Docs / MCP deep dive
Trust Gateway (Component B)
POSThttps://gateway.tokensaver.fr/mcp
A transparent MCP proxy: it forwards every request to an upstream MCP server (e.g. the filesystem server) while enforcing TokenSaver auth, policy, PII redaction, audit, and tracing. The gateway exposes the upstream's tools, not its own.
POSThttps://gateway.tokensaver.fr/mcp
Hosted HTTP
Point your client at the hosted gateway with a Bearer key. Optional headers identify the client and correlate traces:
{
"mcpServers": {
"tokensaver-gateway": {
"url": "https://gateway.tokensaver.fr/mcp",
"headers": {
"Authorization": "Bearer ts_YOUR_KEY",
"X-Tokensaver-Client": "cursor/1.0"
}
}
}
}
Local stdio (wrap your own MCP)
Run tokensaver-mcp-gateway and pass the upstream command with --target. Here it wraps the filesystem MCP server scoped to your project:
{
"mcpServers": {
"tokensaver-gateway": {
"command": "tokensaver-mcp-gateway",
"args": [
"--target",
"npx -y @modelcontextprotocol/server-filesystem /path/to/your/project",
"--workspace",
"dev-local"
],
"env": {
"TOKENSAVER_API_KEY": "ts_YOUR_KEY",
"TOKENSAVER_API_BASE_URL": "https://api.tokensaver.fr/api/v1"
}
}
}
}
What the gateway enforces
- Auth — Bearer
ts_…per request (HTTP) orTOKENSAVER_API_KEYat startup (stdio) - Policy (RBAC/OPA) — allow/deny tool calls per workspace
- PII redaction — scans
tools/callarguments and results - Audit & tracing — every call recorded; pass
X-Tokensaver-Execution-Trace-Idto correlate a run