MCP GATEWAY

One MCP URL for all your connectors.

Connect your accounts once. claude.ai, Claude Code, Cursor — every agent reaches them through a single OAuth-protected endpoint, with scoped writes, enforced constraints, and a full audit trail.

Your agents connect tohttps://app.gentkey.com/mcpclaude.ai (web & mobile) · Claude Code · Cursor · any MCP client

Providers hand your agent a key to the whole house.
Gentkey cuts it a key to one room.

HOW IT WORKS

Four moving parts. One contract.

01

Connect your accounts

Google Ads over OAuth, Stripe with a restricted key, or any remote MCP server by URL. Credentials are encrypted at rest and never leave the server.

02

Hand every agent one URL

Each client completes a standard OAuth flow and lands in its own Gentkey — your connections, nobody else’s. No per-tool API keys to scatter around.

03

The policy gate decides

Read tools work out of the box and can be switched off. Write tools require an explicit grant, bounded by constraints like max $ delta/day = 50.

04

Every decision is recorded

Allowed, denied, or denied by constraint — each call lands in the audit log with the agent, tool, and reason. Filter it live, per connection or per agent.

THE DEMO THAT MATTERS

Same grant, same tool,
different outcome.

GRANTEDgoogle-ads.write.budget · max $ delta/day = 50

Raise the Summer Sale campaign budget by $30.

google_ads.update_budgetallowed

+$30.00 is within the daily cap. Executed upstream, recorded in the log.

Great — now raise it by $500.

google_ads.update_budgetdenied by policy

Δ$500.00 exceeds the $50/day constraint. Nothing changed upstream — and the denial is in the log too.

The agent keeps its autonomy. You keep the blast radius.

WHAT YOU GET

Custody, gating, and audit — built in.

grants

Writes need a grant

Reads work out of the box. Anything that changes state needs a capability you granted explicitly — revoke it and the next call is denied.

constraints

Constraints are enforced, not suggested

Grants carry hard bounds — max budget delta per day, max refund per call. The policy gate does arithmetic, not vibes.

aes-256-gcm

The model never sees a credential

Tokens and keys are encrypted at rest and injected server-side at call time. Nothing secret ever enters the context window.

audit_log

A trail you can act on

Every decision is attributed to the agent that made it. See what each agent called and searched for — and revoke its tokens in one click.

passthrough

Any remote MCP server

Proxy Notion, Linear, Sentry, GitHub — or any URL. Upstream tools default to write-gated; vendor self-labeling isn’t trusted.

search_tools

A catalog that doesn’t eat context

Past 20 tools, agents get three meta-tools (~350 tokens) and search the catalog instead of loading every schema up front.

CONNECTORS

Native connectors, plus any MCP server.

Google Ads and Stripe get deep, semantic constraints. Everything else gets custody, gating, and audit the day its vendor ships an MCP server.

Google AdsStripeNotionLinearSentryGitHubPayPalIntercomSquareWebflowAsanaHugging Face+ any MCP server URL

Cut smaller keys.

Sign in, connect an account, and grant your first scoped capability in under a minute.