HTTP APIs and MCP tool calls — authenticated, logged, cost-tracked, and budget-enforced. Per-agent budgets. Delegation hierarchies. Instant revocation. Connect in 5 minutes.
SatGate protects HTTP REST APIs and MCP tool servers equally. Same policies, same dashboard, same enforcement.
Your agents call OpenAI, Stripe, internal services — SatGate sits in front as a reverse proxy. Every request is authenticated, metered, and budget-checked before reaching the upstream.
SatGate proxies MCP tool calls from AI agents to your tool servers. Every tool/call is intercepted, cost-attributed, and governed — the agent sees standard MCP, your tools see standard MCP.
Every SatGate deployment starts in Observe mode. See the data. Then enforce.
See every API call, every tool invocation, every credit spent — without blocking anything. Shadow reporting shows what enforcement would have caught.
Set per-agent budgets. Get alerts at thresholds. Block requests when budgets are exhausted — agents get HTTP 402. No surprise bills.
Monetize your APIs. Agents pay per request via Lightning micropayments (L402). No API keys, no subscriptions — just pay and go.
Your agents present an identity credential, SatGate mints a budgeted macaroon, and they're through the gate. When the budget runs out or you revoke access — they stop. Instantly.
JWT from any OIDC provider
Issues budgeted macaroon
Budget-enforced, revocable
Revoke any agent's token instantly. Next request gets 401. Cascade revocation kills the entire delegation tree.
Every token carries a spending cap. When credits hit zero, SatGate returns HTTP 402. No surprise bills. No runaway agents.
Agents can delegate sub-tokens to other agents. Revoke the parent — the entire swarm stops. Full tree visibility in the dashboard.
AI agents don't have credit cards. They have API access. Without governance, every request is an unaudited transaction on your cloud bill.
Every agent gets a cryptographic bearer token with built-in scope, expiry, and budget caveats. Not an API key — a capability.
Know exactly which agent called which API or tool and what it cost. Shadow reports show where the money goes before you enforce.
Department → team → agent. Each level gets a budget. Parent tokens delegate to children. Spending rolls up automatically.
Agents start with zero access. Every request is authenticated and authorized. No ambient authority, no overprivileged keys.
Free Observe mode. No credit card. Works with any HTTP API or MCP server.