
skgate
io.github.helv-iov0.10.0更新于 Oct 4, 2026
MCP gateway: OAuth-protected endpoints for remote and hosted MCP servers, plus a Grok API.
概览
自托管的 OAuth 保护网关,可代理远程与本地托管的 MCP 服务器,并提供基于 Grok 的 OpenAI 兼容 API。
- 功能
- skgate 以单个容器运行,在 OAuth 2.1 之后托管 MCP 服务器,可为每个上游提供独立路径,也可将多个上游聚合到一个端点。它能管理来自 npm、PyPI 或 git 仓库的 stdio 服务器,按需启动并在空闲时停止,还能把 Grok 订阅代理为带虚拟密钥和模型别名的 OpenAI 兼容 API。管理员登录与配置通过网页界面完成。
- 适用场景
- 当你希望为多个 MCP 服务器提供统一的认证端点,或想通过 OpenAI 兼容 API 使用 Grok 订阅时,可以使用它。它适合家庭实验室和小型部署,尤其是希望空闲的 MCP 进程不占用内存的场景。
- 运行要求
- 需要本地容器运行时(如 Docker),以及一个带机密客户端的 OIDC 提供方。必需的环境变量:PUBLIC_URL、OIDC_ISSUER、OIDC_CLIENT_ID 和 OIDC_CLIENT_SECRET。完整镜像还需要 Node.js、Python、uv、.NET、Go 和 git 来运行托管服务器;slim 镜像仅做代理。建议但不强制要求 Grok 订阅。
安装
在 SourceWeft 中
- 打开 控制台中的 skgate,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
skgate
Use your Grok subscription as an OpenAI-compatible API, and serve your MCP servers from one OAuth-protected gateway.
Yes, all MCP servers: everyone's welcome. skgate can run them for you too, so no more stacks. It just works.
Name Origin
skgate /ɛsˈkɑːɡeɪt/ (ess-KAH-gate)
"sk" is what most AI API keys start with, or so I perceive it, and "gate" is for gateway. Bit rubbish as names go, but it's ours.
The plane in the logo is an inside joke. The public wouldn't understand it, and I'm not about to explain it. Sorry.
Quick start
Before you start: an OIDC provider with a confidential client for skgate (admin login is OIDC only). Just trying it on one machine? docs/quickstart.md runs skgate with a bundled provider and no accounts.
A Grok subscription is recommended but not required.
docker compose up -d- Open
https://skgate.example.com/adminand sign in through your OIDC provider. - status > Grok > Sign in: open the shown address, enter the code, approve.
- keys > enter a name > Create key. Copy the
sk-...key; it is shown once. - Use it: base URL
https://skgate.example.com/v1, API keysk-...(see Examples).- The base URL is forgiving:
/v1,/api,/api/v1and the bare host all reach the same API, so use whichever form your client expects.
- The base URL is forgiving:
Image tags:
latest: proxy + managed MCP servers (Node.js, Python, uv, .NET, Go, git)slim: proxy only
Upgrade: back up ./data, then docker compose pull && docker compose up -d.
Examples
curl: models and a chat completion
OpenAI client
Model alias: one name that always points at the newest model
Map grok-latest to the latest available model. Change the target in this one place and every app using grok-latest is upgraded at once, with no client config changes.
Grok > Details > Model aliases: alias grok-latest, target the newest model in the list (for example grok-4.7), Save.
Aliases are listed first in /v1/models.
Add an MCP server with Suggest configuration
Needs the latest image and Grok signed in. The first time, Pick MCP helper model next to the button opens the model picker right on the page.
mcp upstreams > Add upstream > Type managed (package or repository):
-
MCP source URL / package, one of:
-
Suggest configuration. skgate fetches the README and manifests (
package.json,pyproject.toml,server.json), the MCP helper model proposes command, args, install step and env names (marked secret or not, required or optional), and the Manual configuration fields are filled in with a confidence and any warnings. Nothing is saved yet. Point it at the repo, fill in the variables it needs, and it just works. -
Set an alias, fill in the variables you need (empty ones are not passed to the server), Save. The server is at
https://skgate.example.com/mcp/<alias>.
If the button is greyed out, hover it: sign in to Grok on status, or use Pick MCP helper model beside it.
MCP client: one upstream or all of them
Hosted connectors use OAuth (leave client ID and secret empty). Scripts and CLIs send a key:
On-demand MCP servers: no RAM while idle
On a RAM-constrained homelab, idle MCP servers should cost nothing. Managed servers (npx, uvx, git) are child processes of skgate. By default (Lifecycle on-demand) one starts on its first request and stops after 10 minutes without requests; the next request starts it again.
- Default is on-demand; Lifecycle
always-onstarts the server at boot instead. - The first request after a stop waits until the server answers
initialize(up to 60 s). - A server with a request in flight is never stopped. Stopping is SIGTERM, then SIGKILL after 5 s.
- Idle time is
idleTimeoutSecondsin import JSON (default 600; not in the form):
- The aggregated
/mcpincludes remote and always-on upstreams marked In /mcp. On-demand servers are left out, so/mcpnever starts them. Point a client at/mcp/<alias>to use one. - Remote upstreams have no process; there is nothing to idle.
- An admin Stop keeps a server stopped until Start or Restart.
Managed MCP server: npx (stdio)
mcp upstreams > import JSON > paste > Import. Needs the latest image.
Served at https://skgate.example.com/mcp/everything. For Python servers use "command": "uvx", "args": ["<package>"].
Managed MCP server: git repository
mcp upstreams > import JSON > paste > Import. skgate clones the repo, runs install, then the command.
Remote MCP server
mcp upstreams > Add upstream > Type remote (URL), or import:
Features
Comparison
As of 2026-10-02; check each provider's terms.
Sources
- xAI, Use Grok in OpenCode
- OpenAI, Sign in with ChatGPT
- Anthropic, Legal and compliance
- Google, Gemini CLI terms
- GitHub, Copilot now supports OpenCode
Configuration
Set under environment: (or env_file); placeholders in .env.example.
Grok needs no variables; its base URL and aliases are in its Details dialog.
Everything lives in /data (skgate.db, secrets.key): back up both.
Reverse proxy
Set PUBLIC_URL to the public https origin. No forward-auth on /v1, /mcp, /authorize, /token, /register, /.well-known. Only Traefik is tested by the author; open an issue with feedback.
Traefik
nginx
Caddy
HAProxy
Apache
OIDC setup
Without OIDC_* the admin answers 503. Every user your provider lets in is an admin: restrict the provider, or set OIDC_ALLOWED_EMAILS / OIDC_ALLOWED_GROUPS. Hints for Authelia, Authentik, Keycloak, Zitadel and Pocket ID: docs/oidc.md.
Security notes
- Virtual keys are stored as SHA-256 hashes; upstream credentials are AES-256-GCM encrypted.
/authorizeneeds an admin session.- Managed upstreams run admin-supplied commands; use the
slimimage to disable them. - A key can be allowed in the URL (
?key=) for clients that cannot send headers. It is off per key by default, because URLs leak into logs, history and referrers.
More: operations.
Built with AI assistance
skgate is built with AI assistance: coding agents write much of the code, tests and docs. The author reviews the changes and runs skgate.
Development
docs/development.md. Contributors and agents: AGENT.md.
License
MIT, see LICENSE.
来源:README.md,提交 9fcab95
工具
0版本历史
1- v0.10.0最新Oct 4, 2026

