MCP Gateway
Use Cases
MCP Gateway addresses a specific problem: employees are connecting AI clients to MCP servers faster than IT can review them. These are the scenarios where centralizing that access — with RBAC, audit logs, and policy enforcement — makes the difference between controlled AI adoption and unmanaged sprawl.
Two motions, two buyers
Govern internal MCP
Buyer: IT, security, platform. Signals: "our employees are wiring Claude and Cursor into servers," "we need audit for compliance," "we can't see what agents can reach."
Ship MCP to customers
Buyer: product and platform engineering. Signals: "we want to offer MCP tools to our customers," "we need a login flow for our MCP endpoint," "we're productizing our API as MCP."
Qualifying questions
- Are you consuming MCP internally, exposing it to customers, or both?
- Who connects to these servers today, and how do they authenticate?
- Do you need to control which tools each user or customer can reach?
- Do you have to prove who called what, for compliance?
- Are these servers yours, third-party, or a mix?
Stopping shadow MCP sprawl
The problem
Employees connect Claude Desktop, Cursor, and ChatGPT to MCP servers without security review — personal OAuth tokens, no audit trail, no visibility into what AI agents can reach.
How MCP Gateway helps
MCP Gateway gives IT a central catalog of approved servers. Security reviews a server once; it's then available to anyone with the right role. The official path becomes easier than the unofficial one.
- One approval process, available org-wide
- Centralized credentials instead of per-employee tokens
- Instant revocation when someone leaves or a server is deprecated
Show them: The central catalog and one-click approval flow.
Team-scoped tool access
The problem
Source MCP servers expose every tool to every user. Finance doesn't need GitHub. Engineering doesn't need payroll. Giving everyone everything creates unnecessary risk.
How MCP Gateway helps
Virtual MCP servers expose only the tools each team needs. Finance sees Stripe and QuickBooks tools. Engineering sees GitHub and Sentry. Customer Success sees Zendesk and Notion. One source of truth, infinite team-specific configurations. Access is scoped by identity, not just by team, and defaults to deny, so a new user or agent starts with nothing until you grant it.
- Scoped views of any MCP server, per team or per user
- Control at the individual tool level, not just the server level
- Default-deny: identities see only the tools you grant
Show them: The capability filter on a virtual server, granting and revoking a single tool.
Audit trail for compliance
The problem
When an AI agent accesses a financial system, customer database, or internal document store, you need to know who authorized it, what it called, and what data it returned — for compliance and incident response.
How MCP Gateway helps
Every tool call routed through MCP Gateway is logged: agent identity, tool name, parameters, response status, and timestamp. Full audit trail across every AI client and MCP server in the organization.
- Structured logs for every tool call
- Who called what, when, and with what parameters
- Data needed for SOC 2, HIPAA, and internal compliance reviews
Show them: The Recent Calls and Top Users views, filtered to one agent.
Credential and auth management at scale
The problem
Managing OAuth tokens for 20 MCP servers across hundreds of employees is operationally impossible. When a token is compromised or an employee leaves, there's no central place to revoke access.
How MCP Gateway helps
MCP Gateway centralizes credentials and handles auth translation. Users get a seamless experience — one login to the gateway — regardless of whether the underlying server uses OAuth, API keys, or a proprietary scheme.
- Single control plane for all MCP server credentials
- Auth translation across OAuth, API keys, and custom schemes
- Immediate revocation without touching individual servers
Show them: Revoking a downstream credential once and cutting access everywhere.
Securing internal MCP servers
The problem
Internal teams building MCP servers deploy them without the same security controls as production APIs — no rate limiting, no auth enforcement, no policy layer. A misconfigured internal server is a lateral movement risk.
How MCP Gateway helps
MCP Gateway applies the same programmable policy layer as AAM's API Management to internal MCP traffic. Rate limiting, authentication, and content policies run on every tool call — whether the server is internal or external.
- Rate limiting per consumer or per tool
- Auth enforcement consistent with the rest of the organization
- PII detection and prompt injection blocking across all traffic
Show them: Rate limiting, PII detection, and prompt-injection blocking on an internal server.
Governing AI coding agents
The problem
Developer AI tools like Cursor and GitHub Copilot connect to MCP servers that can read code, write files, call APIs, and query databases. Without governance, a single misconfigured agent has broad access to production systems.
How MCP Gateway helps
MCP Gateway enforces what coding agents can reach at the gateway level — not by relying on individual developer configs. Engineering teams get approved tools; access to sensitive servers requires explicit approval.
- Approved tool catalog for developer AI clients
- Scope coding agent access to relevant repositories and services
- Audit log of every tool call made during development workflows
Ship a governed MCP endpoint to your customers
The problem
Product teams want to offer MCP tools to their own customers, not just consume MCP internally. Doing it right means a real OAuth flow, per-customer tool scoping, and an audit trail on every call. Teams end up building all of that by hand and getting the auth wrong.
How MCP Gateway helps
MCP Gateway puts a governed endpoint in front of the MCP tools you expose to customers. It runs the full OAuth 2.0 authorization server, scopes tools per customer, and logs every call. Paired with MCP Server to publish your APIs as tools, it takes you from internal use to a productized MCP offering without building auth and governance from scratch.
- Real OAuth flow so customers click Connect, not paste tokens
- Per-customer tool catalogs from one set of upstream servers
- Audit on every customer tool call
Show them: The OAuth Connect flow from a client's point of view.
SSO and OAuth for MCP
The problem
Every MCP client needs auth, and rolling your own OAuth for each server is slow and easy to get wrong. Teams stall on token flows, refresh, and dynamic client registration instead of shipping. Users fall back to raw tokens in config files, the exact thing security teams want gone.
How MCP Gateway helps
MCP Gateway is an OAuth 2.0 authorization server for your MCP traffic. It handles DCR, PKCE, and token scoping per virtual server, and connects to your identity provider so users log in once. Employees and customers authenticate through the front door instead of storing credentials in config files.
- Full OAuth 2.0 authorization server, no build required
- Dynamic Client Registration and PKCE out of the box
- Single sign-on through your existing identity provider
Show them: The OAuth Connect flow from a client's point of view.
Manage many MCP servers from one URL
The problem
A team ends up with a dozen MCP servers, internal and third-party, each with its own URL, its own login, and its own log. Every AI client has to be pointed at each one, and no one has a single place to see what agents are calling.
How MCP Gateway helps
MCP Gateway puts every MCP server, internal and third-party, behind one gateway, with one MCP route per upstream. AI clients connect once. The gateway holds and rotates the downstream credentials, and every call lands in one log. Adding a tenth or twentieth server changes nothing for the user.
- One gateway URL in front of every upstream MCP server
- One login and one log, no per-server secrets to manage
- Add or remove a server without touching client configs
Access by team
Virtual MCP servers give each team a curated view of approved tools. The same source servers, with team-specific access controls applied at the gateway.
Finance
Payment processing, accounting, and spend management tools.
Engineering
Code, error tracking, and issue management — scoped by repo.
Sales
CRM and pipeline tools, without access to engineering systems.
Support
Ticketing and knowledge base — read-only on sensitive customer data.
MCP Gateway is part of AAM
Available on Akamai Connected Cloud — no separate product. Contact the AAM team to get started.