Skip to main content
Glama
aki83reo

Secure Agent MCP Gateway

by aki83reo

Secure Agent MCP Gateway

SOC alert triage with an MCP-to-MCP security gateway: the agent never talks to real tools directly. Every tools/list / tools/call is scoped and authorized by role (viewer | operator | admin).

main.py (agent)  →  gateway  →  mcp_server (tools)

More detail: gateway/README.md.

Quick start (local)

python -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt

cp .env.example .env
# edit .env — set LLM_API_KEY (never commit .env)

Three role services (local)

# 1) Viewer — reputation lookups only
python main.py --mcp --role viewer --alert sample_alert.json

# 2) Operator — triage / summarize / notify (no block or escalate)
python main.py --mcp --role operator --alert sample_alert.json

# 3) Admin — full tool set through the gateway
python main.py --mcp --role admin --alert sample_alert.json

Deterministic path (no MCP / no gateway):

python main.py --alert sample_alert.json

Policy-only check:

python -m gateway.policy

Related MCP server: AgentsGate

Docker deploy

Requires Docker + Compose. Secrets stay outside the image:

cp .env.example .env
# set LLM_API_KEY in .env

Build

docker compose build
# or:
docker build -t secure-agent-mcp-gateway:latest .

Three services (one role each)

Same image; different GATEWAY_ROLE. Each container runs the full chain (maingatewaymcp_server) for that role.

# 1) Viewer
docker compose run --rm triage-viewer

# 2) Operator
docker compose run --rm triage-operator

# 3) Admin
docker compose run --rm triage-admin

Or start by service name:

docker compose up triage-viewer
docker compose up triage-operator
docker compose up triage-admin

Pass the key without a file:

LLM_API_KEY=sk-... docker compose run --rm triage-admin

Plain Docker (no Compose)

docker build -t secure-agent-mcp-gateway:latest .

docker run --rm \
  -e LLM_API_KEY \
  -e LLM_MODEL=gpt-4o-mini \
  -e GATEWAY_ROLE=viewer \
  secure-agent-mcp-gateway:latest \
  python main.py --mcp --role viewer --alert sample_alert.json

docker run --rm -e LLM_API_KEY -e GATEWAY_ROLE=operator \
  secure-agent-mcp-gateway:latest \
  python main.py --mcp --role operator --alert sample_alert.json

docker run --rm -e LLM_API_KEY -e GATEWAY_ROLE=admin \
  secure-agent-mcp-gateway:latest \
  python main.py --mcp --role admin --alert sample_alert.json

Environment

Variable

Purpose

LLM_API_KEY

Required for agent / findings summary

LLM_MODEL

Default gpt-4o-mini

LLM_PROVIDER

Default openai

GATEWAY_ROLE

viewer | operator | admin

.env is gitignored. Only .env.example is committed.

Roles (policy)

Role

Can use

viewer

check_ip_reputation

operator

reputation, triage, summarize, notify

admin

all tools including block_ip + escalate_alert

Defined in gateway/policy.yaml.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    C
    maintenance
    A secure MCP gateway for enterprise AI tool execution, enabling governed invocation of business tools with authentication, RBAC, audit logging, PII redaction, and async processing.
    Apache 2.0
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables AI agents to securely call MCP tools with risk scoring, checkpoints, rollback, and approval workflows.
    17
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Governed MCP gateway that lets AI agents call tools with policy enforcement, prompt-injection screening, a kill-switch, and tamper-evident signed audit logs.
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enables AI agents to safely call enterprise tools through a governed MCP gateway with permission enforcement, blast-radius controls, input validation, and a full audit trail for every invocation.
    MIT