All non-PUBLIC routes have Default Protection — cryptographic verification, caveats, delegation, revocation. Then choose your economic policy: observe (audit), control (budget), or charge (paid-rail policy for admitting external agents).
Protection is the starting state. Economics are configurable.
Deterministic public proof path
The one-click Control scenes are useful for protocol exploration. The deterministic buyer proof lives on the public demo path and shows 401 no authority, 200 allowed, 402/403 denial, revoke/replay denial, and Evidence Pack export without auth or hidden shortcuts.
Layer 0 — Always-On Cryptographic Verification
Default Protection is the foundation of SatGate's security model. Every protected (non-PUBLIC) request is cryptographically verified — signatures, caveats, delegation chains. You can't turn this off. Then you choose your economic policy: observe, control, or charge.
Issues root credentials. Retains authority. Can revoke governed access.
Uses tokens. Can delegate restricted sub-tokens offline.
Receives delegated tokens. Cannot escalate beyond granted scope.
FAQ
SatGate Control protects agent API and MCP tool calls by enforcing scoped capability tokens, budgets, delegation limits, revocation, and audit policy before requests reach upstream services.
Revocable capability tokens give agents narrow, expiring authority that can be delegated safely and denied at policy check without rotating global API keys or service-account credentials.
Control enforces scopes, budgets, and revocation before execution. Prove exports Evidence Packs containing signed receipts for supported receipt-producing decisions across internal and external agent lanes, so an auditor can verify what happened without trusting SatGate.
This demo runs against the live SatGate OSS deployment on Railway.