external-ai-ecosystem-gateway
Provides integration with OpenAI through the gateway's adapter layer, exposing access to supported OpenAI capabilities under the policy and tenant boundary.
Mediates access to Slack through permission-scoped tools, with tenant isolation, safe sandbox mode when no token is configured, and idempotent execution.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@external-ai-ecosystem-gatewaySend a Slack message to #general saying the deploy finished"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
External AI Ecosystem Gateway
A security-oriented Python gateway that exposes permission-scoped tools to MCP-compatible assistant clients while mediating access to external systems such as Slack. It demonstrates tenant isolation, delegated authorization, human confirmation for sensitive writes, idempotent execution, signed webhook verification, revocation-ready grant storage, and a hash-chained audit trail.
This is a portfolio/reference implementation, not a production identity provider. The header-based development auth adapter must be replaced by the OIDC validation middleware described in
docs/security.mdbefore deployment.
Architecture
Assistant / Slack client
|
v
FastAPI edge + auth adapter
|
v
Policy + tenant boundary ----> confirmation tokens
|
v
Sandboxed tool registry -----> Slack / OpenAI / Claude adapters
|
+--------------------> idempotency store
+--------------------> append-only hash-chained audit logRelated MCP server: Nervora
Quick start
python -m venv .venv
source .venv/bin/activate
pip install -e '.[dev]'
uvicorn ecosystem_gateway.app:app --reloadList tools:
curl localhost:8000/mcp/tools \
-H 'X-Subject: user-1' -H 'X-Tenant-Id: tenant-a' -H 'X-Roles: operator'Run the test suite with pytest. When no Slack token is configured, connectors run in a safe
sandbox mode and return the request they would issue.
Security properties
Every principal and idempotency key is tenant-namespaced.
Tool policies combine least-privilege roles with delegated scopes.
Sensitive writes require a short-lived token bound to subject, tenant, tool, and arguments.
Webhook signatures use constant-time comparison and reject stale requests.
Audit records form a SHA-256 chain so deletion or mutation is detectable.
OAuth grants support revocation and never expose refresh tokens through tool results.
See docs/security.md for the production hardening checklist and threat model.
License
MIT
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- AlicenseNot gradedqualityCmaintenanceEnables AI agents to discover and execute tools via a secure MCP server with JWT authentication, RBAC, rate limiting, and audit logging.1MIT
- AlicenseNot gradedqualityCmaintenanceA secure MCP gateway for enterprise AI tool execution, enabling governed invocation of business tools with authentication, RBAC, audit logging, PII redaction, and async processing.Apache 2.0
- FlicenseNot gradedqualityCmaintenanceA single MCP server that exposes safe, permission-checked tools for AI assistants to reach file systems, databases, APIs, Git, cloud services, and business applications.

AgentsGateofficial
AlicenseNot gradedqualityAmaintenanceEnables AI agents to securely call MCP tools with risk scoring, checkpoints, rollback, and approval workflows.134MIT
Related MCP Connectors
Runtime permission, approval, and audit layer for AI agent tool execution.
MCP server for secureFlows: token-free URL builders and integration-linting tools for AI agents.
Phone, SMS & email for AI agents — one remote MCP endpoint, OAuth login, zero install.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/navadiashrey/external-ai-ecosystem-gateway'
If you have feedback or need assistance with the MCP directory API, please join our Discord server