Microsoft MCP Gateway
“Microsoft’s MCP gateway” is really three separate things. Do not conflate them.
AI gateway vs MCP gateway: Azure API Management’s AI gateway capabilities cover model/LLM traffic; its MCP features and the GitHub project below govern tool servers.
1. microsoft/mcp-gateway (open source)
- Repo
microsoft/mcp-gateway, MIT licence per GitHub API; about 866 stars, last push 2026-10-02 (checked 2026-10-08). Described as a reverse proxy and management layer for MCP servers in Kubernetes. Position: MCP gateway (self-hosted, Kubernetes). - README: control plane (REST under
/adaptersand/tools) plus a data plane routing MCP requests to ready servers; StatefulSets and headless services; metadata in Redis (local) or Cosmos DB (cloud). A Tool Gateway Router forwards tool calls to registered tool servers. A React management portal is served at/portal/. - Auth: Microsoft Entra ID bearer tokens; read access for the creator, configured
requiredRolesandmcp.admin; write for the creator ormcp.admin. - Deployment: local Kubernetes, or Azure via Bicep (AKS, Container Registry, Cosmos DB, Application Gateway).
- MCP spec: the current README says it requires MCP
2026-07-28clients (breaking change, no legacy initialisation) and uses stateless per-request routing. Earlier versions described session-aware routing; the repo description still says “session-aware stateful routing”. - Maturity: the Agents and Sessions feature is an opt-in Preview; the README does not give an overall GA label. README notes multi-replica production use needs extra work on session storage and isolation. Data collection may send usage information to Microsoft (can be disabled).
2. Azure API Management as MCP gateway
Per Microsoft Learn (page dated 2026-09-11): API Management can (a) expose any managed REST API as an MCP server (operations become tools) and (b) front an existing MCP server. Policies (rate limiting and quotas, JWT validation including Entra ID, IP filtering, caching) apply to all operations exposed as tools. Monitoring via Azure Monitor and Application Insights. Available in classic tiers (Developer, Basic, Standard, Premium) and v2 tiers, plus the self-hosted gateway. Supports MCP tools only (no resources or prompts) and is not supported in workspaces. New features are previewed through an “AI Gateway” release channel. Position: API gateway with MCP support plus AI gateway capabilities.
3. Azure API Center as MCP registry
Microsoft Learn (dated 2026-05-29): API Center keeps an inventory/registry of local and remote MCP servers, a discovery portal with a test console, sync from API Management and Git, and an MCP registry endpoint (.../v0.1/servers) usable from VS Code and GitHub Copilot. Registered servers can be integrated with Foundry tool catalogs (Microsoft Foundry).
Fit and limits (opinion)
Choose the open-source project for Kubernetes-hosted, Entra-secured MCP server hosting; APIM for exposing existing APIs under existing governance; API Center for discovery. See Microsoft, model-context-protocol, mcp-security-with-gateway, docker-mcp-gateway.
Self-learning
- https://github.com/microsoft/mcp-gateway
- https://learn.microsoft.com/en-us/azure/api-management/mcp-server-overview
- https://learn.microsoft.com/en-us/azure/api-center/register-discover-mcp-server
Sources (fetched 2026-10-08)
- GitHub API repos/microsoft/mcp-gateway; raw README
- https://learn.microsoft.com/en-us/azure/api-management/mcp-server-overview
- https://learn.microsoft.com/en-us/azure/api-center/register-discover-mcp-server
Open items
- Overall GA/preview status of microsoft/mcp-gateway not stated; no GitHub releases found via API.
- Whether APIM MCP features are GA or preview per feature: page does not label; not verified.
- Foundry-specific MCP tooling (tool catalog) only checked via the API Center page link.