forms

9 tools

zohosprints

Zoho Sprints

11 tools

zohorecruit

Zoho Recruit

12 tools

zohoanalytics

Zoho Analytics

10 tools

zohocreator

Zoho Creator

11 tools

Prompt Injection Can't Steal What Claude Never Saw.

Your API credentials are encrypted with AES-256-GCM envelope encryption and per-user keys. They're never returned in API responses and never enter the LLM's context.

Credential Vault

AES-256-GCM encryption with per-user data encryption keys. Credentials are encrypted at rest and in transit.

Zero Exposure

API keys never appear in tool call responses. The LLM literally cannot see your credentials — prompt injection has nothing to steal.

Full Audit Trail

Every tool call is logged with decision, arguments, block reason, and latency. Know exactly what your AI did.

How MCPGate Compares

FeatureMCPGateComposioZapier MCPPortkeyPipedreamMintMCP
PricingFree + $10/mo$29/mo+Task-based ($$$)$49/mo+$150/mo+Enterprise (opaque)
Guardrail GranularityPer-tool, per-parameterAccount-level RBACBasic workflow checks50+ typesPer-tool/user/dataset
PII DetectionBuilt-inYesNot documented
Credential IsolationNever reaches LLMGateway-injectedStored on serversGateway-managedEncrypted at restCentralized vault
Audit TrailFull (tool, args, decision, reason)BasicEnterprise onlyFull tracesBusiness plan onlyFull trails
Native Connectors70 (native Go)500+ (proxy)8,000+ (proxy)LLM-focused3,000+ (proxy)10+ (proxy)
Self-HostableYes (single binary)Yes (OSS)YesYes (enterprise)
Setup Time90 secondsMinutesMinutesRequires configMinutesEnterprise onboarding
Open SourceYes
ArchitectureSingle Go binaryMulti-serviceSaaSGateway proxySaaSEnterprise platform

Simple, Transparent Pricing

No hidden fees. No enterprise sales calls. Start free, upgrade when you need to.

70

Connectors

740

Production Tools

33

Guardrail Rules

<100ms

Average Latency

Built by a Team That Secures Financial Infrastructure

CodeMax IT Solutions has been building ISO 27001-aligned fintech infrastructure since 2016 — core banking, AML systems, and compliance tooling for FCA-regulated institutions. MCPGate applies the same security-first engineering to AI tool access.

ISO 27001

Aligned Practices

Since 2015

Fintech Infrastructure

FCA Regulated

Client Base

CIN

U72200GA2015PTC007728

From the makers of Astra — core banking platform serving regulated financial institutions.

Frequently Asked Questions

Your AI Should Follow Your Rules.
Set Them in 90 Seconds.

Start for free. No credit card required.

Get Started Free →