Lasso Security MCP Gateway
What it is
An open-source, plugin-based security gateway that sits between LLMs/agents and other MCP servers, sanitising requests and responses and scanning servers before loading them. Lasso announced it on 2025-04-15 (company press release). Lasso also sells a commercial AI-agent security platform that includes MCP security (discovery, risk scoring, runtime monitoring, policy), per its MCP security page; the open-source gateway is the part documented here.
Maker and licence
Lasso Security (Tel Aviv). Repo lasso-security/mcp-gateway, MIT. 395 stars on 2026-10-08; latest GitHub release v1.2.0 (2026-01-21); last push 2026-01-22; PyPI package mcp-gateway shows 1.2.1 (all read 2026-10-08).
Position
Security-centric MCP proxy / orchestrator (not an API gateway, not a registry).
Core capabilities (README)
- Reads server definitions from an
mcp.json, manages server lifecycles and exposes one unified interface. - Plugins:
basic(token/secret masking guardrail),xetrack(tracing),lasso(Lasso platform guardrails; needs a Lasso API key). - Security scanner (
--scan): analyses server reputation and tool descriptions, marks serverspassed,blockedorskipped. - Tracking: request/response logs per guardrail, cost evaluation for token-priced MCPs, usage analytics (README claims).
- Deployment:
pip install mcp-gateway, or Docker; runs as a local stdio MCP server in Cursor / Claude configs. - No multi-tenant auth or OAuth features are described in the README.
MCP spec support
Not stated.
Maturity
Last release January 2026; no activity since in GitHub data read. Commercial platform availability is by demo request (vendor site).
Fit and limits (opinion)
Useful as a local guardrail layer and server scanner for developers. For team-wide auth, routing and audit prefer a hosted gateway such as Obot or a proxy-based option like Pomerium.
Related notes
- agentgateway, Arcade MCP Gateway, Portkey, OmniRoute: other gateway notes in this folder
- MCP security with a gateway, Model Context Protocol, A2A protocol
- HyperTool MCP (tool-subset proxy) and Tool Platforms (managed tool/integration platforms) cover adjacent ground and are not repeated here
Self-learning
- Repo and README: https://github.com/lasso-security/mcp-gateway
- Vendor MCP security overview: https://www.lasso.security/use-cases/mcp-security
Sources
- https://raw.githubusercontent.com/lasso-security/mcp-gateway/main/README.md (fetched 2026-10-08)
- https://www.lasso.security/resources/lasso-releases-first-open-source-security-gateway-for-mcp (press release 2025-04-15; fetched 2026-10-08)
- https://www.lasso.security/use-cases/mcp-security (fetched 2026-10-08)
- https://api.github.com/repos/lasso-security/mcp-gateway, https://pypi.org/pypi/mcp-gateway/json (fetched 2026-10-08)
Open items
- The press release calls it the “first” security-centric MCP gateway: vendor claim, not verified.
- Product naming/packaging of the commercial Lasso MCP offering: only a use-case page read; no product docs found (lasso.security/mcp-gateway returns 404).
- MCP spec revision: not stated.