Skip to main content
Glama
alifanov

ScopeGate

by alifanov

ScopeGate

AI Access Proxy Layer. Connect external services (e.g. Google), define granular permissions, and receive an MCP endpoint URL for use in AI agents. Acts as a permission gateway — exposing only the specific capabilities you authorize, more granular than native OAuth scopes.

Tech Stack

  • Framework: Next.js 16 (App Router)

  • Language: TypeScript

  • Database: PostgreSQL + Prisma 7

  • UI: Tailwind CSS v4, shadcn/ui

  • Auth: Better Auth (database-backed sessions, Prisma adapter)

  • MCP: @modelcontextprotocol/sdk (Streamable HTTP)

  • Package Manager: pnpm

Related MCP server: mcpgate

Quick Start (self-hosted)

Full feature parity with the hosted cloud version — nothing is cut for self-host.

git clone https://github.com/alifanov/scopegate.git
cd scopegate
docker compose --profile local up

Open http://localhost:3000. No .env file needed: a local Postgres and a fresh BETTER_AUTH_SECRET are provisioned automatically, and the generated admin login is printed once in the app container logs on first boot (look for Generated admin login) — search it with docker compose logs app | grep -A4 "First run". The password is also saved to the app_data volume so it survives restarts.

To connect real services (Gmail, LinkedIn, GitHub, …), copy .env.example to .env and fill in the OAuth client id/secret for the providers you want — every block is independent and optional, a provider without credentials simply doesn't show up.

Development Setup

Prerequisites

  • Node.js 18+

  • pnpm

  • PostgreSQL

Setup

  1. Clone the repository and install dependencies:

pnpm install
  1. Copy the environment file and fill in your values:

cp .env.example .env

Variable

Description

DATABASE_URL

PostgreSQL connection string

BETTER_AUTH_SECRET

Secret key for session signing

BETTER_AUTH_URL

App base URL (e.g. http://localhost:3000)

ADMIN_EMAIL

Bootstrap admin email

ADMIN_PASSWORD

Bootstrap admin password

  1. Run database migrations:

pnpm prisma migrate dev
  1. Start the development server:

pnpm dev

Open http://localhost:3000.

Project Structure

src/
├── app/
│   ├── (auth)/              # Login & register pages
│   ├── (dashboard)/         # Protected dashboard pages
│   │   └── projects/        # Project management, endpoints, audit, settings
│   ├── api/
│   │   ├── auth/[...all]/    # Better Auth catch-all handler
│   │   ├── projects/        # Projects CRUD, endpoints, services, audit
│   │   └── mcp/[apiKey]/    # MCP Streamable HTTP handler
│   ├── layout.tsx
│   └── page.tsx             # Landing page
├── components/
│   ├── ui/                  # shadcn/ui components
│   ├── layout/              # Sidebar, header
│   └── shared/              # Reusable app components
├── lib/
│   ├── db.ts                # Prisma client singleton
│   ├── auth.ts              # Better Auth server instance
│   ├── auth-client.ts       # Better Auth client SDK
│   ├── auth-middleware.ts   # getCurrentUser() helper
│   ├── bootstrap.ts         # Admin user bootstrap on empty DB
│   └── mcp/
│       ├── permissions.ts   # Permission groups (source of truth)
│       ├── tools.ts         # MCP tool definitions
│       └── handler.ts       # MCP server factory
├── generated/prisma/        # Generated Prisma client
└── middleware.ts             # Route protection

Available Scripts

pnpm dev              # Start development server
pnpm build            # Production build
pnpm start            # Start production server
pnpm lint             # Run ESLint
pnpm prisma generate  # Regenerate Prisma client
pnpm prisma migrate dev  # Create and apply migrations
pnpm prisma studio    # Open Prisma Studio (DB browser)

How It Works

  1. Login — sign in with admin credentials (bootstrapped from env vars on first run)

  2. Create a Project — organize endpoints and services by project

  3. Connect a Service — add a service connection to the project

  4. Create an MCP Endpoint — select a service connection and pick specific permissions (e.g. gmail:read_emails, calendar:create_event)

  5. Use the MCP URL — plug the endpoint URL into any MCP-compatible AI agent; only the allowed actions are exposed

  6. Monitor — track every request in the audit log

Permissions

Permissions are defined in src/lib/mcp/permissions.ts and grouped by service:

Group

Actions

Gmail

gmail:read_emails, gmail:send_email, gmail:list_labels, gmail:search_emails

Google Calendar

calendar:list_events, calendar:create_event, calendar:update_event, calendar:delete_event

Google Drive

drive:list_files, drive:read_file, drive:create_file, drive:delete_file

Database Schema

  • User — authentication, team membership

  • Session — database-backed auth sessions

  • Account — auth provider credentials (email/password)

  • Project — logical grouping for services and endpoints

  • TeamMember — user-project relationship with roles (owner/member)

  • ServiceConnection — OAuth tokens for connected services

  • McpEndpoint — MCP endpoint with API key, rate limit, active status

  • EndpointPermission — allowed actions per endpoint

  • AuditLog — request log with action, status, duration, errors

License

See LICENSE.

A
license - permissive license
-
quality - not tested
A
maintenance

Maintenance

Maintainers
4hResponse time
Release cycle
Releases (12mo)
Commit activity
Issues opened vs closed

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • A
    license
    -
    quality
    C
    maintenance
    Self-hosted credential store and API proxy for AI agents. One Bearer token, all your services. Handles OAuth refresh, encrypted storage, audit logging, and per-agent permissioning.
    63
    MIT
  • F
    license
    -
    quality
    A
    maintenance
    Self-hosted MCP gateway that connects Claude, ChatGPT, and other AI agents to 20+ enterprise tools (GitLab, Jira, Notion, Google Workspace, Slack, Grafana, …) with OAuth, audit logs, and zero data leaving your infrastructure
  • A
    license
    A
    quality
    A
    maintenance
    Local zero-trust permission gateway for AI agents. Enforces policy-based tool authorization, human approvals, scoped permissions, and cryptographically verifiable audit logs.
    4
    5
    Apache 2.0

View all related MCP servers

Related MCP Connectors

  • Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.

  • Authenticated email gateway for AI agents — per-agent inboxes, HITL approval, SPF/DKIM verified.

  • Free public MCP for AI agents — 193 tools, 44 workflows. No API key.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/alifanov/scopegate'

If you have feedback or need assistance with the MCP directory API, please join our Discord server