Install the client
The client ships for both Node.js and Python. Both expose the samegateway-mcp serve command.
- Node.js
- Python
Install the npm package. Use
npx to run it without a global install, or install globally for a persistent gateway-mcp command.Set your credentials
The server reads credentials from environment variables and picks its authentication mode from which ones are present.
When both keys and a token are set, the server uses the key pair (BasicAuth). Set only the variables for the mode you want.
PAT access is per-project: the server exposes your accessible projects and scopes every request to
/api/public/mcp with a ?project_id=<id> query parameter, which it adds automatically. Access is checked on every call, so a project you are invited to later works without restarting the server. Calling the HTTP endpoint directly with a PAT (without the npm server) means passing ?project_id= yourself — the endpoint rejects PAT requests without it.
Never hardcode keys or tokens in your code or commit them to source control. Keep them in environment variables or a secrets manager.
Run the server over stdio
Theserve command starts the server on stdio, the transport every MCP client speaks. Prefix the command with the credentials for your mode.
- Node.js
- Python
Wire it into your MCP client
MCP clients launch the server as a subprocess defined in anmcpServers block. Point the command at the client you installed and pass credentials through env.
- Node.js
- Python
Add a
gateway entry to your client config (claude_desktop_config.json for Claude Desktop, .mcp.json for Claude Code, .cursor/mcp.json for Cursor):GATEWAY_API_TOKEN with GATEWAY_PUBLIC_KEY and GATEWAY_SECRET_KEY. Add GATEWAY_URL to the env block when you target a self-hosted or local instance.
Restart your MCP client after editing its config so it relaunches the server. Then ask the agent to list its tools, or run
describe_project, to confirm the connection.Call the backend endpoint directly
The local proxy is optional. The backend exposes one JSON-RPC 2.0 endpoint,POST /api/public/mcp, callable with any HTTP client. Set the Accept header to application/json, text/event-stream — the endpoint may answer with plain JSON or a server-sent-events stream.
1
Build the BasicAuth header
Base64-encode
public_key:secret_key and send it as a Basic authorization header.2
List the available tools
Send a JSON-RPC
tools/list request. The response contains every tool the instance currently exposes, with its input schema.Authorization: Bearer pat_... instead of the Basic header and append the project to the URL as ?project_id=<id>. Call a tool with tools/call, passing the tool name and arguments in params.
Next steps
- Tool Reference — every tool the server exposes and its key inputs.
- Getting started with worlds — the world-building workflow, with each step’s MCP twin named.