MCP Gateway Comparison 2026: Bifrost, Docker, Microsoft, Kong, Cloudflare
An MCP gateway comparison of Bifrost, Docker, Microsoft, Kong, and Cloudflare on deployment, transports, OAuth, tool filtering, and governance.
TL;DR
- This MCP gateway comparison scores five products on eight criteria: deployment, transports, auth, tool filtering, governance, observability, LLM routing, and license.
- Docker's MCP gateway (MIT license) runs each MCP server in an isolated container and is built around Docker Desktop and the Docker CLI.
- Microsoft MCP Gateway (MIT license) is a Kubernetes-native reverse proxy with Entra ID app roles and requires MCP
2026-07-28clients. - Kong and Cloudflare attach MCP to commercial platforms: Kong's AI MCP Proxy needs an enterprise license, and Cloudflare portals accept remote HTTP servers only.
- Bifrost (Apache 2.0) governs LLM traffic and MCP tool traffic in one gateway process, with the same virtual keys carrying budgets, rate limits, and tool allow-lists.
An MCP gateway comparison between Docker, Microsoft, Kong, and Cloudflare usually comes down to where tool servers run and how much policy has to sit in front of them. Bifrost, the open-source AI gateway built in Go by Maxim AI, is the best choice for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability, because it governs model calls and tool calls in one MCP gateway and LLM gateway plane. This post compares all five head to head, criterion by criterion, using only capabilities each vendor documents publicly.
What an MCP Gateway Does, and the Criteria Used Here
An MCP gateway is a control layer between MCP clients and MCP servers that authenticates callers, decides which tools each caller can see, and logs tool calls. All five products here fill that position. They differ in deployment model, supported transports, identity handling, and how much governance they apply before a call reaches a tool.
The Model Context Protocol specification defines how clients discover and invoke tools, but it leaves fleet-level concerns (who may call which tool, under whose credential, at what cost) to the infrastructure in between. A broader primer on what an MCP gateway is and why production agents need one covers the category; this post focuses on the five named products.

Figure 1: Every gateway in this comparison occupies the same position; they differ in where they run and how much policy they apply on the way through.
| Criterion | What it answers |
|---|---|
| Deployment model | Where the gateway runs and who operates it |
| Transports | Which MCP transports it accepts and speaks to servers |
| Authentication | How clients prove identity, and which identity reaches the tool |
| Tool filtering | How tools are narrowed per user, team, or endpoint |
| Governance | Budgets, rate limits, role-based access, audit trails |
| Observability | What gets logged and where it can be exported |
| LLM gateway in the same plane | Whether model traffic shares the same policy objects |
| Open-source license | Whether the MCP features themselves are open source |
Transports deserve attention because the MCP transports and message lifecycle differ between STDIO, SSE, and Streamable HTTP.
MCP Gateway Comparison at a Glance
Bifrost covers all eight criteria in one self-hosted, Apache 2.0 gateway. Docker and Microsoft are open source but MCP-scoped. Kong and Cloudflare attach MCP to an existing commercial platform. "Not published" means the vendor's public documentation did not describe the capability when this post was researched.
| Criterion | Bifrost | Docker | Microsoft MCP Gateway | Kong AI MCP Proxy | Cloudflare MCP portals |
|---|---|---|---|---|---|
| Deployment | Self-hosted (NPX, Docker, Kubernetes), in-VPC | Docker Desktop, CLI plugin, or Compose | Kubernetes (local or AKS) | Plugin on Kong AI Gateway 3.12+ | Managed, in Cloudflare Zero Trust |
| Upstream transports | STDIO, HTTP, SSE | Servers as containers | Streamable HTTP | Streamable HTTP | Streamable HTTP or SSE, remote only |
| Client auth | Virtual key headers or OAuth 2.1 | Bearer token on TCP transports | Entra ID tokens | Kong auth plugins, MCP OAuth2 | Cloudflare Access |
| Per-user upstream auth | Per-user OAuth or headers, token exchange | Not published | Not published | Not published | Per-user OAuth |
| Tool curation | Virtual key filters, Virtual MCPs | Profile tool allowlists | Per-resource roles | Per-tool ACLs | Per-portal tool selection |
| Budgets | Virtual key, team, customer | Not published | Not published | Not published | Not published |
| LLM gateway in same plane | Yes, same virtual keys | Not published | No (agent preview only) | Separate AI plugins | Separate AI Gateway product |
| License | Apache 2.0 | MIT | MIT | MCP plugins enterprise-only | Proprietary managed service |
For the model side of the same decision, see this production-ready LLM gateway comparison.
Bifrost: MCP Gateway and LLM Gateway in One Plane
Bifrost is an AI gateway that acts as an MCP client to upstream servers and as an MCP server to clients such as Claude Desktop and Cursor, while routing LLM requests across 25+ providers. The same virtual key that carries a model budget also carries a tool allow-list, so model spend and tool access are governed together.
Best for: Bifrost is built for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability. It serves as a centralized AI gateway to route, govern, and secure all AI traffic across models and environments with ultra low latency. Bifrost unifies LLM gateway, MCP gateway, and Agents gateway capabilities into a single platform. Designed for regulated industries and strict enterprise requirements, it supports air-gapped deployments, VPC isolation, and on-prem infrastructure. It provides full control over data, access, and execution, along with robust security, policy enforcement, and governance capabilities.

Figure 2: One virtual key carries the budget, rate limit, and tool allow-list, so model spend and tool access are governed by the same identity.
As Figure 2 shows, the Bifrost AI gateway runs both planes in one process. Its MCP capabilities:
- Gateway mode: Bifrost as an MCP gateway aggregates tools behind one
/mcpendpoint from upstream servers connected over STDIO, HTTP, or SSE. - Virtual MCPs: Virtual MCPs bundle chosen tools from several servers behind a stable
/mcp/<slug>endpoint, reachable only through attached virtual keys. The feature is part of open-source Bifrost. - Three-level filtering: tool filtering stacks client configuration, request headers, and virtual key rules.
- Code Mode: Code Mode replaces large tool catalogs with four meta-tools and runs model-written Python (Starlark) in a sandbox.
- Agent Mode: auto-executes only the tools listed in
tools_to_auto_execute; by default, Bifrost executes no tool call without an explicit API call.
Regulated teams can run Bifrost with in-VPC deployments and clustering through Bifrost Enterprise.
On the model side, Bifrost exposes 10,000+ models from 25+ supported providers through one OpenAI-compatible API and adds 11 microseconds of overhead per request at 5,000 RPS in published benchmarks.
The Bifrost MCP gateway benchmark writeup details the access-control and token-cost results.
Docker: Container-Isolated MCP Servers
The Docker MCP Gateway is Docker's MIT-licensed gateway for MCP servers. It runs each server from the Docker MCP Catalog in an isolated container with restricted privileges, network access, and resources, starts containers on demand, injects credentials, and forwards tool calls from any connected client.
Documented strengths:
- Container isolation: per-server CPU and memory limits (1 CPU and 2 GB by default), image signature verification on by default, and flags that block secrets and network access.
- Profiles: servers are grouped into profiles that can be shared through OCI registries and connected to clients such as Claude Code, VS Code, or Cursor.
- Tool allowlists: tools can be enabled or disabled per server in a profile, or selected at startup with
-serversand-tools. - Secrets and logging: secrets come from Docker Desktop or a
.envfile, OAuth flows are built in, and tool calls are logged by default.
Docker's gateway listens on stdio by default and serves multiple clients only with the sse or streaming transport. Docker states that the MCP Gateway as part of Docker AI Governance is an invite-only feature, and budgets, role-based access, and LLM routing were not published. Teams that need shared infrastructure rather than a desktop component often compare open-source LLM gateways for self-hosted deployments that cover MCP as well.
Best for: Developers and small teams who want MCP servers sandboxed as containers on Docker Desktop or a Docker Engine host.
Microsoft MCP Gateway
Microsoft MCP Gateway is an MIT-licensed reverse proxy and management layer for MCP servers on Kubernetes. A control plane deploys MCP servers ("adapters") and registered tools, and a stateless data plane routes each request to a ready server instance, authorized with Entra ID bearer tokens in cloud mode.
Documented features:
- Kubernetes-native deployment: StatefulSets and headless services, plus a one-click Azure deployment that provisions AKS, Cosmos DB, and Application Insights.
- Stateless routing: each request is authorized independently, with no transport-session affinity.
- Entra ID roles: read access goes to the creator, principals with configured
requiredRoles, andmcp.admin; write access goes to the creator ormcp.admin. - Management portal: a built-in web UI for adapters, tools, pod logs, and JSON-RPC testing.
The current version requires MCP 2026-07-28 clients and adapters and offers no protocol downgrade, which can rule out older clients. Per-user upstream credentials and budgets were not published. Its opt-in Agents and Sessions preview calls an Azure AI Foundry deployment; it is an agent runtime, not a multi-provider LLM gateway. Bifrost reaches a comparable access model through role-based access control without tying deployment to one cloud.
Best for: Platform teams standardized on Kubernetes and Entra ID who want to deploy and route MCP servers as cluster workloads.
Kong MCP Gateway
Kong supports MCP through the AI MCP Proxy plugin on Kong AI Gateway 3.12 and later, available only with an AI Gateway Enterprise license. The plugin bridges MCP and HTTP: it proxies existing MCP servers, converts OpenAPI-described REST APIs into MCP tools, or aggregates tagged tools into one MCP endpoint.
Documented capabilities:
- Tool ACLs: default and per-tool allow and deny lists matched against Consumers and Consumer Groups, with optional audit logging of access attempts.
- Inbound OAuth: the AI MCP OAuth2 plugin (tech preview) validates access tokens as a resource server and forwards selected claims upstream as headers, not the token itself.
- Plugin ecosystem: authentication, rate limiting, logging, and tracing plugins apply to MCP routes.
Kong lists WebSocket and gRPC upstreams, session sharing between instances, and AI guardrails on MCP traffic as not supported. The AI MCP Proxy runs outside the LLM request flow, and Kong advises against configuring it with other AI plugins on the same Service or Route, so model and tool policy live in separate configurations. A wider look at Kong AI Gateway alternatives covers the LLM side of that trade-off.
Best for: Organizations already running Kong Gateway that want to expose existing REST APIs as MCP tools under current plugin policies.
Cloudflare MCP Gateway: MCP Server Portals
Cloudflare's MCP gateway is MCP server portals, a managed feature of Cloudflare Zero Trust (previously called Agents Gateway in some contexts). A portal puts many remote MCP servers behind one /mcp endpoint on a Cloudflare domain, enforces Access policies through an identity provider, and logs tool requests.
Documented capabilities:
- Curation: admins choose which tools and prompts each portal exposes, can hide capabilities by default, and can rename tools with aliases.
- Per-user upstream auth: with "Require user auth" enabled, each user signs in to upstream OAuth servers with their own credentials.
- Code Mode: Cloudflare Code Mode collapses upstream tools into two tools for search and code execution, running agent-written JavaScript in an isolated Dynamic Worker.
- Logging and DLP: portal logs record tool activity, and optional Cloudflare Gateway routing adds DLP scanning.
Cloudflare MCP portals support only remote HTTP MCP servers, so STDIO-only servers must be self-hosted behind an HTTP endpoint first. Each portal supports up to 80 MCP servers, and some Access policy features, such as independent MFA, are not enforced through a portal. Model traffic runs through Cloudflare AI Gateway, a separate product. Teams weighing that half can review Cloudflare AI Gateway alternatives.
Best for: Organizations already on Cloudflare Zero Trust that want a managed, policy-gated portal for remote MCP servers.
MCP Authentication Compared: OAuth, Per-User Credentials, and Token Exchange
MCP authentication runs in two directions. Inbound authentication decides who the caller is; outbound authentication decides whose credential reaches the upstream tool. Inbound coverage is broad across the five. The larger differences are outbound: shared credentials, per-user OAuth, or exchanging the caller's identity token on every call.

Figure 3: Inbound auth decides who is calling; outbound auth decides whose identity reaches the tool, and the gateways compared here differ most on the outbound side.
| MCP auth capability | Bifrost | Docker | Microsoft | Kong | Cloudflare |
|---|---|---|---|---|---|
| Inbound OAuth for clients | Built-in OAuth 2.1 server | Not published | Entra ID | Token validation (preview) | Access managed OAuth |
| Per-user upstream OAuth | Yes, plus per-user headers | Not published | Not published | Not published | Yes |
| Token exchange | Yes (enterprise) | Not published | Not published | Not published | Not published |
On the inbound side, Bifrost gateway authentication accepts virtual key headers, Bifrost-issued JWTs, or both, and implements protected resource metadata (RFC 9728), Dynamic Client Registration, and PKCE so standard clients connect without custom code. Outbound, the MCP authentication options cover none, headers, OAuth 2.0, per-user OAuth, per-user headers, and token exchange.
Per-user OAuth authenticates each end user on the first tool call and stores the credential against a virtual key, signed-in user, or session ID. Token exchange suits internal servers: Bifrost exchanges the caller's identity-provider token through RFC 8693 for a short-lived, server-scoped token and stores nothing per user. These choices are covered in depth in this guide to OAuth 2.1 patterns for MCP authentication.
Tool Filtering, Governance, and Observability Compared
Filtering limits what an agent can see, governance limits what it can spend, and observability proves what happened. Bifrost applies all three through virtual keys shared with LLM traffic. The other four cover filtering and logging in different forms, while budgets for tool traffic were not published for any of them.
| Capability | Bifrost | Docker | Microsoft | Kong | Cloudflare |
|---|---|---|---|---|---|
| Rate limits | Virtual key level | Not published | Not published | Rate limiting plugins | Not published |
| RBAC and audit | RBAC, signed audit logs (enterprise) | Not published | Entra app roles | ACL audit logs | Not published |
| Tool call logs | MCP logs beside LLM logs | Call logging and tracing | Adapter logs, Application Insights | MCP logs and metrics | Portal and Gateway logs |
| Content controls | Prompt guardrails on MCP (enterprise) | Secret and network blocking | Not published | Not supported for MCP | DLP via Gateway |
In Bifrost, MCP tool filtering per virtual key is deny-by-default and enforced at listing and again at execution, and request headers can only narrow a key's grant. The same keys carry budgets and rate limits at the virtual key, team, and customer levels, while enterprise audit logs record administrative changes.
Bifrost records MCP logs alongside LLM logs in its built-in observability, with OpenTelemetry and Prometheus export. This walkthrough of auditing every AI tool call at the gateway shows how those logs are used, and the Bifrost governance overview explains how virtual keys tie the controls together.
Code Mode and context size
Only Bifrost and Cloudflare document a code execution mode among these five. Bifrost Code Mode exposes four meta-tools and runs model-written Python in a Starlark sandbox; with 508 tools across 16 servers, it cut input tokens by 92.8% and estimated cost by 92.2% at a 100% pass rate. Cloudflare Code Mode exposes two tools and runs JavaScript. The mechanics are explained in this post on cutting MCP token costs with Code Mode, and the MCP gateway resource page summarizes the cost results.
Which MCP Gateway Fits Your Team
The right MCP gateway depends on the first constraint a team hits. If model spend and tool access need one policy, Bifrost governs both through the same virtual keys in one self-hosted gateway. Desktop sandboxing points to Docker, an existing Kong estate to Kong, Kubernetes with Entra ID to Microsoft, and Cloudflare Zero Trust users to MCP portals.

Figure 4: The first question decides the most: if model spend and tool access need one policy, only a combined LLM and MCP gateway answers it.
Three patterns recur when teams work through Figure 4:
- Tool access without spend control: every product here can restrict tools, but Bifrost attaches that restriction to the same virtual key that enforces a model budget. Budgets for tool traffic were not published for the other four.
- Identity lock-in: Microsoft relies on Entra ID, Cloudflare on Cloudflare Access, and Kong on its Consumer model. Bifrost accepts virtual keys, OAuth 2.1, or enterprise SSO identities on the same
/mcpendpoint. - Transport gaps: Kong and Cloudflare expect remote HTTP servers, Microsoft deploys Streamable HTTP workloads in Kubernetes, and Docker runs local containers. Bifrost connects to STDIO, HTTP, and SSE servers from one gateway.
Before a proof of concept, the cluster guide on how an MCP gateway centralizes tool access for agents covers the core architecture.
Frequently Asked Questions
What is an MCP gateway?
An MCP gateway is a control layer between MCP clients and MCP servers. It authenticates callers, aggregates tools from many servers behind one endpoint, filters which tools each caller can see, and logs tool calls. Docker's gateway, Microsoft MCP Gateway, Kong AI MCP Proxy, Cloudflare MCP server portals, and Bifrost all fill this role with different deployment models and governance depth.
What is MCP gateway vs MCP server?
An MCP server exposes tools, resources, and prompts for one system, such as a database or ticketing tool. An MCP gateway sits in front of many MCP servers and gives clients one endpoint with shared authentication, tool filtering, and logging. Bifrost acts as both: an MCP client to upstream servers and an MCP server to external clients such as Claude Desktop and Cursor.
Do we need an MCP gateway?
A team needs an MCP gateway once more than a few agents or users connect to more than a few MCP servers. Without one, each client stores its own credentials and there is no central record of tool calls. A gateway such as Bifrost adds per-identity tool allow-lists, per-user credentials, budgets, and audit logs in one place.
What is the difference between a proxy and an MCP gateway?
A proxy forwards MCP traffic and may add authentication or logging. An MCP gateway also aggregates tools from many servers, curates which tools each identity can see, manages upstream credentials, and applies governance such as budgets and audit trails. This comparison of an MCP proxy and an MCP gateway covers where the line sits.
Is Docker MCP Gateway open source?
Yes. Docker's MCP gateway is released under the MIT license and runs as a Docker CLI plugin, inside Docker Desktop with MCP Toolkit enabled, or as a container with Docker Compose. Docker states that the MCP Gateway as part of Docker AI Governance is an invite-only feature. Microsoft MCP Gateway is also MIT-licensed, and Bifrost is licensed under Apache 2.0.
Is the Kong MCP gateway free?
No. Kong Gateway itself is open source under Apache 2.0, but the AI MCP Proxy and AI MCP OAuth2 plugins are available only with Kong's AI Gateway Enterprise offering, on Kong Gateway 3.12 or later. Bifrost includes MCP gateway mode, Virtual MCPs, and virtual key tool filtering in its open-source release.
Try Bifrost as Your MCP Gateway
This MCP gateway comparison shows Docker, Microsoft, Kong, and Cloudflare each solving part of the MCP problem inside their own platform. Bifrost covers all eight criteria in one self-hosted gateway, governing tool calls and model calls with the same virtual keys, budgets, and logs. Explore the Bifrost resources or book a Bifrost demo to see Bifrost as an MCP gateway with your own servers and identity provider.