s-gw MCP server
A local stdio MCP server that enables coding agents to discover credential handles and create scoped action requests with local approval and sanitized output.
README
<p align="center"> <img src="assets/icons/s-gw-128.png" alt="s-gw" width="96" height="96"> </p>
<h1 align="center">s-gw</h1>
<p align="center"> <strong>Local credential control for coding agents.</strong><br> Approve bounded actions locally. Keep raw credentials out of model context and tool output. </p>
<p align="center"> <a href="https://github.com/sgateway/s-gw/actions/workflows/ci.yml"><img alt="CI" src="https://github.com/sgateway/s-gw/actions/workflows/ci.yml/badge.svg"></a> <a href="https://www.npmjs.com/package/@s-gw/s-gw"><img alt="npm" src="https://img.shields.io/npm/v/%40s-gw%2Fs-gw"></a> <a href="LICENSE"><img alt="License: Apache-2.0" src="https://img.shields.io/badge/license-Apache--2.0-2ea44f"></a> <img alt="Node.js 20+" src="https://img.shields.io/badge/Node.js-20%2B-43853d"> <a href="https://s-gw.com"><img alt="Website: s-gw.com" src="https://img.shields.io/badge/website-s--gw.com-22c55e"></a> <img alt="Project status: preview" src="https://img.shields.io/badge/status-preview-f59e0b"> </p>
<p align="center"> <a href="https://s-gw.com">Demo</a> · <a href="#quick-start">Quick start</a> · <a href="docs/README.md">Documentation</a> · <a href="SECURITY.md">Security</a> · <a href="CONTRIBUTING.md">Contributing</a> </p>
s-gw is a local gateway between coding agents and credentials. Agents work with typed handles and scoped action requests. You approve the request on your machine, s-gw resolves the credential inside a constrained local process, and the agent gets sanitized output instead of the raw value.
[!IMPORTANT] s-gw is an early preview. Storage formats and interfaces may change, Windows support is still experimental, and the project has not completed an independent security audit. Do not treat it as a replacement for endpoint security or a hardened enterprise secrets platform yet.
What It Does
| Govern | Approve | Execute | Audit |
|---|---|---|---|
| Turn secrets into typed local handles that agents can reference safely. | Review the requesting agent, handle, command, environment binding, working directory, and target before access is granted. | Inject the credential only into the approved child process on the same machine. | Record request, approval, execution, policy, and destination evidence without storing returned raw secrets. |
Why Teams Use It
- Local custody: raw values stay in macOS Keychain, Windows Credential Manager, 1Password, or the encrypted local ledger.
- Action-scoped access: grants bind to the agent, handle, command, environment variable, working directory, target, approval mode, and optional time window.
- Useful handles: agents can request real work with stable handle names instead of seeing keys, passwords, tokens, or SSH material.
- Output sanitization: command output is scanned before it returns to the agent, replacing detected credential values with handles.
- Agent-aware setup: Codex, Claude Code, Cursor, OpenCode, Gemini CLI, GitHub Copilot, VS Code, and other MCP clients get profile-specific configuration.
- Local operator UI: the macOS app, menu helper, CLI, and web console show approvals, credential inventory, policies, usage flow, activity, and audit history.
Demo
Public demo: s-gw.com. The demo highlights the local console, trust loop, approval flow, supported agent catalog, and usage map.

How It Works
flowchart LR
A["Coding agent"] -->|"Handle + action request"| G["s-gw local gateway"]
G --> U["Local approval"]
U --> R["Constrained runner"]
K[("Keychain / Credential Manager / encrypted store")] --> R
R -->|"Sanitized output"| G
G --> A
The agent never needs the unlock passphrase or raw credential. Approval is scoped to the requested operation rather than granting general access to the store.
Core Surfaces
| Surface | Purpose |
|---|---|
s-gw CLI |
Setup, credential enrollment, approvals, policies, agent snippets, guard mode, and diagnostics. |
s-gw-mcp |
Stdio MCP server for agent-facing handle discovery and request creation. |
| Native macOS app | Approval queue, credential inventory, policy rules, usage flow, activity, and audit review. |
| Menu-bar helper | Fast visibility into pending approvals and local daemon status. |
| Local web console | Browser-accessible fallback UI bound to 127.0.0.1. |
| Guard mode | Launch agents with credential-looking environment values replaced by s-gw handles. |
Quick Start
Requirements: Node.js 20 or newer.
npm install -g @s-gw/s-gw
s-gw setup
s-gw status
To build from source, use a stable Rust toolchain. Building the native macOS surfaces also requires a Swift toolchain.
git clone https://github.com/sgateway/s-gw.git
cd s-gw
npm ci
npm run build
npm link
s-gw setup
s-gw status
s-gw setup generates local unlock material, stores it in the operating system credential store, initializes the encrypted ledger, and starts the local UI surfaces available on the current platform.
Add a credential from your terminal without placing the value in chat or a process argument:
printf '%s' "$MY_API_TOKEN" | s-gw secret add-keychain \
--name demo-token \
--type api-token \
--value-stdin \
--inject-env API_TOKEN \
--allow-command "$(command -v printenv)"
Then inspect the non-secret handle metadata:
s-gw secret list
The end-to-end trust loop walks through a disposable request, local approval, execution, and output sanitization without touching a real credential.
Agent Integration
List the known agent profiles and render the configuration for one client:
s-gw agent list
s-gw agent mcp-snippet codex
s-gw agent mcp-snippet claude-code
s-gw agent mcp-snippet opencode
For CLI agents, guard mode can replace credential-looking launch environment values with s-gw handles before the agent starts:
s-gw run codex --dry-run -- -v
s-gw run codex -- --ask-for-approval never
MCP registration does not intercept every prompt, file read, shell, or environment variable. See agent integration and the agent profile matrix for the supported paths and current limitations.
Example Request Flow
- An agent sees
s-gw:credential:prod-readonlyand asks to runaws sts get-caller-identity. - s-gw creates a pending request with the agent name, command, handle, environment binding, working directory, target, and policy result.
- You approve once, for a time window, for the login session, or deny it.
- s-gw starts the approved local process with the credential injected into the requested environment variable.
- s-gw scans the process output before it returns to the agent.
The model can complete the task without receiving the raw access key.
Platform Status
| Platform | Status | Credential store | User interface |
|---|---|---|---|
| macOS 14+ | Primary development platform | Keychain | Native app, menu helper, local web console |
| Windows 10/11 | Preview | Credential Manager | PowerShell client, tray helper, local web console |
| Linux | Experimental CLI | Environment-provided unlock material | Local web console |
Preview installers are available from GitHub Releases. The macOS DMG is ad-hoc signed and unnotarized, and the Windows package is unsigned preview software. Build the same artifacts locally with npm run build:installers.
Security Model
s-gw is designed to reduce accidental credential exposure to coding agents. It does not protect against a compromised operating system account, a malicious approved executable, screen capture, kernel-level access, or every transformed derivative of a secret.
Read the threat model before relying on s-gw for sensitive workflows. Report suspected vulnerabilities through GitHub private vulnerability reporting, not a public issue.
Project Status
- Public source distribution is preview quality.
- macOS is the primary development and test platform.
- Windows Credential Manager support is present but still needs broader native QA.
- Linux currently depends on environment-provided unlock material.
- Desktop preview downloads are unsigned and intended for evaluation.
- The repository is prepared for open-source collaboration, but security-sensitive changes should come with focused tests and threat-model updates when behavior changes.
Documentation
- Documentation index
- Quick start and trust-loop demo
- Architecture
- Threat model
- Agent integrations
- Credential stores and 1Password
- Deployment and packaging
- Third-party assets and licenses
Contributing
Issues and focused pull requests are welcome. Start with CONTRIBUTING.md, and use SECURITY.md for anything that may expose credentials or bypass approval.
License
Apache-2.0. See LICENSE and NOTICE. Third-party names and artwork remain the property of their respective owners and are documented in TRADEMARKS.md and the third-party notices.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。