Agentgate
About
<p align="center"> <h1 align="center">AgentGate</h1> <p align="center"> <strong>Human-in-the-loop approval system for AI agents.</strong><br> Agents request. Policies decide. Humans approve.<br> <em>Keep humans in control of what AI agents can do.</em> </p> </p> <p align="center"> <a…
Explore
- Policy engine for auto-approve, auto-deny, or human routing.
- Multi-channel approvals via Slack, Discord, email, and web dashboard.
- TypeScript SDK + MCP integration with Claude Desktop.
- Webhooks with retry and exponential backoff.
- Full audit trail for every request and decision.
- Docker-ready with one docker-compose up.
- API key authentication with fine-grained scopes and rate limiting.
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
AgentgateCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
bash
pnpm install
bash
import { AgentGateClient } from '@agentgate/sdk';
// Create client with API key
const client = new AgentGateClient({
baseUrl: 'http://localhost:3000',
apiKey: process.env.AGENTGATE_API_KEY,
});
// Request approval
const request = await client.request({
action: 'send_email',
params: {
to: '[email protected]',
subject: 'Order shipped!',
},
urgency: 'normal',
});
// Wait for human decision
const decided = await client.waitForDecision(request.id, {
timeout: 60000, // 1 minute
});
if (decided.status === 'approved') {
// Execute the action
await sendEmail(decided.params);
} else {
console.log('Action denied:', decided.decisionReason);
}
npm install -g @agentgate/cli
agentgate config show
Configuration is stored in ~/.agentgate/config.json. You can also use environment variables:
export AGENTGATE_URL=http://localhost:3000
export AGENTGATE_API_KEY=agk_...
Add to your claude_desktop_config.json:
{
"mcpServers": {
"agentgate": {
"command": "npx",
"args": ["@agentgate/mcp"],
"env": {
"AGENTGATE_URL": "http://localhost:3000",
"AGENTGATE_API_KEY": "agk_..."
}
}
}
}
AgentGate uses API keys for authentication. All API requests (except /health) require a valid API key.
Set rate limits when creating or updating API keys:
// Via API (requires admin scope)
POST /api/keys
{
"name": "My Agent",
"scopes": ["request:create", "request:read"],
"rateLimit": 60 // 60 requests per minute
}
// null = unlimited
{
"name": "Internal Service",
"scopes": ["admin"],
"rateLimit": null
}
| Variable | Default | Description |
|----------|---------|-------------|
| PORT | 3000 | Server port |
| DATABASE_URL | ./data/agentgate.db | SQLite database path |
| AGENTGATE_API_KEY | - | API key for SDK/CLI |
| SLACK_BOT_TOKEN | - | Slack bot token (for Slack integration) |
| SLACK_SIGNING_SECRET | - | Slack signing secret |
| DISCORD_BOT_TOKEN | - | Discord bot token (for Discord integration) |
| DISCORD_DEFAULT_CHANNEL | - | Default Discord channel for notifications |
Policies are stored in the database and can be managed via API:
// Example: Auto-approve low-risk emails
{
name: "auto-approve-emails",
priority: 10,
enabled: true,
rules: [
{
match: { action: "send_email" },
decision: "auto_approve"
}
]
}
AgentGate provides Docker images for easy self-hosted deployments.
pnpm install
agentgate_request
Submit an approval request. Returns request ID and initial status.
agentgate_get
Get the current status of an approval request by ID.
agentgate_list
List approval requests with optional filters.
agentgate_decide
Approve or deny a pending request. Use when you are the designated approver.
agentgate_list_policies
List all policies ordered by priority.
agentgate_create_policy
Create a new policy with rules.
agentgate_update_policy
Replace an existing policy (all fields required).
agentgate_delete_policy
Delete a policy by ID.
agentgate_list_audit_logs
List audit log entries with optional filters and pagination.
agentgate_get_audit_actors
Get unique actor values from audit logs.
| Tool | Description |
|------|-------------|
| agentgate_request_approval | Create a new approval request |
| agentgate_check_request | Get status of an approval request |
| agentgate_list_requests | List pending approval requests |
| agentgate_list_policies | List configured policies |
| agentgate_create_policy | Create a new policy rule |
| agentgate_update_policy | Update an existing policy |
| agentgate_delete_policy | Delete a policy |
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"agentgate": {
"agentgate": {
"command": "npx",
"args": [
"@agentgate/mcp"
],
"env": {
"AGENTGATE_URL": "",
"AGENTGATE_API_KEY": ""
}
}
}
}
}
McpServers
{
"agentgate": {
"command": "npx",
"args": [
"@agentgate/mcp"
],
"env": {
"AGENTGATE_URL": "",
"AGENTGATE_API_KEY": ""
}
}
}
<p align="center">
<h1 align="center">AgentGate</h1>
<p align="center">
<strong>Human-in-the-loop approval system for AI agents.</strong><br>
Agents request. Policies decide. Humans approve.<br>
<em>Keep humans in control of what AI agents can do.</em>
</p>
</p>
<p align="center">
<a href="https://www.npmjs.com/search?q=%40agentgate"></a>
<a href="./LICENSE"></a>
<a href="#"></a>
<a href="#"></a>
</p>
---
<p align="center">

</p>
Your AI agent wants to send an email, delete a file, or deploy to production.
Should it? AgentGate lets you define policies that auto-approve safe actions,
auto-deny dangerous ones, and route everything else to a human — via dashboard, Slack, Discord, or email.
✨ Highlights
- 🛡️ Policy engine — auto-approve, auto-deny, or route to humans based on rules
- 👥 Multi-channel approvals — Slack, Discord, email, or web dashboard
- 🔌 TypeScript SDK + MCP — works with any agent framework or Claude Desktop
- 🪝 Webhooks with retry — real-time notifications with exponential backoff
- 📝 Full audit trail — every request, decision, and action logged
- 🐳 Docker-ready — one docker-compose up for the full stack
- 🔐 Production-hardened — SSRF protection, ReDoS defense, structured logging, graceful shutdown
- 🔗 One-click decision links — approve or deny directly from notification emails and webhooks
- ♿ Accessible UI — keyboard-navigable approval modals, focus trapping, ARIA labels
- 💀 Skeleton loading — smooth loading states across every dashboard page
- ⚡ Fast & lightweight — Hono server, SQLite or PostgreSQL
Dashboard
See all pending requests at a glance, color-coded by urgency so you know what needs attention first.
Approval Requests
Review, approve, or deny requests — filter by status to focus on what matters.
Audit Log
Search through every decision with filters for event type, action, actor, and date range.
Request Detail
Drill into any request to see parameters, context, timeline, and audit trail — with one-click Approve/Deny buttons.
API Keys
Manage API keys with fine-grained scopes, rate limits, and usage tracking. Create, edit, or revoke keys from the dashboard.
Webhooks
Configure webhook endpoints for real-time notifications. Add URLs, pick events, and let AgentGate handle retries automatically.
Login
Sign in with your API key — create one via the CLI or ask your admin.
---
Table of Contents
- Quick Start
- Architecture
- Packages
- SDK Usage
- CLI
- MCP Integration
- Authentication
- API Endpoints
- Rate Limiting
- Webhooks
- Configuration
- Docker Deployment
- Development
- Troubleshooting
- Contributing
- License
---
Quick Start
1. Install dependencies
pnpm install
2. Run database migrations
pnpm --filter @agentgate/server db:migrate
3. Bootstrap (create admin API key)
pnpm --filter @agentgate/server bootstrap
Save the API key - it's shown once only! Set it in your environment:
export AGENTGATE_API_KEY="agk_..."
4. Start the development environment
# Start server (port 3000) and dashboard (port 5173)
pnpm dev
5. Run the demo
In a new terminal (with API key set):
export AGENTGATE_API_KEY="agk_..."
pnpm demo
6. Open the dashboard
Visit http://localhost:5173 to view and manage approval requests.
Architecture
┌─────────────────────────────────────────────────────────────────┐
│ AI Agents │
│ (use @agentgate/sdk or MCP to request approvals) │
└───────────────────────────┬─────────────────────────────────────┘
│ HTTP API (authenticated)
▼
┌─────────────────────────────────────────────────────────────────┐
│ AgentGate Server │
│ ┌──────────────┐ ┌──────────────┐ ┌──────────────┐ │
│ │ Policy Engine│ │ Request Store│ │ Audit Logger │ │
│ ├──────────────┤ ├──────────────┤ ├──────────────┤ │
│ │ API Keys │ │ Webhooks │ │ MCP Server │ │
│ └──────────────┘ └──────────────┘ └──────────────┘ │
└───────────────────────────┬─────────────────────────────────────┘
│
┌─────────────┼─────────────┐
▼ ▼ ▼
┌────────────────┐ ┌────────────────┐ ┌────────────────┐
│ Web Dashboard │ │ Slack Bot │ │ Discord Bot │
│(React+Tailwind)│ │(approve in DM) │ │(approve in ch) │
└────────────────┘ └────────────────┘ └────────────────┘
│ │ │
└─────────────┼─────────────┘
▼
┌──────────┐
│ Humans │
└──────────┘
Packages
| Package | Description | Docs |
|---------|-------------|------|
| @agentgate/core | Types, schemas, policy engine | - |
| @agentgate/server | Hono API server | - |
| @agentgate/sdk | TypeScript SDK for agents | README |
| @agentgate/cli | Command-line interface | - |
| @agentgate/mcp | MCP server for Claude Desktop | - |
| @agentgate/slack | Slack bot integration | README |
| @agentgate/discord | Discord bot integration | README |
| @agentgate/dashboard | React web dashboard | - |
SDK Usage
import { AgentGateClient } from '@agentgate/sdk';
// Create client with API key
const client = new AgentGateClient({
baseUrl: 'http://localhost:3000',
apiKey: process.env.AGENTGATE_API_KEY,
});
// Request approval
const request = await client.request({
action: 'send_email',
params: {
to: '[email protected]',
subject: 'Order shipped!',
},
urgency: 'normal',
});
// Wait for human decision
const decided = await client.waitForDecision(request.id, {
timeout: 60000, // 1 minute
});
if (decided.status === 'approved') {
// Execute the action
await sendEmail(decided.params);
} else {
console.log('Action denied:', decided.decisionReason);
}
CLI
AgentGate includes a command-line interface for managing approval requests.
Installation
# From the monorepo
pnpm --filter @agentgate/cli build
Or install globally (when published)
npm install -g @agentgate/cli
Configuration
Configure the CLI with your server URL and API key:
# Set server URL
agentgate config set serverUrl http://localhost:3000
Set API key
agentgate config set apiKey agk_your_api_key
View current config
agentgate config show
…
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



