Skip to main content
Glama
willdynan

mcp-data-gateway

by willdynan

mcp-data-gateway

tests

Hand an AI client to one person and MCP is easy. Hand it to a team — analysts, people-ops, leads, each entitled to different systems — and the server needs an answer it can defend: who is calling, and what may they touch? This repo is that answer, cut down to its load-bearing parts.

One allows() decision drives everything. It filters what each identity sees and refuses what they try anyway, so the tool list is never the only thing standing between a caller and a system. Grants fail closed: a missing or corrupt store denies everyone except a break-glass superuser who lives in code, precisely so no store outage can lock out the person who fixes stores. Every call — and every denial — lands as a size-capped audit line.

Opinions baked in:

  • Grants name tools one by one. Globs get rejected at load time, because the write tool someone ships next quarter must not inherit its way into a read-only identity.

  • A tool that joins two systems declares both, and the caller needs both. The reads are what leak, not the names.

  • A snapshot test pins the tool surface, and a second one holds the write surface at exactly one tool.

  • The SQL gate gives fast, specific refusals — but the real fence is the database identity's permissions. You can talk past a text scan. You cannot talk past IAM.

Quickstart

python3 -m unittest discover -s tests   # no dependencies
python3 -m gateway.demo                 # three identities, one denial on the record
pip install mcp && GATEWAY_IDENTITY=analyst@example.com python3 -m gateway.server

Related MCP server: mcp-policy-gateway

Going deeper

docs/design.md walks the pieces with captured output. docs/rules.md gives every rule its reason and its test. docs/lineage.md holds the honest limits and provenance.

Distilled August 2026 from production gateways that earned each rule the hard way. The commit log starts at the distillation.

Maintenance

ActivityMaintained
ResponsivenessNo issues

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Connectors

Related MCP Servers

  • A
    license
    Not graded
    quality
    B
    maintenance
    A least-privilege enforcement proxy for MCP servers. It sits between MCP clients and upstream servers, enforcing tool policies, hiding denied tools, requiring human approval for risky actions, and providing a structured audit trail.
    MIT
  • A
    license
    Not graded
    quality
    A
    maintenance
    An authorizing reverse proxy for MCP servers that enforces per-call policy rules on tool arguments with audit logging, dry-run, and rate limiting.
    Apache 2.0
  • A
    license
    Not graded
    quality
    C
    maintenance
    Enforces deterministic security policies as an inline firewall for MCP server tool calls, with AST-based validation, cryptographic audit logging, and CLI-based evaluation and verification.
    MIT
  • A
    license
    Not graded
    quality
    B
    maintenance
    Enables developers to scaffold secure-by-default MCP servers with deny-all permissions, typed tool stubs, and pre-wired audit hooks, while enforcing security posture through CI.
    2
    MIT