</>MCP Agents Market
MCP Server

ThinkWatch

by ThinkWatchProject814RustUpdated 2026-09-15

Enterprise AI bastion host for secure AI API and MCP access, with unified proxying, RBAC, audit logs, rate limiting, and cost tracking across OpenAI, Anthropic, Gemini, and self-hosted LLMs.

Claude CodeClaude DesktopCursorContinueCline

ThinkWatch is an enterprise AI gateway that provides unified secure access to both AI APIs and MCP servers with granular access control, audit logging, and cost tracking. It functions as a centralized bastion host for AI infrastructure, proxying requests to OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, and MCP servers while enforcing role-based permissions, rate limits, and budget caps. The platform maintains per-user OAuth credentials for upstream MCP services, ensuring real user identity propagation to GitHub, Notion, Linear, Slack, and other integrations rather than using shared service accounts. Organizations deploy ThinkWatch to eliminate scattered API keys, gain visibility into AI usage and costs, and maintain compliance through comprehensive audit trails.

Key Features

MCP gateway with per-user OAuth token propagation to upstream services (GitHub, Notion, Linear, Slack, Atlassian, GitLab) instead of shared service accounts
Multi-provider AI API gateway supporting OpenAI, Anthropic, Google Gemini, Azure OpenAI, and AWS Bedrock with automatic format conversion
Composable rate limits and budget caps across multiple time windows (1m/5m/1h/1d/1w/monthly) applied per user, API key, provider, or MCP server
Virtual API key system (tw- prefix) with scoped permissions, automatic rotation, and unified access to both AI and MCP surfaces
Role-based access control with five tiers (Super Admin, Admin, Team Manager, Developer, Viewer) and tool-level permission grants
ClickHouse-powered audit logging with forwarding to Syslog, Kafka, or HTTP webhooks for SIEM integration
Built-in MCP Store with 23+ pre-configured OAuth templates and one-click RFC 9728/8414/7591 discovery flow
Real-time cost tracking with per-model pricing, token weighting, and team attribution across all AI and MCP usage

Use Cases

  • 01Centralize AI API access for engineering teams using Claude Code, Cursor, Continue, or custom agents with unified authentication and budgets
  • 02Enforce per-developer token budgets and rate limits across multiple LLM providers to control monthly AI spend
  • 03Maintain compliance audit trails showing which user invoked which MCP tool with what parameters and whose upstream credentials
  • 04Provision scoped API keys for CI/CD pipelines with restricted model access and separate MCP tool allowlists
  • 05Replace scattered GitHub/Notion personal access tokens with organization-managed OAuth flows and automatic rotation
  • 06Monitor and attribute AI costs across teams with detailed analytics showing token consumption by user, model, and time period

Related MCP Servers

View more

ThinkWatch — FAQ

What is ThinkWatch?+

ThinkWatch is an enterprise gateway that provides secure, audited access to AI APIs (OpenAI, Anthropic, Gemini) and MCP servers. It acts as a single control plane for authentication, authorization, rate limiting, and cost tracking across all organizational AI usage.

How do I install and configure ThinkWatch?+

ThinkWatch is deployed via Docker or Kubernetes with PostgreSQL, Redis, and ClickHouse dependencies. After deployment, access the first-run setup wizard at /setup to create the admin account, configure providers, and generate virtual API keys. The /gateway/guide page provides copy-paste configuration for Claude Code, Cursor, and other clients.

Which AI clients and MCP servers work with ThinkWatch?+

The AI gateway works with any client supporting OpenAI or Anthropic APIs, including Claude Code, Cursor, Continue, Cline, and official SDKs. The MCP gateway supports any RFC-compliant MCP server and includes pre-configured templates for GitHub, Notion, Linear, Slack, Atlassian, GitLab, Cloudflare, Discord, Google, and Feishu.

What API keys or credentials do I need?+

You need upstream provider API keys (OpenAI, Anthropic, etc.) to configure in ThinkWatch. For MCP servers, users connect their own OAuth accounts or personal access tokens through the /connections interface. ThinkWatch encrypts all credentials with AES-256-GCM and issues virtual tw- keys to clients.

Is ThinkWatch free and open source?+

The repository is publicly available on GitHub under the ThinkWatchProject organization. Check the repository license file for specific terms and usage restrictions.

How does ThinkWatch handle per-user MCP authentication differently?+

Unlike typical MCP proxies that use a single shared admin token, ThinkWatch propagates each user's individual OAuth tokens or PATs to upstream services. This ensures audit logs show the real user identity and permissions match each user's actual access scope in systems like GitHub or Atlassian.

How do I install ThinkWatch?+

Open the source repository on GitHub and follow its README. ThinkWatch is a mcp server — MCP Agents Market links you directly to the official repo.

Is ThinkWatch free?+

ThinkWatch is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches