Research

MCP gateways: tool access vs document permissions

An MCP gateway sits between AI assistants and the MCP servers they call. It decides which servers and tools each identity may reach, and it logs the calls. This page lists the gateways available in September 2026, open source and commercial, with what each one governs in its own words, and names the decision that has to happen behind the gateway: which passages a search returns to the person asking.

01What an MCP gateway does

An assistant such as Claude, ChatGPT, Copilot or a coding agent reaches tools through the Model Context Protocol. Once a company has more than a few MCP servers, it wants one door in front of them. A gateway gives it that door:

  • One endpoint for many MCP servers, often with a registry of the approved ones.
  • Identity: the assistant signs in, usually with OAuth, and the gateway knows which person or agent is calling.
  • Tool policy: which servers, tools, operations and sometimes parameters that identity may use.
  • A log of the calls: who called which tool, when, and with what arguments.

Some gateways also scan traffic for secrets, prompt injection or text patterns. None of that tells the gateway which documents the person behind a search is allowed to read. Aembit says it plainly in its own documentation: "The Gateway doesn't replace the MCP server's internal authorization logic."

02Open source MCP gateways

GitHub stars as of September 27 and 28, 2026. The description in each row is the project's own.

GatewayLicenseStarsWhat it governs
agentgatewayApache 2.05,059An open source proxy for agent traffic, MCP included, created by Solo.io and now a Linux Foundation project.
PomeriumApache 2.05,019 (whole project)An identity-aware proxy whose policy language controls "which MCP tools each user or group can call". Every tool call is logged "with the method, tool name, and parameters".
IBM ContextForgeApache 2.04,534"An AI Gateway, registry, and proxy that sits in front of any MCP, A2A, or REST/gRPC APIs", with role-based access for its admin UI and API.
ArchestraAGPL 3.0 core, plus an enterprise license4,306An MCP gateway, private registry and model proxy in one platform. MCP clients sign in with OAuth 2.1 or an identity provider's tokens, and a tool call "can be allowed early in a session and refused after the agent reads restricted or untrusted content".
UnlaMIT2,233A lightweight gateway written in Go that turns existing REST and gRPC services into MCP endpoints by configuration.
Stacklok ToolHiveApache 2.02,213Runs MCP servers in isolated containers, with a gateway and a registry server "combining multi-tenant claim-based authorization, multi-source aggregation, and SIEM-compliant audit logging".
Docker MCP GatewayMIT1,587Runs MCP servers as containers behind one endpoint; Docker calls it "a secure enforcement point between agents and external tools".
MCPJungleMPL 2.01,283A self-hosted gateway and registry whose "enterprise mode lets you control which MCP clients can access which MCP servers".
ObotMIT1,071In its words, "a single governed entry point to every MCP server a user is allowed to reach", with server and tool access set "by user or identity-provider group".
Microsoft MCP GatewayMIT853In its words, "a reverse proxy and management layer for MCP servers", with session-aware routing and lifecycle management in Kubernetes.

03Commercial and hosted MCP gateways

GatewayWhere it runsWhat it governs
Cloudflare MCP server portalsCloudflare, generally available since September 24, 2026One portal for an organization's approved MCP servers, enforcing "the same granular access policies for your AI connections that you do for your human users".
Kong AI Gateway 2.0Kong's gateway, generally available since September 1, 2026Bundles tools from several MCP servers behind one route, with an OAuth 2 plugin for MCP and identity-aware policies.
Traefik Hub MCP GatewayTraefik HubAuthorization across tasks (business objectives), tools (system access) and transactions (parameter-level constraints). "Response rules scan the tool result for text."
AWS Bedrock AgentCore GatewayFully managed by AWSAccess control "at multiple levels": gateway, tool, operation and parameter, through interceptors you write. Supports the 2026-07-28 MCP specification.
Azure API ManagementYour Azure subscriptionCan expose "a REST API managed in API Management as a remote Model Context Protocol (MCP) server"; a dedicated AI Gateway tier is in public preview.
TrueFoundry"VPC, on-prem, air-gapped""Apply RBAC policies per MCP Server for fine-grained control."
Permit.io MCP GatewayCloud; on-premises or in your VPC on Enterprise plans"Every tool call is checked with Permit before it reaches the MCP server."
MintMCPHosted; "VPC/self-hosted on request""Configure tool access by role, enabling read-only operations while excluding write tools."
RunlayerNot stated on its pages"Runlayer policies can apply to whole servers, specific tools, specific resources, groups, roles, users, agent accounts, clients, and runtime conditions."
ZuploThe Zuplo platform"Curate which tools each route exposes." Every tool call and auth event is logged.
NatomaNot stated on its pages"Define exactly which users can invoke which tools under what conditions", with user attribution for every tool invocation.
Aembit MCP Identity GatewayAembit's cloud, or a Linux host you run (beta)Tells the agent's identity apart from the person's and applies access policies on every request.

04MCP authorization in September 2026

The current MCP specification is dated 2026-07-28. Three things in it and around it matter to anyone choosing a gateway or a server:

  • Client registration moved. The specification now says "Dynamic Client Registration is deprecated and retained for backwards compatibility with authorization servers that do not support Client ID Metadata Documents." A server that registers clients from their metadata documents is on the current path.
  • Your identity provider can decide. Okta's Cross App Access "is now incorporated as the MCP authorization extension 'Enterprise-Managed Authorization'". Claude Enterprise lets an organization authorize a connector once, and "your team inherits access automatically on first login".
  • Gateways are catching up. AWS lists the 2026-07-28 version among the ones AgentCore Gateway supports, beside the three before it.

05The decision no gateway makes

A gateway can decide that a person's assistant may call a search tool. It cannot decide which passages that search returns, because it does not hold the documents or their rules. That decision belongs to the server behind the gateway, and it is where the risk is: a search tool that anyone may call, over documents that not everyone may read.

The servers that make this decision say so in their own documentation. Onyx: "All of your existing Onyx permissions and access controls are enforced automatically." Sinequa: "Agents only see what the user is authorized to see." Notion: "Notion MCP continues to respect all existing Notion permissions." Coveo: "tools inherit Coveo's identity and permission models."

A few gateways look inside what comes back, but by pattern, not by permission: Traefik's response rules "scan the tool result for text". Matching text is useful against leaked secrets. It is not a record of who may read which file.

So the stack has two layers, and each needs its own answers:

  • At the gateway: which assistants may reach which servers and tools, and how they sign in.
  • At the knowledge server: which documents each person may read, whether that is decided before anything is ranked, what happens to superseded or stale material, and what the log keeps about each answer.

The second list is the subject of Permission-aware RAG: before or after retrieval. The servers themselves are compared on Self-hosted MCP servers for company documents.

Where PremAgentic fits

PremAgentic is the second layer. It is on-premises knowledge retrieval for agents: it indexes the Markdown, text, PDF, Word and Excel files your organization keeps and gives your people and your AI assistants cited passages out of them, with your rules enforced before anything is retrieved. A gateway in front of it can decide which assistants may call it; PremAgentic decides which passages each caller receives.

  • Access. Who may read what is set in PremAgentic, folder by folder, and checked on every search. Each person's assistant sees what that person may read and nothing more.
  • Where the model runs. Every agent declares whether its model runs inside your network or at a hosted vendor, and a folder marked never for hosted models is never served to an assistant whose model runs outside the network.
  • The record. Every question is logged with who asked, the text of the question, where the assistant's model ran and the passages returned.
  • Read only. Agents connect over MCP with a token PremAgentic issues and get two read-only tools. They never write.

It runs on your own servers, Windows or Linux, on stock PostgreSQL 14 or later, with a local embedding model. PremAgentic is open source under the GNU Affero General Public License 3.0. The code is at github.com/premagentic/premagentic, and the latest release has the Linux and Windows archives.

Sources

Every fact about another product comes from that product's own pages, read on September 27 and 28, 2026.

  1. Aembit, MCP Identity Gateway
  2. Linux Foundation, agentgateway; agentgateway on GitHub
  3. Pomerium, MCP
  4. IBM ContextForge on GitHub
  5. Archestra on GitHub; MCP gateway; guardrails
  6. Unla on GitHub
  7. Stacklok ToolHive; registry server
  8. Docker, MCP Gateway
  9. MCPJungle on GitHub
  10. Obot on GitHub
  11. Microsoft MCP Gateway on GitHub
  12. Cloudflare changelog, MCP server portals generally available; Cloudflare blog
  13. Kong AI Gateway 2.0
  14. Traefik Hub MCP Gateway
  15. AWS Bedrock AgentCore Gateway; fine-grained access control; MCP 2026-07-28 support
  16. Azure API Management, expose a REST API as an MCP server
  17. TrueFoundry MCP Gateway
  18. Permit.io MCP Gateway
  19. MintMCP
  20. Runlayer
  21. Zuplo MCP Gateway
  22. Natoma
  23. MCP specification, authorization; authorization extensions
  24. Okta, Cross App Access
  25. Claude, authorize MCP connectors for your organization
  26. Onyx MCP server; Sinequa MCP; Notion MCP; Coveo MCP server