Skip to main content
Glama
SoWhatI

MCP Asset Gateway

MCP Asset Gateway

English | 简体中文

A self-hosted asset gateway that provides AI clients with a single, controlled MCP entry point. Manage assets, account credentials, clients, and authorization groups through a web console, with full tool-call auditing.

Features

Type

Highlights

MySQL

Read-only queries and schema reads by default; restricted INSERT/UPDATE/DELETE after allow_write is explicitly enabled per account, with mandatory WHERE on UPDATE/DELETE

SSH

Non-interactive command execution; command arguments controlled by per-group allow/block lists; no PTY or interactive input

FileBrowser

SFTP-based restricted directory browsing and file reading

MCP

Forwards upstream tools with per-account approval of tool definition versions

Redis

Key scanning and reading within allow-list patterns; write tools enabled explicitly per account policy

Kubernetes

Resource listing, details, Pod logs, and non-interactive k8s_exec; token or client-certificate auth — see Kubernetes assets (Chinese)

Git repositories

Gateway-hosted read-only code mirrors: code search, file reading, commit history, diffs, directory tree, and branch listing

Jenkins

Direct Jenkins HTTP API calls without any MCP plugin; 19 tools for jobs, builds, logs, tests, SCM, and Replay — see Jenkins assets (Chinese)

Admin console

Multi-dimensional search in the authorization matrix, group management, tool select-all/clear, parameter allow/block lists (exact/regex), debugging, and audit export

Security foundation

Fernet-encrypted credentials, hashed client tokens, admin sessions with CSRF protection, egress target allow-listing, consistent SQLite backups

Related MCP server: nice

Authorization & Security Model

  • An authorization group links multiple clients with multiple asset accounts; each client in the group gets the selected tools that actually exist on each account. Permissions across groups are merged (union), and identically named tools are published once. Full rules: Authorization groups & parameter rules (Chinese).

  • Tools are unauthorized by default; write operations and high-risk tools (MySQL allow_write, Jenkins write tools, k8s_exec, etc.) must be checked explicitly in an authorization group.

  • Client tokens are shown only once; credentials are stored encrypted; keep the master key separate from the database.

  • Optional egress registration restricts reachable targets; loopback, link-local, multicast, and cloud metadata addresses are always denied. An allow-list is not a substitute for a firewall.

Quick Start

Docker is recommended; Docker and Compose 2.30+ required. No Python needed on the host:

mkdir mcp-asset-gateway && cd mcp-asset-gateway
curl -fsSLO https://raw.githubusercontent.com/SoWhatI/mcp-asset-gateway/main/docker-compose.yml
docker run --rm ghcr.io/sowhati/mcp-asset-gateway:0.1.0 \
  python -m app.cli setup --public-url https://gateway.example.com --output - > .env
chmod 600 .env
docker compose up -d
docker compose run --rm --no-deps gateway python -m app.cli init-admin --generate-password

gateway.example.com is a placeholder — replace it with your actual address; use http://localhost:8303 for local evaluation. Open the console, sign in as admin admin with the one-time password, then change it; there is no built-in default password. For image upgrades, reverse proxying, building from source, and backup/restore, see Deployment & operations (Chinese); for installation, onboarding, and configuration checklists, see the User guide (Chinese).

Run from Source

Requirements: Python 3.11+, Node.js 22 (minimum 20.19), Linux/macOS; on Windows use WSL2 or Docker. Git assets additionally require a system Git with http.curloptResolve support and OpenSSH. SQLite WAL and process file locks are used, so a single instance with a single Uvicorn worker is supported; do not place the database on shared network filesystems.

Local evaluation (from the project root):

python3 -m venv .venv
source .venv/bin/activate
python -m pip install --require-hashes -r requirements.lock
npm ci --prefix web --no-audit --no-fund
npm run build --prefix web
python -m app.cli setup --public-url http://localhost:8303
python -m app.cli init-admin --generate-password
uvicorn app.main:app_factory --factory --host 127.0.0.1 --port 8303 --workers 1 --no-access-log

Open http://localhost:8303, sign in as admin admin with the one-time password, then change it. setup never overwrites an existing .env and supports --output - to print to stdout for generating it inside a container.

Documentation

Document

Contents

User guide

Installation, first sign-in, asset onboarding, authorization, MCP configuration, backups, FAQ

Authorization groups & parameter rules

Group model and tool parameter allow/block lists

Kubernetes assets

Account policy, authentication, and k8s_exec tool reference

Jenkins assets

Native Jenkins tools, permissions, and budgets

Deployment & operations

Docker build/push/upgrade, data migration, backup & restore

Security policy

Security boundaries, verification scope, private vulnerability reporting

Contributing

Commit conventions, verification commands, pre-release checklist

Changelog

Version history

The documentation is currently written in Chinese.

Development & Testing

python -m pip install -r requirements-dev.txt
ruff check app tests scripts
ruff format --check app tests scripts
python -m pytest -q
npm test --prefix web
npm run build --prefix web
python scripts/release_check.py

Default tests never touch real assets; remote contract, Docker lifecycle, and real-browser acceptance tests require explicit configuration and are skipped by default. The isolated local-container acceptance entry point is python tests/local_stack.py --help; never configure production assets or credentials for tests.

  • app/asset_types/: adapters for the eight asset types (MySQL, SSH, FileBrowser, MCP, Redis, Kubernetes, Git repositories, Jenkins).

  • app/core/: storage migrations, authorization, execution, and security infrastructure.

  • app/main.py, app/cli.py: HTTP/MCP entry points and maintenance commands.

  • web/src/: Vue admin UI; build output goes to static/ and is not committed.

  • tests/: API, isolation, migration, and protocol regression tests.

See SECURITY.md for the security boundary and vulnerability reporting, and CONTRIBUTING.md for contribution guidelines.

Who's Using It?

If your company or team runs this gateway in production, please register your usage. Verified cases will be showcased here.

Star History

License

MIT

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    D
    maintenance
    A secure MCP gateway for enterprise AI tool execution, enabling governed invocation of business tools with authentication, RBAC, audit logging, PII redaction, and async processing.
    Apache 2.0
  • A
    license
    Not graded
    quality
    B
    maintenance
    Provides a secure MCP gateway for AI agents to access APIs without exposing raw credentials, with scoped access, audit logging, and OAuth support.
    MIT
  • A
    license
    Not graded
    quality
    C
    maintenance
    MCP server for AI-native credential management, enabling agents to securely store, retrieve, and manage API keys with encryption, spending budgets, and audit logging.
    MIT