MCP Gateway: What It Does, When You Need One, and Costs

What an MCP gateway controls, when a small team needs one, and the costs of Cloudflare, Docker, and Lasso options.

Sunday, October 4, 2026Omid Saffari
MCP Gateway: What It Does, When You Need One, and Costs

Add an MCP gateway when you need shared access rules across agent clients. Six developers using four clients with eight MCP servers can mean 192 separate client-to-server configuration entries. The useful purchase is one place to control access and investigate tool calls, with a clear owner for its running costs.

What an MCP Gateway Does

An MCP gateway is one control point between agents and MCP servers for authentication, tool allow-lists, logging, and rate limits. Model Context Protocol, or MCP, is the common interface through which an AI application discovers tools and asks them to act. A gateway brings those connections under shared management. The precise controls depend on the implementation. Kong's gateway explanation describes this proxy and policy role.

Think of an operations assistant looking up a customer and then updating a support ticket. The MCP servers expose those actions. The gateway should establish who is calling, which actions that identity can use, and what happened when an action ran.

For developers using Claude, ChatGPT, Codex, and Cursor, the benefit is consistent tool access across the clients your organization approves. Client plans, authentication support, and connection methods still need checking individually.

The controls have different jobs:

  • Authentication: establish the person or workload making the request. Authorization then decides what that identity may do. One shared API key can hide individual accountability.
  • Tool allow-lists: expose and permit a deliberate set of actions. A support assistant might be allowed to look up a customer while being denied a deletion tool. Enforce the rule when the tool is called, as well as when tools are listed.
  • Logging: preserve the actor, server, tool, policy decision, and outcome needed to investigate an action. Decide which arguments may be recorded and how sensitive values are handled.
  • Rate limits: bound calls by the identity, tool, or upstream service you need to protect. A repeating agent should hit a controlled limit before it overwhelms a backend.

Those are requirements to verify, rather than a feature bundle guaranteed by the word gateway. A local tool aggregator can be useful while leaving organizational identity or rate limiting for you to implement.

Architectural section showing agents passing through gateway identity, tool permission, and usage controls before reaching MCP servers
The gateway governs the call; the upstream MCP server performs the work

MCP Gateway vs MCP Server

An MCP server supplies capabilities; an MCP gateway governs access to one or more servers. A server might expose a database query or a ticket-creation action. The gateway presents approved capabilities to clients, routes calls, and applies its configured controls.

In MCP's architecture, a client discovers tools using tools/list and invokes them using tools/call. A gateway can act as a server toward your agent and as a client toward upstream servers. The underlying application still decides which records the caller may read or change.

For example, allowing a ticket-update tool does not establish that every customer account is accessible. Record-level permissions and tenant boundaries remain the responsibility of the application and its server integration.

How It Differs From an AI or LLM Gateway

An AI or LLM (large language model) gateway controls requests to models. An MCP gateway controls requests to tools. That difference decides which problem each one can solve.

Cloudflare AI Gateway documents model-request logging, caching, rate limiting, retries, and fallbacks. Those controls help with inference cost and provider reliability. An MCP gateway's tool policy can instead decide whether an agent may call an approved action on a customer system.

Some products cover both paths. Evaluate each path separately: a model budget does not prove a tool permission, and a tool allow-list does not cap every model request. Use the AI gateways for coding agents comparison when the funded problem is model routing, inference spend, or provider failures.

An ordinary API gateway can also authenticate and throttle HTTP requests. MCP-aware governance adds the meaning inside those requests: tool discovery, tool names, and invocation arguments. Several actions can share the same /mcp URL, so a rule permitting that URL alone can be much broader than the tool policy you intended.

What Actually Changed on September 24, 2026

Cloudflare made MCP Server Portals generally available to all Cloudflare customers on September 24, 2026. Its primary announcement describes one endpoint for approved servers and Access logs for tool, prompt, and resource activity.

The release also names service-token authentication for autonomous agents, Gateway routing for richer HTTP logging and data loss prevention, and Logpush support for exporting activity. Data loss prevention, or DLP, inspects content against rules for sensitive information.

The durable consequence is a managed way to centralize remote MCP access without operating the gateway process yourself. Availability still leaves two decisions: whether your servers and clients are compatible, and whether the plan includes the audit features you require.

MCP gateways already existed as an architectural pattern. This release changes one managed option's availability; it does not make a gateway mandatory for every MCP connection.

When a Small Team Needs an MCP Gateway

You need a gateway when access decisions must survive changes of client, employee, or server owner. More than a handful of servers is a useful warning sign, but policy fragmentation is the stronger trigger.

Act when the same developer uses several clients and each client needs the same restricted tools. Act when operations needs to revoke access, reconstruct an action, or apply a common policy across sensitive or write-capable tools. A small estate with a consequential write action can justify this work sooner than a large collection of public documentation tools.

Consider an illustrative estate of six developers, four agent clients, and eight MCP servers, with every developer configuring every server in every client:

  • Direct configuration: 6 × 4 × 8 = 192 client-to-server entries.
  • One shared gateway: 6 × 4 = 24 client-to-gateway entries, plus 8 upstream endpoint definitions.
  • Combined endpoint references: 32.

This is our configuration arithmetic, not an observed deployment or a performance result. You may already distribute settings centrally, and different roles may need different gateways or profiles. Upstream OAuth grants, the authorizations each user gives a service, also remain separate from endpoint definitions.

The value is that changing an approved server address or tool policy can become a central operation. It is still possible to make a central mistake. Version the policy and decide who can change it.

Wait when one owner can already manage a small, low-risk tool set through existing identity controls and shared configuration. A gateway creates another service, dependency, and failure path. It should solve a named operating problem.

You are unaffected if your agents do not use MCP tools. If you only need to control model requests, start with the LLM-side gateway decision. If your application already enforces the required tool policy and audit path, add a gateway only when it improves that boundary.

What It Means for Builders, Operators, and Buyers

Builders: Transport Comes First

Choose a gateway that can reach the servers you run. stdio means a client talks to a local process through its input and output streams. Streamable HTTP carries MCP traffic to a remote endpoint. The protocol architecture describes both.

A managed remote gateway cannot automatically launch an stdio process on your laptop. Converting that process into a hosted HTTP service creates deployment and credential work. Establish transport compatibility before replacing client settings.

Operators: Govern the Actual Route

A common policy helps only when the relevant calls pass through it. Inventory direct credentials and endpoints alongside gateway connections. Define how approved clients reach tools, where incidents are logged, and who owns recovery if the gateway fails.

For a support workflow, the useful evidence is the identity and action that changed a ticket. A connection-success log alone cannot answer that question. Verify the records your chosen product produces rather than assuming every logging feature supplies the same evidence.

Buyers: Buy the Required Boundary

Budget the gateway, the upstream servers, and the person responsible for both. A Free plan may fit headcount while failing your retention requirement. Open-source software may fit deployment requirements while needing additional identity integration.

If the requirement expands to discovery of unapproved servers, detailed runtime inspection, or enterprise incident response, the MCP security platform comparison covers that broader purchase.

Three MCP Gateway Options, Verified October 4, 2026

Cloudflare fits a managed remote boundary; Docker fits containerized server operation; Lasso fits plugin-based orchestration. The choice turns on transport, access controls, logging, and who operates the service.

Prices and licenses below were verified against the owners' public pages and repositories on October 4, 2026. The cost scenarios later are calculations with stated assumptions.

OptionBest fitPrice or licenseMain operating boundary
Cloudflare MCP Server PortalsManaged access to remote HTTP serversFree: $0, up to 50 users; Pay-as-you-go: $7/user/monthLocal stdio servers need hosting; audit export has a separate entitlement
Docker MCP GatewayOperating MCP servers as containersMIT gateway codeYou own the runtime; Docker Desktop has separate licensing
Lasso MCP GatewayPlugin-based request and response controlsMIT gateway codeThe optional Lasso API plugin has a separate service dependency

Sources: Cloudflare plans, Docker's license, and Lasso's license.

Cloudflare MCP Server Portals

Cloudflare MCP Server Portals is the managed choice for approved remote MCP servers when Cloudflare One fits your identity and operating requirements. It combines servers behind one HTTP endpoint, uses Cloudflare Access for authentication, and lets administrators choose the tools and prompts exposed through a portal.

Cloudflare MCP Server Portals documentation showing the managed request path and configuration
Cloudflare MCP Server Portals

The current plan table lists Free at $0 with a 50-user limit, Pay-as-you-go at $7 per user/month, and a Contract plan with a custom annual price per user. It lists standard log retention of up to 24 hours on Free and up to 30 days on Pay-as-you-go; retention depends on the service used.

The wall is compatibility and audit entitlement. Cloudflare's portal documentation supports remote HTTP MCP servers, with up to 80 servers per portal. An stdio-only server must first be hosted behind an authenticated HTTP endpoint. Some upstream servers reject proxy-based clients.

Portal logging and external log export are also different purchases: Cloudflare's Logpush integration is Enterprise-only. Check that entitlement before promising your auditor an external archive.

Pick it for compatible remote tools when you want a shared boundary without owning gateway compute. Read Is Cloudflare MCP Portals Free? for the separate headcount, hosting, and audit costs.

Docker MCP Gateway

Docker MCP Gateway is the open-source choice when running the MCP servers is part of your problem. It starts servers in isolated containers, manages their lifecycle, handles credentials and routing, and groups available servers in profiles. A profile is a saved set of servers made available to a client.

Docker MCP Gateway repository with features, profiles, installation, and license
Docker MCP Gateway

The standalone gateway code is MIT licensed. Docker documents manual installation with Docker Engine as well as the Docker Desktop path. You still own the host, updates, credentials, and deployment design.

Docker Desktop has a separate commercial boundary. Docker's licensing page says qualifying small businesses must have fewer than 250 employees and less than $10 million in annual revenue for free commercial Desktop use. Larger organizations and government entities need a paid subscription. Docker Pro is $11 per user/month on monthly billing, or $9 per user/month on an annual plan. Those are Desktop subscription costs, not gateway-code fees.

There is another packaging boundary: Docker's current gateway docs separately label MCP Gateway as part of Docker AI Governance invite-only, through sales. The public MIT repository remains the standalone code option. Do not budget the commercial governance offering by assigning it the repository's license price.

Pick Docker when container isolation and server operation matter and someone owns that runtime. A gateway running on each laptop can consolidate local tools; shared organizational policy and remote-client access still need a deliberate deployment design.

Lasso MCP Gateway

Lasso MCP Gateway is a plugin-based intermediary for MCP requests and responses. It reads server configurations, manages configured servers, and exposes their capabilities through a unified interface. Its repository includes examples for Cursor and Claude Desktop.

Lasso MCP Gateway repository showing configuration, guardrail plugins, tracing, and MIT license
Lasso MCP Gateway

The gateway code is MIT licensed. The basic plugin masks tokens and secrets. The optional presidio plugin handles personal-information masking, and xetrack adds tracing with SQLite-backed events and its own installation requirement.

The important wall is the plugin's operating boundary. The lasso plugin requires a Lasso API key and sends content through Lasso's API for checks. The gateway's MIT license does not establish the price or terms of that hosted API, and the README does not quote its price. Treat it as a separate service dependency when budgeting or deciding where content may travel.

Pick Lasso when you need to extend request and response handling and can own the surrounding operations. Its README does not establish a turnkey shared identity, per-user tool permission, and rate-limit service. Require those controls explicitly if they are the reason you are adding a gateway.

What Running an MCP Gateway Costs

The software license is only one line of the budget. Separate gateway software or subscription fees, compute and logs, operator time, and the models and upstream applications used by the workflow.

For a managed service, include its identity-seat or usage meter and any required export or security add-ons. For self-hosting, include gateway and server compute, log retention, updates, credential handling, and recovery work. A free gateway can front a paid SaaS account and a paid model.

Here is a planning example for a small team. Assume an internal loaded labor rate of $100/hour, meaning the cost of staff time including overhead. Assume $20/month for incremental self-hosted compute and logs. These are chosen budget inputs, not vendor quotes or measured hosting requirements.

RouteGateway and infrastructure assumptionMonthly operator time assumptionModeled monthly total
Existing direct connections$0 incremental gateway spend4 hours × $100$400
Self-hosted MIT gateway$20 compute and logs2 hours × $100$220
Compatible managed gatewaySubscription fee M0.5 hour × $100M + $50

On these assumptions, self-hosting saves $180/month against the direct-configuration support baseline. It costs $220/month, despite a gateway-code license charge of $0. If rollout takes eight staff hours, add $800. The first-year estimate is 12 × $220 + $800 = $3,440, against $4,800 for the stated direct-support baseline.

Those savings depend entirely on whether the gateway reduces your support burden as assumed. Measure your current time and replace the inputs. A direct setup maintained by one simple shared configuration may cost much less.

Apply the Vendor Numbers to Your Estate

For six active Cloudflare users, Free can mean $0 in Cloudflare plan charges within the 50-user allowance. In the table's compatible-managed scenario, the assumed internal policy labor would still be $50/month. Hosted upstream servers, model usage, subscriptions, and add-ons remain outside that figure.

For 60 purchased Pay-as-you-go seats, the published $7 rate gives 60 × $7 = $420/month, or $5,040/year. This budgets all 60 paid seats. Free's 50-user limit describes a separate plan; it is not a 50-seat deduction in this calculation. Cloudflare's seat documentation says available seats follow purchased users and one identity occupies one seat regardless of applications accessed.

For six new Docker Pro monthly subscriptions, if required for the chosen Desktop route, 6 × $11 = $66/month using Docker's own price. If qualifying subscriptions already exist, incremental subscription spend may be $0. An Engine-based deployment has its own infrastructure budget.

For Lasso, start with the MIT gateway code, then add your host and logging budget. If you enable its API-dependent plugin, obtain the hosted-service terms separately. An unpriced dependency cannot honestly enter the budget as $0.

Choose Direct Connections, Self-Hosted, or Managed

Keep direct connections while your existing controls satisfy the workflow. This is the right choice for a small, controlled tool set with an accountable owner and a workable revocation and audit process. Review the decision when another client, role, or sensitive action makes policy diverge.

Choose self-hosted open source when you can name its runtime owner. Docker is the clearer starting point for containerized MCP servers. Lasso is the more relevant example when you need plugin-based interception. Budget identity integration, hosting, and logs separately, and prove the controls you require.

Choose managed when compatible remote tools need shared policy and you do not want to own gateway operation. Cloudflare is a practical first evaluation for a small Cloudflare One estate. Verify transport, upstream authorization, tool policy, and the required audit plan before broad rollout.

Architectural decision route asking whether shared rules are needed and whether an operator can run the gateway, leading to direct, self-hosted, or managed access
Shared policy creates the need; operating ownership helps choose the route

One requirement can flip the choice: if managed cannot reach your servers or provide your required controls, assign a self-hosting owner or retain the controlled direct route. A provider's feature count cannot repair a mismatched operating boundary.

What's Overhyped About MCP Gateways

One URL does not automatically produce one trustworthy permission system. The strongest misunderstanding is that connecting to a gateway completes authorization, audit, and security in one step.

A portal login may still be followed by upstream OAuth authorization. Your gateway policy and the upstream application's record permissions both matter. MCP's security guidance explicitly warns against accepting tokens intended for other resources and forwarding them unchanged.

Similarly, allowing a tool is only part of controlling its use. A permitted action can still receive unsafe arguments or affect the wrong tenant if the server integration permits it. Response masking does not replace application permissions or human approval for consequential actions.

Cloudflare provides a concrete policy example. Its portal docs say independent MFA, purpose justification, and temporary authentication are not enforced when a server is authorized through a portal, while selectors such as groups and device posture still apply. MFA means an additional authentication factor. Read that policy limitation before treating the portal as an approval workflow.

Finally, a gateway cannot log tool traffic sent around it. Define the approved route, preserve upstream permissions, and keep server maintenance in scope. The product adds a useful control point; the owner determines how complete the boundary is.

Your Monday Move

Pilot one workflow and prove the control you are buying. Choose a low-risk tool and a consequential tool from that workflow, then use the agent clients your operators already depend on.

  1. Map the current connections

    Record each client, server endpoint, transport, credential owner, exposed tool, and log destination. Identify the repeated policy change you want to centralize. Preserve the existing client configuration for a rollback.

  2. Choose the operating route

    Use direct connections if existing controls suffice. Choose a self-hosted pilot only with a runtime owner. For a Cloudflare pilot, go to Zero Trust > Access controls > MCP Portals, add compatible HTTP servers, assign server and portal Access policies, and select the allowed tools and prompts.

  3. Check discovery and invocation

    Connect each selected client using its supported method. Verify that the low-risk action is available and callable, and that a forbidden action is denied even when explicitly requested. Check upstream data permissions as well as the gateway's tool list.

  4. Revoke access and follow the record

    Remove the pilot identity's permission and confirm the next attempted action fails. Locate the allowed and denied requests in the records your product supplies. Confirm the log destination and retention match your requirement.

  5. Price the job and keep an owner

    Record subscription fees, upstream hosting, logging, and staff time. Expand only after the policy and recovery path work. Document how to return to the previous controlled configuration without creating an ungoverned bypass.

Frequently Asked Questions

What is a MCP gateway?

An MCP gateway is a control point between AI clients and MCP servers. It can centralize authentication, tool allow-lists, logging, rate limits, and routing. Verify each control in the specific implementation rather than assuming every aggregator supplies it.

What is MCP gateway vs MCP server?

An MCP server exposes tools, resources, and prompts. A gateway governs access to one or more servers and can present approved capabilities through a shared interface. The upstream server and application still perform and authorize the underlying work.

Do we need an MCP gateway?

Use one when several clients or roles need a common tool policy, revocation process, or audit path. Direct connections can remain appropriate when an owner already meets those requirements. There is no protocol rule that makes a gateway mandatory at a particular server count.

What is the difference between a proxy and an MCP gateway?

A basic proxy forwards traffic. An MCP-aware gateway can understand tool discovery and invocation, aggregate capabilities, and apply tool-specific policy. Because MCP actions can share one HTTP endpoint, URL-level permissions alone may not express the action restrictions you need.

Is MCP like an API gateway?

MCP itself is a protocol. An MCP gateway plays a role similar to an API gateway, but governs MCP capabilities and calls. An API gateway can still sit in the same architecture for HTTP authentication, network controls, or throttling.

Is MCP the same as HTTP?

No. MCP defines the messages and capabilities; HTTP is one way to carry those messages to remote servers. MCP also supports stdio for local processes. That transport distinction is why a managed HTTP gateway cannot directly use every local-only server.

Why use MCP instead of rest?

MCP gives compatible AI clients a common way to discover and call tools. A server can wrap an existing REST API, so you may retain REST underneath it. Prefer the interface your actual clients need; adding MCP does not require rewriting every application API.

Is MCP based on JSON?

Yes. MCP uses JSON-RPC 2.0 messages for requests, responses, and notifications. Its protocol defines what those messages mean, including tool discovery and invocation; it is more than a generic JSON endpoint.

What is MCP vs rag?

MCP is an integration protocol for tools and data. RAG, retrieval-augmented generation, retrieves information to inform a model's answer. A retrieval tool can be exposed through MCP, so they can work together. Adding a gateway does not by itself improve retrieval quality.

For more practical infrastructure decisions and dated pricing checks, subscribe to the newsletter.

Last Updated
Oct 4, 2026
Category
Build

Prefer this site in Google

Add omidsaffari.com as a preferred source in Google Search

Mark omidsaffari.com as preferred and Google lifts it in Top Stories, AI Overviews and AI Mode for you.

Related Articles
OpenAI API Pricing (2026): GPT-6.1 Sol and Three App Budgets

OpenAI API Pricing (2026): GPT-6.1 Sol and Three App Budgets

OpenAI API rates verified October 2026, with GPT-6.1 Sol, Luna and Astra budgets plus voice, images, search and container costs.Oct 3, 2026Build
Pi Coding Agent

Pi Coding Agent

Set up Pi 1.0, connect your existing model account, add AGENTS.md and complete a first task. Includes provider pricing and honest limits.Oct 3, 2026Build
Best No Code AI Agent Builder in 2026: MindStudio, Gumloop and n8n (8 Compared)

Best No Code AI Agent Builder in 2026: MindStudio, Gumloop and n8n (8 Compared)

Compare eight no-code AI agent builders by job, entry price, billing unit, integrations and the point where API setup or code becomes necessary.Oct 1, 2026Build
Lovable Pricing (2026): What a Month of Credits Costs

Lovable Pricing (2026): What a Month of Credits Costs

Lovable costs $25/month for Pro or $50 for Business. See annual fees, credit top-ups, expiry, Cloud, app AI and a worked internal-tool budget.Oct 1, 2026Build
How to Set Up Codex Security After DevDay

How to Set Up Codex Security After DevDay

Set up Codex Security Cloud, PR review, and the CLI. Current team costs, real Gogs findings, SARIF in CI, and the checks you still need.Sep 30, 2026Build
LearnWorlds Pricing (2026): When Pro Costs Less

LearnWorlds Pricing (2026): When Pro Costs Less

Calculate LearnWorlds pricing for AI-built business training, including credits, learners, enrollment fees, and the point where an upgrade pays.Sep 30, 2026Build
ChatGPT Space vs Notion

ChatGPT Space vs Notion

Compare ChatGPT Space and Notion for shared documents, project databases, agents, permissions, pricing, and the launch limits that affect a switch.Sep 30, 2026Build
How to Use Kitesurf WebMCP

How to Use Kitesurf WebMCP

Connect an agent to Kitesurf, discover WebMCP tools, and run a checked task. See the setup and the limits that need a fallback.Sep 30, 2026Build
Newsletter

One letter, every Sunday.Working systems, not hot takes.

Weekly. No spam. Unsubscribe anytime.