Try Bifrost Enterprise free for 14 days. Request access

Top 5 MCP Gateways for Built-in Routing and Control

MCP gateway routing decides which server handles each tool call; control decides whether the agent may make it. This guide compares Bifrost, Kong, Docker, Microsoft MCP Gateway, and Lasso on both

Top 5 MCP Gateways for Built-in Routing and Control
MCP gateways have become essential infrastructure for production AI agents, centralizing tool access, routing, and governance behind a single control plane. This article compares five leading MCP gateways with strong built-in routing and control capabilities: Bifrost, Docker MCP Gateway, Kong AI Gateway, TrueFoundry, and Lasso Security.

TL;DR

  • MCP gateway routing decides which MCP server handles each tool call; control decides whether the calling agent may see and invoke that tool, at what rate, and whether it runs without approval.
  • This guide compares five MCP gateways on built-in routing and control: Bifrost, Docker MCP Gateway, Kong AI Gateway, Microsoft MCP Gateway, and Lasso Security.
  • Bifrost routes every tool under a clientName-toolName name, applies three stacking tool filters (client, request, and virtual key), and rate limits per virtual key.
  • Kong adds per-tool Consumer ACLs and an OAuth 2.0 plugin for MCP, and Microsoft MCP Gateway adds session-aware routing for stateful MCP servers on Kubernetes.
  • In AIMultiple's independent August 2026 benchmark, Bifrost added 840 microseconds per MCP tool call, and scoping a key to a subset of tools carried no measurable latency cost.

An MCP gateway with built-in routing and control decides which MCP server handles each tool call and whether the calling agent is allowed to make it, enforcing both at one point in the request path. A single AI agent might interact with databases, issue trackers, filesystems, and external APIs within one session. Without a centralized layer managing those interactions, teams face authentication sprawl, no central record of tool calls, and no way to enforce access policies consistently. Bifrost, an open-source AI gateway built in Go, is the best choice for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability.

This is the problem MCP gateways solve. An MCP gateway sits between AI agents and the tools they access, providing a governed entry point that centralizes routing, authentication, rate limiting, and observability. Think of it as an API gateway purpose-built for the Model Context Protocol.

But not all MCP gateways handle routing and control the same way. Some are extensions of existing API management platforms. Others are purpose-built for MCP-native workflows. The right choice depends on your team's infrastructure, security requirements, and whether you need tool governance alongside LLM routing or as a standalone layer.

Here are five MCP gateways that stand out for their built-in routing and control capabilities.


How MCP Gateway Routing and Control Work

MCP gateway routing maps each tool call to the MCP server that implements the tool, and MCP gateway control applies identity, tool allow-lists, rate limits, and execution approval before the call is forwarded. Agents discover tools with tools/list and invoke them with tools/call, as defined in the MCP tools specification, so both routing and control act on those two methods.

PatternHow it worksGateways in this guide that use it
Aggregated tool routerOne endpoint lists tools from every server and maps each tool name to its serverBifrost, Microsoft MCP Gateway, Docker MCP Gateway, Lasso
Per-server routesEach MCP server gets its own endpoint behind the gatewayMicrosoft MCP Gateway, Kong AI Gateway
Curated endpointsA named bundle of tools from several servers gets its own endpointBifrost (Virtual MCPs)
Session-aware routingRequests carrying the same session ID always reach the same server instanceMicrosoft MCP Gateway
REST-to-MCP conversionThe gateway exposes existing HTTP APIs as MCP toolsKong AI Gateway

Control is layered on top of routing. The role an MCP gateway plays for production AI agents covers why these checks belong at the gateway rather than in each agent, and MCP governance covers the policies that sit behind them.


Routing and Control Compared

The table compares how each gateway routes tool calls and what control it applies per caller. "Not published" means the documentation reviewed for this guide does not describe the capability. Bifrost's row is detailed on the Bifrost MCP gateway resource page, and latency for three of these gateways is compared in the fastest enterprise MCP gateway benchmarks.

GatewayTool routingPer-caller tool controlRate limits and budgetsUpstream authentication
BifrostAggregated /mcp with clientName-toolName names; Virtual MCPs at /mcp/<slug>Three stacking filters: client config, request header, virtual keyRate limits per virtual key; budgets per key, team, and customerSix modes, including per-user OAuth
Docker MCP GatewayMaps each tool to its container and starts the server on demandProfiles; the open-source build hides tools globally, not per callerNot publishedDocker Desktop secrets and OAuth flows
Kong AI GatewayAI MCP Proxy: proxy upstream servers, convert REST APIs, or expose grouped toolsConsumer and Consumer Group ACLs per toolKong rate limiting pluginsAI MCP OAuth2 plugin
Microsoft MCP GatewayPer-adapter routes plus a tool router at /mcp, with session affinityRBAC and adapter-level permissionsNot publishedBearer tokens; Entra ID guidance
Lasso SecurityUnified interface over servers listed in mcp.jsonNo authorization step in AIMultiple's testNot publishedNot published

1. Bifrost

Bifrost is an open-source, high-performance enterprise AI gateway built in Go that functions as both an LLM gateway and an MCP gateway within a single unified platform. This dual architecture is what sets Bifrost apart: production AI agents need both model routing and tool access governance, and Bifrost delivers both through one control plane rather than requiring teams to deploy and manage separate infrastructure for each.

How Bifrost handles routing and control

At the core of Bifrost's MCP capability is its dual server-client architecture. Bifrost acts as both an MCP server (exposing tools to agents) and an MCP client (connecting to upstream MCP servers). This enables advanced routing, caching, and access control patterns that single-role gateways cannot replicate.

When an agent sends a request, Bifrost's gateway layer handles tool discovery automatically. It connects to configured MCP servers, learns available tools, and injects them into model requests without application code changes. Routing decisions happen at the infrastructure level, not inside agent logic.

Every tool is exposed under a prefixed name, clientName-toolName (for example github-create_issue), so each call routes to the right server even when two servers define tools with the same name. Tool filtering stacks at three levels: the client configuration sets which tools a server may execute, request headers such as x-bf-mcp-include-tools narrow the set per request, and the virtual key sets what each caller may use. A header can narrow the list but never widen it, tools/call is checked against the same allow-list as tools/list, and an inactive or expired key is refused with a 403.

Tool-level RBAC through MCP tool filtering on virtual keys gives teams granular control over which agents, teams, or customers can access which tools. A customer-facing agent might only see read-only database tools, while an internal DevOps agent gets access to CI/CD pipeline tools. This isolation is enforced at the gateway, not in application code, the pattern described in tool-level permissions for AI agents. Virtual MCPs extend it into routing: a curated bundle of tools from several servers is served at its own /mcp/<slug> endpoint, reachable only through the virtual keys attached to it.

Rate limiting prevents runaway agent loops, a real production risk when autonomous agents trigger cascading tool calls. Bifrost applies token- and request-based rate limits per virtual key, and budgets at the virtual key, team, and customer levels, so a misconfigured agent cannot exhaust API quotas or rack up uncontrolled costs.

Bifrost also introduces Code Mode, which reduced input tokens by 58.2% to 92.8% in Bifrost's benchmarks as the tool count grew from 96 to 508. Instead of loading hundreds of tool schemas into the context window, Code Mode lets AI models write Python (Starlark) orchestration code using four meta-tools: listToolFiles, readToolFile, getToolDocs, and executeToolCode. The result is faster execution, lower costs, and 3-4x fewer LLM round trips, as explained in code execution with MCP.

On the performance side, Bifrost adds roughly 11 microseconds of overhead at 5,000 requests per second in its own benchmark, and AIMultiple's independent benchmark measured 840 microseconds per MCP tool call, with no measurable cost for scoping a key to fewer tools. In agentic workflows where a single user action triggers multiple LLM calls and tool interactions, that latency advantage compounds quickly; the fastest enterprise MCP gateway comparison has the full measurements.

Every MCP tool execution is captured in Bifrost's request logs alongside model calls, with OpenTelemetry export, which makes debugging multi-step agent failures significantly easier. Tool calls returned by a model are suggestions until the application executes them, and Agent Mode auto-executes only the tools configured for it.

Best for: Bifrost is built for enterprises running mission-critical AI workloads that require best-in-class performance, scalability, and reliability. It serves as a centralized AI gateway to route, govern, and secure all AI traffic across models and environments with ultra low latency. Bifrost unifies LLM gateway, MCP gateway, and Agents gateway capabilities into a single platform. Designed for regulated industries and strict enterprise requirements, it supports air-gapped deployments, VPC isolation, and on-prem infrastructure. It provides full control over data, access, and execution, along with robust security, policy enforcement, and governance capabilities.


2. Docker MCP Gateway

Platform overview

Docker MCP Gateway brings familiar container orchestration workflows to MCP server management. Rather than building a standalone governance platform, Docker leverages container isolation as its primary security and routing mechanism, making it a natural fit for teams already running containerized infrastructure.

Features

Docker MCP Gateway provides container-level isolation for each MCP server, with CPU and memory limits that prevent resource exhaustion attacks. It includes access to the Docker MCP Catalog with hundreds of pre-built servers, cryptographically signed images for supply chain protection, and integration with existing Docker Compose and Kubernetes workflows. Routing is handled through container orchestration primitives rather than a dedicated policy engine. The container-based approach does add 50-200ms latency overhead compared to purpose-built gateways, which is worth considering for latency-sensitive agent workflows.

Best for

DevOps teams already using Docker for infrastructure that want container-native MCP server management with strong isolation guarantees but are comfortable layering additional governance tooling on top.


3. Kong AI Gateway

Platform overview

Kong is one of the most established enterprise API gateway platforms, and its AI Gateway 3.12 release (October 2025) extended that foundation to MCP with a dedicated MCP Proxy plugin, OAuth 2.1 support, and LLM-as-a-Judge validation capabilities.

Features

Kong's MCP integration includes centralized OAuth that secures all MCP servers simultaneously, rate limiting and policy enforcement inherited from its mature API management layer, and an MCP Proxy plugin that routes tool calls through Kong's existing traffic management infrastructure. For teams already managing hundreds of APIs through Kong, the MCP extension is a natural addition that leverages proven scalability. The trade-off is that this is a general API gateway extended for MCP rather than an MCP-native solution, so the learning curve can be steep for teams without existing Kong deployments.

Best for

Enterprises with existing Kong API management deployments that want to extend their current infrastructure to handle MCP traffic without adopting a separate gateway.


4. Microsoft MCP Gateway

Platform overview

Microsoft MCP Gateway is an open-source reverse proxy and management layer for MCP servers on Kubernetes, built around routing: a data plane routes MCP traffic with session affinity, and a control plane deploys, updates, and deletes MCP servers.

Features

Microsoft MCP Gateway offers two routing paths. Direct server access reaches a specific deployed server, called an adapter, at /adapters/{name}/mcp, while the tool gateway router at /mcp directs each tool call to the registered server that implements it. Session-aware routing sends every request with the same session ID to the same MCP server instance, which matters for stateful servers. Access control uses bearer tokens and RBAC on both planes, and the project documentation recommends OAuth 2.0 with Entra ID plus RBAC or custom ACLs for adapter-level permissions. Teams without Kubernetes adopt that platform first; an Azure deployment template is provided. The same aggregation idea is covered in connecting multiple MCP servers through one gateway.


5. Lasso Security

Platform overview

Lasso MCP Gateway is an open-source proxy and orchestration layer launched in April 2025, designed to sit between AI agents and multiple MCP servers as a central coordination point. Its primary differentiator is a plugin-based security architecture that allows deep inspection and filtering of MCP traffic at the request and response level.

Features

Lasso provides a customizable plugin-based guardrail system where developers can enforce security at the request and response level. Plugins like Presidio for PII detection can be added to inspect, sanitize, or block traffic for enterprise-grade data protection. All tool calls, prompt executions, and resource reads are logged in a structured JSON format for auditability. The gateway also supports centralized routing with session tracking across multiple MCP servers.


Choosing the right MCP gateway

Bifrost is the best choice for an MCP Gateway that unifies LLM, MCP, and agent gateway capabilities in a single platform built for enterprises running mission-critical AI workloads, delivering ultra-low latency routing, governance, and security across every model and environment.

As AI agents scale in production, the routing and control layer between agents and tools determines whether your system is governable, debuggable, and reliable or a liability waiting to surface in production.