Best Open Source MCP Gateways in 2026
The best open source MCP gateways of 2026 compared: performance, governance, security, and enterprise readiness for AI teams scaling agentic workflows.
TL;DR
- Six open source MCP gateways worth evaluating in 2026: Bifrost, Docker MCP Gateway, IBM ContextForge, Microsoft MCP Gateway, Obot, and Agentgateway.
- License matters more than it looks. Five are Apache 2.0, one is MIT, and two of the six reserve identity-provider integration for a paid tier, so "open source" covers different amounts of the product in each case.
- Only two of the six combine LLM routing and MCP tool governance in one process. The rest govern tools and leave model traffic to a separate gateway.
- Bifrost is open source under Apache 2.0, adds 11 microseconds of overhead at 5,000 RPS, and is the only option here publishing a gateway overhead figure at all.
- Token cost is the axis most of these projects do not address. Code Mode cut input tokens 92.8% at 508 tools across 16 servers with pass rate held at 100%.
The Model Context Protocol (MCP) has crossed 97 million monthly downloads and achieved adoption across every major AI vendor. What started as a developer convenience has become production-critical infrastructure. When Cisco announced dedicated MCP security tooling at RSA Conference 2026, the signal was clear: the "this is a dev tool" phase is over.
For AI engineering teams, the question is no longer whether to use MCP, but how to govern it at scale. Without a gateway, every agent manages its own server connections and credentials, creating fragmented, unauditable, and insecure tool access. An open source MCP gateway centralizes authentication, enforces access control, logs every tool invocation, and provides a single policy enforcement point across your entire agent fleet.
This post compares the five best open source MCP gateways available in 2026, evaluated on performance, security model, governance depth, and production readiness.
What to Look for in an Open Source MCP Gateway
Six criteria separate a production-ready open source MCP gateway from a protocol bridge. The one that trips teams up most often is not on the usual feature list: it is how much of the product the open source license actually covers, because several projects here place identity-provider integration behind a paid tier.
Before comparing options, it helps to establish the criteria that actually matter for production AI teams:
- Access control depth: Can the gateway enforce permissions at the server level, the tool level, and the parameter level? Agent over-privilege is one of the most common governance failures in agentic deployments.
- Authentication: Support for OAuth 2.0/2.1, token refresh, and integration with enterprise identity providers (Okta, Entra ID).
- Audit trails: Immutable, queryable logs of every tool invocation for compliance with SOC 2, HIPAA, GDPR, and ISO 27001.
- Performance overhead: Latency added by the gateway in p99 conditions. For high-throughput agent workflows, this is non-trivial.
- Deployment flexibility: Docker, Kubernetes, binary deployment. Whether you can run it in-VPC without external dependencies.
- LLM routing integration: Whether the gateway also handles model routing and failover, or whether you need a separate AI gateway alongside it.
- License scope: Which capabilities the open source license covers, and which are reserved for an enterprise edition. SSO, RBAC, and audit retention are the features most often held back.
- Token efficiency: Whether the project has any answer to tool-schema bloat. Past roughly 100 tools, schema injection dominates the prompt and degrades tool selection regardless of how well the gateway routes.
If the category itself is new, what an MCP gateway is and where it sits in a production agent stack covers the architecture, and how a gateway differs from an MCP proxy and an MCP server covers the boundary these six projects sit on.
1. Bifrost

Best for teams that need a combined LLM gateway and MCP gateway in a single deployment.
Bifrost is a high-performance, open-source AI gateway built in Go by Maxim AI. It is the only tool on this list that handles both LLM routing and MCP tool orchestration from a single binary, eliminating the need to maintain two separate infrastructure components.
Bifrost acts as both an MCP client and an MCP server: it connects to external tool servers over STDIO, HTTP, or SSE, aggregates their tools, and exposes them to external clients like Claude Desktop, Cursor, and Claude Code through a single /mcp endpoint. At the same time, it routes model requests across 20+ LLM providers with automatic failover and load balancing.
Key MCP capabilities:
- Agent Mode: Autonomous tool execution with configurable auto-approval, available from
v1.4.0-prerelease1. By default Bifrost does not auto-execute tool calls at all: a model returns a suggestion and execution requires an explicit call, which keeps a human or an application in the loop for sensitive operations. - Code Mode: Rather than injecting every tool schema into context, the model writes code against a virtual filesystem of tool stubs and Bifrost executes it in a sandboxed Starlark interpreter. Benchmarked at 508 tools across 16 servers, input tokens fell 92.8% and execution ran roughly 40% faster, with pass rate held at 100%. Code execution with MCP covers the mechanism.
- Six authentication types: Shared headers, OAuth 2.0 with PKCE and Dynamic Client Registration, per-user headers, per-user OAuth, and token exchange, so user-scoped tools can be governed individually rather than behind one shared credential.
- Tool filtering per virtual key: Control exactly which MCP tools each team, consumer, or workflow can access, enforced at the gateway level.
- Federated auth for enterprise APIs: Transform existing internal APIs into MCP tools without writing new server code, using Bifrost's federated authentication layer.
- Tool hosting: Register and expose custom tools without deploying a separate MCP server process. This is currently available when using Bifrost as a Go SDK rather than in the gateway deployment.
On the governance side, Bifrost uses virtual keys as the primary access control entity: each key carries its own budget, rate limits, and permitted tool set. Audit logs provide immutable trails for compliance. Enterprise deployments support HashiCorp Vault, AWS Secrets Manager, Google Secret Manager, and Azure Key Vault for credential management.
Performance benchmarks show Bifrost adds 11 microseconds of overhead per request at 5,000 requests per second sustained, making it the lowest-latency option in this comparison.
License: Apache 2.0 | Language: Go | Deployment: Binary, Docker, Kubernetes
2. Docker MCP Gateway

Docker's open-source MCP Gateway runs each MCP server in its own isolated Docker container with cryptographically signed images, restricted network access, and built-in secrets injection. It manages the full server lifecycle: when an AI application requests a tool, the gateway starts the appropriate container if it is not already running, injects credentials, and proxies the request.
Docker's approach offers strong isolation guarantees. Each server runs in a separate container with restricted privileges, which limits blast radius if a tool server is compromised. The gateway integrates natively with Docker Desktop's MCP Toolkit, giving developers a low-friction path to getting started locally.
The primary constraint is that Docker MCP Gateway is designed primarily for developer-local and container-native environments rather than multi-tenant enterprise governance. Cross-team access control and organizational policy enforcement require additional tooling on top. It also does not handle LLM routing, so teams running both LLM traffic and MCP tool traffic need a separate AI gateway.
License: Apache 2.0 | Language: Go | Deployment: Docker Desktop, Docker Engine binary
3. IBM ContextForge (MCP Context Forge)
IBM's ContextForge is an open-source registry and proxy that federates MCP servers, A2A agents, and REST/gRPC APIs behind a single endpoint. It provides centralized governance, dynamic tool discovery, and OpenTelemetry-based observability for heterogeneous AI infrastructure.
ContextForge's distinguishing feature is protocol translation: it can convert REST and gRPC services into MCP-compatible tool definitions, allowing teams to expose existing internal APIs to AI agents without rewriting them as MCP servers. It supports 40+ plugins for additional transports and integrations.
Key capabilities include an Admin UI for real-time configuration and log monitoring, Redis-backed caching for multi-cluster federation, built-in retries and rate limiting, and OpenTelemetry integration with Phoenix, Jaeger, and Zipkin. It deploys via PyPI or Docker and scales to Kubernetes multi-cluster environments.
ContextForge is built in Python rather than Go, which produces higher per-request overhead than Bifrost. It is also a newer project than some others on this list, and enterprise governance features (RBAC, SSO integration, audit trails) are still maturing compared to more established options.
License: Apache 2.0 | Language: Python | Deployment: PyPI, Docker, Kubernetes
4. Microsoft MCP Gateway
Microsoft's open-source MCP Gateway is a reverse proxy and management layer for MCP servers designed specifically for Kubernetes environments. It provides session-aware stateful routing (ensuring all requests with a given session ID consistently reach the same MCP server instance), lifecycle management via a control plane, and Azure Entra ID (AAD) integration for authentication.
The gateway introduces the concept of Adapters as logical representations of MCP servers managed under a single /adapters scope. A Tool Gateway Router, itself an MCP server, acts as an intelligent router directing tool execution requests to the appropriate registered tool servers based on tool definitions.
Microsoft's gateway is a strong fit for organizations already running Azure infrastructure and Kubernetes-native workloads, where Entra ID authentication and RBAC are the standard access control model. It is not a general-purpose MCP gateway for teams outside the Azure ecosystem, and it does not provide LLM routing capabilities.
License: MIT | Language: Go | Deployment: Kubernetes
5. Obot MCP Gateway

Obot is an open-source MCP gateway and AI platform focused on organizational MCP server management. It provides a searchable catalog of available MCP servers with IT-verified trust levels, role-based access control, audit logging, and Kubernetes deployment. Users generate per-agent URLs to connect MCP servers to their preferred clients, including VS Code, Claude Desktop, and GitHub Copilot.
Obot's differentiator is its catalog approach: rather than requiring teams to configure individual server connections, it provides a managed directory that IT can curate and approve. This reduces the operational burden of onboarding new MCP servers and gives IT visibility into what agents are connecting to.
The open-source edition includes the core gateway, RBAC, and audit logging. Features like Okta and Entra ID integration are part of Obot Enterprise Edition.
License: Apache 2.0 | Language: Go | Deployment: Kubernetes, Docker
6. Agentgateway

Agentgateway is an open source proxy built on AI-native protocols, handling agent-to-LLM, agent-to-tool, and agent-to-agent traffic in a single data plane. The project has joined the Agentic AI Foundation, the same Linux Foundation body that now governs MCP itself.
Its MCP gateway connects models to tools with tool federation, stdio, HTTP, SSE and Streamable HTTP transports, OpenAPI integration, and OAuth authentication. Alongside that it routes traffic to major LLM providers through a unified OpenAI-compatible API with budget and spend controls, load balancing, and failover, and it carries an A2A gateway for agent-to-agent communication. It installs as a standalone binary or runs in Kubernetes.
Agentgateway is the closest architectural parallel to Bifrost on this list: both combine LLM routing and MCP governance rather than treating them as separate infrastructure. The differences are in emphasis. Agentgateway extends furthest on protocol coverage, carrying A2A alongside MCP and traditional HTTP and gRPC service traffic. Agentgateway does not publish a gateway overhead figure, and it does not offer a token-reduction execution model, so context bloat at high tool counts remains a separate problem to solve. The shape of that problem is covered in how MCP tools are discovered, invoked, and access-controlled.
License: Apache 2.0 | Language: Rust | Deployment: Binary, Kubernetes
How the Six Compare
Two of the six combine LLM routing with MCP governance; the other four govern tools only. Only one publishes a measured gateway overhead figure, which is worth reading as a gap in the public record rather than evidence the others are slow. The Bifrost methodology and raw numbers are in the performance benchmarks.
| Capability | Bifrost | Docker | IBM ContextForge | Microsoft | Obot | Agentgateway |
|---|---|---|---|---|---|---|
| License | Apache 2.0 | Apache 2.0 | Apache 2.0 | MIT | Apache 2.0 | Apache 2.0 |
| Language | Go | Go | Python | Go | Go | Rust |
| MCP client + server | Yes | Client only | Client only | Client only | Client only | Yes |
| LLM routing | Yes | No | No | No | No | Yes |
| A2A support | Coming Soon | No | Yes | No | No | Yes |
| Token-reduction model | Code Mode | No | No | No | No | No |
| OAuth 2.0 | Yes | No | Yes (partial) | Yes (Entra) | Enterprise only | Yes |
| Per-user auth | Yes | No | No | Via Entra | Enterprise only | Not published |
| Tool-level RBAC | Yes | No | Partial | Yes | Yes | Yes |
| Container isolation per server | No | Yes | No | No | No | No | OpenAPI |
| Published gateway overhead | 11 µs at 5,000 RPS | Not published | Not published | Not published | Not published | Not published |
What "Open Source" Actually Covers
| Capability | In the open source build | Commonly behind a paid tier |
|---|---|---|
| MCP aggregation and single endpoint | All six | None |
| Tool-level authorization | Bifrost, Microsoft, Obot, Agentgateway | Partial in IBM ContextForge |
| Identity-provider integration (Okta, Entra) | Microsoft (Entra), Agentgateway | Obot Enterprise Edition |
| Clustering and high availability | Docker, Microsoft, IBM, Agentgateway | Bifrost enterprise tier |
| Signed audit logs with archival | Microsoft, IBM, Obot | Bifrost enterprise tier |
| Secret manager integration | Docker (Desktop) | Bifrost enterprise tier |
The practical test is to list the three capabilities your deployment cannot ship without, then check each against the open source build specifically rather than the marketing page. The Bifrost governance stack documents which primitives sit on each side of that line. For most teams that list is per-tool authorization, per-user authentication, and exportable logs, and it is the second of those that most often turns out to sit behind a licence.
Choosing the Right Open Source MCP Gateway
The right choice follows from which problem is currently blocking you rather than from a feature count. If model traffic and tool traffic both need governing, the field narrows to Bifrost and Agentgateway. If isolating untrusted community servers is the concern, Docker's container-per-server model is the strongest answer here. If existing REST and gRPC services need exposing as MCP tools, IBM ContextForge does protocol translation the others do not. If the estate is Azure and Kubernetes, Microsoft MCP Gateway inherits the identity model already in place. If the bottleneck is server discovery and IT approval, Obot's curated catalog addresses that directly.
For teams building production AI agents that need both LLM routing and MCP tool orchestration at scale, Bifrost offers the most complete architecture: a single open source AI gateway that handles model traffic, tool orchestration, governance, and observability without additional infrastructure components. Teams weighing it against commercial options can also review the best MCP gateways for production AI systems, and the governance model is covered in what MCP governance requires in practice.
To see how an open source MCP gateway fits your existing agent infrastructure, book a demo with the Bifrost team.
Frequently Asked Questions
Which open source MCP gateway has the lowest latency?
Bifrost is the only project in this comparison publishing a measured figure: 11 microseconds of overhead per request at 5,000 RPS sustained. The others may perform comparably, but they do not publish overhead numbers, so a like-for-like ranking cannot be built from public sources.
Can an open source MCP gateway handle LLM routing too?
Two of the six can. Bifrost and Agentgateway both combine model routing and MCP tool governance in one process. Docker MCP Gateway, IBM ContextForge, Microsoft MCP Gateway, and Obot govern tools only, so teams running both need a second gateway alongside.
Do open source MCP gateways solve token cost?
Mostly not. Five of the six here govern tool access without addressing tool-schema injection, which is the larger cost driver past roughly 100 tools. Code Mode is the exception in this comparison, cutting input tokens 92.8% at 508 tools across 16 servers.
How do I self-host an open source MCP gateway?
All six deploy as a container or a binary, and four support Kubernetes directly. Bifrost starts with a single command and no configuration file, then connects upstream MCP servers through the dashboard or config. Point one agent at the gateway first, confirm its tool catalog and logs, then migrate remaining clients. Adding and governing MCP servers in Claude Code walks through that first connection.