SingleBrain Gateway

Hosted service at gateway.singlebrain.com whose headline is “one MCP key for all your team’s tools”. It is the MCP/HTTP access layer of SingleBrain from Single Grain; the terms say the service “is operated by Single Grain” (no legal suffix given; the page footer says ”© 2026 Single Brain”, “Made in Los Angeles”). Closed, managed SaaS. Position: managed MCP gateway / connector hub (not an LLM gateway).

Capabilities (vendor statements, 2026-10-08)

  • Clients: Claude, ChatGPT, Cursor via one MCP endpoint (https://gateway.singlebrain.com/mcp); “plain HTTP for everything else”, with a bearer-key API, e.g. GET /api/data/google/properties.
  • Example registration: claude mcp add singlebrain --url https://gateway.singlebrain.com/mcp
  • Managed auth: OAuth, token refresh and revocation; users grant access with their own login and can revoke it. A key reaches only the accounts the organization connected, so tools are visible only for connected accounts. Per support page, keys act as the member who created them and stop when that membership ends.
  • Connected services: Google Analytics, Search Console, Google Sheets, Slack, HubSpot, Stripe, Gong, Coda, Asana, OpenAI, Perplexity (privacy policy also lists Meta Ads as preview).
  • Org separation in Postgres with row-level security; credentials encrypted with AES-256-GCM bound to organization and service (vendor claims).
  • Activity log of every tool call: who, which service, request type; returned data is not stored. Privacy policy: not used to train generalized models; deletion within 30 days on request.
  • Integrations are read-only except Slack (terms); the key can read Slack but not post, per the homepage.
  • Billing: “free to start”; connected accounts are not charged and paid tools are metered per call. See the site for current terms.
  • SOC 2: homepage says “in progress”.

MCP spec details

Not documented. The support page covers contact, troubleshooting and deletion only. /.well-known/oauth-protected-resource, /.well-known/oauth-authorization-server and /llms.txt returned 404 on 2026-10-08, so transport (Streamable HTTP vs SSE), spec revision, and the client-facing OAuth flow are unverified.

Fit and limits (opinion)

Suits small marketing/revenue teams wanting a hosted connector hub for GA, HubSpot, Stripe and similar services. Compared with self-hosted gateways such as agentgateway, it offers no policy engine, routing or guardrail features that are documented. Security background: MCP security with a gateway; protocol: Model Context Protocol.

Sources (fetched 2026-10-08)

Open items

  • MCP spec revision, transports and OAuth flow for clients: undocumented.
  • Plan names and current credit terms: not stated beyond “free to start”.
  • Legal entity; SOC 2 audit status (homepage “in progress” only).
  • Security claims (RLS, AES-256-GCM) are vendor statements, not independently verified.