Docs
Security

Security

API key hygiene, team isolation, log retention, and rate limits for SmartGate.

SmartGate is designed for multi-tenant teams connecting untrusted agent loops to production infrastructure. Follow these practices to stay safe.

API keys

  • Treat keys like passwords — never commit them to git or embed in client-side code.
  • Create separate keys per environment (dev/staging/prod) when possible.
  • Rotate keys from Dashboard → API Keys if exposure is suspected; revoke old keys immediately.
  • We store only a hashed form of keys, not the raw secret.

Free plans allow up to 2 keys; Pro 10; Teams 30 (Enterprise: custom).

Authentication

  • MCP and REST require Authorization: Bearer sk_live_….
  • Dashboard access uses Auth.js (magic link + Google OAuth) with session cookies over HTTPS.
  • All teams are isolated by teamId — API keys cannot access another team's data.

Activity logs and retention

Audit entries power Dashboard → Activity Logs and Usage Reports. Retention depends on plan:

PlanRetention
Free7 days
Pro30 days
Teams90 days
Enterprise180 days

Logs may include tool names, timestamps, optional correlation IDs, and fetch URLs you requested. See our Privacy Policy.

Rate limits

SmartGate applies tiered rate limits to protect shared infrastructure:

  • MCP requests — counted per API key (e.g. Free: 120 req/min per key for Cursor and agent integrations). Each key on a team has its own MCP allowance; higher tiers also enforce a team-wide MCP ceiling.
  • REST write requests — counted per team (create/update/delete operations). Limits scale with plan (Free: 60/min; Enterprise: 600/min).

When you exceed a limit, responses return HTTP 429 with a limit_scope field indicating whether the throttle was mcp_per_key, mcp_team_ceiling, or rest_write_team. Reduce concurrency or upgrade if you hit limits consistently.

Audit headers (optional)

For REST integrations, optional headers (X-SmartGate-Correlation-Id, etc.) help group agent tasks in Logs. Details: MCP Endpoint. Do not put secrets in header values.

Reporting issues

Email support@smartgate.network for security questions or suspected abuse. Include team ID and timestamps when possible.

We do not offer a public bug bounty at this time; responsible disclosure is appreciated.

Compliance notes

  • SmartGate processes URLs and tool metadata you submit; you must have rights to that content.
  • Enterprise customers may request additional data processing terms — contact support@smartgate.network.