# Decentralized MCP Gateway

> Sidekick Gateway is a decentralized MCP gateway: no central gateway to fail, human approval for sensitive actions, and records ready for your auditors.

Source: https://sidekickmachines.com/products/gateway/

Flagship product

## Sidekick Gateway

Decentralized MCP gateway

Let every AI agent use your systems safely: no central gateway to fail, human approval for sensitive actions, every request on record.

[Talk about a license: Sidekick Gateway](mailto:hello@sidekickmachines.com?subject=Sidekick%20Gateway%20license) See how it works

At a glance

1. No central gateway
2. Human approval
3. Every request on record

No central gateway

### Every agent has its own permission check.

Risky calls go to that agent’s own approver. If one check pauses, only its agent waits. Every other agent keeps working.

- Allowed
- Approved by its approver
- Blocked
- One check pauses: only its agent waits

Swipe sideways to follow a call.

How it works

### Every request, checked and recorded.

A central gateway puts every agent behind one service: a single point of failure. Sidekick Gateway has no central gateway, so a problem stays contained and other agents keep working.

How Sidekick Gateway works: no central gateway that every agent depends on. This example shows three agents, each acting as itself, with its own identity. Each request goes through MCP tools, a role check and human approval. Each agent can use just those tools and actions approved for its role. A sensitive action waits until a person approves that exact request, and every request, check and approval is recorded for audit. Permitted requests reach enterprise systems that use modern or legacy sign-in methods; requests outside an agent’s role are denied. If one agent hits a problem, it stays contained: other agents keep working.

1. #### An agent asks to act

   An agent asks to use a tool in one of your systems.

2. #### Its role is checked

   Each agent can use just those tools and actions approved for it. Anything else is refused.

3. #### Sensitive actions wait

   A person approves that exact request. One approval covers one request.

4. #### Agent acts as itself

   It works under its own identity, never a person’s, and never sees a password or key.

5. #### Everything goes on record

   Every request, check and approval is recorded: who approved what, and when.

Features

### Control without a choke point.

- #### No central gateway

  A central gateway puts every agent behind one service. Sidekick Gateway has none, so a problem stays contained.

  Other agents keep working.

- #### Human approval, built in

  Sensitive actions wait for a person to approve that exact request. One approval covers one exact request, and nothing more.

  People decide on sensitive actions.

- #### One approval, one request

  An approval covers that one request and nothing more. A different request waits for a person again.

  No blanket approvals.

- #### Auditor-ready records

  Every request, check and approval is recorded: who approved what, and when.

  Answers ready when auditors ask.

- #### Each agent acts as itself

  Every agent has its own identity and never borrows a person’s.

  Your records show which agent acted.

- #### Access by role

  Each agent can use just those tools and actions approved for it.

  Agents stay inside their job.

Security and audit

### Ready for your security team and your auditors.

- #### No passwords for agents

  Agents never see passwords or keys.

- #### Modern and legacy sign-in

  Works with modern and legacy sign-in methods, so older enterprise systems can join in.

- #### Runs in your environment

  Sidekick Gateway runs in your own environment.

FAQ

### Questions, answered.

#### How is it different from a central gateway?

A central gateway puts every agent behind one service: a single point of failure. Sidekick Gateway has no central gateway, so a problem stays contained and other agents keep working.

#### What is an MCP gateway?

MCP is the standard way AI agents use tools. An MCP gateway stands between your agents and those tools and decides what each agent may do.

#### How do approvals work?

Sensitive actions wait for a person to approve that exact request. Each approval covers that one request, and every decision is on record: who approved what, and when.

#### Do agents ever see passwords or keys?

Never. Each agent works as itself, with its own identity, and passwords and keys stay out of its reach.

#### Can older systems connect?

Yes. Sidekick Gateway works with modern and legacy sign-in methods, so older enterprise systems can join in.

### Pairs with

#### Engineering

- [Enterprise MCP Tooling](https://sidekickmachines.com/capabilities/enterprise-mcp-tooling/)
- [Agent HITL](https://sidekickmachines.com/capabilities/agent-hitl/)
- [Agent Identity & Access](https://sidekickmachines.com/capabilities/agent-identity-access/)
- [Agent Security](https://sidekickmachines.com/capabilities/agent-security/)

#### Products

- [Agent Studio: From request to live agent in Microsoft Teams](https://sidekickmachines.com/products/agent-studio/)
- [Sidekick Sovereign: Every Sidekick product in your own Microsoft Azure](https://sidekickmachines.com/products/sovereign/)

Licenses and engineering

### Put Sidekick Gateway to work.

Tell us about your agents and systems. We’ll help you choose a license, an engagement or both.

[Talk about a license](mailto:hello@sidekickmachines.com?subject=Sidekick%20Gateway%20license)

Microsoft, Microsoft Azure, and Microsoft Teams are trademarks of the Microsoft group of companies.
