AgentStack
MCP verified MIT Self-run

Cloudgentic Gateway

mcp-cloudgentic-cloudgentic-gateway · by cloudgentic

Open-source AI agent account gateway — security layer between AI agents and your Gmail, Calendar, Slack, and 15+ services. Kill switch, anomaly detection, rules engine, encrypted vault.

No reviews yet
0 installs
15 views
0.0% view→install

Install

$ agentstack add mcp-cloudgentic-cloudgentic-gateway

✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README — it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-cloudgentic-cloudgentic-gateway)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming — see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps — measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Cloudgentic Gateway? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

CloudGentic Gateway

[](https://opensource.org/licenses/MIT) [](https://hub.docker.com) [](https://python.org) [](https://nextjs.org) [](https://github.com/cloudgentic/cloudgentic-gateway/releases)

The open-source security layer between AI agents and your accounts.

CloudGentic Gateway is a self-hosted AI agent account gateway -- a secure, rules-enforced bridge that lets AI agents (OpenClaw, Agent Zero, LangChain, etc.) access your Gmail, Calendar, Drive, Slack, and 15+ services while you stay in control.

> You wouldn't give an intern unrestricted access to your Gmail. Why give it to an AI agent?


Security-First Design

  • Emergency Kill Switch -- One click to revoke all agent access instantly
  • Behavior Anomaly Detection -- Automatic alerts when agents act unusually
  • Dry-Run Mode -- Test agent actions without executing them
  • Skill Security Scanner -- Scan OpenClaw skills for malware before installing
  • Mandatory 2FA -- Every self-hosted instance requires TOTP authentication
  • AES-256-GCM Vault -- Military-grade encryption for all stored tokens
  • Append-Only Audit Log -- Immutable record of every agent action

Quick Start

git clone https://github.com/cloudgentic/cloudgentic-gateway.git
cd cloudgentic-gateway
cp .env.example .env

Edit .env and set the required values:

# Generate keys:
openssl rand -hex 32  # GATEWAY_MASTER_KEY
openssl rand -hex 32  # GATEWAY_JWT_SECRET

# Set passwords:
POSTGRES_PASSWORD=your_secure_password
REDIS_PASSWORD=your_secure_password

Start everything:

docker compose up -d

Open http://localhost:3050 -- create your admin account and set up 2FA.

  • Dashboard: http://localhost:3050
  • API Docs: http://localhost:8421/docs

Features

Core Gateway

| Feature | Description | |---------|-------------| | Encrypted Token Vault | AES-256-GCM + salted HKDF per-user key derivation | | 15 Provider Wizards | Step-by-step OAuth setup for Google, Slack, X, Salesforce, HubSpot, and more | | Agent API Keys | cgw_ prefixed, SHA-256 hashed, scoped permissions, expiration | | Rules Engine | Rate limits, whitelists, blacklists, approval workflows, action chains, dry-run | | 5 Rule Templates | One-click presets: Read-Only Gmail, Safe Social, Business Hours, and more | | MCP Server | FastMCP tools for Gmail, Calendar, Drive -- works with any MCP-compatible agent |

Security & Monitoring

| Feature | Description | |---------|-------------| | Emergency Kill Switch | Instantly revoke all agent access from dashboard, API, or MCP | | Anomaly Detection | Rate spikes, burst detection, unusual hours, new action alerts | | Skill Scanner | Pattern-based malware analysis for OpenClaw ClawHub skills | | Provider Health | Token status, rate limit usage, API availability per account | | Multi-Agent Dashboard | All agents side-by-side with 24h stats |

Events & Automation

| Feature | Description | |---------|-------------| | Webhook Events | Subscribe to gateway events, receive at your endpoints | | Action Chains | "If Gmail send succeeds, notify Slack" -- simple workflows | | Push Notifications | Alerts via Email, Telegram, Discord, or custom webhook | | Audit Export | Streaming CSV download with date range and filters | | Preflight API | Agent startup health check -- verify accounts, keys, rules |

Dashboard Pages

| Page | What it does | |------|-------------| | Provider Setup | Step-by-step OAuth wizards with direct developer console links | | Connected Accounts | Connect/disconnect accounts, shows only configured providers | | API Keys | Create/revoke keys, shown once on creation | | Agents | Multi-agent overview with 24h activity stats | | Rules | Visual builder + template gallery | | Webhooks | Subscribe to events, view delivery status | | Security | Kill switch, anomaly feed, skill scanner | | Health | Token expiry bars, rate limit usage, overall status | | Audit Log | Filterable table + CSV export | | Notifications | Toggle channels, configure credentials, test buttons | | Settings | Profile, password change, 2FA management |


Architecture

+-----------------+   +-----------------+   +-----------------+
|  OpenClaw Agent |   | Agent Zero      |   |  Any AI Agent   |
+--------+--------+   +--------+--------+   +--------+--------+
         |                      |                      |
         +----------------------+----------------------+
                                |  API Key (cgw_...) / MCP
                  +-------------v--------------+
                  |   CLOUDGENTIC GATEWAY       |
                  |   - Rules Engine            |
                  |   - Token Vault (AES-256)   |
                  |   - Anomaly Detection       |
                  |   - MCP Server              |
                  |   - Audit Logger            |
                  +-------------+--------------+
                                | OAuth Tokens
         +----------------------+----------------------+
         |                      |                      |
+--------v--------+   +--------v--------+   +---------v-------+
| Google APIs     |   | CRMs            |   | Social / Chat   |
| Gmail,Cal,Drive |   | HubSpot, SF, GL |   | Slack, X, etc.  |
+-----------------+   +-----------------+   +-----------------+

Docker Compose Stack (5 services)

| Service | Port | Description | |---------|------|-------------| | gateway-api | 8421 | FastAPI backend | | gateway-web | 3050 | Next.js 15 dashboard | | gateway-worker | -- | Celery background tasks | | gateway-db | 5432 | PostgreSQL 16 | | gateway-redis | 6379 | Redis 7 |


Tech Stack

| Layer | Technology | |-------|------------| | API | FastAPI 0.115+ (Python 3.12) | | Frontend | Next.js 15, React 19, Tailwind CSS, Framer Motion | | Database | PostgreSQL 16 with Alembic migrations | | Cache | Redis 7 | | Task Queue | Celery 5 | | MCP Server | FastMCP | | Encryption | AES-256-GCM + salted HKDF | | Password Hashing | Argon2id | | 2FA | TOTP | | Containers | Docker + Docker Compose |


Agent Integration

REST API

curl -X POST http://localhost:8421/api/v1/agent/execute \
  -H "Authorization: Bearer cgw_your_api_key" \
  -H "Content-Type: application/json" \
  -d '{
    "provider": "google",
    "service": "gmail",
    "action": "send",
    "params": {
      "to": "user@example.com",
      "subject": "Hello",
      "body": "Sent via CloudGentic Gateway"
    }
  }'

Dry-Run Mode

curl -X POST http://localhost:8421/api/v1/agent/execute \
  -H "Authorization: Bearer cgw_your_api_key" \
  -H "X-Gateway-Dry-Run: true" \
  -H "Content-Type: application/json" \
  -d '{"provider": "google", "service": "gmail", "action": "send", "params": {...}}'

Preflight Check

curl http://localhost:8421/api/v1/agents/preflight \
  -H "Authorization: Bearer cgw_your_api_key"

MCP Server

docker exec gateway-api fastmcp run app.mcp.server:mcp

CLI Management

# List users
docker exec gateway-api python -m app.cli list-users

# Reset password
docker exec gateway-api python -m app.cli reset-password user@email.com "newpassword"

# Disable 2FA (emergency recovery)
docker exec gateway-api python -m app.cli disable-2fa user@email.com

# Create admin
docker exec gateway-api python -m app.cli create-admin admin@email.com "password"

Providers

Fully implemented

| Provider | Services | |----------|----------| | Google | Gmail (list, read, send, search), Calendar (list, create, delete), Drive (list, read, download) |

OAuth setup wizards (connect flow ready, service proxy coming)

Slack, Twitter/X, Facebook, Instagram, TikTok, Stripe, HubSpot, GoHighLevel, Salesforce, Discord, LinkedIn, GitHub, Notion, Shopify


Documentation

  • [Architecture](docs/ARCHITECTURE.md)
  • [Security Measures](docs/SECURITY-AUDIT.md)
  • [Git Workflow](docs/GIT-WORKFLOW.md)
  • [Feature Roadmap](docs/FEATURE-ROADMAP.md)
  • API Reference (auto-generated OpenAPI)

Contributing

We welcome contributions! Please read our [Contributing Guide](CONTRIBUTING.md).

If you discover a vulnerability, please report it via [SECURITY.md](SECURITY.md).


License

MIT License -- see [LICENSE](LICENSE) for details.


Built by CloudGentic AI -- A product of Forester Information Technology Corp.

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet — be the first.

Versions

  • v0.1.0 Imported from the upstream source.