Rivano · mcpgw v0.8.1 · self-hosted

Self-hosted MCP policy.
Audit and telemetry included.

mcpgw sits between MCP clients and servers, enforcing policy and guardrails while emitting JSONL audit records and OpenTelemetry — without rewriting either side.

OTLP-NATIVESELF-HOSTEDNO PHONE-HOME
Policy · Audit · Telemetry
Policy
action: deny
tool: shell_exec
rule_id: deny-shell
http: 403 -32001
✓ deny · redact · rate_limit
Audit
Local JSONLcanonical
S3 · Object Locktamper-evident
GCS · Kafka · webhookasync
⚠ jq-queryable · SIGHUP-reloadable
Telemetry
OTLP/HTTPnative
Datadog Agent:4318
Export pathasynchronous
stable mcp.* span attrs

mcpgw is a self-hosted MCP gateway that turns agent tool traffic into something you canroute, govern, trace, and audit.

Community and commercial licensing →
THE GAP

Your agents are calling filesystems, databases, and shells — through MCP.

Without a gateway, those calls are scattered across clients and servers with inconsistent logging, weak policy, and little observability.

Without mcpgw
  • MCP tool calls invisible to Datadog APM
  • shell_exec reachable from agents that should never call it
  • Bearer tokens and sk- keys reach upstream verbatim
  • "Which tools did agent X call last week?" has no answer
  • Audit story is whatever the underlying tool happens to log
  • Adding a control means a code deploy across every agent
One inline enforcement point
  • Authenticate MCP clients
  • Route calls to the right upstream server
  • Deny, redact, rate-limit, or strip risky content
  • Trace every call with mcp.* telemetry
  • Write one audit record per decision
  • Support Claude Desktop-style stdio clients through a bridge
Policy

Six actions. First match wins. Hot-reloadable.

allow, deny, redact, rate_limit, strip_app, and guardrail. Rules can match methods, tools, direction, claims, and result type. Omitted default_action is deny in v0.7.0+.

Policy actions

  • deny — 403 + JSON-RPC -32001
  • redact — regex over body, upstream sees [REDACTED]
  • rate_limit — principal-keyed token bucket; Redis optional
  • allow / strip_app / guardrail — explicit pass, UI removal, or webhook verdict

Five matcher primitives

tool_nameexact
tool_prefix"fs_"
tool_glob"fs_*read*"
tool_regexanchored
tool_name_in[a, b, c]

Same matchers in routes and policy.

Sample policy

YAML
policy:
  default_action: deny
  rules:
    - id: deny-shell
      action: deny
      when: { tool_name: shell_exec }
    - id: rl-fs-write
      action: rate_limit
      when: { tool_name: fs_write }
      tokens_per_second: 10
      burst: 20
    - id: redact-secrets
      action: redact
      when: { tool_name: "*" }
      redact:
        - regex: 'Bearer [A-Za-z0-9._-]+'
          replacement: "[REDACTED]"

Audit + Telemetry

Structured audit per request. Trace the gateway and upstream hop.

Every governed request produces structured audit metadata. A request has a SERVER span and, when forwarded, a CLIENT child span. Audit can ship locally and to S3, GCS, Kafka, or HTTPS webhooks; OTLP works with Datadog and other compatible collectors.

Audit · JSONL + sinks
  • One JSONL line per request — local file is canonical
  • decision, rule_id, auth_key_id, latency_ms
  • S3 with Object Lock governance retention
  • GCS, Kafka, or HTTPS webhook sinks (SIGHUP-reloadable)
  • Append-only on POSIX, queryable with jq
Telemetry · OTLP → Datadog
  • mcp.tool.name, mcp.session.id, mcp.policy.decision
  • mcp.upstream, mcp.payload.bytes_in/out
  • Datadog Agent OTLP/HTTP receiver — no new pipeline
  • Measure gateway overhead in your own deployment
  • Async export — never blocks request path

Local audit · durable sinks · Datadog-native spans

Self-hosted

One binary. Your VPC. No phone-home.

mcpgw is a single Go binary with a distroless multi-architecture container for linux/amd64 and linux/arm64. License verification is offline against an Ed25519 key embedded in the binary — no analytics ping, update check, or live revocation API.

Docker

ghcr.io/seanfraserio/mcpgw

Distroless multi-arch image. Liveness /healthz, readiness /readyz.

Kubernetes

Multi-replica HA

A production Helm chart, Redis-backed shared rate limits, readiness, PDB, anti-affinity, HPA, and two-stage drain are shipped.

Air-gapped

Offline license verify

Ed25519 JWT verification entirely offline. No outbound dependency on rivano.ai/mcpgw.

systemd · ECS · Nomad · raw binary — anywhere a Go binary runs

INTEGRATIONS

Speaks MCP. Ships to your existing stack.

Any MCP-spec client connects natively over HTTP. stdio clients (Claude Desktop, Cursor, Zed) bridge via the bundled mcpgw stdio subcommand. Telemetry lands in your Datadog Agent. Audit ships to whatever durable sink your compliance team already uses.

MCP clients
Claude DesktopCursorZedCustom HTTP MCPstdio MCP via mcpgw stdio
Telemetry + audit destinations
Datadog APM (OTLP)Amazon S3 (Object Lock)Google Cloud StorageApache KafkaHTTPS webhook (Splunk, Loki, any SIEM)
Get started

From install to observed traffic.

01
Pull the image.
docker pull ghcr.io/seanfraserio/mcpgw:latest. The published container uses a distroless runtime image.
02
Drop your license.
Place the JWT from rivano.ai/mcpgw at /etc/mcpgw/license.jwt with mode 0600. Free Community tier is self-serve.
03
Write your policy.
Deny shell_exec, rate-limit fs_write, or redact Bearer / sk- patterns. Policy rules are hot-reloadable on SIGHUP.
04
Watch in Datadog.
Point telemetry.customer.endpoint at your Datadog Agent's OTLP/HTTP receiver, make a request, and confirm the mcp.tools.call span in APM.
Where it fits

Don't replace your MCP servers. Put mcpgw in front of them.

Your MCP servers stay the same. Your controls get serious.

mcpgw is
  • An MCP-aware gateway/proxy
  • A policy checkpoint for agent tool calls
  • An audit and telemetry layer for MCP traffic
  • A router across multiple upstream MCP servers
  • A stdio-to-HTTP bridge for local MCP clients
mcpgw is not
  • A native resource store
  • A prompt-template server
  • A general REST/GraphQL-to-MCP wrapper
  • A sandbox for unsafe tools
  • A multi-tenant SaaS control plane
Licensing

Run it in your environment.

Proprietary, closed-source software. Public binaries are licensed under the applicable Community, Team, or Enterprise EULA; Enterprise source review or escrow is contractual. Community license issuance is public; commercial terms are confirmed directly rather than inferred from stale web copy.

Put policy in the MCP path.

Download a public artifact, issue a Community license, and follow the tested quickstart.