Releases: SamuelSupe/contextGate
Release list
ContextGate 0.8.0 — Guided query publishing
ContextGate 0.8.0
From an existing business query to a reusable Agent tool.
简体中文 · Publishing guide · Support demo · Installation
What's new
- One publishing workflow. Choose a source, provide a native query or fixed HTTP read operation, explain its inputs/results, run real checks, review the full source draft and publish. Save progress and recover from editing conflicts without overwriting unrelated entries.
- Concepts lead to queries. Link mapped ontology concepts by name, start a query from an entity, and inspect its definitions in the same editor. Published coverage separates linked queries from currently executable queries. Agents discover authorized concept/query links through the existing semantic tools.
- One query catalog. Available queries, administrator drafts, queries needing attention and all definitions have separate views. A query name opens its workspace; returning restores filters, the snapshot page, position and focus. Choosing an Agent removes management views, with the same boundary enforced by the API.
- Clear client confirmation. Connect an Agent, copy the tool call and wait for evidence. Waiting is bounded to two minutes and cancels when leaving or hiding the page, closing the panel, or changing the query/access. Confirmation matches the source, template, execution version and selected Agent; previews do not count.
- Less interface overhead. Home retains up to five account-scoped recent queries and highlights one next step. Contextual help, focused settings, compact rows, clear empty states, parameter examples and responsive ontology inspectors reduce navigation and repeated explanation.
Publication, execution checks, connection checks, health checks and business acceptance remain separate facts. A successful call is not a business-correctness verdict. The pilot worksheet provides a way to measure actual setup effort, answer quality and sustained reuse; no customer benefit is inferred from fixture tests.
Compatibility and upgrade
From 0.6.x or 0.7.x, back up the PostgreSQL metadata database, matching master key and deployment configuration. Stop ContextGate, replace the complete archive or image with 0.8.0 and restart with the same database URL, key and source-file directories. Verify a known query and audit record afterward.
This release adds no metadata migration or forced credential rotation. Administrator accounts, personal Configuration MCP identities, query Agent/OAuth grants, semantic publications, ontology mappings and old routes remain compatible. Semantic exports remain format v2 with v1 import support. There are still 15 query MCP tools and 22 Configuration MCP tools; query tools reuse execute_query_template, not one new MCP tool per template.
Saved browser resume records migrate to a bounded recent list when a query is opened. Storage contains only source/template/Agent IDs, scoped to the current administrator; query content, parameters, results and credentials remain excluded. A disabled browser store affects shortcuts, not saved server drafts.
From 0.4.x or 0.5.x, also follow the administrator migration checklist: sign in as admin with the retained password and issue personal Configuration MCP tokens to replace revoked legacy tokens. From 0.3.x or earlier, follow the PostgreSQL metadata migration guidance.
Packages and evidence
Download contextgate-0.8.0-linux-arm64.tar.gz or contextgate-0.8.0-linux-amd64.tar.gz and verify SHA256SUMS. Keep the launcher, libexec and private C++ libraries together. Both packages include the embedded UI, bilingual help, query/ontology/cloud examples, Apache-2.0 LICENSE/NOTICE and dependency notices. Linux glibc 2.36+ and PostgreSQL metadata are required; Node.js is not required at runtime.
The release provides release-verification.json, both dist-*.json and both download-*.json reports, identifying the exact commit, CI jobs, archive hashes and independently downloaded package checks. The package workflow includes PostgreSQL/HTTP API reads, HTTP/stdio, templates and ontology context, administrator recovery, revocation and both OTLP transports. Local amd64 execution uses OrbStack emulation; CI runs on native arm64 and amd64 runners.
See validation for each stage's actual scope. The full 18-product / 20-version matrix remains historical evidence; this release's package checks do not claim a new full-matrix run. Snowflake, Databricks SQL, BigQuery and Redshift remain preview connectors without real vendor verification. No federation, ontology instance store, inference engine, automatic query compilation or new resource-isolation model is introduced.
ContextGate 0.7.0 — Cloud warehouse previews
ContextGate 0.7.0
Cloud warehouse previews for the same semantic data workflow.
简体中文 · Cloud warehouse guide · Examples · Installation
What's new
Snowflake, Databricks SQL, Google BigQuery and Amazon Redshift join ContextGate as preview connectors. They use the existing query_sql tool, Agent-to-source grants, semantic catalogs, verified native templates, ontology mappings, and audit/OTLP pipeline. Configuration is available in the English/Chinese UI and Configuration MCP.
| Connector | Access and query interface | Parameters |
|---|---|---|
| Snowflake | SQL API with PAT or preissued OAuth access token | Positional ? |
| Databricks SQL | Statement Execution API with PAT or preissued OAuth access token | Named :name |
| Google BigQuery | Jobs API with Google service account JSON and automatic token refresh, or a supplied access token | Named @name |
| Amazon Redshift | PostgreSQL protocol with username/password, TLS and per-query read-only transactions | Positional $1 |
The three HTTPS adapters use fixed API paths, verified TLS, bounded polling and native result pages, and best-effort remote cancellation. BigQuery performs a dry run requiring a SELECT statement and applies a configurable billed-byte limit. Source discovery, credential editing and reader-declaration evidence follow the existing configuration workflow. Each connector includes source JSON and an importable semantic-template example.
Preview boundaries
No real Snowflake, Databricks, BigQuery or Redshift environment has been verified. These connectors are included in the packages, but are excluded from the verified 18-product / 20-version database count. API fixtures establish local behavior, not vendor compatibility, grants, billing or production readiness.
Cloud SQL accepts a conservative SELECT subset. Advanced vendor syntax can be rejected; native parameters are scalar, and SQL pagination is explicit. Use dedicated reader principals. A successful connection or administrator reader declaration is not proof of account privileges. See the guide for exact authentication, discovery, types, cancellation and cost boundaries.
HTTPS source versions are manually maintained connection-contract versions. Update the version after relevant cloud contract changes, then trial and publish affected templates again. This release does not add cross-source queries, a unified SQL compiler or entity-result conversion.
Upgrade
From 0.6.x, back up the PostgreSQL metadata database, matching master key and deployment configuration. Stop the service, replace the package or image with 0.7.0, then start with the same database URL, key and data directories. This release introduces no new metadata migration or forced credential rotation. Existing administrator accounts, personal Configuration MCP identities, query Agent/OAuth grants, semantic publications and ontology mappings remain in place. Check a known query and its audit record after restarting.
From 0.4.x or 0.5.x, the administrator migration introduced in 0.6.0 still applies: sign in as admin with the retained password, and replace revoked legacy Configuration MCP tokens with personal tokens. Follow the account upgrade checklist. From 0.3.x or earlier, follow the PostgreSQL storage migration guidance.
Packages and verification
Download contextgate-0.7.0-linux-arm64.tar.gz or contextgate-0.7.0-linux-amd64.tar.gz with SHA256SUMS. Both include the embedded UI, private C++ runtime libraries, English/Chinese help, cloud examples, Apache-2.0 LICENSE/NOTICE and dependency notices. Linux glibc 2.36+ and PostgreSQL metadata are required; Node.js is not needed at runtime.
Release attachments record the exact commit, native arm64/amd64 CI, and checks on both built archives and independent GitHub downloads. Archive workflows exercise PostgreSQL and HTTP API queries, HTTP/stdio, semantic/ontology templates, administrator access, recovery and both OTLP transports. Local amd64 archive execution uses OrbStack emulation. The validation record separates the open-source database matrix, local Chrome checks and simulated cloud API tests from the remaining real-cloud validation gap.
Downloads
Verified release gates
- Native amd64 and arm64 CI: Go, race, UI tests, production UI and CLI builds passed.
- Open-source database matrix: 18 products / 20 versions, 135 query/error cases and 104 denied operations passed.
- Each architecture passed 54 archive checks and another 54 checks after an independent GitHub download, including HTTP/stdio, semantic/ontology templates, administrator recovery and OTLP HTTP/gRPC.
- Archive hashes and source commit
89cf20d7c55a145f22c29e2019a792a858711af4match. Four cloud connectors remain Preview; no real vendor environment was verified.
ContextGate 0.6.0 — Named administrators and Apache-2.0
ContextGate is a Semantic Data Gateway for AI Agents: business concepts, verified native queries and controlled access to databases and HTTP APIs.
What's new in 0.6.0
- Named administrator accounts with Super administrator and Administrator roles, temporary passwords and mandatory first-login password replacement.
- One personal Configuration MCP identity per administrator, with owner-only token issuance/rotation and targeted cancellation when access is revoked.
- Audit records identify the actual administrator, configuration identity and entry point, including Agent previews. Account security events are restricted to super administrators.
- OTLP Logs over HTTP/protobuf and gRPC carry the new administrator fields. Two-administrator UI and Configuration MCP attribution is verified against a real Collector.
- ContextGate is now open source under the Apache License 2.0. LICENSE, NOTICE and third-party notices are included with the source, images and distributions.
- English and Simplified Chinese account management, personal-token settings, audit filters and help.
Upgrade notice
Back up the PostgreSQL metadata database and its matching master key, then stop the previous service before replacing it.
Sign in again with username admin and the existing administrator password. All old Configuration MCP tokens are revoked: each account owner must issue a new personal token in Settings → My configuration MCP and update their clients. Data sources, semantics, ontology versions, query Agent/OAuth grants, evaluations and audit history are preserved.
Do not run old and new server versions against the same metadata database. CLI password recovery now accepts --username; omission is allowed only with one administrator account.
Downloads
contextgate-0.6.0-linux-arm64.tar.gzcontextgate-0.6.0-linux-amd64.tar.gzSHA256SUMS
Linux glibc 2.36+ and a PostgreSQL metadata database are required. Archives include the embedded UI, private C++ libraries, bilingual help, examples and licenses. No Node.js runtime is required. The mcpdbhub launcher alias and MCPDBHUB_* settings remain supported.
Validation
The attached records identify the exact release commit, passing native arm64/amd64 CI and independent checks of the downloaded archives. Package checks cover HTTP/stdio MCP, source/template/ontology persistence, HTTP API workflows, password recovery, credential revocation and real OTLP delivery. Local amd64 archive execution uses OrbStack emulation.
The administrator feature's 18-product / 20-version matrix passed 135 query/error cases and 104 denied operations; its original digest and test-stage boundaries are retained in administrators.json. Release packaging does not relabel that matrix as a new run. release-verification.json records final delivery evidence.
Help
Getting started · Installation · Administrator accounts and upgrade · Configuration MCP · Release notes · 中文说明
ContextGate 0.5.0 — HTTP APIs and guided Agent workflows
ContextGate 0.5.0
Semantic Data Gateway for AI Agents — connect real data, explain business meaning, and publish controlled queries.
Highlights
- HTTP API sources: fixed GET/POST JSON operations, authentication, exact scalar parameters, declared fields and token pagination. Use native
query_http_apior trialled, published templates through the same source grants and audit controls. - Business query catalog: find executable queries first, explore published concepts, and preview linked templates in context.
- Guided authoring: native query editors, permitted parameter-position suggestions, templates from configured API operations, and entity-focused ontology mapping with metadata field selection.
- Single-answer checks: capture real Agent calls, review an answer and retain its own history; comparison evaluations remain available.
- Clearer administration: source-aware onboarding, publication/change review, separated audit activity, credential-expiry navigation, settings sections and bilingual responsive refinements.
Install or upgrade
Download the archive for your Linux architecture and verify SHA256SUMS. Packages include the UI, private C++ libraries, bilingual help, runnable examples and dependency notices. Require glibc 2.36+ and PostgreSQL metadata; no Node.js runtime is needed.
For upgrades from 0.4.x, back up and preserve the existing PostgreSQL store, matching master key and deployment settings. Keep key storage outside temporary directories. Versions through 0.3.x require the documented metadata-backend transition. Existing MCP inputs, MCPDBHUB_* settings and the mcpdbhub command alias remain supported.
Verification and boundaries
Full Go/race suites, nine UI workflow tests and two lossless request tests passed. The OrbStack 18-product / 20-version database matrix passed 135 query/error cases and 104 denied operations, with unchanged fixture data and native/template equivalence. HTTP APIs are an additional source type.
Attached reports identify the exact source commit, native arm64/amd64 CI, independently executed archives, OTLP HTTP/gRPC checks and GitHub-download verification. Local amd64 archive execution uses OrbStack emulation. UI and historical validation records state the workflows and limitations actually observed.
HTTP read-only behavior is administrator-declared: ContextGate enforces fixed request contracts but cannot prove arbitrary upstream operations have no side effects. This release adds no federation, ontology instance storage or inference engine.
ContextGate 0.4.0 — Semantic Data Gateway for AI Agents
ContextGate 0.4.0
Semantic Data Gateway for AI Agents
Understand your business. Query data safely.
The first release under ContextGate, formerly MCP DB Hub. The repository is now SamuelSupe/contextGate; history and earlier releases remain available.
What's new
- Configuration MCP — 22 typed tools at
/mcp/configlet trusted Agents prepare sources, semantic catalogs, templates, ontologies and mappings. Dedicated expiring credentials, real read-only trials and administrator publication keep configuration and query access separate. - Graphical ontology editor — contextual entity/property/relationship editing, source mappings and template usage.
- Guided Agent setup — client configuration, readiness, lossless parameter forms, query previews and saved evaluation history.
- Operations — management audit and OTLP Logs, semantic publication history, restore-to-draft, health checks, regression cases, deployment diagnostics and backup verification.
- English-first presentation — new logo, product screenshots and documentation hub, with English/Chinese UI and help.
- PostgreSQL metadata and read-only/authentication hardening.
Installation and downloads
| Platform | Archive |
|---|---|
| Linux arm64 | contextgate-0.4.0-linux-arm64.tar.gz |
| Linux amd64 | contextgate-0.4.0-linux-amd64.tar.gz |
Verify the downloaded archive with SHA256SUMS. Keep the full extracted directory and launch ./contextgate; mcpdbhub remains an alias. Packages contain the embedded UI, private C++ libraries, bilingual help, examples and dependency notices. Requires glibc ≥ 2.36 and a PostgreSQL metadata database. Docker Compose is available in the source repository for Docker/OrbStack users. No native macOS/Windows or Alpine/musl archive is included.
Breaking upgrade: metadata storage
0.4.0 does not import metadata from the SQLite store used by 0.3.0 and earlier. Back up the old metadata and matching key, initialize a fresh PostgreSQL store and administrator, recreate connections/grants, and update client tokens. Review/import semantic and ontology exports as drafts and rerun validation/trials. SQLite remains supported as a query data source. Existing MCPDBHUB_* configuration keys and telemetry attribute names are retained.
Read the upgrade checklist before switching.
Verified
- OrbStack: 18 products / 20 versions, 135 query/error cases, 104 denied operations, unchanged fixture data, seven query families with native/template equivalence and ontology mappings.
- Full Go tests and race checks; 10 frontend tests and production UI build.
- Native Linux arm64 and amd64 GitHub CI.
- Independently extracted packages: PostgreSQL initialization, HTTP/stdio queries, Configuration MCP, template/ontology workflows, restart, revocation, password recovery and OTLP HTTP/gRPC delivery.
- Published archives downloaded from GitHub and checked again before release publication; attached reports bind results to the source commit and archive SHA-256.
Local amd64 package execution uses OrbStack emulation on an arm64 host. The full database matrix runs on Linux arm64; it does not claim every database/version on both architectures.
Help
Documentation · Install · Getting started · Configuration MCP · Operations · 中文帮助 · Changelog
MCP DB Hub 0.3.0 — Shared business ontologies
MCP DB Hub 0.3.0 adds shared business ontologies with independent, version-pinned mappings for each authorized data source. Define Customer and Order once, map PostgreSQL tables and MongoDB documents separately, then let Agents discover the relevant native query templates.
What is included
- English Ontologies management and Semantics → Ontology mapping, with multilingual business definitions, single inheritance, entity identity, properties, relationships and declarative cardinality.
- Encrypted drafts, immutable versions, explicit upgrade differences, atomic source publication, metadata verification and administrator-declared fields. Referenced versions are protected from deletion.
- Source-authorized concept discovery through the existing 14 MCP tools. Native template results include
ontology_context; definition-only changes preserve query trials and running executions. - Semantic JSON v2 with v1 import compatibility, PostgreSQL/MongoDB reuse examples, English and Chinese guides, and ontology correlation in audit records and OTLP Logs.
- Includes the semantic catalogs, verified query templates and templates-only access introduced during the 0.2.0 development cycle.
Installation
Choose linux-arm64 or linux-amd64, download its archive plus SHA256SUMS, and verify the archive checksum. Extract the entire directory and run ./mcpdbhub serve; the bundled launcher keeps the required private libraries together. Linux glibc 2.36 or newer is required. No Node.js runtime is needed.
English installation · 中文安装说明 · Ontology guide · 本体指南
Back up the configuration database and its separate master key before upgrading. Existing sources remain unbound, with their grants, query modes and template trial evidence preserved. Short-lived pagination must restart after relevant publication or version changes.
Actual verification
- OrbStack: all 18 database products / 20 version combinations, seven query families, 132 native query/error cases, 89 denied operations, unchanged target data, and template/native equivalence with ontology mappings.
- Real shared Customer/Order acceptance on PostgreSQL and MongoDB, plus authorization projection, immutable version lifecycle, conflicts, encrypted restart recovery and request-start context checks.
- Local Chrome: create/edit/import/export, invalid definitions, both source mappings, Agent preview, independent version adoption, keyboard behavior and 390×844 layout.
- Native GitHub Linux amd64/arm64 CI: Go tests, race checks, embedded UI and CLI builds. Both actual dist archives independently passed 33 checks, then were downloaded from GitHub and checked again, including HTTP/stdio, ontology context, OTLP and restart recovery.
The attached VALIDATION.json records the exact commit, checks and platform scope. Local amd64 package checks run through OrbStack emulation; the external database matrix runs on arm64.
This feature supplies definitions and query guidance. It does not store entity instances, infer facts, compile cross-source queries, convert native results into unified entities, or claim full OWL 2 / SHACL conformance.
MCP DB Hub v0.1.1 — OTLP audit logs
MCP DB Hub v0.1.1 adds OTLP audit log export to OpenTelemetry Collector and compatible observability backends. Configure it in the English administration UI under Settings → Audit log export.
New in this release
- HTTP/protobuf and gRPC, with HTTPS, custom CA certificates, and encrypted authentication headers.
- Asynchronous export from the persisted audit trail, bounded batches, retry/backoff, saved delivery progress, and recovery after service or receiver restarts.
- Test log and delivery status in Settings, including pending/accepted/rejected counts and safe error feedback. Stored authentication headers are never returned by the API.
- Sanitized OTLP records: caller, source, operation, request ID, keyed query fingerprint, timing, row count, and error category. SQL text, parameters, results and credentials are excluded.
- English default README, installation instructions and release content, with complete Simplified Chinese documentation alongside them.
Export is disabled by default. Enabling starts with new audit events. Delivery may repeat events after ambiguous acknowledgements; use service.instance.id plus mcpdbhub.audit.id for deduplication. Partial/permanent rejections are counted and not retried; permanent errors pause subsequent exports until corrected settings are saved. Unsent events share the 30-day local audit retention limit.
OTLP setup and delivery semantics · Collector configuration · 中文说明
Download and upgrade
| Asset | Platform / purpose |
|---|---|
mcpdbhub-0.1.1-linux-amd64.tar.gz |
Linux x86_64 / amd64 |
mcpdbhub-0.1.1-linux-arm64.tar.gz |
Linux aarch64 / arm64 |
SHA256SUMS |
SHA-256 checksums for both packages and the validation report |
VALIDATION.json |
Source commit, CI, focused database and actual archive verification |
Packages require glibc 2.36 or newer and include the embedded UI, private C++ libraries, bilingual documentation, examples and third-party notices. No Go or Node.js runtime is needed. Keep the complete extracted directory and launch ./mcpdbhub serve.
Stop the existing service, back up its configuration database and matching master key, then start the new program with the existing data directory. Source credentials and Agent grants are retained. See the installation and upgrade guide.
Verification scope
-
All four uploaded assets were downloaded again from GitHub and matched local SHA-256 hashes. Both downloaded packages independently passed all 21 installation and OTLP checks again.
-
Native Linux amd64 and arm64 GitHub CI passed: Go tests, race checks, UI/numeric-parameter checks and CLI build.
-
Both actual distribution archives passed 21 checks each after independent extraction, including HTTP/stdio MCP, OTLP HTTP/protobuf and gRPC, receiver outage, restart recovery, token revocation and password recovery.
-
OrbStack: full Go race checks, frontend build and lossless numeric-parameter checks passed. Real PostgreSQL 17.11 adapter and HTTP MCP checks passed, including six query/error and six rejected-operation cases.
-
Official OpenTelemetry Collector 0.160.0 accepted real HTTP/protobuf and gRPC logs. Receiver downtime did not prevent queries; pending records survived Hub restart and were delivered after recovery.
-
Local Chrome verified the English configuration flow, errors, credential clearing, keyboard interaction and desktop/390px layouts without application console errors.
The database adapters are unchanged. The full 18-product / 20-version matrix remains the historical v0.1.0 evidence; it was not rerun for this audit-export update. Linux amd64 package execution on the local arm64 OrbStack host uses emulation; native architecture CI is recorded separately. Native macOS, Windows and Alpine/musl distributions are not included.
A project license has not yet been selected. Third-party notices are included in the repository and packages.
MCP DB Hub v0.1.0
The first MCP DB Hub release brings native, read-only database queries to AI agents, with an embedded English administration UI, per-Agent data-source grants, OAuth, and audit records.
Included
- 18 database products, 20 tested version combinations: PostgreSQL, MySQL, MariaDB, TiDB, CockroachDB, TimescaleDB, SQLite, DuckDB, ClickHouse, MongoDB, Redis, Valkey, Elasticsearch, OpenSearch, Neo4j, Cassandra, ScyllaDB, and InfluxDB 1.x / 2.x / 3 Core.
- 11 MCP tools: four discovery tools and seven native query families, over Streamable HTTP or a stdio bridge.
- Enforced query boundaries: read-only engine settings and accounts where available, query validation, operation allowlists, timeouts, cancellation, bounded results, and lossless value encoding. InfluxDB 3 Core uses explicitly labeled query API isolation.
- Administration: data-source configuration and connection evidence, Agent grants and token rotation/revocation, PKCE OAuth, encrypted database credentials, query previews, audit filtering, and local password recovery.
The support matrix records tested versions, capabilities and limits. Protocol compatibility alone does not establish verified support.
Download
| Asset | Platform |
|---|---|
mcpdbhub-0.1.0-linux-amd64.tar.gz |
Linux x86_64 / amd64 |
mcpdbhub-0.1.0-linux-arm64.tar.gz |
Linux aarch64 / arm64 |
SHA256SUMS |
SHA-256 checksums for the packages and validation report |
VALIDATION.json |
Source commit, database matrix, CI and actual archive validation records |
Packages require glibc 2.36 or newer and include the embedded UI, private C++ runtime libraries, bilingual documentation, examples, and third-party notices. Go and Node.js are unnecessary at runtime. Keep the entire extracted directory and launch it with ./mcpdbhub serve.
On macOS, use OrbStack or Docker to build from the tagged source. This release does not provide native macOS, Windows or Alpine/musl packages.
Installation guide · Agent examples · Simplified Chinese documentation
Verification
- OrbStack Linux arm64: all 18 products / 20 version combinations passed, including 132 query/error cases and 89 rejected-operation cases.
- GitHub CI: native Linux amd64 and arm64 UI builds, Go tests, race checks, numeric-parameter checks, and CLI builds passed.
- Both actual dist archives were independently extracted and run in clean Debian containers: HTTP/stdio MCP discovery and PostgreSQL queries, persistent restart recovery, token revocation, and password recovery passed. Local amd64 archive execution used OrbStack emulation.
- All four uploaded assets were downloaded again from GitHub and matched their local hashes. Both downloaded archives also passed the 16-check installation workflow.
- The English management UI and published documentation were checked in local Chrome. Screenshots show the running product with isolated sample databases.
These checks cover the versions and scenarios recorded in the validation documentation; they do not establish compatibility with every database version, clustered deployment, or operating system. This release targets one instance and one administrator.
License
A project license has not yet been selected. Third-party licenses and notices are included in the source and packages.