Skip to main content
Glama
dschnurbusch

mattergate

by dschnurbusch

Mattergate

A self-hostable MCP permissions gateway for legal-tech systems.

The goal is simple: connect legal apps once, then expose only the MCP tools each team member should actually use. Mattergate is not a data lake. It is a thin policy and audit layer over vendor APIs.

Current status

This is a scaffold. It includes:

  • TypeScript npm workspace project

  • Policy engine with job-title presets and deny precedence

  • Connector SDK with a mock legal connector

  • MCP gateway core that filters visible tools and enforces permissions on invocation

  • Minimal HTTP server and CLI placeholders

  • Lightweight admin UI scaffold

  • Public landing page app for the open-source project

  • Research and planning docs

Real Lawmatics/Filevine/Clio/MyCase/etc. connectors come later.

Related MCP server: MCPGate

Why this exists

Legal-tech APIs are inconsistent. Some vendors enforce the authenticated user's in-app permissions. Others expose broad account-level API access, weak scopes, service-account access, or docs that are silent. Lawmatics is the clearest reason to build a policy gateway: its public OAuth docs state that it does not support scopes and authorization grants full CRUD access to the account.

Quick start

npm install
npm run verify
npm run dev:server

In another shell:

curl http://127.0.0.1:4317/health
curl -H 'x-legal-mcp-user-id: demo-paralegal' http://127.0.0.1:4317/tools

Admin UI scaffold:

npm run dev:admin

Public landing page:

npm run dev:landing

Repository layout

apps/
  server/     Minimal HTTP gateway API scaffold
  cli/        Local stdio/CLI scaffold
  admin/      Lightweight admin UI scaffold
  landing/    Public open-source project landing page
packages/
  core/       Shared domain types, errors, audit helpers, external-content labels
  policy/     RBAC/ABAC evaluator and job-title presets
  connectors/ Connector SDK and mock legal connector
  mcp/        Tool filtering and policy-enforced invocation core
docs/
  architecture.md
  connector-development.md
  deployment.md
  policy-model.md
  project-plan.md
  project-tracker.md
  research/   Ignored local research markdown files

Security posture

  • Bring-your-own vendor OAuth app/client credentials. Do not ship shared client secrets.

  • Encrypt OAuth refresh tokens, API keys, and vendor client secrets before any real connector work.

  • Hide tools a user cannot invoke, but also enforce permission checks on every invocation.

  • Default writes to dry-run where possible.

  • Label external vendor content as untrusted data.

  • Audit metadata, not raw legal content.

License

MIT.

A
license - permissive license
-
quality - not tested
B
maintenance

Maintenance

Maintainers
Response time
Release cycle
Releases (12mo)
Commit activity

Resources

Unclaimed servers have limited discoverability.

Looking for Admin?

If you are the server author, to access and configure the admin panel.

Related MCP Servers

  • F
    license
    -
    quality
    B
    maintenance
    A multi-tenant integration platform that connects MSP systems like HaloPSA, Microsoft 365, and HubSpot to a single remote MCP server. It provides normalized, AI-safe tools for managing third-party services with built-in security policies and audit logging.
    Last updated
  • A
    license
    -
    quality
    C
    maintenance
    MCPGate aggregates multiple MCP servers into a single unified endpoint, enabling centralized tool management with granular filtering, automatic namespacing, and observability. Features a real-time web dashboard and optional PostgreSQL-backed audit trails for monitoring and controlling AI tool access across local and remote deployments.
    Last updated
    10
    Apache 2.0
  • F
    license
    -
    quality
    A
    maintenance
    Self-hosted MCP gateway that connects Claude, ChatGPT, and other AI agents to 20+ enterprise tools (GitLab, Jira, Notion, Google Workspace, Slack, Grafana, …) with OAuth, audit logs, and zero data leaving your infrastructure
    Last updated
  • A
    license
    A
    quality
    B
    maintenance
    Self-hosted source-available MCP gateway that turns REST, SOAP/WSDL, GraphQL, and SQL/NoSQL databases into MCP tools. Imports OpenAPI/Postman/WSDL/GraphQL specs and bridges multiple MCP servers behind one endpoint. Ships with 29 pre-built adapters and built-in OAuth2 + RBAC + audit log.
    Last updated
    4
    168
    AGPL 3.0

View all related MCP servers

Related MCP Connectors

  • Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.

  • A paid remote MCP for CLI tool MCP, built to return verdicts, receipts, usage logs, and audit-ready

  • Connect AI to millions of laws and court cases with the Lawstronaut MCP.

View all MCP Connectors

Latest Blog Posts

MCP directory API

We provide all the information about MCP servers via our MCP API.

curl -X GET 'https://glama.ai/api/mcp/v1/servers/dschnurbusch/mattergate'

If you have feedback or need assistance with the MCP directory API, please join our Discord server