Skip to main content
Glama
taiyofujiwara

Agent Data Gateway

Agent Data Gateway (ADG)

Open-core middleware that gives AI agents secure, auditable access to production data. Converts existing APIs/DBs into MCP tools with credential hiding, data scoping, and immutable audit logs.

Architecture (M1)

┌─────────────┐     ┌──────────────────────────────────┐     ┌──────────────┐
│   Agent     │────▶│      ADG Proxy (Fastify)          │────▶│  Backend     │
│ (no creds)  │     │  ┌────────────┐  ┌─────────────┐  │     │  API / DB    │
│             │     │  │ Interceptor │──│ Credential   │  │     │              │
└─────────────┘     │  │ inject creds│  │ Store (mem) │  │     └──────────────┘
                    │  └────────────┘  └─────────────┘  │
                    │  ┌────────────┐                    │
                    │  │  Audit Log  │                    │
                    │  └────────────┘                    │
                    └──────────────────────────────────┘

Related MCP server: heddle

Quick Start

# Install
npm install

# Build
npm run build

# Configure
cp examples/config.yaml config.yaml
# Edit config.yaml with your sources

# Run
npm start        # production
npm run dev      # development with hot reload

API Endpoints

POST /proxy

Agent sends a request referencing a source by name. Proxy injects credentials server-side.

{
  "source": "stripe-api",
  "url": "https://api.stripe.com/v1/charges",
  "method": "GET"
}

GET /health

Health check — returns status and source count.

GET /sources

Lists known source names (no credentials).

Security

  • Credentials stored in-memory only, never persisted to disk after boot

  • All credential fields redacted from logs, error messages, and responses

  • CredentialNotFoundError leaks only the source name, never credential values

  • Credential store is immutable after initialization

Project Structure

├── src/
│   ├── index.ts               # Entry point & Fastify server
│   ├── config/
│   │   ├── loader.ts          # YAML config loader
│   │   └── schema.ts          # Zod schema & types
│   ├── credentials/
│   │   ├── store.ts           # In-memory credential store
│   │   ├── types.ts           # Credential types
│   │   └── redact.ts          # Credential redaction utilities
│   ├── proxy/
│   │   └── interceptor.ts     # Credential injection middleware
│   └── audit/
│       └── logger.ts          # Immutable audit logger
├── tests/
│   ├── credentials/
│   │   ├── redact.test.ts
│   │   └── store.test.ts
│   └── proxy/
│       └── interceptor.test.ts
├── examples/
│   └── config.yaml
├── docker-compose.yml
└── package.json

Related MCP Connectors

Related MCP Servers

  • A
    license
    C
    quality
    D
    maintenance
    Enables secure, zero-trust access to MCP tools through short-lived, signed capability leases that bind tool execution to specific sessions, intents, and constraints. Prevents prompt injection attacks and privilege escalation with dynamic risk scoring, policy enforcement, and tamper-evident audit logging.
    4
    1
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    Enables users to define and run MCP tools using declarative YAML configs with built-in trust enforcement, credential brokering, and tamper-evident audit logging.
    14
    MIT
  • A
    license
    Not graded
    quality
    D
    maintenance
    Turns any web API into a governed, agent-ready MCP server with lockfile-based approval, fail-closed enforcement, and full audit trail.
    MIT