Last updated: 6 October 2026
Quick Answer: An MCP gateway is a proxy between AI agents and MCP servers that centralizes authentication, access control and logging for tool calls. Leading options in 2026 are Docker MCP Gateway and Microsoft's open-source mcp-gateway, AWS Bedrock AgentCore Gateway, Kong's AI MCP Proxy, TrueFoundry, and LiteLLM and Portkey, which pair MCP control with LLM routing.
One agent calling one Model Context Protocol server needs no extra infrastructure. Four teams sharing twenty servers, with tokens in config files and no record of which agent called which tool, need one place to authenticate, authorize and log every call.
There is no single best MCP gateway. These products came out of container tooling, Kubernetes, a cloud control plane, an API gateway and an LLM router, so the choice follows what you run.
What is an MCP gateway?
An MCP gateway is a reverse proxy between MCP clients, your agents and AI coding tools, and the servers that expose tools and resources. Every call passes through it, so it is where identity, permissions, rate limits and the fleet's audit trail live.
It exists because MCP distributes trust by default. Each server sets its own authentication, and the MCP specification revision 2026-07-28 states that "Authorization is OPTIONAL for MCP implementations." Some of your servers will carry no auth at all.
How is an MCP gateway different from an LLM gateway or an API gateway?
Three kinds of traffic, three layers. Teams running agents in production need the first two, and the products increasingly overlap.
| Layer | What it governs | Typical controls | Examples |
|---|---|---|---|
| MCP gateway | Agent tool calls | OAuth per server, tool allow-lists, call logs | Docker, Microsoft mcp-gateway, TrueFoundry |
| LLM gateway | Model calls | Routing, fallbacks, budgets, rate limits | LiteLLM, Portkey, Kong AI Gateway |
| API gateway | HTTP to your services | TLS, authentication, quotas | Kong Gateway, NGINX, Amazon API Gateway |
They fail differently. A model gateway outage degrades answer quality and cost control; a missing tool gateway means an agent with a stale token can still write to production unrecorded. For the model layer, see what an LLM gateway is; for the protocol boundary, MCP versus a conventional API.
Which MCP gateway options exist in 2026?
Eight products are worth shortlisting.
MCP and routing capabilities as documented by each vendor on 6 October 2026.
| Option | Open source | Where it runs | MCP features | LLM routing | Best for |
|---|---|---|---|---|---|
| Docker MCP Gateway | Yes, MIT | Docker hosts or Desktop | Proxy, lifecycle, credential injection, tracing | No | Servers already containerized |
| Microsoft mcp-gateway | Yes, MIT | Kubernetes | Reverse proxy, lifecycle, routing, Entra ID with RBAC | No | Kubernetes platform teams |
| AWS Bedrock AgentCore Gateway | No, managed | AWS | APIs and Lambda to MCP tools, A2A passthrough, two-way auth | Yes, across providers | One managed AWS endpoint |
| Kong AI MCP Proxy | No, Enterprise tier | Wherever Kong runs | REST to MCP tools, passthrough, metrics, audit logs | Yes, AI Proxy Advanced | APIs already behind Kong |
| LiteLLM | Yes | Self-hosted or managed | One endpoint, access by key, team or org, namespacing | Yes, balancing, fallbacks | A self-hosted control point |
| Portkey | Yes, MIT for the AI gateway | Self-hosted or managed | Central auth, access control, observability, per-user tools | Yes, conditional routing | Both policies, one console |
| TrueFoundry | Not documented publicly as of 6 October 2026 | Your VPC, on-premise, air-gapped | Unified access, OAuth 2.0 discovery, guardrails, OpenAPI to MCP | Yes, its AI gateway | A gateway in your perimeter |
| Composio | Not documented publicly as of 6 October 2026 | Hosted | Hosted server configurations with toolkit auth | No | Third-party tool integration |
What is Docker MCP Gateway?
Docker calls it "Docker's open source solution for orchestrating Model Context Protocol (MCP) servers." The Docker MCP Gateway documentation describes a centralized proxy managing each server's lifecycle, injecting credentials and tracing every call. Reach for it when your servers are already containers; its weakest fit is per-user OAuth against an enterprise identity provider.
What does Microsoft's mcp-gateway do?
The Microsoft MCP gateway calls itself "a reverse proxy and management layer for MCP servers" built for "Kubernetes environments". The microsoft/mcp-gateway repository is MIT licensed. It documents server lifecycle operations, Entra ID with role-based access control, dynamic tool routing and telemetry, and it now requires clients on the 2026-07-28 revision, a breaking change. Choose it when Kubernetes is your substrate and Entra ID your identity provider.
How does AWS Bedrock AgentCore Gateway work?
The AWS MCP gateway is Amazon Bedrock AgentCore Gateway, broader than a tool proxy. Per the AgentCore Gateway developer guide it "converts APIs, Lambda functions, and existing services into Model Context Protocol (MCP)-compatible tools". It also fronts other agents through passthrough targets, including agent-to-agent traffic, routes inference across providers from one endpoint, and handles inbound and outbound auth.
Choose it when your agents and identity already live in AWS. One caution: a per-virtual-key spend cap is not documented publicly as of 6 October 2026.
What do TrueFoundry and Composio offer?
The TrueFoundry MCP gateway is documented as a "centralized MCP gateway for enterprise AI agents" with unified access, OAuth, observability and guardrails. Its docs also describe how to "convert existing OpenAPI specifications into MCP tools without writing a custom server". Location is its argument to security reviewers: the control plane runs in your VPC, on-premise or air-gapped. Choose it when the gateway must sit inside your perimeter.
Composio hosts MCP server configurations so agents reach third-party toolkits with auth handled, though its docs now steer new work elsewhere: "use a regular session instead."
Which gateways handle both MCP tools and LLM routing?
Four products govern tool calls and model calls in one place: LiteLLM, Portkey, Kong AI Gateway and AWS Bedrock. Most orgs want that pairing: the team needing a tool policy is usually already routing Claude, Codex and internal models for its coding tools.
What does the LiteLLM MCP gateway add to its router?
The LiteLLM MCP Gateway lets you "use a fixed endpoint for all MCP tools and control MCP access by Key, Team," over Streamable HTTP, SSE and stdio, plus organization-level control. It prefixes each tool name with its server name to stop collisions and tracks cost per invocation, per the LiteLLM MCP documentation.
The router adds load balancing, fallbacks, retries and cooldowns, and the proxy enforces budgets and tpm or rpm limits per key, user or team. Budgets read from a database, so a deployment without PostgreSQL caps nothing. It suits teams that want one self-hosted process over both layers.
What does Portkey combine in one gateway?
Portkey's MCP Gateway is documented as "centralized authentication, access control, and observability for MCP servers". It supports OAuth, API keys and custom headers per server, tool provisioning that enables or disables individual tools per user, rate limiting, guardrails, approval workflows, and logs of every call with caller identity and parameters. Its AI Gateway repository is MIT licensed, with fallbacks, retries, load balancing and conditional routing. Portkey earns its place when an approval step on sensitive tools is required.
Where does Kong AI Gateway fit?
The Kong MCP gateway path is the ai-mcp-proxy plugin. It converts API schemas into MCP tool definitions, proxies incoming MCP requests to an upstream server in passthrough mode, and records MCP traffic for metrics and audit logs. Two constraints: it arrived in Kong Gateway 3.12, and "This plugin is only available as part of our AI Gateway Enterprise offering".
Model routing comes from AI Proxy Advanced: seven load-balancing algorithms from round-robin to semantic and priority, plus retries and cross-provider failover. Token and cost limits sit in AI Rate Limiting Advanced. Choose Kong when it is already your edge; open source is better if licensing blocks you.
How do AWS Bedrock and AgentCore handle both?
AgentCore Gateway covers tools and cross-provider routing. The model half inside Bedrock is Intelligent Prompt Routing, which routes "between different foundational models within the same model family," with a configured fallback model as the baseline, and the console takes exactly two models from one family. Choose this pair when AWS is the system of record; a neutral gateway is better if one policy must span Anthropic, OpenAI and self-hosted models.
What security controls should an MCP gateway enforce?
Six controls, in this order. Authentication on every server, which the specification leaves optional. Per-agent tool allow-lists, so a code-review agent cannot reach the payments tool just because it is registered. Inspection of tool inputs and outputs, because a tool result is untrusted text re-entering the model's context. Rate limits per agent and per tool. An audit log carrying caller identity, tool, arguments and result. And credentials held by the gateway, not in agent config files.
Those map onto two entries in the OWASP Top 10 for Agentic Applications. ASI02, Tool Misuse, is what allow-lists and output inspection address. ASI03, Identity and Privilege Abuse, is what per-agent identity and scoped, short-lived tokens address.
Should you self-host an MCP gateway?
Self-host when tool traffic touches internal systems; use a managed service when speed to a pilot matters more. The open source MCP gateway choices are Docker's gateway and Microsoft's mcp-gateway for tool governance alone, and LiteLLM or Portkey where you want model routing in the same process.
What the tools do decides this, not what the models cost. Servers fronting a data warehouse, a payment ledger or source control make the gateway a privileged component, and most security teams will want it on infrastructure they control. If every tool is a public third-party API, a hosted control plane is a reasonable trade.
The trade-offs are weighed in self-hosted LLM gateways compared. For teams serving their own weights, LiteLLM in front of vLLM gives one OpenAI-compatible endpoint for commercial and local models.
How do you roll out MCP across many agents and teams?
Four steps, and none of them is the gateway install. Start with a server registry: one list of MCP servers with a named owner, the systems each touches, and the identity it uses. Second, put the gateway in front of existing servers and leave clients pointed at it, so the first change is observability, not behavior. Third, stage the permissions, read-only tools first, then writes behind explicit approval.
Fourth, instrument before you expand, so call volume, error rates and latency per server are visible before the fleet doubles. Patterns that keep a running system stable are in AI agent integration patterns.
What mistakes should you avoid when rolling out an MCP gateway?
These four recur. Registering every server on day one, which turns a permissions problem into an incident. Treating the gateway as a network hop rather than a policy point. Giving every agent the same service account, which erases the identity your audit log depends on. And pinning nothing: revisions carry breaking changes, as Microsoft's move to 2026-07-28 shows.
How Origins AI Coding Tool's LLM gateway fits beside an MCP gateway
Origins AI (originshq.com) builds the model-side half of this architecture. Its product page describes the Origins AI Coding Tool as a "self-hosted AI coding assistant and LLM gateway for your own infrastructure," documenting an OpenAI-compatible REST API offered as a drop-in replacement for existing tooling, with routing across OpenAI, Anthropic, Meta Llama, Mistral and CodeLlama or a model you bring.
It also lists rate limiting, cost tracking, role-based access control, per-team and per-engineer token quotas, local logging of every request, and redaction of secrets, API keys and PII before content reaches the model layer.
Deployment usually decides the review. The documented modes are on-premise, private cloud in your own AWS, Azure or GCP account, air-gapped with locally hosted models, and hybrid with a local gateway calling hosted models. In on-premise and air-gapped modes the page states that no source code is sent to an external service; in hybrid mode the submitted context leaves the network. Origins AI reports the gateway can be live within one week.
The Origins AI Coding Tool page documents an LLM gateway and does not document MCP support, so treat it as the model-side control plane beside whichever tool gateway governs your agents.
Talk to an engineer
Scoping a gateway layer for agents and AI coding tools? Book a call with an engineer who has deployed this inside customer networks.


