mattergate
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@mattergatelist my permitted MCP tools"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Mattergate
A self-hostable MCP permissions gateway for legal-tech systems.
The goal is simple: connect legal apps once, then expose only the MCP tools each team member should actually use. Mattergate is not a data lake. It is a thin policy and audit layer over vendor APIs.
Current status
This is a scaffold. It includes:
TypeScript npm workspace project
Policy engine with job-title presets and deny precedence
Connector SDK with a mock legal connector
MCP gateway core that filters visible tools and enforces permissions on invocation
Minimal HTTP server and CLI placeholders
Lightweight admin UI scaffold
Public landing page app for the open-source project
Research and planning docs
Real Lawmatics/Filevine/Clio/MyCase/etc. connectors come later.
Related MCP server: anythingmcp
Why this exists
Legal-tech APIs are inconsistent. Some vendors enforce the authenticated user's in-app permissions. Others expose broad account-level API access, weak scopes, service-account access, or docs that are silent. Lawmatics is the clearest reason to build a policy gateway: its public OAuth docs state that it does not support scopes and authorization grants full CRUD access to the account.
Quick start
npm install
npm run verify
npm run dev:serverIn another shell:
curl http://127.0.0.1:4317/health
curl -H 'x-legal-mcp-user-id: demo-paralegal' http://127.0.0.1:4317/toolsAdmin UI scaffold:
npm run dev:adminPublic landing page:
npm run dev:landingRepository layout
apps/
server/ Minimal HTTP gateway API scaffold
cli/ Local stdio/CLI scaffold
admin/ Lightweight admin UI scaffold
landing/ Public open-source project landing page
packages/
core/ Shared domain types, errors, audit helpers, external-content labels
policy/ RBAC/ABAC evaluator and job-title presets
connectors/ Connector SDK and mock legal connector
mcp/ Tool filtering and policy-enforced invocation core
docs/
architecture.md
connector-development.md
deployment.md
policy-model.md
project-plan.md
project-tracker.md
research/ Ignored local research markdown filesSecurity posture
Bring-your-own vendor OAuth app/client credentials. Do not ship shared client secrets.
Encrypt OAuth refresh tokens, API keys, and vendor client secrets before any real connector work.
Hide tools a user cannot invoke, but also enforce permission checks on every invocation.
Default writes to dry-run where possible.
Label external vendor content as untrusted data.
Audit metadata, not raw legal content.
License
MIT.
This server cannot be deployed
Maintenance
Related MCP Connectors
Zero-setup MCP gateway securely connecting AI to your tools with authentication and workflows
Self-hosted federated MCP gateway: one OAuth 2.1 MCP server in front of N apps, user-level scopes.
Zero-secret MCP gateway for AI agents: risk-scored, audited calls with human-in-the-loop approval.
- GentkeyOAuthcom.gentkey
One MCP URL for all your connectors — scoped writes, enforced constraints, and a full audit trail.
Related MCP Servers
FlicenseNot gradedqualityBmaintenanceSelf-hosted MCP gateway that connects Claude, ChatGPT, and other AI agents to 20+ enterprise tools (GitLab, Jira, Notion, Google Workspace, Slack, Grafana, …) with OAuth, audit logs, and zero data leaving your infrastructure-- AlicenseAqualityBmaintenanceSelf-hosted, open-source (AGPL-3.0) MCP gateway that turns REST, SOAP/WSDL, GraphQL, and SQL/NoSQL databases into MCP tools. Imports OpenAPI/Postman/WSDL/GraphQL specs and bridges multiple MCP servers behind one endpoint. Ships 188 pre-built adapters, 26 of which need no API key, plus per-tool response mapping, OAuth2/RBAC/SSO and a full audit log.4260AGPL 3.0
- FlicenseNot gradedqualityCmaintenanceMiddleware that converts existing APIs/DBs into MCP tools with secure credential injection, data scoping, and immutable audit logs.-
- FlicenseNot gradedqualityBmaintenanceA self-hosted MCP gateway with Google OAuth and role-based access control, allowing MCP clients like Claude and Cursor to connect and interact with configured Zendesk and Chargebee connectors through an admin dashboard.12 npm-