Self-hosted MCP policy.
Audit and telemetry included.
mcpgw sits between MCP clients and servers, enforcing policy and guardrails while emitting JSONL audit records and OpenTelemetry — without rewriting either side.
mcpgw is a self-hosted MCP gateway that turns agent tool traffic into something you canroute, govern, trace, and audit.
Community and commercial licensing →Your agents are calling filesystems, databases, and shells — through MCP.
Without a gateway, those calls are scattered across clients and servers with inconsistent logging, weak policy, and little observability.
- MCP tool calls invisible to Datadog APM
- shell_exec reachable from agents that should never call it
- Bearer tokens and sk- keys reach upstream verbatim
- "Which tools did agent X call last week?" has no answer
- Audit story is whatever the underlying tool happens to log
- Adding a control means a code deploy across every agent
- Authenticate MCP clients
- Route calls to the right upstream server
- Deny, redact, rate-limit, or strip risky content
- Trace every call with mcp.* telemetry
- Write one audit record per decision
- Support Claude Desktop-style stdio clients through a bridge
Six actions. First match wins. Hot-reloadable.
allow, deny, redact, rate_limit, strip_app, and guardrail. Rules can match methods, tools, direction, claims, and result type. Omitted default_action is deny in v0.7.0+.
Policy actions
- deny — 403 + JSON-RPC -32001
- redact — regex over body, upstream sees [REDACTED]
- rate_limit — principal-keyed token bucket; Redis optional
- allow / strip_app / guardrail — explicit pass, UI removal, or webhook verdict
Five matcher primitives
Same matchers in routes and policy.
Sample policy
YAMLpolicy:
default_action: deny
rules:
- id: deny-shell
action: deny
when: { tool_name: shell_exec }
- id: rl-fs-write
action: rate_limit
when: { tool_name: fs_write }
tokens_per_second: 10
burst: 20
- id: redact-secrets
action: redact
when: { tool_name: "*" }
redact:
- regex: 'Bearer [A-Za-z0-9._-]+'
replacement: "[REDACTED]"Audit + Telemetry
Structured audit per request. Trace the gateway and upstream hop.
Every governed request produces structured audit metadata. A request has a SERVER span and, when forwarded, a CLIENT child span. Audit can ship locally and to S3, GCS, Kafka, or HTTPS webhooks; OTLP works with Datadog and other compatible collectors.
- One JSONL line per request — local file is canonical
decision,rule_id,auth_key_id,latency_ms- S3 with Object Lock governance retention
- GCS, Kafka, or HTTPS webhook sinks (SIGHUP-reloadable)
- Append-only on POSIX, queryable with
jq
mcp.tool.name,mcp.session.id,mcp.policy.decisionmcp.upstream,mcp.payload.bytes_in/out- Datadog Agent OTLP/HTTP receiver — no new pipeline
- Measure gateway overhead in your own deployment
- Async export — never blocks request path
Local audit · durable sinks · Datadog-native spans
One binary. Your VPC. No phone-home.
mcpgw is a single Go binary with a distroless multi-architecture container for linux/amd64 and linux/arm64. License verification is offline against an Ed25519 key embedded in the binary — no analytics ping, update check, or live revocation API.
ghcr.io/seanfraserio/mcpgw
Distroless multi-arch image. Liveness /healthz, readiness /readyz.
Multi-replica HA
A production Helm chart, Redis-backed shared rate limits, readiness, PDB, anti-affinity, HPA, and two-stage drain are shipped.
Offline license verify
Ed25519 JWT verification entirely offline. No outbound dependency on rivano.ai/mcpgw.
systemd · ECS · Nomad · raw binary — anywhere a Go binary runs
INTEGRATIONS
Speaks MCP. Ships to your existing stack.
Any MCP-spec client connects natively over HTTP. stdio clients (Claude Desktop, Cursor, Zed) bridge via the bundled mcpgw stdio subcommand. Telemetry lands in your Datadog Agent. Audit ships to whatever durable sink your compliance team already uses.
From install to observed traffic.
Don't replace your MCP servers. Put mcpgw in front of them.
Your MCP servers stay the same. Your controls get serious.
- An MCP-aware gateway/proxy
- A policy checkpoint for agent tool calls
- An audit and telemetry layer for MCP traffic
- A router across multiple upstream MCP servers
- A stdio-to-HTTP bridge for local MCP clients
- A native resource store
- A prompt-template server
- A general REST/GraphQL-to-MCP wrapper
- A sandbox for unsafe tools
- A multi-tenant SaaS control plane
Run it in your environment.
Proprietary, closed-source software. Public binaries are licensed under the applicable Community, Team, or Enterprise EULA; Enterprise source review or escrow is contractual. Community license issuance is public; commercial terms are confirmed directly rather than inferred from stale web copy.
Put policy in the MCP path.
Download a public artifact, issue a Community license, and follow the tested quickstart.