Docker MCP Gateway

What it is

Docker’s open-source proxy between AI clients and MCP servers. Each catalog server runs in its own container; the gateway handles routing, credentials and logging. It is the engine behind the MCP Toolkit in Docker Desktop and is fed by the Docker MCP Catalog. Position: MCP gateway (local-first, container-based), not an LLM/AI gateway: it does not route model calls.

AI gateway vs MCP gateway: an AI (LLM) gateway sits between apps and model providers (routing, caching, token cost). An MCP gateway sits between agents and tool servers (tool discovery, auth, tool-level access). See agentgateway and PortKey for the LLM side, mcp-security-with-gateway for the security case.

Maker, licence

Docker, Inc. (Docker). Repo docker/mcp-gateway (described as “docker mcp CLI plugin / MCP Gateway”), MIT licence; about 1,589 GitHub stars on 2026-10-08, last push 2026-09-23 (GitHub API). The repo shows no tagged GitHub release via the API.

Core capabilities (README)

  • OCI-based catalogs: create, push and pull; profiles group servers from the catalog, OCI images, the MCP Registry or local files, and can be exported or pushed to registries.
  • Per-profile server configuration and enabling or disabling individual tools.
  • Secrets kept out of environment variables (Docker Desktop secrets); built-in OAuth flows for servers that need tokens.
  • Transports: stdio by default, or sse / streaming to serve several clients on a port.
  • Built-in logging and call tracing; connect or disconnect clients such as Claude Code and Cursor per profile.
  • Docs: servers run in containers with restricted privileges, network access and resources; the gateway injects credentials before forwarding.
  • Runs inside Docker Desktop (4.59 or later per README) or standalone (DOCKER_MCP_IN_CONTAINER=1, Docker CE, WSL2).

Catalog and Hub

Docs state the Docker MCP Catalog offers 300+ servers packaged as container images with versioning, provenance and security updates, and that organisations can create custom catalogs. Docker Hub MCP server listings: not verified here (see Open items).

MCP spec, maturity

Spec revision supported: not stated in the README or docs fetched. Maturity label (beta/GA): not stated. The docs describe the gateway “as part of Docker AI Governance” as an invite-only feature (contact Docker sales). The core open-source plugin is usable without that.

Fit and limits (opinion)

Best for developers and small teams that want containerised, isolated MCP servers shared across clients on a workstation. Not a multi-tenant, Kubernetes-scale control plane; for that see microsoft-mcp-gateway or ibm-contextforge. Compare tool aggregation approaches in docker-mcp-vs-gradio-toolsets-comparison. Related: model-context-protocol.

Self-learning

Sources (fetched 2026-10-08)

Open items

  • MCP spec revision supported and formal maturity label: not found.
  • Docker Hub mcp/ namespace and signing/provenance details: not on the pages fetched.
  • Whether interceptors exist: not in the README fetched.