Skip to main content
Glama
dschnurbusch

mattergate

by dschnurbusch

Mattergate

A self-hostable MCP permissions gateway for legal-tech systems.

The goal is simple: connect legal apps once, then expose only the MCP tools each team member should actually use. Mattergate is not a data lake. It is a thin policy and audit layer over vendor APIs.

Current status

This is a scaffold. It includes:

  • TypeScript npm workspace project

  • Policy engine with job-title presets and deny precedence

  • Connector SDK with a mock legal connector

  • MCP gateway core that filters visible tools and enforces permissions on invocation

  • Minimal HTTP server and CLI placeholders

  • Lightweight admin UI scaffold

  • Public landing page app for the open-source project

  • Research and planning docs

Real Lawmatics/Filevine/Clio/MyCase/etc. connectors come later.

Related MCP server: anythingmcp

Why this exists

Legal-tech APIs are inconsistent. Some vendors enforce the authenticated user's in-app permissions. Others expose broad account-level API access, weak scopes, service-account access, or docs that are silent. Lawmatics is the clearest reason to build a policy gateway: its public OAuth docs state that it does not support scopes and authorization grants full CRUD access to the account.

Quick start

npm install
npm run verify
npm run dev:server

In another shell:

curl http://127.0.0.1:4317/health
curl -H 'x-legal-mcp-user-id: demo-paralegal' http://127.0.0.1:4317/tools

Admin UI scaffold:

npm run dev:admin

Public landing page:

npm run dev:landing

Repository layout

apps/
  server/     Minimal HTTP gateway API scaffold
  cli/        Local stdio/CLI scaffold
  admin/      Lightweight admin UI scaffold
  landing/    Public open-source project landing page
packages/
  core/       Shared domain types, errors, audit helpers, external-content labels
  policy/     RBAC/ABAC evaluator and job-title presets
  connectors/ Connector SDK and mock legal connector
  mcp/        Tool filtering and policy-enforced invocation core
docs/
  architecture.md
  connector-development.md
  deployment.md
  policy-model.md
  project-plan.md
  project-tracker.md
  research/   Ignored local research markdown files

Security posture

  • Bring-your-own vendor OAuth app/client credentials. Do not ship shared client secrets.

  • Encrypt OAuth refresh tokens, API keys, and vendor client secrets before any real connector work.

  • Hide tools a user cannot invoke, but also enforce permission checks on every invocation.

  • Default writes to dry-run where possible.

  • Label external vendor content as untrusted data.

  • Audit metadata, not raw legal content.

License

MIT.

Related MCP Connectors

Related MCP Servers

  • F
    license
    Not graded
    quality
    B
    maintenance
    Self-hosted MCP gateway that connects Claude, ChatGPT, and other AI agents to 20+ enterprise tools (GitLab, Jira, Notion, Google Workspace, Slack, Grafana, …) with OAuth, audit logs, and zero data leaving your infrastructure
    -
  • A
    license
    A
    quality
    B
    maintenance
    Self-hosted, open-source (AGPL-3.0) MCP gateway that turns REST, SOAP/WSDL, GraphQL, and SQL/NoSQL databases into MCP tools. Imports OpenAPI/Postman/WSDL/GraphQL specs and bridges multiple MCP servers behind one endpoint. Ships 188 pre-built adapters, 26 of which need no API key, plus per-tool response mapping, OAuth2/RBAC/SSO and a full audit log.
    4
    260
    AGPL 3.0
  • F
    license
    Not graded
    quality
    B
    maintenance
    A self-hosted MCP gateway with Google OAuth and role-based access control, allowing MCP clients like Claude and Cursor to connect and interact with configured Zendesk and Chargebee connectors through an admin dashboard.
    12 npm
    -

Appeared in Searches