Budget, payment and audit controls for AI agent API calls and MCP tool calls.
satgate — Model Context Protocol (MCP) Server
The io.github.SatGate-io/satgate MCP server provides budget, payment, and audit controls for AI agent API calls and MCP tool calls. It is designed to manage usage and related operational controls by applying the same governance approach across both agent-facing requests and tool executions.
🛠️ Key Features
Budget controls for AI agent API calls and MCP tool calls
Payment controls for AI agent API calls and MCP tool calls
Audit controls for AI agent API calls and MCP tool calls
🚀 Use Cases
Enforce budget limits for AI agent API usage
Control and govern payment-related behavior for tool calls
Track or audit activity spanning agent API calls and MCP tool calls
⚡ Developer Benefits
Centralized control over both agent API calls and MCP tool calls
Consistent budgeting, payment, and auditing behavior across call types
⚠️ Limitations
Available information does not specify specific tools, configuration options, or implementation details beyond the stated controls
SatGate is a gateway in front of APIs and MCP tools. It meters agent and MCP traffic (Observe), enforces owner budgets before work runs (Control), and charges outside agents on the routes you choose (Admit; the Charge policy in the dashboard). Every allow or deny comes with a signed receipt.
Try it as an agent. This hosted route costs 10 sats:
The public packages install today; the issue/pay/verify API namespace is in private beta. Calls without private-beta access raise a structured error instead of returning fake receipts:
text
SatGateAuthError: This API namespace requires private beta access. Visit cloud.satgate.io/docs to request access.
Runnable examples:
examples/python/issue_pay_verify.py
examples/node/issue-pay-verify.mjs
Works with: MCP · OpenAI tools · Anthropic tools · LangChain · CrewAI · Raw HTTP
🎬 See SatGate in Action
☁️ Don't want to self-host? Try SatGate Cloud
Managed SaaS — zero setup, multi-tenant isolation, enterprise dashboard.
Free Observe tier. No credit card required.
The Problem
AI agents are making API calls autonomously. They spawn sub-agents, call MCP tools, and run overnight while you sleep.
Your existing stack answers: "Is this request authenticated?"
Nobody answers: "Should this agent have authority to spend, delegate, or invoke this paid resource?"
code
✓ Network Firewall → "Can this packet enter?"
✓ Application Firewall → "Is this request safe?"
? Economic Firewall → "Should this agent act, spend, or pay?"
That's the gap. SatGate fills it.
What is SatGate?
SatGate is an Economic Firewall for AI agent requests. Drop it in front of your APIs and MCP tools to enforce scoped authority, budgets, paid-rail context, and Evidence Pack receipts before agents act.
Not another routing layer. Routing gateways (Bifrost, LiteLLM, Portkey) optimize which provider handles a call. SatGate governs whether the call should happen at all based on authority, policy, budget, and paid-rail context.
🛡️ Capability Tokens (Macaroons) — Cryptographic credentials with built-in caveats, delegation, and next-request revocation. Not API keys — tokens that agents can safely sub-delegate.
🎯 MCP-Aware — Parses MCP JSON-RPC tool calls. Know that Agent X spent $47 on search_database and $12 on send_email — not just "1,000 requests."
💰 Budget Enforcement — Hard stops per agent, team, or API. When the budget hits zero, requests are blocked. Not logged. Not alerted. Blocked.
⚡ Paid-Rail Governance — Govern paid API access across L402, x402, API-key billing, and enterprise ledgers without making any one rail the control plane.
🔒 Default-Deny — All routes require valid credentials unless explicitly public. Zero Trust by design.
🚀 <50ms Overhead — Lightweight Go proxy. Adds governance without adding latency.
📦 Self-Hosted — Your infrastructure, your rules. Single binary, Docker, or Kubernetes.
🔌 Drop-in — Works with any HTTP backend. REST, GraphQL, MCP servers. No code changes.
Quick Start
60-Second Demo
bash
# Download the binary (macOS Apple Silicon — see Releases for other platforms)
curl -L https://github.com/satgate-io/satgate/releases/latest/download/satgate-darwin-arm64 -o satgate
chmod +x satgate
# Start with example config (mock Lightning, auto-generated keys)export ADMIN_TOKEN=my-secret-token
export LIGHTNING_BACKEND=mock
./satgate --config examples/gateway.yaml
Try the three policies:
bash
# 1. Public — no auth needed
curl http://localhost:8080/health
# 2. Protected — mint a capability token, then use it
curl -X POST http://localhost:8080/api/capability/mint \
-H "X-Admin-Token: my-secret-token" \
-H "Content-Type: application/json" \
-d '{"scope": "api:read", "duration": "1h"}'# Use the token:
curl -H "Authorization: Bearer YOUR_CAPABILITY_TOKEN" \
http://localhost:8080/api/capability/ping
# 3. Paid — get a payment challenge (L402 today; x402/other rails as governed context)
curl http://localhost:8080/api/micro
Public → Protected → Paid. Three policies, one gateway; paid rails are governed context, not the product boundary.
Hosted paid demo (Admit; Charge in the dashboard). No local Lightning node:
# Docker
docker run -v $(pwd)/gateway.yaml:/etc/satgate/gateway.yaml \
-e ADMIN_TOKEN=my-secret-token -e LIGHTNING_BACKEND=mock \
-p 8080:8080 ghcr.io/satgate-io/satgate:latest
# Build from source
git clone https://github.com/satgate-io/satgate.git
cd satgate && go build -o satgate ./cmd/satgate
Configuration
yaml
version:1server:listen:":8080"admin:capabilityRootKey:"${CAPABILITY_ROOT_KEY}"lightning:provider:"${LIGHTNING_BACKEND}"config:connectionString:"${NWC_CONNECTION_STRING}"upstreams:api:url:"http://localhost:3000"routes:-name:public-healthmatch:pathPrefix:/healthupstream:apipolicy:kind:public-name:protected-apimatch:pathPrefix:/api/upstream:apipolicy:kind:capabilityscope:"api:read"-name:premium-apimatch:pathPrefix:/premium/upstream:apipolicy:kind:l402# paid-rail policy; use payment_context to preserve L402/x402/ledger evidencepriceSats:100
Policy Types
Policy
Description
Use Case
public
No authentication
Health checks, docs, webhooks
capability
Requires valid Macaroon
Protected API endpoints
l402
Requires Lightning payment and records paid-rail context
Monetized endpoints; x402/ledger context can be preserved in Evidence Packs
Macaroons: Bearer tokens with embedded caveats (expiry, scope, budget, IP). Not API keys — they support delegation without server roundtrips.
Delegation: Agent A gives Agent B a sub-token with reduced permissions and a $50 budget cap. B can't escalate.
MCP Parsing: SatGate reads MCP JSON-RPC payloads to attribute costs to specific tool calls, not just HTTP endpoints.
Paid-rail context: SatGate treats L402, x402, API-key billing, and enterprise ledgers as rails to govern around. Evidence Packs preserve which rail was involved without making the rail the product.