Traefik Hub MCP Gateway
What it is
An MCP middleware in Traefik Hub’s API gateway that makes a route act as an OAuth-compliant gateway in front of MCP servers: centralised access control, resource-metadata discovery and fine-grained policy on MCP tools and resources (Traefik Hub docs, read 2026-10-08).
Maker and licence
Traefik Labs. Traefik Hub is the vendor’s API gateway / API management product built on Traefik Proxy; the docs feature matrix lists it separately from Traefik Proxy. Traefik Proxy itself is MIT (repo traefik/traefik, 65,108 stars on 2026-10-08, v3.7.14 released 2026-10-06). The MCP middleware is documented under Traefik Hub, not Proxy; its licensing terms were not checked (see Open items).
Position
API gateway with MCP awareness (middleware), Kubernetes-native (Middleware, IngressRoute CRDs).
Core capabilities (docs)
- Acts as an OAuth 2.0/2.1 Resource Server; exposes
/.well-known/oauth-protected-resource/<path>metadata for each MCP route. - Works with the JWT middleware for authentication; policies are expression-based and can match
mcp.method,mcp.params.*(tool name, arguments, resource URI) and JWT claims such as groups, withallow/denyactions and a default action. listPoliciesshow or hide items intools/list,prompts/list,resources/list.- Task-Based Access Control (TBAC): authorization by tasks, tools and transactions (parameter constraints); on-behalf-of authentication is covered in the best-practices guide.
- Observability with OpenTelemetry metrics and traces (getting-started guide). Enabled via Helm
hub.mcpgateway.enabled=true; default max request body 1 MB.
MCP spec support
Requires MCP servers using the streamable HTTP transport. The docs mention handling for clients built against spec versions before 2026-07-28 (initialize handshake always allowed) and for the subscriptions/listen request of 2026-07-28 clients.
Maturity
Documented in the live Traefik Hub docs on 2026-10-08; GA/preview status is not labelled on the pages read.
Fit and limits (opinion)
Good fit if Traefik already fronts your Kubernetes services and you want MCP policy at the same ingress. It governs MCP traffic to servers you point it at; it is not a registry or a hosting platform. It requires JWT-based authentication context from upstream middleware.
Related notes
- agentgateway, Arcade MCP Gateway, Portkey, OmniRoute: other gateway notes in this folder
- MCP security with a gateway, Model Context Protocol, A2A protocol
- HyperTool MCP (tool-subset proxy) and Tool Platforms (managed tool/integration platforms) cover adjacent ground and are not repeated here
Self-learning
- Overview and configuration: https://doc.traefik.io/traefik-hub/mcp-gateway/mcp
- Getting started: https://doc.traefik.io/traefik-hub/mcp-gateway/guides/getting-started
- Understanding TBAC: https://doc.traefik.io/traefik-hub/mcp-gateway/guides/understanding-tbac
- Traefik Hub docs home: https://doc.traefik.io/traefik-hub/
Sources
- https://doc.traefik.io/traefik-hub/mcp-gateway/mcp (fetched 2026-10-08)
- https://doc.traefik.io/traefik-hub/mcp-gateway/guides/getting-started and …/understanding-tbac (fetched 2026-10-08)
- https://doc.traefik.io/traefik-hub/ (fetched 2026-10-08)
- https://api.github.com/repos/traefik/traefik (fetched 2026-10-08)
Open items
- Edition/licence required for the MCP middleware (Hub tier names): not verified.
- GA vs preview status and launch date of the MCP Gateway: not stated in the pages read.
- Behaviour with MCP spec revisions other than those named above: not checked.