Free for teams up to 5 users

Self-hosted MCP gateway — one governed door from your AI to your company’s tools.

Ground it in your company’s context, let it act on your behalf, keep the reins — PII pseudonymized before the model sees it, every action policy-checked and audited. One endpoint for Claude, Codex, ChatGPT, Gemini.

Stores nothing in transitPII pseudonymizedSelf-hostedThis site is cookie-free
ConfluenceJiraM365NotionSlack+ moreFigmaWorkspaceGitLabYou + AIclientGrafana

The harness around your AI

The model is the easy part. A raw model is confident and clueless about your company. mcpgate is the harness that makes it work — it feeds the AI your context, holds the reins on what it may do, lets it act on your behalf (safely), and keeps the receipts. One harness, shared across everyone’s AI.

Context in: chains across your tool stack in one prompt

The AI knows which Jira ticket links to which MR links to which Slack thread. One prompt, no tab switching, no copy-paste.

# "What's blocking the Q2 release?"

jira: PBE-2674 → blocked by PBE-2701
gitlab: MR !891 awaiting review
slack: thread in #release, 14:32

# Answer assembled. No copy-paste.

Safe action: Markdown to ADF, project templates, link-back — automatic

Pre-hooks apply Jira project templates, convert Markdown to Atlassian Document Format, link the ticket back to the Slack thread. The AI writes prose; the gateway handles the schema.

mcpgate14:32
Created PBE-2842 from your Slack thread. Markdown converted to Jira ADF, project template applied, linked back to #release.
Open in Jira

Reins & receipts: audit, sanitization, exfiltration alerts

PII pseudonymized before the model sees it, rehydrated for the real tool call. Every action — with its byte volume — lands in the audit log; a 50 MB spike at 3 am is visible, not invisible.

  • Role-based access — admin / internal / external / viewer, per-user audit
  • Whole-document release — sensitive terms stripped in the browser before the AI sees contracts or HR files
  • Destructive actions gated — admin approval the AI can’t self‑grant

Ever gotten a confident answer that was just wrong?

Confidence — how sure it soundsActual quality — needs contextthe gap =overconfidencegap persistsit often parks here — it doesn't feel the need to look things upContext / data the AI has →level (low → high)
An answer sounds just as sure whether it's grounded or guessing. Without your context the AI parks at high confidence, low quality — the gap is overconfidence, and it never fully closes.
shared (company)+ personalcontext moves you rightConfidenceActual qualityContext / grounding →
Two layers close it: a shared, curated company map moves every answer right, and personal context moves it further — quality climbs toward confidence. The gap shrinks; it doesn't vanish, and we don't pretend it does.

An answer sounds just as sure whether it's grounded in your reality or guessing. Without context, the AI parks at high confidence, low quality — that gap is overconfidence.

A shared, curated company map moves every answer right; personal context moves it further — quality climbs toward confidence. The gap shrinks; it doesn't vanish, and we don't pretend it does.

Automations run through the same door

Not just Windmill: whatever runs your automation connects as a service-account user and acts on your behalf through the same door — no credentials handed to the automation platform.

The same governed door — with or without youANY TRIGGERYou askin your AI clientIt just runson a schedule or eventWindmill · n8n · cron · your agentmcpgateacts as you (OAuth)· policy · auditno tokens leave the gatewayYOUR TOOLS…and the rest of your stack
An automation isn't a side door. Whatever triggers it — you, a schedule, another agent — it runs through the same harness: your identity by OAuth delegation, the same policy and audit, and not one service token ever leaves the gateway.

Works with Claude, ChatGPT, Codex, Gemini — any MCP client. One admin connects it once; the whole team gets it, with per-client consent.

Source-available — read what runsSelf-hostedStores nothing in transitNo cookies, no analytics

Room for the right context

Fewer tokens per connected tool. Plus per-action audit, PII scrubbing and policy hooks raw MCP doesn’t give you. Drag to model your own stack:

How much context do your connected tools cost?
Direct MCP — curated tools resident
tokens, re-sent every turn
Via the gateway — resident
tokens — flat per service

Full calculator & method →

Speaking of the right context — only a lean set of tools stays resident. The rest — thousands of actions across every connected service — stay out of your window, discovered on demand via search when the AI needs them. That’s why each added service costs ~550 tokens here, not 11k.

Boringly simple to run

One command — a browser wizard does the rest: login, pick your services, connect your AI. That’s the whole setup — the harness is the part we already built. No .env file needed.

# one command — reviewable, runs on your infra
$ curl -fsSL https://mcpgate.de/install.sh | bash

# then open localhost:8642 — the wizard does the rest
Full quickstart →

Try mcpgate now

Explore the full gateway with demo data. No signup, no install, no credit card.