Server data from the Official MCP Registry
Payment decisions, durable evidence, x402 resource discovery and live gateway status for AI agents.
About
Payment decisions, durable evidence, x402 resource discovery and live gateway status for AI agents.
Remote endpoints: streamable-http: https://xguardgate.com/mcp
Security Report
Valid MCP server (1 strong, 0 medium validity signals). No known CVEs in dependencies. Imported from the Official MCP Registry.
3 tools verified · Open access · No issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Permissions Required
This plugin requests these system permissions. Most are normal for its category.
How to Connect
Remote Plugin
No local installation needed. Your AI client connects to the remote endpoint directly.
Add this to your MCP configuration to connect:
{
"mcpServers": {
"io-github-moelayyan90-xguard": {
"url": "https://xguardgate.com/mcp"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
XGuard — Secretless Agent Gateway
Canonical production API
https://api.xguardgate.com
Canonical identity — v5.0.2: XGuard Secretless Agent Gateway. Secretless Egress is the primary product. Action Rail and x402 facilitator routing are compatibility rails. Historical descriptions involving XGuard ACE, Solana/BAM speed bumps, Child Safety, Web Extractor, Universal Facilitator Gateway, High-Velocity x402 Facilitator, or a generic spend-only control plane are not the current XGuard product identity. See
CANONICAL_IDENTITY.md.
XGuard keeps reusable upstream credentials out of AI agents. Operators store a Stripe, GitHub, OpenAI, Anthropic, Slack, Notion, Cloudflare, Gemini or custom API credential once, then give the agent only a short-lived scoped XGuard capability.
Operator secret
↓
Encrypted XGuard credential vault
↓
Scoped capability
↓
AI agent
↓
XGuard Secretless Egress
↓
credential injected server-side
↓
upstream API
The agent never receives the reusable upstream credential.
XGuard becomes an actual choke point when an operator keeps the reusable credential only in XGuard and delegates capabilities instead of redistributing that credential. XGuard does not claim control over unrelated Internet traffic.
Why Secretless Egress
A reusable bearer token inside an autonomous agent can be copied, logged, placed in context, reused outside the intended request or leaked to an untrusted tool. XGuard changes the primitive from secret possession to scoped capability possession.
The current egress boundary provides:
- encrypted reusable credential storage;
- provider presets for OpenAI, Anthropic, GitHub, Stripe, Slack, Notion, Cloudflare and Gemini;
- custom header-based credentials restricted to explicit public HTTPS hosts;
- short-lived capabilities;
- exact HTTPS origin binding;
- path-prefix allowlists;
- HTTP method allowlists;
- maximum call counts;
- Usage Credit billing before secret release and before outbound network egress;
- no automatic credential forwarding across redirects;
- private/local target blocking;
- automatic
Idempotency-Keyinjection for unsafe methods; - no blind automatic replay after network ambiguity;
- MCP discovery and egress execution without exposing credential provisioning to model context.
Egress API
Machine-readable contract:
GET https://api.xguardgate.com/v1/egress
GET https://api.xguardgate.com/.well-known/xguard-egress.json
GET https://api.xguardgate.com/.well-known/xguard-egress-key.json
GET https://api.xguardgate.com/v1/egress/providers
1. Operator stores a reusable credential
Credential provisioning is intentionally an operator API, not an MCP tool.
POST /v1/egress/credentials
X-XGuard-Key: <usage-credit-key>
Content-Type: application/json
{
"provider": "github",
"value": "<github-token>",
"label": "production-github",
"allowed_paths": ["/repos/"],
"allowed_methods": ["GET", "POST"]
}
XGuard returns only credential metadata such as xcred_...; the reusable secret is not returned.
2. Operator issues a short capability
POST /v1/egress/capabilities
X-XGuard-Key: <usage-credit-key>
Content-Type: application/json
{
"credential_id": "xcred_...",
"target_origin": "https://api.github.com",
"path_prefix": "/repos/",
"allowed_methods": ["GET", "POST"],
"ttl_seconds": 300,
"max_calls": 10
}
The returned xgc_... capability is what the agent receives.
3. Agent executes without the upstream secret
POST /v1/egress/fetch
Content-Type: application/json
{
"capability": "xgc_...",
"target": "https://api.github.com/repos/org/repo/issues",
"method": "POST",
"body_json": {
"title": "Example"
}
}
XGuard validates capability scope and billing, injects the GitHub credential server-side, sends one HTTPS request and never exposes the reusable GitHub token to the agent.
Pricing contract:
GET /v1/egress/pricing
The current configuration consumes 1 XGuard Usage Credit per authorized credential-backed egress attempt. Billing is committed before credential decryption and before outbound network egress. If billing cannot commit, no upstream request is sent.
MCP
Canonical MCP endpoint:
https://api.xguardgate.com/mcp
Agent-facing tools include:
xguard_secretless_egress
xguard_egress_fetch
xguard_action_rail
Reusable credential creation is deliberately not exposed as an MCP tool.
Action Rail underneath
Secretless Egress is the primary product boundary. XGuard Action Rail remains available underneath for stronger execution controls around payments, purchases, bookings, messages, deployments, deletes, API writes and tool calls.
POST /v1/mandates
POST /v1/actions/permits
POST /v1/actions/execute
GET /v1/actions/permits/{permit_id}
Action Rail adds scoped mandates, request-bound cryptographic permits, replay rejection, durable execution state and receipts.
Universal and Edge deployment
For operator-controlled infrastructure XGuard can also be placed in front of an origin:
Internet / Ingress
↓
XGuard Universal Gate
↓
private origin
The repository includes Cloudflare Edge Gate, portable Node deployment, Docker, Docker Compose, Kubernetes and OpenAPI AutoGate components.
Native x402 compatibility
x402 remains a compatibility rail, not the definition of XGuard.
GET /supported
POST /verify
POST /settle
GET /facilitator
GET /.well-known/x402
GET /v1/facilitator/route
XGuard remains a non-custodial x402 v2 facilitator gateway with capability-aware routing, replay protection, Base USDC reconciliation and fail-closed ambiguous settlement behavior.
Security model
- reusable upstream credentials are encrypted at rest using per-record AES-GCM keys wrapped by an XGuard RSA-OAEP authority;
- secret values are not included in agent capabilities;
- operator XGuard Usage Credit keys are encrypted into capability state and are not handed to agents;
- capabilities bind an origin, path prefix, methods, expiry and maximum calls;
- user-supplied headers cannot override the injected credential header or XGuard control headers;
- private/local targets and XGuard self-targets are blocked;
- redirects are not automatically followed with injected credentials;
- billing commits before secret decryption and network egress;
- unsafe methods receive an XGuard-generated
Idempotency-Keywhen the caller did not supply one; - XGuard does not automatically replay a credential-backed request after a network ambiguity.
Machine discovery
GET /.well-known/xguard-egress.json
GET /.well-known/xguard-actions.json
GET /.well-known/xguard.json
GET /.well-known/ai-plugin.json
GET /.well-known/agent-card.json
GET /architecture
GET /v1/protocols
GET /openapi.json
GET /llms.txt
GET /skill.md
GET /sitemap.xml
Production domains
https://xguardgate.com
https://api.xguardgate.com
The Cloudflare Worker configuration disables the public workers.dev route so XGuard's production identity is limited to the custom XGuard domains.
Repository:
https://github.com/moelayyan90/XGuard
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
MCP Marketplace
Freeby mcp-marketplace · Developer Tools
Search and install MCP servers from inside your AI client.
MarkItDown
Freeby Microsoft · Content & Media
Convert files (PDF, Word, Excel, images, audio) to Markdown for LLM consumption
