[{"data":1,"prerenderedAt":21},["ShallowReactive",2],{"blog-post-en-what-is-an-mcp-gateway":3},{"slug":4,"lang":5,"title":6,"description":7,"heading":8,"translationKey":9,"date":10,"keywords":11,"readingMinutes":17,"html":18,"alternates":19},"what-is-an-mcp-gateway","en","What Is an MCP Gateway and When Do You Need One?","An MCP gateway sits between AI agents and tools like Jira. What it checks on every call, how it differs from direct MCP servers, and when to use one.","What is an MCP gateway, and when does a team need one?","mcp-gateway","2026-07-10",[12,13,14,15,16],"MCP gateway","what is an MCP gateway","MCP server security","Model Context Protocol gateway","self-hosted MCP gateway",7,"\u003Cp>The Model Context Protocol (MCP) has become the common way to connect AI assistants to other\nsystems. An MCP client, for example Claude Code, Cursor or VS Code, talks to an MCP server, and the\nserver offers tools such as &quot;search Jira issues&quot; or &quot;create a pull request comment&quot;. The model\ndecides which tool to call, and the server executes the call against the real system.\u003C\u002Fp>\n\u003Cp>This works well for one developer and one tool. It becomes harder to manage when a company has\nmany agents, many tools and requirements from security or compliance. An MCP gateway addresses this\nby putting one control point between all MCP clients and all tools. This article explains what a\ngateway does, how it differs from connecting MCP servers directly, and when the additional\ncomponent is worth it.\u003C\u002Fp>\n\u003Ch2>How agents connect without a gateway\u003C\u002Fh2>\n\u003Cp>In the direct setup, every developer configures the MCP servers they need in their client. Each\nserver authenticates to its target system with a credential, typically a personal API token or an\nOAuth grant of the person who set it up. Some vendors now offer their own remote MCP servers, which\nwork the same way: the agent acts with the permissions of the connected user.\u003C\u002Fp>\n\u003Cp>This has three practical consequences. First, the agent usually holds the full rights of a person,\nalthough it only needs a small part of them. A token that allows reading tickets often also allows\ndeleting them. Second, there is no single place to see which agents can reach which systems; the\nconfiguration lives in individual clients and personal tokens. Third, logging depends on each\ntarget system. Some record API calls in detail, some barely at all, and none of them record what\nthe agent tried but was not allowed to do.\u003C\u002Fp>\n\u003Ch2>What an MCP gateway does\u003C\u002Fh2>\n\u003Cp>A gateway is a proxy that speaks MCP to the clients and talks to the target systems on their\nbehalf. The agent no longer holds credentials for Jira or GitHub; it holds one key for the gateway.\nThe credentials for the target systems are stored in the gateway, encrypted, and are never handed\nback to the client.\u003C\u002Fp>\n\u003Cp>For every call, a gateway typically runs the same sequence:\u003C\u002Fp>\n\u003Col>\n\u003Cli>\u003Cstrong>Authentication.\u003C\u002Fstrong> Who is calling? The request carries an API key that identifies a person or\nan agent.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Authorization.\u003C\u002Fstrong> May this caller run this operation, on this resource, with these parameter\nvalues? For example: read issues, but only in project \u003Ccode>MOB\u003C\u002Fcode>, and never delete.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data rules.\u003C\u002Fstrong> Are there values in the request or the response that must not pass, such as\nemail addresses or bank account numbers? These can be masked or removed.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Rate limiting.\u003C\u002Fstrong> Is the caller within its limits? A misbehaving agent loop should be slowed\ndown before it creates hundreds of tickets.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Audit.\u003C\u002Fstrong> The call is recorded with its outcome, whether it was allowed, denied, held for\napproval or rate limited.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cfigure class=\"post-figure\">\n\u003Csvg viewBox=\"0 0 760 240\" xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" role=\"img\" aria-labelledby=\"mcpgw-flow-title\">\n  \u003Ctitle id=\"mcpgw-flow-title\">An MCP gateway runs five checks on every call between the agent and the tool.\u003C\u002Ftitle>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"16\" y=\"100\" width=\"112\" height=\"60\" rx=\"10\"\u002F>\n  \u003Ctext class=\"fig-t fig-c-ai\" x=\"72\" y=\"126\" text-anchor=\"middle\">AI agent\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"72\" y=\"145\" text-anchor=\"middle\">Claude Code\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--primary\" x=\"140\" y=\"40\" width=\"470\" height=\"180\" rx=\"14\"\u002F>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"156\" y=\"66\">VORDIX · MCP GATEWAY\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"594\" y=\"66\" text-anchor=\"end\">every call\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow\" d=\"M72 160 V182 H640\"\u002F>\n  \u003Cpath class=\"fig-flow\" d=\"M610 182 C625 182 625 70 640 70\"\u002F>\n  \u003Cpath class=\"fig-flow\" d=\"M610 182 C625 182 625 126 640 126\"\u002F>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"152\" y=\"92\" width=\"84\" height=\"64\" rx=\"8\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"194\" y=\"110\" text-anchor=\"middle\">01\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t\" x=\"194\" y=\"130\" text-anchor=\"middle\">Identify\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"194\" y=\"147\" text-anchor=\"middle\">API key\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"244\" y=\"92\" width=\"84\" height=\"64\" rx=\"8\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"286\" y=\"110\" text-anchor=\"middle\">02\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t\" x=\"286\" y=\"130\" text-anchor=\"middle\">Authorize\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"286\" y=\"147\" text-anchor=\"middle\">op · value\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"336\" y=\"92\" width=\"84\" height=\"64\" rx=\"8\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"378\" y=\"110\" text-anchor=\"middle\">03\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t\" x=\"378\" y=\"130\" text-anchor=\"middle\">Mask\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"378\" y=\"147\" text-anchor=\"middle\">PII\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"428\" y=\"92\" width=\"84\" height=\"64\" rx=\"8\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"470\" y=\"110\" text-anchor=\"middle\">04\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t\" x=\"470\" y=\"130\" text-anchor=\"middle\">Rate limit\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"470\" y=\"147\" text-anchor=\"middle\">per key\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"520\" y=\"92\" width=\"84\" height=\"64\" rx=\"8\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"562\" y=\"110\" text-anchor=\"middle\">05\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t\" x=\"562\" y=\"130\" text-anchor=\"middle\">Audit\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"562\" y=\"147\" text-anchor=\"middle\">hash chain\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Crect class=\"fig-box\" x=\"640\" y=\"48\" width=\"104\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"692\" y=\"75\" text-anchor=\"middle\">Jira\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"640\" y=\"104\" width=\"104\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"692\" y=\"131\" text-anchor=\"middle\">GitHub\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"640\" y=\"160\" width=\"104\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"692\" y=\"187\" text-anchor=\"middle\">Confluence\u003C\u002Ftext>\n\u003C\u002Fsvg>\n\u003Cfigcaption>One call through the gateway: the five checks run in order before the request reaches Jira, GitHub or Confluence.\u003C\u002Ffigcaption>\n\u003C\u002Ffigure>\n\n\u003Cp>A useful side effect is that the agent only sees the tools it may call. The list of available tools\nis filtered before it reaches the model, which also reduces the chance that the model tries an\noperation it has no business with.\u003C\u002Fp>\n\u003Ch2>Gateway vs. direct MCP servers\u003C\u002Fh2>\n\u003Cp>The difference is less about features and more about where decisions are made. With direct servers,\naccess control is a property of each token and each target system. With a gateway, it is a policy in\none place, evaluated on every call.\u003C\u002Fp>\n\u003Cfigure class=\"post-figure\">\n\u003Csvg viewBox=\"0 0 760 310\" xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" role=\"img\" aria-labelledby=\"mcpgw-compare-title\">\n  \u003Ctitle id=\"mcpgw-compare-title\">Without a gateway every client holds tokens for every tool; with one, agents hold one key and a single policy decides.\u003C\u002Ftitle>\n  \u003Ctext class=\"fig-h fig-c-deny\" x=\"20\" y=\"32\">WITHOUT GATEWAY\u003C\u002Ftext>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"400\" y=\"32\">WITH GATEWAY\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M370 20 V296\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 80 C180 80 180 80 244 80\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 80 C180 80 180 150 244 150\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 80 C180 80 180 220 244 220\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 150 C180 150 180 80 244 80\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 150 C180 150 180 150 244 150\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 150 C180 150 180 220 244 220\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 220 C180 220 180 80 244 80\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 220 C180 220 180 150 244 150\"\u002F>\n  \u003Cpath class=\"fig-edge\" d=\"M116 220 C180 220 180 220 244 220\"\u002F>\n  \u003Ccircle class=\"fig-box fig-box--deny\" cx=\"180\" cy=\"115\" r=\"4\"\u002F>\n  \u003Ccircle class=\"fig-box fig-box--deny\" cx=\"180\" cy=\"150\" r=\"4\"\u002F>\n  \u003Ccircle class=\"fig-box fig-box--deny\" cx=\"180\" cy=\"185\" r=\"4\"\u002F>\n  \u003Ccircle class=\"fig-box fig-box--deny\" cx=\"180\" cy=\"220\" r=\"4\"\u002F>\n  \u003Ccircle class=\"fig-box fig-box--deny\" cx=\"180\" cy=\"80\" r=\"4\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"20\" y=\"60\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"68\" y=\"85\" text-anchor=\"middle\">Laptop\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"244\" y=\"60\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"292\" y=\"85\" text-anchor=\"middle\">Jira\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"20\" y=\"130\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"68\" y=\"155\" text-anchor=\"middle\">CI job\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"244\" y=\"130\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"292\" y=\"155\" text-anchor=\"middle\">GitHub\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"20\" y=\"200\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"68\" y=\"225\" text-anchor=\"middle\">Agent\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"244\" y=\"200\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"292\" y=\"225\" text-anchor=\"middle\">Slack\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--primary\" x=\"516\" y=\"60\" width=\"108\" height=\"180\" rx=\"12\"\u002F>\n  \u003Ctext class=\"fig-t fig-c-primary\" x=\"570\" y=\"146\" text-anchor=\"middle\">Vordix\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"570\" y=\"164\" text-anchor=\"middle\">one policy\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"400\" y=\"60\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"448\" y=\"85\" text-anchor=\"middle\">Laptop\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"644\" y=\"60\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"692\" y=\"85\" text-anchor=\"middle\">Jira\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M496 80 C506 80 506 150 516 150\"\u002F>\n  \u003Cpath class=\"fig-flow\" d=\"M624 150 C634 150 634 80 644 80\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"400\" y=\"130\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"448\" y=\"155\" text-anchor=\"middle\">CI job\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"644\" y=\"130\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"692\" y=\"155\" text-anchor=\"middle\">GitHub\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M496 150 C506 150 506 150 516 150\"\u002F>\n  \u003Cpath class=\"fig-flow\" d=\"M624 150 C634 150 634 150 644 150\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"400\" y=\"200\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"448\" y=\"225\" text-anchor=\"middle\">Agent\u003C\u002Ftext>\n  \u003Crect class=\"fig-box\" x=\"644\" y=\"200\" width=\"96\" height=\"40\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"692\" y=\"225\" text-anchor=\"middle\">Slack\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M496 220 C506 220 506 150 516 150\"\u002F>\n  \u003Cpath class=\"fig-flow\" d=\"M624 150 C634 150 634 220 644 220\"\u002F>\n  \u003Ctext class=\"fig-s\" x=\"20\" y=\"268\">× 9 personal tokens\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"20\" y=\"284\">× full rights of the owner\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"20\" y=\"300\">× denied attempts not logged\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s fig-c-ok\" x=\"400\" y=\"268\">✓ 1 key per agent\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s fig-c-ok\" x=\"400\" y=\"284\">✓ rights per operation\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s fig-c-ok\" x=\"400\" y=\"300\">✓ every call logged\u003C\u002Ftext>\n\u003C\u002Fsvg>\n\u003Cfigcaption>Left: every client holds its own token for every tool. Right: each agent holds one gateway key, and one policy decides what reaches each tool.\u003C\u002Ffigcaption>\n\u003C\u002Ffigure>\n\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Question\u003C\u002Fth>\n\u003Cth>Direct MCP servers\u003C\u002Fth>\n\u003Cth>MCP gateway\u003C\u002Fth>\n\u003C\u002Ftr>\n\u003C\u002Fthead>\n\u003Ctbody>\u003Ctr>\n\u003Ctd>Which rights does the agent have?\u003C\u002Ftd>\n\u003Ctd>Those of the token owner\u003C\u002Ftd>\n\u003Ctd>Those granted per operation\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Where is access configured?\u003C\u002Ftd>\n\u003Ctd>In each client and each tool\u003C\u002Ftd>\n\u003Ctd>In one policy\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Are denied attempts recorded?\u003C\u002Ftd>\n\u003Ctd>Usually not\u003C\u002Ftd>\n\u003Ctd>Yes, with the reason\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Can one key be revoked for all tools?\u003C\u002Ftd>\n\u003Ctd>No, one token per tool\u003C\u002Ftd>\n\u003Ctd>Yes\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003Ctr>\n\u003Ctd>Who holds the tool credentials?\u003C\u002Ftd>\n\u003Ctd>The client machine\u003C\u002Ftd>\n\u003Ctd>The gateway\u003C\u002Ftd>\n\u003C\u002Ftr>\n\u003C\u002Ftbody>\u003C\u002Ftable>\n\u003Cp>A gateway does not replace the permission model of the target system. Jira still enforces its own\nrights on the account the gateway uses. The gateway adds a narrower layer on top, specific to the\nagent and the task.\u003C\u002Fp>\n\u003Ch2>When a team needs a gateway\u003C\u002Fh2>\n\u003Cp>Not every team needs one. A single developer experimenting with an agent against a test project can\nwork without a gateway, and adding one would mostly add setup effort.\u003C\u002Fp>\n\u003Cp>The situation changes when several of the following apply:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>More than a handful of people or agents use AI clients against shared systems.\u003C\u002Fli>\n\u003Cli>Agents are allowed to write, not only read: tickets, pull requests, pages, messages.\u003C\u002Fli>\n\u003Cli>The systems contain personal or customer data.\u003C\u002Fli>\n\u003Cli>Security or compliance asks who can access what, and wants evidence.\u003C\u002Fli>\n\u003Cli>The company uses more than one AI client or provider and does not want to configure governance\nagain for each of them.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>In these cases, the effort of one central component is usually lower than the effort of reviewing\naccess spread across many tools and personal tokens.\nTwo concrete examples of such write access are an agent that\n\u003Ca href=\"\u002Fblog\u002Fai-agent-jira-sprint-planning\">prepares sprints in Jira\u003C\u002Fa> and an agent that\n\u003Ca href=\"\u002Fblog\u002Fai-code-review-permissions-github-azure-devops\">reviews pull requests on GitHub or Azure DevOps\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>What to look for in an MCP gateway\u003C\u002Fh2>\n\u003Cp>Gateways differ considerably. The following criteria help to compare them:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Granularity.\u003C\u002Fstrong> Can access be limited per operation and per parameter value (for example, per\nrepository or per Jira project), or only per tool?\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Response filtering.\u003C\u002Fstrong> Can fields or sensitive values be removed from what the tool returns,\nbefore the model sees it?\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Audit quality.\u003C\u002Fstrong> Is the log tamper evident? Does it include denied calls? Can it be exported to\nexisting security tooling?\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Deployment.\u003C\u002Fstrong> Does the gateway run on your infrastructure, or does every call pass through a\nthird party&#39;s cloud?\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Interfaces.\u003C\u002Fstrong> Is it MCP only, or can scripts and CI jobs use the same governed operations over\nREST?\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Coverage.\u003C\u002Fstrong> Which tools and which operations are supported today?\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>How Vordix implements this\u003C\u002Fh2>\n\u003Cp>Vordix is a self-hosted MCP gateway. It runs as a Docker Compose deployment on the customer&#39;s own\ninfrastructure, and no Vordix-operated service sits in the request path.\u003C\u002Fp>\n\u003Cp>Access is configured in three levels. The organisation sets a ceiling of what may be allowed at\nall; a project selects within that ceiling; and a workspace, which is a gateway endpoint with its\nown URL, rate limit and kill switch, is what an agent actually connects to. Rules that apply to a\nsingle agent are expressed by giving that agent its own workspace. Within these levels, access can\nbe limited by integration, operation, parameter value and response field. Every operation is\navailable over MCP and over REST.\u003C\u002Fp>\n\u003Cp>Every call is written to an append-only, hash-chained audit log, including denied calls and the\nreason. Human users can sign in via SSO (for example Entra ID or Okta), and API keys are shown once\nand stored only as hashes. The supported tools cover planning, documentation, code, data and\ncommunication; the \u003Ca href=\"\u002Fblog\u002Fai-agents-software-development-lifecycle\">overview of AI agents in the software development lifecycle\u003C\u002Fa>\nwalks through them stage by stage.\u003C\u002Fp>\n\u003Ch2>Trade-offs and limitations\u003C\u002Fh2>\n\u003Cp>A gateway adds a network hop to every call, and it adds a component that has to be operated and\nkept available; if the gateway is down, the agents cannot reach the tools. It also needs someone who\nowns the policies. The main limitation in practice is coverage: a gateway can only govern the\noperations it implements, so a team should check that the operations it needs are supported before\nmoving agents behind it.\u003C\u002Fp>\n\u003Ch2>Conclusion\u003C\u002Fh2>\n\u003Cp>An MCP gateway turns agent access from a property of many personal tokens into one reviewable\npolicy, evaluated on every call and recorded in one log. For a single developer this is often more\nthan needed. For a team with several agents, write access and sensitive data, it is a practical way\nto let agents work without losing track of what they can do. How such a log should look is covered\nin \u003Ca href=\"\u002Fblog\u002Fai-agent-audit-trail-eu-ai-act\">what an audit trail for AI agents should contain\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>To see a gateway configured for your own tools, you can request a Vordix demo.\u003C\u002Fp>\n",{"de":20,"en":4},"was-ist-ein-mcp-gateway",1790588073004]