MCP gateways compared (as of 2026-10-08)
An MCP gateway sits between agents (Claude, ChatGPT, Cursor, in-house agents) and the MCP servers and tools they use. It centralises authentication, tool-level authorisation, routing and aggregation, rate limits, audit logs and sometimes guardrails, so each agent does not hold credentials for every server. Background: model-context-protocol, mcp-security-with-gateway.
Terms that get mixed up
| Kind | Sits in front of | Typical job |
|---|---|---|
| MCP gateway | MCP servers and tools | Aggregate servers behind one endpoint, per-tool access control, OAuth, audit |
| LLM / AI gateway | Model providers | One API for many models, keys, quotas, failover, cost tracking |
| API gateway with MCP support | Existing APIs | Existing API-management product that adds MCP policies or turns APIs into MCP tools |
| Registry / catalog | Server metadata | Discover and approve servers; may or may not proxy traffic |
| Managed connector hub | SaaS accounts | Hosted account connections exposed through one MCP key |
Most products below span two or three of these. The table columns say which.
The Agentic AI Foundation’s gateways
The foundation (agentic-ai-foundation) hosts two gateway projects, both Apache-2.0 (foundation project list read 2026-10-08):
- agentgateway (agentgateway): created by Solo.io, accepted by the Linux Foundation on 2025-08-25 and announced as an AAIF project on 2026-06-04. Handles MCP (stdio, HTTP, SSE, Streamable HTTP, with OAuth and JWT) and A2A traffic, plus LLM routing.
- Agent Router, formerly Envoy AI Gateway (envoy-ai-gateway): announced as joining AAIF on 2026-09-09, with nine maintainer seats shared across Bloomberg, Nutanix, AMD, Tetrate and Netflix. Kubernetes-native on Envoy; its
MCPRouteaggregates MCP servers with OAuth, JWT/CEL authorisation and tool filtering, alongside an OpenAI-compatible model API.
kgateway (the Envoy-based Kubernetes gateway that agentgateway’s creator also built) is a separate CNCF Sandbox project, not an AAIF project.
Landscape
| Product | Kind | Licence / delivery | MCP specifics (from its note) |
|---|---|---|---|
| agentgateway | MCP + A2A + LLM gateway | Apache-2.0, self-host; enterprise distribution from Solo.io | Tool-level policy, JWT/OAuth; spec revisions not stated |
| Agent Router | MCP + LLM gateway | Apache-2.0, Kubernetes or standalone CLI | MCPRoute; docs claim June 2025 spec compliance (vendor) |
| litellm | LLM proxy with MCP gateway and A2A | MIT outside enterprise/ | MCP gateway docs; spec revision not stated |
| kgateway | Kubernetes gateway | Apache-2.0, CNCF Sandbox | AI/MCP behaviour not detailed in sources read |
| higress | AI-native API gateway | Apache-2.0, CNCF Sandbox | A newer-spec claim appears only as a site news item (unverified) |
| ibm-contextforge | MCP gateway + registry | Apache-2.0 | Federates MCP, A2A and REST; no official-support statement in the README |
| docker-mcp-gateway | MCP gateway + catalog | MIT repo; described in docs as part of Docker AI Governance, invite-only | Containerised servers; spec revision not stated |
| microsoft-mcp-gateway | Kubernetes reverse proxy; plus Azure API Management and API Center | MIT repo; Azure services | README requires MCP 2026-07-28 clients; API Management exposes tools only |
| kong-ai-gateway | API gateway with MCP proxy plugin | Core Apache-2.0; MCP plugin Enterprise-only | MCP 2025-06-18 |
| traefik-hub-mcp-gateway | API gateway with MCP middleware | Traefik Hub (edition not confirmed) | OAuth resource-server middleware, tool-aware policies |
| gravitee-agent-gateway, wso2-agent-gateway | API-management vendors | See notes | Status, licence and spec revision not confirmed |
| cloudflare-mcp-portals | Managed portals + remote MCP hosting | Cloudflare service | One portal in front of several servers; the McpAgent path is deprecated for new servers |
| aws-agentcore-gateway | Managed gateway | AWS service; AgentCore GA 2025-10-13 | Turns APIs and Lambda functions into MCP tools |
| google-apigee-mcp-gateway | API management with MCP | Google service | MCP in Apigee GA 2026-03-31; Cloud API Registry is Preview |
| obot | MCP gateway + hosting + registry | MIT | Also an LLM gateway; Device Management beta |
| metamcp | MCP aggregator/proxy | MIT | Latest release 2025-12-19; maintained slowly |
| mcpjungle | MCP gateway/registry | MPL-2.0 | Docs: downstream OAuth/SSO not supported yet |
| lasso-mcp-gateway | Guardrail/scanner gateway | MIT repo; commercial platform separate | Vendor “first MCP gateway” claim is unverified |
| pomerium-mcp | Identity-aware proxy | Apache-2.0 | Upstream OAuth bridging, tool-level policy |
| truefoundry-mcp-gateway | AI gateway with MCP | See note | Open-source status and spec versions not confirmed |
| PortKey | LLM gateway with MCP features | Acquired by Palo Alto Networks (see note) | See note |
| arcade-ai-mcp-gateway | Managed tool/connector gateway | Vendor service | See note |
| singlebrain-gateway | Managed connector hub | Vendor service (Single Grain) | “One MCP key”; spec details not documented |
| omniroute, hypertool-mcp, zapier-mcp, rube | Routers and connector hubs | See notes | See notes |
| Databricks Unity Gateway (databricks-unity-catalog) | Governance gateway inside a data platform | Databricks service | Managed MCP and tool governance on Unity Catalog |
What differs in practice
- Where policy lives. API-management vendors (Kong, Traefik, Gravitee, WSO2, Apigee) apply existing policy engines to MCP; MCP-native projects (agentgateway, Agent Router, ContextForge, Obot, MCPJungle) model servers and tools directly.
- Open source versus gated. Several MCP features sit behind enterprise editions (Kong’s MCP proxy plugin; LiteLLM’s
enterprise/directory; Docker’s AI Governance), so check which edition includes the MCP piece before choosing. - Spec drift. Documents name different MCP spec revisions (2025-06-18 in Kong, a June 2025 claim in Agent Router, 2026-07-28 in Microsoft’s README), and many projects state none; confirm which revision your clients use.
- Identity. Passing the end user’s identity through to upstream tools (not a shared service key) is the hard part; check how each product handles OAuth on both sides.
- Managed versus self-hosted. Cloud-provider and SaaS gateways remove operations but tie you to one platform; foundation-hosted projects keep neutral governance.
Choosing (opinion)
- Kubernetes shop wanting neutral governance: start with agentgateway or Agent Router.
- Already running an API gateway: use its MCP support first (Kong, Traefik, Apigee, Azure API Management), mindful of edition limits.
- Mostly need model routing plus a little MCP: LiteLLM or Portkey-style gateways.
- Small team or single developer: MetaMCP, MCPJungle or Obot, or a managed hub such as Arcade.
- Security-first: Lasso, Pomerium or Docker’s governance features, after reading their open items.
Open items
- Which MCP spec revision each product supports is stated for only a few; none was tested against a client here.
- No independent benchmarks or security reviews of any gateway were found.
- Several licences and editions (Traefik Hub, Gravitee, WSO2, TrueFoundry) were not confirmed from primary pages.
- Status labels (GA, preview, beta) are as dated in each linked note.
Sources
Every row is sourced in its own note. Foundation facts: https://aaif.io/projects , https://aaif.io/blog/agent-router-joins-aaif (read 2026-10-08).