Best MCP Gateways in 2026: Options Compared

Last updated ·Read as Markdown
Answer

The main MCP gateways in 2026 are Metorial, Runlayer, Cloudflare MCP server portals, Docker MCP Gateway, Microsoft MCP Gateway, IBM ContextForge, and Obot. Cloudflare, Docker, Microsoft, ContextForge, and Obot fit teams that already run the surrounding infrastructure. Runlayer and Metorial are product platforms with per-user access policy and activity logs. The right one depends on who should operate it and how much you need beyond routing.

An MCP gateway sits between AI clients and MCP (Model Context Protocol) servers and handles sign-in, tool access, and logging in one place. The options below differ mostly in who operates them and how much they do beyond routing.

If you need
Look at
One entry point for servers, using Cloudflare for employee access already
Cloudflare MCP server portals
An open-source gateway you run on Kubernetes with Azure sign-in
Microsoft MCP Gateway
An open-source registry and gateway that also federates REST APIs
IBM ContextForge
MCP servers running as isolated containers
Docker MCP Gateway
Open-source governance for MCP servers and model access together
Obot
Discovery of unapproved tools and runtime scanning of calls
Runlayer
A managed gateway with per-user connections, skills, and call logs
Metorial

What does an MCP gateway do?

It proxies MCP traffic so authentication, access rules, and logs live in one layer instead of inside each server. What is an MCP gateway? covers the mechanics. The rest of this page compares products.

What should you compare?

Four things separate these products in practice.

  • Who runs it. A gateway you host means upgrades, scaling, and on-call are yours. A managed one means your traffic passes through someone else's infrastructure.
  • How users sign in. Some gateways map to your identity provider (the system behind employee single sign-on), others expect you to wire that up.
  • What it records. A log that names the person and the tool call answers "what did the agent do." One that names only a service account does not.
  • How far it reaches. Some products route MCP only. Others also cover model access, device discovery, or plain REST APIs.

The options

Metorial: managed gateway with per-user connections

Best forTeams that want sign-in, tool access, and logs working without running infrastructure.

Metorial provides Magic MCP endpoints, portals where users connect their own accounts, and shared skills. Admins allow or deny integrations and skills per group, and connection logs show each tool call's arguments and result. It links remote MCP servers and offers a catalog of 1,000+ integrations. The catalog repository is Apache 2.0 and the platform can be self-hosted.

Where it falls short. Per Metorial pricing, access management and SAML (Security Assertion Markup Language) single sign-on are Enterprise-plan features. The free Dev plan is limited to 2 team members and 10 provider integrations. It is also broader than needed if you only route traffic to servers you already run.

Runlayer: control plane with discovery and runtime scanning

Best forSecurity teams that want to find unmanaged tools and scan calls as they happen.

Runlayer's MCP gateway is part of a wider platform. Its pages describe shadow AI discovery through existing device management, policies by user, group, role, or agent account down to individual tools, and runtime security that scans tool calls and outputs. It deploys as a single-tenant hosted environment on AWS, or self-hosted on AWS or Kubernetes.

Where it falls short. Pricing is not listed on the pages checked, and the platform page points to booking a demo. The scope is larger than a team needs if it only wants a proxy.

Cloudflare MCP server portals: one endpoint inside Cloudflare Access

Best forOrganizations already using Cloudflare Zero Trust for employee access.

Portals put several MCP servers behind one HTTP endpoint governed by Cloudflare Access policies. Admins can alias tools, override descriptions, and allowlist a subset. Logs show tool calls per user, and Enterprise plans can export them to a SIEM (security information and event management) system.

Where it falls short. A portal supports up to 80 servers, stdio-only servers cannot be added, and some Access features, including independent multi-factor authentication, are not enforced during server authorization through portals. It also needs a Cloudflare One subscription and a configured identity provider.

Docker MCP Gateway: containerized servers

Best forTeams that want each MCP server isolated in its own container.

Docker's open-source gateway (MIT license) runs servers in containers with restricted privileges, network access, and resource usage, and injects credentials before forwarding requests. It starts from docker mcp gateway run and ships with Docker Desktop's MCP Toolkit. Docker's separate MCP Enterprise Gateway adds identity-provider sign-in, tool scoping, and audit events streamed to a SIEM.

Where it falls short. The enterprise gateway's pricing goes through Docker sales, and Docker lists its multi-tenant cloud option as coming soon.

Microsoft MCP Gateway: Kubernetes reverse proxy

Best forTeams on Azure and Kubernetes that want an MIT-licensed gateway they control.

It is a reverse proxy and management layer that routes requests to MCP servers deployed in Kubernetes, authenticating with Microsoft Entra ID bearer tokens and role-based access control (RBAC). The repository documents a one-click Azure deployment and a local Kubernetes setup.

Where it falls short. The agent and session subsystem is a single-replica preview that its documentation says is not suitable for multi-tenant production. It assumes Kubernetes and Entra ID.

IBM ContextForge: open-source registry and proxy

Best forTeams that want one open-source layer across MCP servers, agent-to-agent endpoints, and REST or gRPC APIs.

ContextForge is Apache 2.0 and describes itself as a registry and proxy that federates MCP, A2A (agent-to-agent), and REST and gRPC APIs. It has an admin UI, user-scoped OAuth tokens, OpenTelemetry tracing, and deploys through Docker, Helm, or PyPI, including air-gapped environments.

Where it falls short. You operate it yourself, including scaling, patching, and secret configuration.

Obot: open-source governance across MCP and models

Best forTeams that want an MCP gateway, a model gateway, and catalogs in one open-source platform.

Obot (MIT license) combines an MCP gateway, an LLM gateway, MCP and skills registries, sandboxed server hosting on Docker or Kubernetes, and correlated audit logs. Obot Sentry extends logging to tool calls on user devices.

Where it falls short. It is broader than a gateway, so a team that needs only MCP routing carries more to run.

Who should pick what?

  • Cloudflare if employees already sit behind Cloudflare Access.
  • Docker if container isolation per server is the priority.
  • Microsoft MCP Gateway if you run Azure and Kubernetes.
  • ContextForge or Obot if open source and self-hosting are requirements.
  • Runlayer if discovery and runtime scanning drive the decision.
  • Metorial if you want a managed gateway with per-user connections and logs. See also self-hosted vs managed MCP gateways.

Frequently asked questions

What is an MCP gateway?

A proxy between AI clients and MCP (Model Context Protocol) servers. It handles authentication, decides which tools each user or agent can call, and records the calls, so those rules do not have to be rebuilt inside every server.

Which MCP gateways are open source?

Docker MCP Gateway and Microsoft MCP Gateway are MIT licensed, IBM ContextForge is Apache 2.0, and Obot is MIT licensed. Metorial publishes its integration catalog under Apache 2.0 and its platform can be self-hosted. Cloudflare and Runlayer are commercial products.

Do I need a gateway if I only run one MCP server?

Usually not. A single server with its own OAuth sign-in is simpler to run. A gateway starts to pay off when several servers need the same sign-in rules and one shared log.

Can a gateway restrict which tools an agent can call?

Yes, most can. Cloudflare portals support allowlist patterns, Docker describes tool scoping in its enterprise gateway, Runlayer supports tool-level policies, and Metorial lets you limit tools with tool filters and allow or deny a resource per group.

How do I choose between self-hosted and managed?

Self-host when data must stay in your network or you already operate Kubernetes and an identity system. Choose a managed gateway when you want sign-in, policy, and logs working without running the infrastructure. See the self-hosted versus managed comparison for the trade-offs.

Sources

  1. Metorial docs: Review connection logs
  2. Cloudflare docs: MCP server portals
  3. Docker docs: MCP Gateway
  4. Microsoft MCP Gateway on GitHub
  5. IBM ContextForge on GitHub

Ready to build with Metorial?

Connect any AI agent to any tool or data source. Govern every action.