# Sealgate [Health: Active]

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/Edison-Watch/sealgate-mcp  
**GitHub Stars:** 1  
**npm Downloads (last month):** 191  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/sealgate

## Description
Sealgate gateway proxy: list governed MCP servers and review agent session and audit status.

## Tools
Capabilities this server exposes over MCP:

- **list_mcp_servers** — List the MCP servers governed by your Sealgate gateway, with access-control classification and connection status.
- **get_session_status** — Review recent agent sessions and audit events: what agents did, which data flowed, and any blocked actions.

## Claude Desktop Quick Installation
Install path detected from listing signals. Uses `npx` (confidence: high):

```json
"mcpServers": {
  "sealgate": {
    "command": "npx",
    "args": ["-y","@sealgate/mcp"],
    "env": {
      "SEALGATE_GATEWAY_URL": "",
      "SEALGATE_API_KEY": ""
    }
  }
}
```

**Requires environment variables:** `SEALGATE_GATEWAY_URL`, `SEALGATE_API_KEY` — the values above are empty placeholders; fill in real credentials before running (see the repository for what each one is for).

## Documentation

## What Sealgate MCP server does

The Sealgate MCP server is a thin bridge between an MCP client and a Sealgate gateway. Sealgate is positioned as a security gateway and data firewall between AI agents and an organisation’s data and tools. This package does not provide a broad collection of independent application tools; it forwards a focused set of requests to the configured gateway.

Its two exposed tools support operational visibility:

- `list_mcp_servers` reports the MCP servers governed by the gateway, including each server’s access-control classification and connection status.
- `get_session_status` retrieves recent agent sessions and audit events, including agent actions, data movement, and actions that were blocked.

Use the Sealgate MCP server when an agent needs to examine which governed MCP services are available or review what recent agent activity was permitted, recorded, or denied.

## How it works

The managed deployment is available at `https://mcp.sealgate.ai/mcp` as a remote, streamable HTTP endpoint. It acts as a per-user proxy for enabled MCP servers and applies Sealgate access-control policies to calls passing through the gateway. Browser-based OAuth 2.1 authentication is the normal connection method, so compatible clients can sign in without manually pasting an API key.

OAuth uses dynamic client registration, PKCE with the `S256` method, and refresh tokens through the `offline_access` scope. Discovery, consent, and token endpoints are hosted on the gateway origin. Organisations running a demo or self-hosted gateway can substitute their own host instead of using the managed release host.

Clients that cannot perform OAuth can use a URL containing a Sealgate API key and an optional session label. In that mode, the key is placed in the path rather than sent as an `Authorization` header. Treat such URLs as sensitive credentials.

## Setup and configuration

For the hosted gateway, add the remote streamable HTTP endpoint to a compatible MCP client and complete the browser sign-in flow. The README documents direct setup paths for Claude, ChatGPT, Claude Code, Cursor, VS Code, Goose, Grokbot, and other MCP clients. Cline, Zed, and Windsurf are also identified as working clients, although their configuration field names differ.

The npm package is the stdio alternative for clients that cannot use a remote server. Configure it with these environment variables:

- `SEALGATE_GATEWAY_URL`: the base URL of the organisation’s Sealgate Management API, such as `https://dashboard.sealgate.ai`.
- `SEALGATE_API_KEY`: an API key issued through the Sealgate dashboard.

Both values are supplied by the organisation operating the gateway. If either variable is absent, the tools return a configuration message instead of crashing. The package is available through `npx` and is also listed in the MCP Registry as `ai.sealgate/gateway`.

## Tools and capabilities

`list_mcp_servers` is useful for checking the governed server inventory before selecting a service. Its response includes access-control classification and whether each connection is currently available.

`get_session_status` is intended for reviewing recent agent activity. It covers sessions and audit events, with information about actions taken, data that flowed during those actions, and requests the gateway blocked.

The gateway also fronts Sealgate messaging connectors, including WhatsApp, Telegram, iMessage, Signal, LinkedIn DMs, Instagram, Messenger, Discord, X, and LINE. Those connectors are accessed through the gateway’s broader client and connector setup; the two tools documented here focus on server inventory and session or audit status.

## Limitations and notes

This package is a proxy, so its useful results depend on the configured Sealgate gateway, its policies, and the organisation’s enabled servers. The managed endpoint is remote and uses streamable HTTP; local stdio execution is a separate npm-based option requiring gateway credentials.

API-key URL authentication is not equivalent to OAuth and exposes the key in the URL path. Prefer the browser OAuth flow when the client supports it. The README does not document additional MCP tools beyond `list_mcp_servers` and `get_session_status`.

_Full upstream README: https://allmcps.com/mcp/sealgate/readme_

