ScopeGate
Permission gateway that hands an AI agent a scoped MCP endpoint instead of an OAuth token: connect 27 services (Gmail, Google Calendar/Drive/Ads/Search Console, Slack, Notion, GitHub, Jira, Salesforce, HubSpot, Stripe, LinkedIn, X, Meta Ads and more), grant per-action permissions finer than native OAuth scopes, audit every call and revoke a key in one click. Self-hostable, MIT.
README
ScopeGate
Never hand an AI agent a full OAuth scope again.
ScopeGate sits between your agents and the accounts they reach — yours or your clients'. You connect a service once, tick the exact actions an agent may call, and hand it an MCP endpoint that can do nothing else. Every call is logged; one click kills the key without touching the connection.
- Per-action permissions —
gmail:read_emailsyes,gmail:send_emailno. Finer than any provider's OAuth scopes. - Audit trail — who, which tool, what outcome, how long. Per project, exportable.
- One-click revocation — regenerate an endpoint key; the service connection stays.
- Tokens never leave — AES-256-GCM at rest, refreshed automatically, agents only ever see
sg_….
Run it yourself in one command:
docker compose --profile local up
Open http://localhost:3000 — the admin login is printed in the container logs on first boot. Details in Quick Start.
Tech Stack
- Framework: Next.js 16 (App Router)
- Language: TypeScript
- Database: PostgreSQL + Prisma 7
- UI: Tailwind CSS v4, shadcn/ui
- Auth: Better Auth (database-backed sessions, Prisma adapter)
- MCP:
@modelcontextprotocol/sdk(Streamable HTTP) - Package Manager: pnpm
Quick Start (self-hosted)
Full feature parity with the hosted cloud version — nothing is cut for self-host.
git clone https://github.com/alifanov/scopegate.git
cd scopegate
docker compose --profile local up
Open http://localhost:3000. No .env file needed: a local
Postgres and a fresh BETTER_AUTH_SECRET are provisioned automatically, and the
generated admin login is printed once in the app container logs on first boot
(look for Generated admin login) — search it with docker compose logs app | grep -A4 "First run".
The password is also saved to the app_data volume so it survives restarts.
To connect real services (Gmail, LinkedIn, GitHub, …), copy .env.example to .env
and fill in the OAuth client id/secret for the providers you want — every block is
independent and optional, a provider without credentials simply doesn't show up.
Development Setup
Prerequisites
- Node.js 20.19+, 22.12+ or 24+ (required by Prisma 7)
- pnpm
- PostgreSQL
Setup
- Clone the repository and install dependencies:
pnpm install
- Copy the environment file and fill in your values:
cp .env.example .env
| Variable | Description |
|---|---|
DATABASE_URL |
PostgreSQL connection string |
BETTER_AUTH_SECRET |
Secret key for session signing |
BETTER_AUTH_URL |
App base URL (e.g. http://localhost:3000) |
ADMIN_EMAIL |
Bootstrap admin email |
ADMIN_PASSWORD |
Bootstrap admin password |
- Run database migrations:
pnpm prisma migrate dev
- Start the development server:
pnpm dev
Open http://localhost:3000.
Project Structure
src/
├── app/
│ ├── (auth)/ # Login & register pages
│ ├── (dashboard)/ # Protected dashboard pages
│ │ └── projects/ # Project management, endpoints, audit, settings
│ ├── api/
│ │ ├── auth/[...all]/ # Better Auth catch-all handler
│ │ ├── projects/ # Projects CRUD, endpoints, services, audit
│ │ └── mcp/[apiKey]/ # MCP Streamable HTTP handler
│ ├── layout.tsx
│ └── page.tsx # Landing page
├── components/
│ ├── ui/ # shadcn/ui components
│ ├── layout/ # Sidebar, header
│ └── shared/ # Reusable app components
├── lib/
│ ├── db.ts # Prisma client singleton
│ ├── auth.ts # Better Auth server instance
│ ├── auth-client.ts # Better Auth client SDK
│ ├── auth-middleware.ts # getCurrentUser() helper
│ ├── bootstrap.ts # Admin user bootstrap on empty DB
│ ├── provider-registry.ts # Every supported provider — the one file to edit
│ └── mcp/
│ ├── permissions.ts # Permission groups (derived from the registry)
│ ├── tools/ # One file per service, aggregated in index.ts
│ ├── service-fetch.ts # Unified, SSRF-safe transport for all providers
│ └── handler.ts # MCP server factory + audit logging
├── generated/prisma/ # Generated Prisma client
└── middleware.ts # Route protection
Available Scripts
pnpm dev # Start development server
pnpm build # Production build
pnpm start # Start production server
pnpm lint # Run ESLint
pnpm prisma generate # Regenerate Prisma client
pnpm prisma migrate dev # Create and apply migrations
pnpm prisma studio # Open Prisma Studio (DB browser)
How It Works
- Login — sign in with admin credentials (bootstrapped from env vars on first run)
- Create a Project — organize endpoints and services by project
- Connect a Service — add a service connection to the project
- Create an MCP Endpoint — select a service connection and pick specific permissions (e.g.
gmail:read_emails,calendar:create_event) - Use the MCP URL — plug the endpoint URL into any MCP-compatible AI agent; only the allowed actions are exposed
- Monitor — track every request in the audit log
Permissions
A permission is a single action, not a service — gmail:read_emails can be granted
without gmail:send_email. Groups are derived from src/lib/provider-registry.ts
(27 providers: Google Workspace, Google Ads & Search Console, Meta, LinkedIn,
Twitter, Slack, Notion, Jira, HubSpot, Salesforce, Stripe, Airtable, …) and listed
in src/lib/mcp/permissions.ts. Adding a provider means editing the registry —
transport, token strategy and permission groups are all derived from it.
A few Google examples:
| Group | Actions |
|---|---|
| Gmail | gmail:read_emails, gmail:send_email, gmail:list_labels, gmail:search_emails |
| Google Calendar | calendar:list_events, calendar:create_event, calendar:update_event, calendar:delete_event |
| Google Drive | drive:list_files, drive:read_file, drive:create_file, drive:delete_file |
Database Schema
- User — authentication, team membership
- Session — database-backed auth sessions
- Account — auth provider credentials (email/password)
- Project — logical grouping for services and endpoints
- TeamMember — user-project relationship with roles (owner/member)
- ServiceConnection — OAuth tokens for connected services
- McpEndpoint — MCP endpoint with API key, rate limit, active status
- EndpointPermission — allowed actions per endpoint
- AuditLog — request log with action, status, duration, errors
License
See LICENSE.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。