Agentgateway

agentgateway

A proxy for agentic traffic: routes and secures connections to MCP servers, LLMs, and other agents over A2A

MCP serverOfficial

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Sits in the path of all agent traffic to MCP servers, LLMs and other agents
  • Configures authentication and access policies; a misconfiguration can open up unintended access
All reasons and checks

agentgateway/agentgateway

Install

Manual install

Text for your agent

Deploy agentgateway using the standalone quickstart at agentgateway.dev/docs for a single service, or the Helm charts under controller/install/helm for Kubernetes. There is no single one-line command in the README; follow the documentation section for your scenario.

This is third-party code. Review the repository files before installing.

What it does

Agentgateway is a Rust proxy that sits between agents and whatever they talk to: MCP servers, LLM providers, and other agents over the A2A protocol. It federates several MCP servers behind one entry point, supports stdio, HTTP, SSE and Streamable HTTP transports, and adds OAuth authentication plus OpenAPI integration. For LLM traffic it exposes one OpenAI-compatible interface to different providers with load balancing and spend controls. It also has a guardrails layer with content filtering and CEL-based access policies, plus OpenTelemetry metrics and tracing. It deploys as a standalone process or as a Kubernetes controller via the Gateway API.

Who it is for. For devops engineers and teams who need to manage agent access to multiple MCP servers and LLMs from one place.

Good fit when

  • Your team has several MCP servers and agents and needs one authenticated entry point
  • You need to restrict which tools agents can reach based on roles and policies
  • You need routing and spend control across requests to different LLM providers

Not a fit when

  • You have a single local MCP server for personal use and don't need a proxy in front of it
  • You have no infrastructure team to deploy and maintain a proxy layer

Example request

Set up agentgateway so it federates my MCP servers behind one entry point with OAuth

Limitations

Requires its own deployment and configuration, either as a standalone service or via Helm on Kubernetes. The README doesn't give a single one-line local run command; separate documentation pages cover the standalone and Kubernetes setups.

How to disable. Stop the agentgateway process or pod, or remove the Helm release in the cluster (helm uninstall for the agentgateway-crds and agentgateway-standalone charts).

MCP

Transport
stdio, http, sse
Authentication
OAuth

Security check

  • Sits in the path of all agent traffic to MCP servers, LLMs and other agents
  • Configures authentication and access policies; a misconfiguration can open up unintended access

README in short

The README calls agentgateway the first complete connectivity solution for agentic AI and lists four layers: an LLM gateway with one OpenAI-compatible API, an MCP gateway with tool federation across transports, an A2A gateway for agent-to-agent communication, and inference routing for self-hosted models based on GPU metrics. It also describes guardrails with content filtering across several providers and a security layer with JWT, API keys, OAuth, CEL-based RBAC and OpenTelemetry telemetry. Setup points to separate documentation pages for standalone and Kubernetes scenarios, and the repository ships ready Helm charts.

FAQ

Is this an MCP server or a proxy in front of MCP servers?

A proxy. Agentgateway doesn't implement tools itself; it federates and secures access to existing MCP servers, LLMs and other agents.

Does it work outside Kubernetes?

Yes, there's a standalone mode driven by flat YAML config, separate from the Kubernetes controller with Gateway API support.

Editors’ pick

An MCP server built into the Netdata agent: metrics, logs, alerts and live process, service and container data for an AI assistant

MCP serverMedium riskNo VPN needed80.7KRepository stars
Editors’ pick

GitHub's official MCP server: code, issues, pull requests, Actions and security alerts straight from the agent

MCP serverHigh risk33.3KRepository stars

Agent Skills for Google products

Agent Skills for Google products and technologies

Editors’ pick

Official Google skill collection for working with Google Cloud, BigQuery, GKE, ads and analytics from an agent

SkillHigh risk20.5KRepository stars
Official

AWS's official MCP server suite: docs, IaC, containers, serverless, databases, cost and monitoring

MCP serverHigh risk9.7KRepository stars
Foxx AIAgentgateway

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.