Security
API key hygiene, team isolation, log retention, and rate limits for SmartGate.
SmartGate is designed for multi-tenant teams connecting untrusted agent loops to production infrastructure. Follow these practices to stay safe.
API keys
- Treat keys like passwords — never commit them to git or embed in client-side code.
- Create separate keys per environment (dev/staging/prod) when possible.
- Rotate keys from Dashboard → API Keys if exposure is suspected; revoke old keys immediately.
- We store only a hashed form of keys, not the raw secret.
Free plans allow up to 2 keys; Pro 10; Teams 30 (Enterprise: custom).
Authentication
- MCP and REST require
Authorization: Bearer sk_live_…. - Dashboard access uses Auth.js (magic link + Google OAuth) with session cookies over HTTPS.
- All teams are isolated by
teamId— API keys cannot access another team's data.
Activity logs and retention
Audit entries power Dashboard → Activity Logs and Usage Reports. Retention depends on plan:
| Plan | Retention |
|---|---|
| Free | 7 days |
| Pro | 30 days |
| Teams | 90 days |
| Enterprise | 180 days |
Logs may include tool names, timestamps, optional correlation IDs, and fetch URLs you requested. See our Privacy Policy.
Rate limits
SmartGate applies tiered rate limits to protect shared infrastructure:
- MCP requests — counted per API key (e.g. Free: 120 req/min per key for Cursor and agent integrations). Each key on a team has its own MCP allowance; higher tiers also enforce a team-wide MCP ceiling.
- REST write requests — counted per team (create/update/delete operations). Limits scale with plan (Free: 60/min; Enterprise: 600/min).
When you exceed a limit, responses return HTTP 429 with a limit_scope field indicating whether the throttle was mcp_per_key, mcp_team_ceiling, or rest_write_team. Reduce concurrency or upgrade if you hit limits consistently.
Audit headers (optional)
For REST integrations, optional headers (X-SmartGate-Correlation-Id, etc.) help group agent tasks in Logs. Details: MCP Endpoint. Do not put secrets in header values.
Reporting issues
Email support@smartgate.network for security questions or suspected abuse. Include team ID and timestamps when possible.
We do not offer a public bug bounty at this time; responsible disclosure is appreciated.
Compliance notes
- SmartGate processes URLs and tool metadata you submit; you must have rights to that content.
- Enterprise customers may request additional data processing terms — contact support@smartgate.network.