Traefik Hub MCP Gateway

What it is

An MCP middleware in Traefik Hub’s API gateway that makes a route act as an OAuth-compliant gateway in front of MCP servers: centralised access control, resource-metadata discovery and fine-grained policy on MCP tools and resources (Traefik Hub docs, read 2026-10-08).

Maker and licence

Traefik Labs. Traefik Hub is the vendor’s API gateway / API management product built on Traefik Proxy; the docs feature matrix lists it separately from Traefik Proxy. Traefik Proxy itself is MIT (repo traefik/traefik, 65,108 stars on 2026-10-08, v3.7.14 released 2026-10-06). The MCP middleware is documented under Traefik Hub, not Proxy; its licensing terms were not checked (see Open items).

Position

API gateway with MCP awareness (middleware), Kubernetes-native (Middleware, IngressRoute CRDs).

Core capabilities (docs)

  • Acts as an OAuth 2.0/2.1 Resource Server; exposes /.well-known/oauth-protected-resource/<path> metadata for each MCP route.
  • Works with the JWT middleware for authentication; policies are expression-based and can match mcp.method, mcp.params.* (tool name, arguments, resource URI) and JWT claims such as groups, with allow / deny actions and a default action.
  • listPolicies show or hide items in tools/list, prompts/list, resources/list.
  • Task-Based Access Control (TBAC): authorization by tasks, tools and transactions (parameter constraints); on-behalf-of authentication is covered in the best-practices guide.
  • Observability with OpenTelemetry metrics and traces (getting-started guide). Enabled via Helm hub.mcpgateway.enabled=true; default max request body 1 MB.

MCP spec support

Requires MCP servers using the streamable HTTP transport. The docs mention handling for clients built against spec versions before 2026-07-28 (initialize handshake always allowed) and for the subscriptions/listen request of 2026-07-28 clients.

Maturity

Documented in the live Traefik Hub docs on 2026-10-08; GA/preview status is not labelled on the pages read.

Fit and limits (opinion)

Good fit if Traefik already fronts your Kubernetes services and you want MCP policy at the same ingress. It governs MCP traffic to servers you point it at; it is not a registry or a hosting platform. It requires JWT-based authentication context from upstream middleware.

Self-learning

Sources

Open items

  • Edition/licence required for the MCP middleware (Hub tier names): not verified.
  • GA vs preview status and launch date of the MCP Gateway: not stated in the pages read.
  • Behaviour with MCP spec revisions other than those named above: not checked.