{"_id":"@askturret/mcp-gateway","_rev":"4-1833b28e1cce23010baf69c4000c3681","name":"@askturret/mcp-gateway","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@askturret/mcp-gateway","version":"0.1.0","license":"Apache-2.0","_id":"@askturret/mcp-gateway@0.1.0","maintainers":[{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},{"name":"alprimak","email":"alprimak@gmail.com"}],"bin":{"askturret-mcp-gateway":"dist/cli.js"},"dist":{"shasum":"f97c6ddc067fade86a82797367973c4cc35a0737","tarball":"https://registry.npmjs.org/@askturret/mcp-gateway/-/mcp-gateway-0.1.0.tgz","fileCount":34,"integrity":"sha512-WvBtMRiF3QiPIhIvTXg0eBdgvgO+vWBOFy604PmQskF/vU3pk111tZ8B43OTjwdNPuDSPUP5hZx5mfVZ+1Kquw==","signatures":[{"sig":"MEYCIQDK+/fRA3TJPU4Iomi4wEu3I/VNS5A68yoZHp+nKbFf4gIhAM3ZfMpmABdWfDvKJfFOlROkh8lUf+B5hiFpLQTYHV4O","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":133622},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"c54b62a19421ed3bc620807cfc871e2c94b76576","scripts":{"lint":"echo \"Linting not yet configured\"","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"tsc"},"_npmUser":{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},"_npmVersion":"11.8.0","description":"Standalone compatibility gateway - serves MCP from an OpenAPI spec and proxies to an existing API","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@askturret/mcp-core":"^0.1.0","@askturret/mcp-transports":"^0.1.0","@askturret/mcp-observability":"^0.1.0","@askturret/mcp-sources-openapi":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.1.0","typescript":"*","@types/jest":"^29.5.0","@types/node":"^20.14.0","@jest/globals":"^29.7.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-gateway_0.1.0_1788200478315_0.008521108553078305","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@askturret/mcp-gateway","version":"0.1.1","keywords":["askturret","mcp","server","client"],"license":"Apache-2.0","_id":"@askturret/mcp-gateway@0.1.1","maintainers":[{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},{"name":"alprimak","email":"alprimak@gmail.com"}],"bin":{"askturret-mcp-gateway":"dist/cli.js"},"dist":{"shasum":"6853da34652859d9a8f3378b1ac3557836c9781b","tarball":"https://registry.npmjs.org/@askturret/mcp-gateway/-/mcp-gateway-0.1.1.tgz","fileCount":36,"integrity":"sha512-fn6/lHxovjHss2Y+neLqUSl5oZwv7cF9DOQS6uqLk5kaJ9SMswM8BkMYrmoslXl6lZpDnSjtjfoub5QkZlPPvw==","signatures":[{"sig":"MEYCIQDErdTCZqxr64KRgzf2WukMjo7evVWHaa7AmqkVctn7yQIhAJmY49vBSuz+XnSaMwVxpIatz8gOmq/nkBRwGuWHW3K+","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":155273},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"69d35f79c070c6322357902e786a527261463d3f","scripts":{"lint":"echo \"Linting not yet configured\"","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"tsc"},"_npmUser":{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},"_npmVersion":"11.8.0","description":"Standalone compatibility gateway - serves MCP from an OpenAPI spec and proxies to an existing API","directories":{},"_nodeVersion":"25.5.0","dependencies":{"@askturret/mcp-core":"^0.1.0","@askturret/mcp-transports":"^0.1.0","@askturret/mcp-observability":"^0.1.0","@askturret/mcp-sources-openapi":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.1.0","typescript":"*","@types/jest":"^29.5.0","@types/node":"^20.14.0","@jest/globals":"^29.7.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-gateway_0.1.1_1788458646525_0.46240837666558243","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@askturret/mcp-gateway","version":"0.1.2","keywords":["askturret","mcp","server","client"],"license":"Apache-2.0","_id":"@askturret/mcp-gateway@0.1.2","maintainers":[{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},{"name":"alprimak","email":"alprimak@gmail.com"}],"homepage":"https://github.com/askturret/mcp#readme","bugs":{"url":"https://github.com/askturret/mcp/issues"},"bin":{"askturret-mcp-gateway":"dist/cli.js"},"dist":{"shasum":"bfb9411147129406851aa8318d468b00cd9fb9af","tarball":"https://registry.npmjs.org/@askturret/mcp-gateway/-/mcp-gateway-0.1.2.tgz","fileCount":36,"integrity":"sha512-PfQQbtwP4mhTqkpibe/vWTrafYThzgJU7ehO2+2UR0/0dSSer5JN+Y4mfGETL8NoKSTfcC2Ir8v1B8RO8ZLcLw==","signatures":[{"sig":"MEQCIGI5NRL/WPInuf/xAflpTea9oAMeyt3UWYAGi5EcW8FbAiAbzFTzE88TVPeld1aWSSjZ346DX6ek6WiPTV5IBQZo+g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askturret%2fmcp-gateway@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":155603},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"ec334b34d1a55df0d4f8c2d5f69c7e80679476e5","scripts":{"lint":"echo \"Linting not yet configured\"","test":"NODE_OPTIONS=--experimental-vm-modules jest","build":"tsc"},"_npmUser":{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},"repository":{"url":"git+https://github.com/askturret/mcp.git","type":"git","directory":"packages/gateway"},"_npmVersion":"10.8.2","description":"Standalone compatibility gateway - serves MCP from an OpenAPI spec and proxies to an existing API","directories":{},"_nodeVersion":"20.20.2","dependencies":{"@askturret/mcp-core":"^0.1.0","@askturret/mcp-transports":"^0.1.0","@askturret/mcp-observability":"^0.1.0","@askturret/mcp-sources-openapi":"^0.1.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.1.0","typescript":"*","@types/jest":"^29.5.0","@types/node":"^20.14.0","@jest/globals":"^29.7.0"},"_npmOperationalInternal":{"tmp":"tmp/mcp-gateway_0.1.2_1788607226111_0.7311974221570985","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@askturret/mcp-gateway","version":"0.2.0","description":"Standalone compatibility gateway - serves MCP from an OpenAPI spec and proxies to an existing API","type":"module","license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/askturret/mcp.git","directory":"packages/gateway"},"homepage":"https://github.com/askturret/mcp#readme","bugs":{"url":"https://github.com/askturret/mcp/issues"},"main":"./dist/index.js","types":"./dist/index.d.ts","bin":{"askturret-mcp-gateway":"dist/cli.js"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc","test":"NODE_OPTIONS=--experimental-vm-modules jest","lint":"echo \"Linting not yet configured\""},"dependencies":{"@askturret/mcp-core":"^0.2.0","@askturret/mcp-observability":"^0.2.0","@askturret/mcp-sources-openapi":"^0.2.0","@askturret/mcp-transports":"^0.2.0"},"devDependencies":{"typescript":"*","@types/node":"^20.14.0","@jest/globals":"^29.7.0","@types/jest":"^29.5.0","jest":"^29.7.0","ts-jest":"^29.1.0"},"keywords":["askturret","mcp","server","client"],"_id":"@askturret/mcp-gateway@0.2.0","gitHead":"01db00fa88fb96dac636f82fc70bd248e834c9c7","_nodeVersion":"20.20.2","_npmVersion":"10.8.2","dist":{"integrity":"sha512-SfOMkFQL2VjMSNPlZI7hLIriODGlq4cO1XXwiXQ00iGW+hYAcsz6QnV0mYGtLW8YKF9J8bGlu/uTWv5r3hKQcg==","shasum":"0588040849362ee1373cb6e6537f23851f7abc7e","tarball":"https://registry.npmjs.org/@askturret/mcp-gateway/-/mcp-gateway-0.2.0.tgz","fileCount":36,"unpackedSize":154191,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askturret%2fmcp-gateway@0.2.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIFvw2lKWKrEGlEtWrlHf+sl89P9JK+xXmD/DO/Au1vWGAiBHDhrgWXk02jzEUE8zbSgxeDgNMZDth+pLgRjYmrZdDQ=="}]},"_npmUser":{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},"directories":{},"maintainers":[{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},{"name":"alprimak","email":"alprimak@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/mcp-gateway_0.2.0_1789133929228_0.016052915749061425"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-31T18:21:18.027Z","modified":"2026-09-11T13:38:49.707Z","0.1.0":"2026-08-31T18:21:18.456Z","0.1.1":"2026-09-03T18:04:06.669Z","0.1.2":"2026-09-05T11:20:26.239Z","0.2.0":"2026-09-11T13:38:49.366Z"},"bugs":{"url":"https://github.com/askturret/mcp/issues"},"license":"Apache-2.0","homepage":"https://github.com/askturret/mcp#readme","keywords":["askturret","mcp","server","client"],"repository":{"type":"git","url":"git+https://github.com/askturret/mcp.git","directory":"packages/gateway"},"description":"Standalone compatibility gateway - serves MCP from an OpenAPI spec and proxies to an existing API","maintainers":[{"name":"didi178","email":"dmitry.stepanov37@gmail.com"},{"name":"alprimak","email":"alprimak@gmail.com"}],"readme":"# @askturret/mcp-gateway\n\nStandalone compatibility gateway — serves MCP from an OpenAPI spec and proxies\nto an existing API (§11.3, ADR-020, #57).\n\n```bash\nnpx @askturret/mcp-gateway \\\n  --spec ./openapi.yaml \\\n  --overlay ./askturret.mcp.yaml \\\n  --upstream https://api.example.com \\\n  --port 7078\n```\n\n> **`@askturret/mcp-gateway` is on npm**, so the `npx` line above resolves\n> without a checkout. No version is quoted here on purpose — `npm view\n> @askturret/mcp-gateway version` is the authoritative answer and cannot go\n> stale, whereas a number written on this page can.\n> [`docs/releasing.md`](https://github.com/askturret/mcp/blob/main/docs/releasing.md)\n> lists which workspaces are public.\n\n## What it is for\n\nThe gateway is the topology for adopters whose **application code cannot be\nmodified**. §11.3 is explicit that this is a *secondary* path: it adds a network\nhop and an auth boundary the embedded runtime does not have. Prefer\n`expressMcp()` / `fastifyMcp()` when you can change the application.\n\nIt is **not** a replacement for the embedded runtime, and **not** the\nmulti-tenant fleet layer (§20.3.A, commercial).\n\n## It is the same runtime\n\nDiscovery, compilation, the overlay pass, the dispatcher, the policy engine, the\naudit sink and the transport are all `@askturret/mcp-*`. What the gateway adds\nis process-shaped: argument parsing, a config file, two listeners and a shutdown\nsequence. Nothing in it re-decides anything §10.2 or §5.3 already decides.\n\nThat matters most for the **presets**. `--preset regulated` calls core's\n`regulatedPreset()` and lets its refusals propagate untouched — so\n`--audit-sink stdout` refuses at boot with core's own message and its stable\n`control` field, rather than with a gateway paraphrase that could drift from\n§10.2.\n\n## Configuration\n\nEvery setting is available as a CLI flag and as a config-file key. **Flags beat\nthe file.** Unknown keys are *refused*, not ignored — a typo would otherwise\nboot a gateway that looks configured and is not.\n\n```yaml\n# askturret.gateway.yaml\nspec: ./openapi.yaml\noverlay:\n  - ./askturret.mcp.yaml\nupstream: https://api.example.com\nport: 7078\nbasePath: /mcp\npreset: production\naudit:\n  sink: jsonl\n  path: /var/lib/askturret/audit.jsonl\nmetricsPort: 9464\npermissions:\n  listPets: [pets:read]\n```\n\n```bash\nnpx @askturret/mcp-gateway --config ./askturret.gateway.yaml --port 8080\n```\n\nRun `--help` for the full flag list. YAML is parsed by core's deliberately small\nsubset parser, which **refuses what it does not understand** rather than\nguessing — a mis-parsed `upstream` is a gateway proxying somewhere nobody asked\nfor.\n\n### Regulated mode needs a module, not just a file\n\n`RegulatedPresetOptions.verifyEvidence` is a **function**, and no YAML can hold\none. Core refuses to ship a default on purpose: a verifier that accepted any\nproof would make the evidence policy decorative, and one that rejected every\nproof would fail each guarded call at runtime instead of at boot.\n\nSo the gateway takes a module path:\n\n```bash\n--preset regulated \\\n--audit-sink jsonl --audit-path /var/lib/askturret/audit.jsonl \\\n--acknowledge-redaction-review \\\n--verify-evidence ./verify-evidence.js\n```\n\n```js\n// verify-evidence.js\nexport function verifyEvidence(evidence, context) { /* your scheme */ }\n```\n\nOmit it and core refuses at boot — which is the correct outcome, and is the\n*library's* refusal rather than one the gateway invented.\n\n## Observability\n\n- **Audit** — core's sinks (`stdout`, `jsonl`), forwarded to the dispatcher.\n- **Metrics** — a Prometheus scrape endpoint on its own port (default `9464`),\n  driven off core's `METRIC_DEFINITIONS` so the exposition cannot drift from the\n  catalogue. Label cardinality is *enforced* via `assertLabelsAllowed`.\n- **Traces** — core's no-op tracer by default (§Delivery makes no-exporter the\n  default). Wire an OTel SDK to export spans; the compose example runs a\n  collector.\n\nTwo ports is deliberate: an operator can publish the MCP port and keep the\nscrape endpoint on an internal interface.\n\nHistograms expose `_sum` and `_count` but **no `_bucket` series**, so no\nquantiles — bucket boundaries are a per-metric choice §9.2 does not specify, and\nguessing them would bake the guess into an exposition format. Use the OTel path\nif you need quantiles.\n\n## Health\n\n`/health/live` and `/health/ready` are served on the **MCP port**, not the\nmetrics port: an orchestrator probes the port it routes traffic to, and a probe\nanswered by a different listener can report healthy while the one carrying\nrequests is wedged.\n\n## Docker\n\n```bash\n# From the workspace root — the image compiles the gateway and its siblings\n# from source rather than installing them, so it builds the working tree.\ndocker build -f packages/gateway/Dockerfile -t askturret/mcp-gateway .\n```\n\nA full worked setup — gateway + mock upstream + OTel collector, in one command —\nis in [`examples/gateway-compose`](https://github.com/askturret/mcp/tree/main/examples/gateway-compose).\n\n## Publishing\n\nThree acceptance items on #57 are **release steps, not engineering steps**, and\nare tracked separately:\n\n| Step | State |\n|---|---|\n| npm publish | **done** — the package is on the registry; `npm view @askturret/mcp-gateway version` is the authoritative answer |\n| Docker image publish | outstanding — registry choice + credentials |\n| MCP Registry entry | outstanding — the above, plus the §18.8 metadata process |\n\nThe gateway is installable from npm and runnable from source. What remains is\nthe Docker and MCP-Registry distribution, not npm. See the follow-up issue\nlinked from #57.\n\n---\n*Operum Engineer · [operum.ai](https://operum.ai)*\n","readmeFilename":"README.md"}