Distribute · MCP Gateway

Secure every MCP connection.One enterprise gateway.

The MCP Gateway is the one governed entry point between your agents and your systems. OAuth 2.1 through your IdP, RBAC scoped by team and role, prompt injection detection on every tool call, and audit logs that stand up to review.

Trusted byGoogleMoonPayLaunchDarklyCentsPlanetScalePolar

Customer stories

MoonPay brought 200+ MCP servers under the MCP Gateway, going from proof of concept to a company-wide rollout in 30 days.

MoonPay used the MCP Gateway to broker every MCP connection through its existing Okta identity, with permissions scoped per server, per tool, and per team. The security team has full visibility across 60K+ agent sessions, and unsanctioned shadow MCP servers are blocked by default.

Read the case study

01 · The problem

Agents are connecting to company systems. Can you control what data they reach?

Without the MCP Gateway
What can AI reach?
No inventory. Each team wires its own connections to production systems
Who approved the access?
API keys shared in DMs, allowlists nobody owns
What did an agent do last quarter?
A reconstruction from partial logs across every server
Behind the MCP Gateway
What can AI reach?
One catalog of every system, server, and tool agents can touch
Who approved the access?
Access granted by team and role, provisioned through your IdP
What did an agent do last quarter?
Every tool call in one exportable record, tied to a named employee

Employees were connecting MCP servers we had no inventory of. Now every server runs behind the gateway, scoped by team and role, and anything unsanctioned is blocked by default.

Thierry Dang

Security Operations

MoonPay

02 · The MCP Gateway

The MCP Gateway between
every agent and every server

One control point between every agent and every system. Security writes policy once at the MCP Gateway, and every team's agents inherit it. Adoption speeds up because governance stops being per-project work.

Read the guide: what is an MCP gateway?

Architecture

Where the MCP Gateway sits

Agents never hold credentials and servers never manage auth. Every session signs in through your IdP, every tool call crosses the MCP Gateway's policy layer, and every MCP server sits behind one audited entry point.

Agents

claude
cursor
chatgpt
copilot

MCP Gateway

  • OAuth 2.1 · SSO via your IdP
  • RBAC by team, role, and tool
  • Prompt injection detection
  • PII redaction in flight
  • Audit logs → your SIEM

gateway.acme.dev/mcp

MCP servers

github
slack
linear
{}internal-api
Works with every identity providerOktaMicrosoft Entra IDAuth0WorkOSGoogle WorkspacePing IdentityAny SAML / OIDC

Curated servers

MCP server catalog

Browse and connect to MCP servers through the MCP Gateway. Every server in the catalog is fully vetted and inherits the MCP Gateway's auth, RBAC, and audit logs. Bring your own servers, and they get the same controls.

Search MCP servers…

03 · Enterprise support

Support that speeds up development

Rollouts move as fast as the answers you get. Support is measured against SLAs, not best effort — these are the current numbers.

100%

SLA compliance

Every response-time commitment met, across every support tier.

23.9m

p90 first response

90% of support requests answered in under 24 minutes.

98%

Satisfaction rate

Measured across every resolved support conversation.

Speakeasy's AI control plane has been indispensable in enabling Fivetran's AI transformation.

Eli Davis

Fivetran

Fivetran

Questions

What is an MCP gateway?
An MCP gateway sits in front of every MCP server and turns many ad-hoc tool connections into one governed entry point. Every agent, every prompt, and every tool call passes through the gateway, where authentication, authorization, and inspection happen consistently. Without a gateway, each MCP server has its own auth, its own audit logs, and its own way of being misconfigured.
How is the MCP Gateway different from running individual MCP servers?
Individual MCP servers solve point problems but leave you with N auth surfaces, N audit logs, and N places to enforce policy. The MCP Gateway gives you one URL for every agent, one identity surface, one policy layer, and one audit log. New servers join the catalog and inherit the MCP Gateway's controls instead of being rolled out one by one.
Which AI agents connect through the MCP Gateway?
Claude, Claude Code, ChatGPT, Cursor, Copilot, Codex, and any internal or product agents you run. Speakeasy supports OAuth 2.1 with PKCE and DCR even when the upstream MCP server does not, so the MCP Gateway works with clients that expect modern auth and servers that do not yet implement it.
What identity providers does the MCP Gateway integrate with?
Okta, Microsoft Entra ID, Auth0, WorkOS, Google Workspace, Ping Identity, and any SAML or OIDC provider. Plug your IdP in once at the MCP Gateway and every MCP server behind it inherits your auth, with SCIM and directory sync available where supported.
How does runtime guardrailing work?
Every prompt, response, and tool call is inspected in real time. PII and data exfiltration patterns are actively blocked. Prompt injection and shadow MCPs are passively detected. Alerts integrate with your existing SIEM and incident response workflows so the security team works in the tooling they already use.
Can I bring my own MCP servers?
Yes. The MCP Gateway works with any MCP server: pre-built integrations from the Speakeasy catalog, MCP servers you build in-house, and third-party servers you adopt. Every server inherits the MCP Gateway's auth, RBAC, and audit logs, regardless of where it came from.
What do the audit logs capture?
Who called which tool, on which server, with what arguments, against which data, with what result, and when. Audit logs are exportable, queryable, and integrate with the same SIEM your security team already uses for the rest of the stack.
How do teams roll out the MCP Gateway across an organization?
Most teams start by routing one client (often Claude or Cursor) at one MCP server through the MCP Gateway, then expand. Per-team registries let you scope what each team sees, so engineering, sales, and security each get the right catalog without one team blocking another's adoption.

AI everywhere.

Control here.