Saturn MCP

The MCP gateway that decides what your agents may do.

Saturn MCP is the MCP server your agents talk to. Behind it sit your real MCP servers — CRM, payments, databases, cloud consoles. Saturn exposes only the tools you approve, evaluates every call against policy, pauses the sensitive ones for a human, and records everything.

Standards-compliant MCP over HTTP. Works with Claude, ChatGPT, Cursor, Saturn App, or any MCP client.

policy    Payments  v3  production

rule      payments.transfer
when      amount > 1000 AND currency == "USD"
decision  approval_required

rule      payments.transfer
when      true
decision  allow

rule      db.drop_table
when      true
decision  deny

A policy as the engine evaluates it. Conditions are matched against the arguments of each call.

Up and running in four steps.

No SDK, no agent code changes. Saturn works at the protocol level.

01

Connect your MCP servers

Register each server by URL. Saturn discovers its tools, handles OAuth where needed, and seals the credentials in its vault.

02

Build tool sets

Pick the tools each agent should have — across servers. Mark any tool as Call (automatic) or Approval (needs a person).

03

Write policies

Add rules with conditions on arguments. Decide per rule: allow, approval required, or deny. Policies are versioned.

04

Point agents at Saturn

Give every agent the same Saturn MCP endpoint. They sign in with OAuth and see only their tool set.

What teams run through Saturn.

Four examples of agents that are useful precisely because they are governed.

Finance operations

An agent that pays vendors — with a human on large amounts

The finance agent reconciles invoices and triggers payments through the payments MCP server. Small transfers run automatically. Anything above the threshold waits for a reviewer, who sees the amount, the recipient, and the invoice reference before approving.

  • payments.transfer · amount ≤ 1000 → allow
  • payments.transfer · amount > 1000 → approval required
  • payments.refund · amount > 10000 → deny

Customer support

A support agent that can read and reply, but never delete

The support agent gets a tool set with CRM lookup, ticket updates, and email reply. Destructive CRM tools are not in the set, so for this agent they do not exist. Emails to external domains require approval; internal notes go straight through.

  • crm.get_customer · allow
  • tickets.update · allow
  • email.send · recipient not in company domain → approval required
  • crm.delete_customer · not in tool set

Platform and DevOps

A release agent that deploys to staging freely, to production with sign-off

The release agent runs rollouts through your deployment MCP server. Staging is automatic. Production rollouts pause for an on-call engineer. Schema-destroying operations are denied outright, regardless of environment.

  • deploy.rollout · environment == "staging" → allow
  • deploy.rollout · environment == "production" → approval required
  • db.drop_table · deny

Data and analytics

Analyst agents for every team, each confined to its own data

Each team gets analyst agents with read-only warehouse tools. Server mapping decides which teams may attach the warehouse at all. Editors are scoped to their own agents, and every query is attributed to the person the agent acted for.

  • warehouse.query · allow
  • warehouse.export · row_count > 100000 → approval required
  • Marketing accounts · warehouse server not mapped

What the gateway handles for you.

Everything between the agent’s request and your upstream server.

Identity

OAuth 2.1 with PKCE for every agent. Each session is bound to a user or an organization; the profile is checked on every request.

Tool discovery

Register MCP servers by URL. Saturn discovers tools, keeps the catalog current, and manages upstream OAuth and token refresh.

Tool sets

Curated tools per agent, across servers. Only those tools appear in tools/list. Each tool is Call or Approval.

Policy engine

Ordered, versioned rules with conditions on arguments. Every call records the policy id, version, and matched rule.

Approval queue

Sensitive calls wait in the console with full context. Reviewers approve or reject; agents can be paused instantly.

Credential vault

Upstream tokens and secrets sealed with ML-KEM-1024 and AES-256-GCM. Agents never see them; every read is audited.

Audit trail

Requested, evaluated, approval requested, granted or rejected, executed, credential accessed — per call, with arguments.

Cost tracking

Wallets and x402 payments attribute cost to each tool call and each agent.

Security built into the request path.

An agent can never obtain more than the result of an authorized call. These are the mechanisms behind that guarantee.

  • Post-quantum credential vault

    Access tokens, refresh tokens, and client secrets are sealed individually with ML-KEM-1024 key encapsulation and AES-256-GCM, keys derived via HKDF-SHA384. The key seed lives in configuration, never in the database.

  • No plaintext over the API

    Console and client APIs report whether a secret exists — never its value. Every secret read generates a credential_accessed audit event.

  • Managed upstream OAuth

    Saturn discovers the authorization server, performs dynamic client registration where supported, uses PKCE, and refreshes tokens automatically when an upstream returns 401.

  • Network boundaries

    Upstream URLs must use HTTPS (or HTTP on localhost). Private, link-local, and cloud metadata addresses are refused.

  • Denied means never sent

    A denied call never leaves Saturn. A held call returns approval_required with a reference id. A paused agent cannot start a call.

  • Role-based access control

    Four console resources, three access levels each. Preset roles admin, operator, viewer, or custom sets. Editors can be scoped to specific agents.

Put Saturn in front of your first MCP server today.

Create a free account, connect a server, and write one rule. The first approval request shows you the whole path.