Kong AI Gateway

What it is

Kong’s API gateway extended with AI traffic governance. Kong’s docs describe AI Gateway as a “connectivity and governance layer” that secures, governs and observes LLM, MCP and A2A traffic through one endpoint. Position: AI (LLM) gateway that also acts as an MCP gateway, built on an API gateway.

AI gateway vs MCP gateway: the LLM side routes, load-balances and guards model calls (providers incl. OpenAI, Anthropic, Azure AI, Bedrock, Gemini); the MCP side (AI MCP Proxy / AI MCP Server) governs tools.

Maker, licence

Kong Inc. The core Kong/kong repo is Apache-2.0 (about 44,252 stars, 2026-10-08), described as “The API and AI Gateway”. The MCP plugin below is Enterprise-only. No Kong company note in the vault.

Core capabilities (docs)

  • Routing, load balancing, failover across AI providers; streaming; ACLs; usage analytics (requests, tokens, errors, latency).
  • AI policies: prompt guarding, PII redaction, semantic caching, prompt compression, rate limiting, guardrails.
  • MCP: AI MCP Server entity turns existing REST APIs into tools; aggregate tools; govern external MCP servers; OAuth2 via AI Auth Strategies.
  • AI MCP Proxy plugin modes: passthrough-listener, conversion-listener, conversion-only, listener (aggregation). Needs AI Gateway 3.12 or later; ACL tool control from 3.13+. Auth via standard Kong auth plugins (key auth, OIDC). Limits: not combinable with other AI plugins on the same Service/Route, no WebSocket/gRPC upstream, no AI Guardrails with it.
  • Deployment: Konnect-managed control plane with self-hosted, cloud or Kubernetes data planes.

MCP spec

The plugin page states MCP protocol 2025-06-18; upstream servers may use 2025-06-18 or 2025-11-25; 2024 versions unsupported.

Maturity

Docs describe AI Gateway 2.0 and later as an entity model replacing the v1 AI Proxy plugins. GA/preview labels for the MCP features are not stated on the pages read.

Fit and limits (opinion)

Natural for organisations already running Kong for APIs; one policy plane for APIs, LLMs and MCP. MCP features require the paid tier. Related: agentgateway, PortKey, mcp-security-with-gateway, model-context-protocol.

Self-learning

Sources (fetched 2026-10-08)

Open items

  • Date MCP support first shipped, and GA vs preview status: not stated on the pages read.
  • Whether the AI Gateway 2.x entity model is available in open-source Kong: docs say not specified.