MCP Gateway for GigaChat and YandexGPT
MCP Gateway
An MCP gateway to GigaChat and YandexGPT with automatic failover between them and 152-FZ personal-data anonymization
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Forwards user text to external cloud LLMs (GigaChat, YandexGPT), even after anonymization
- Personal-data masking relies on heuristics and may miss non-standard formats
Install
Manual install
git clone https://github.com/kvochkin-dev/mcp-gateway.git && cd mcp-gateway && cp .env.example .env && docker-compose up -dThe README method: clone, fill in .env with your keys, and bring it up via Docker Compose.
This is third-party code. Review the repository files before installing.
What it does
A FastAPI server exposes a single MCP endpoint to two Russian LLMs: GigaChat as the primary provider and YandexGPT as a fallback, with local Ollama as a third backup. On errors or a 429 rate limit, requests automatically switch to the next provider. Before sending text out, the server runs it through an anonymizer that finds and masks phone numbers, tax IDs, passport data, SNILS numbers and addresses, presented as compliance with Russia's 152-FZ personal-data law. It has a health endpoint reporting each provider's status and a Docker Compose file for deployment.
Who it is for. For teams that want one endpoint to Russian LLMs with failover and basic personal-data protection before sending text to the cloud.
Good fit when
- You want one MCP interface to GigaChat and YandexGPT with automatic failover
- You need phone numbers, tax IDs, passports and SNILS masked before text goes to a cloud LLM
- You can self-host a FastAPI service via Docker
Not a fit when
- You want a ready hosted service, not your own server: you deploy and operate the gateway yourself
- Anonymization must be guaranteed complete: this is regex-and-heuristic detection, not a certified solution
Example request
Process this text with a customer's phone number via GigaChat, but mask the personal data firstLimitations
You need your own GigaChat keys (GIGACHAT_CLIENT_ID/SECRET) and YandexGPT keys (YANDEXGPT_API_KEY, YANDEXGPT_FOLDER_ID), stored in .env. PII anonymization is a set of heuristics and regular expressions, not a certified data-protection system, test it against your own data before relying on it in production. The repository contains many internal working files and article drafts (test reports, a Habr draft) unrelated to the server's actual operation.
How to disable. Stop the container with docker-compose down, or stop the mcp-gateway systemd service if it was installed as one.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| GIGACHAT_CLIENT_ID required, secret | GigaChat API application client ID. |
| GIGACHAT_CLIENT_SECRET required, secret | GigaChat API application client secret. |
| YANDEXGPT_API_KEY required, secret | YandexGPT API key, used as the fallback provider. |
| YANDEXGPT_FOLDER_ID required | Yandex Cloud folder ID for YandexGPT. |
Security check
- Forwards user text to external cloud LLMs (GigaChat, YandexGPT), even after anonymization
- Personal-data masking relies on heuristics and may miss non-standard formats
README in short
The README presents the project as a production-ready gateway that saves on tokens by preferring GigaChat over YandexGPT, gives an architecture diagram, a Docker Compose quick start, an endpoint table, and a section on 13 of 13 passing tests for the anonymizer and fallback logic.
FAQ
What happens if GigaChat is unavailable?
The request automatically falls back to YandexGPT, and to local Ollama if both are unavailable and it's configured.
Is anonymization guaranteed to hide all personal data?
No, it's regex-based heuristics for common formats (phone, tax ID, passport, SNILS, address), not a certified solution.
Related
Open-source personal AI assistant on your own machine: answers in Telegram, Slack, Discord and WhatsApp, extended with skills and plugins
A self-improving agent from Nous Research with a TUI, messaging gateway, cron jobs and skills it writes itself
An open source coding agent for the terminal and desktop with build and plan modes
Open prompt library with a Claude Code plugin, MCP server and CLI: search, fetch and improve prompts and skills from an agent