Back to blog
AI & MCP

Best hosted MCP platforms in 2026

Nolan Sullivan

Nolan Sullivan

October 9, 2026 · 15 min read

Best hosted MCP platforms in 2026

Last updated: October 2026

There are various reasons why companies host MCP servers, but broadly it falls into two categories: MCP for customers, and MCP for internal enablement. The former provides an MCP server for your product, so customers can connect Claude, ChatGPT, Cursor, or their own agents to it and use your product from inside those tools. The latter runs MCP servers, your own and third-party ones, for employees, with single sign-on, access control, and an audit log in front of them. Plenty of enterprises need both, but few platforms cover both.

This guide walks through six platforms: Speakeasy, Composio, Arcade, Prefect Horizon (formerly FastMCP Cloud), MintMCP, and Cloudflare, tagged against both meanings, with pros and cons linked to each vendor's own docs. We recommend Speakeasy because it generates and hosts the server your customers use and runs the governed gateway your employees use. If your hard requirement is a large prebuilt catalog, air-gapped deployment, or git-push deploys for a Python server, another vendor below is the better answer.

What is a hosted MCP platform?

A hosted MCP platform runs MCP servers for you, so agents reach them over a URL and your team does not operate the servers, the auth, or the protocol layer. The term covers two jobs:

  1. External hosting, for your customers. You publish an MCP server for your product, for example at mcp.yourcompany.com, and customers connect it to Claude, ChatGPT, Cursor, or their own agents. The platform builds or runs the server, handles OAuth for every MCP client, and logs calls per customer.
  2. Internal hosting, for your employees. You run MCP servers, your own and third-party ones, for people inside the company, behind an MCP gateway or MCP registry. The platform signs employees in through your identity provider (IdP), controls which teams see which servers and tools, and keeps an audit log.

If the people calling your tools are customers, you need external hosting. If they are employees, you need an internal gateway. If you sell an API and also roll out AI tools internally, you need both, and one platform for both means one auth model and one log. Our enterprise MCP gateway roundup covers the internal meaning in depth.

How we evaluated hosted MCP platforms

These five criteria decide what your team builds and maintains after signing:

  • Where servers come from. Generated from an OpenAPI document, written by your team with an SDK, packaged as a container, or picked from a prebuilt catalog. This decides who maintains the server when your API changes.
  • Auth. OAuth 2.1 for MCP clients, Dynamic Client Registration (DCR) and Client ID Metadata Documents (CIMD), and sign-in through your IdP. See CIMD vs DCR for MCP OAuth.
  • Internal governance. Single sign-on (SSO), role-based access to servers and tools, and audit logs that name the user.
  • Deployment. Vendor-managed SaaS, your VPC, self-hosted, or air-gapped. A hard requirement for some buyers and irrelevant to most.
  • Pricing transparency. Whether you can estimate cost from a public page.

We did not benchmark latency or uptime. Facts are as of October 2026.

Hosted MCP platforms compared

Hosted MCP platforms compared

Vendor
Speakeasy
External hosting (customers)
Yes, generated and hosted on Speakeasy, OAuth handled
How servers are built
Generated from your OpenAPI document, plus TypeScript functions; catalog and remote servers on the gateway
Pricing
Free to start; Enterprise tailored
Internal gateway (employees)
Yes, MCP gateway with IdP sign-in, team access, and tool logs
Deployment
Managed by Speakeasy; no self-hosted or air-gapped option
Composio
External hosting (customers)
Yes, MCP servers from toolkits with per-user URLs
How servers are built
Prebuilt catalog of 1,500+ toolkits; your own APIs as custom tools
Pricing
Free tier; $29/mo credit then $0.0003 per tool call; Enterprise custom
Internal gateway (employees)
Yes, MCP Gateway with SAML/OIDC, SCIM, and audit metadata
Deployment
Composio Cloud; VPC or self-hosted on Enterprise
Arcade
External hosting (customers)
Yes, arcade deploy to Arcade Cloud
How servers are built
You write servers with the Python SDK
Pricing
Free tier; $25/mo plus per auth event and per tool call; Enterprise custom
Internal gateway (employees)
Yes, MCP Gateways over hosted and remote servers
Deployment
Arcade Cloud; VPC or air-gapped on Enterprise
Prefect Horizon
External hosting (customers)
Yes, git push to a live URL
How servers are built
You write Python FastMCP servers in a Git repo
Pricing
Free for personal servers; production compute billed; team pricing not published
Internal gateway (employees)
Yes, Registry and Gateway with IdP integration
Deployment
Prefect-managed; self-hosting not publicly documented
MintMCP
External hosting (customers)
Not the focus
How servers are built
1,000+ prebuilt connectors; container images for custom servers
Pricing
Per-user licensing plus platform fee; no public numbers
Internal gateway (employees)
Yes, gateway with managed server hosting for internal rollout
Deployment
Cloud or self-hosted
Cloudflare
External hosting (customers)
Yes, you build and deploy on Workers
How servers are built
You write TypeScript servers on Workers
Pricing
Workers free tier; paid from $5/mo
Internal gateway (employees)
Yes, MCP server portals in Cloudflare One
Deployment
Cloudflare's network

Best for: companies that want to ship their API as an MCP server to customers and govern MCP for employees on the same platform.

Coverage: external hosting, yes. Internal gateway, yes.

Speakeasy's hosted MCP server product generates, hosts, and secures your MCP server. Every operation in your OpenAPI document becomes a tool, regenerated on each push from CI, and you add TypeScript functions where a workflow needs custom logic (building servers). Each push produces an immutable deployment, and a bad deployment rolls back in one step. For auth, you connect the IdP or authorization server you already run, such as Auth0, or use Speakeasy as the authorization server; the platform handles client registration for every MCP client, and servers also accept API keys or bearer tokens (secure with OAuth). Servers run on a custom domain if you want one, and every call is logged with the customer, tool, client, and result, streamable to Datadog or any OpenTelemetry collector.

The same servers are part of the Speakeasy MCP gateway, a component of the AI Control Plane. Generated servers, catalog servers, remote third-party servers, and tunneled servers running inside your network sit behind one gateway, and gateway endpoints put many servers behind one URL. Employees sign in through your IdP, team access rules grant servers by role or directory group, tool logs record each call, and plugins publish server bundles to the Claude Code, Cursor, and Codex marketplaces (gateway docs).

PlanetScale launched its MCP server on Speakeasy in February 2026 and grew from about 4,700 tool calls in its first month to more than 200,000 a month by its fifth, a 44x increase in five months (PlanetScale case study). "Speakeasy made it trivial to turn our database platform API into a production MCP server," said Mike Coutermarsh of PlanetScale. Speakeasy's hosting platform serves Google and PlanetScale. With Google, Speakeasy built the Gemini Docs MCP server, which ships pre-bundled in Antigravity. On the internal side, MoonPay ran a 30-day proof of concept and then went live company-wide, with OAuth 2.1 and PKCE tied to its IdP, permissions scoped per server, per tool, and per team, and audit data exported to its SIEM. Its case study lists 200+ MCP servers under governance (MoonPay case study).

Pros

  • The server is regenerated from your OpenAPI document on every push, so it tracks the API without a separate codebase.
  • A customer-facing server and internal servers share one auth model, one log, and one protocol layer.
  • Auth covers your own IdP, Speakeasy as the authorization server, Enterprise Managed Authorization, and verified clients.
  • Protocol changes, including the MCP 2026-07-28 specification, ship on the platform rather than in your code.

Cons

  • No self-hosted, VPC, or air-gapped deployment. The platform and gateway run as Speakeasy's managed service. The CLI can generate a standalone TypeScript MCP server you run yourself, but that sits outside the hosted platform.
  • Tailscale private access requires an Enterprise organization with the option enabled, and it controls how clients reach hosted endpoints, not outbound connections.
  • MCP-scoped guardrails are enabled per organization on request. Checks read the first 50 KiB of a call and let it through on a timeout or larger content.
  • No redaction or masking of payloads.
  • A smaller prebuilt catalog than Composio or MintMCP. The strength is generating servers from your own APIs.

Pricing: free to start; AI Control Plane Enterprise pricing is tailored, per the pricing page.

Composio: the largest prebuilt catalog, on both sides

Best for: teams whose agents need many third-party SaaS integrations with managed auth.

Coverage: external hosting, yes. Internal gateway, yes.

Composio is catalog-first, with 1,500+ toolkits and managed auth (pricing). For external use, you create MCP servers from toolkits and get per-user server URLs; requests need an x-api-key by default, and Composio recommends its Sessions path (MCP docs). For internal use, the MCP Gateway adds team-scoped endpoints, action-level policies, SAML/OIDC with SCIM, and audit metadata (payloads are not stored) retained from 7 days to 1 year with CSV or SIEM export. Composio lists SOC 2 Type II and ISO 27001, and deploys in Composio Cloud, your VPC, or self-hosted.

Pros

  • The largest prebuilt catalog in this list, far larger than Speakeasy's.
  • Public, per-call pricing.
  • VPC and self-hosted deployment on Enterprise, which Speakeasy does not offer.

Cons

  • Built around its catalog: your own API comes in as custom tools rather than a server generated from your OpenAPI document.
  • In Composio Cloud, Composio holds end-user credentials; VPC or self-hosted custody is an Enterprise arrangement (token custody).

Pricing: under pricing effective August 15, 2026, Hobby is $0 with 100K tool calls a month, Pro is a $29 monthly credit then $0.0003 per tool call, and Enterprise is custom with SSO, SCIM, customer-managed keys, a BAA, and an SLA.

Arcade: per-user authorization, with an air-gapped option

Best for: agents that act on behalf of individual users and need per-user authorization, including in air-gapped environments.

Coverage: external hosting, yes. Internal gateway, yes.

Arcade is a tool-calling platform built around user-level authorization. arcade deploy hosts a server you write with Arcade's Python SDK on Arcade Cloud (deploy docs). MCP Gateways federate tools, including remote servers Arcade does not host, with three auth modes: Arcade Auth, User Source (an OIDC IdP such as Okta, Entra, Auth0, Clerk, or Stytch), and Arcade Headers. A CIMD allowlist skips consent for approved clients, Contextual Access hooks run custom checks, and audit logs record calls.

Pros

  • Per-user authorization for agents acting on a user's behalf.
  • The gateway fronts remote servers Arcade does not host.
  • VPC and fully air-gapped deployment on Enterprise, which Speakeasy does not offer.

Cons

  • You write and maintain server code in Python rather than generating it from an API spec.
  • Team pricing charges per auth event as well as per tool call, so model your auth volume before you scale.

Pricing: Free includes 2,000 auth events and 2,000 tool calls a month; Team is $25 a month plus $0.10 per auth event and $0.01 per tool call; Enterprise adds SSO, RBAC, audit logs, and a private registry (pricing).

Prefect Horizon (formerly FastMCP Cloud): git-push hosting for Python servers

Best for: Python teams already building on FastMCP.

Coverage: external hosting, yes. Internal gateway, yes.

FastMCP Cloud was renamed Prefect Horizon on January 21, 2026, and fastmcp.cloud now redirects to horizon.prefect.io (announcement). Horizon has four parts: Deploy, Registry, Gateway, and Agents. Deploy turns a git push into a live URL in about 60 seconds, with OAuth 2.1 and DCR, PR previews, rollbacks, and autoscaling to zero; hosted servers are Python FastMCP servers from a Git repo (hosted servers docs). Gateway adds tool-level RBAC, auth, and audit logs, integrates with Okta, Entra, Google Workspace, and other IdPs over SAML, OIDC, and SCIM, and works with any spec-compliant MCP server.

Pros

  • For hand-written Python servers, a git-push workflow that Speakeasy does not match.
  • PR previews and rollbacks on every push.

Cons

  • You write and maintain the server code.
  • Team and enterprise pricing is not published.
  • Prefect does not publicly document a self-hosted option.

Pricing: free for personal servers; in production, "pay only for compute you use."

MintMCP: managed hosting for internal rollout

Best for: rolling Claude and Cursor out across a company with many prebuilt connectors, in the cloud or self-hosted.

Coverage: external hosting, not the focus. Internal gateway, yes.

MintMCP is an enterprise MCP gateway that hosts MCP servers for internal rollout of Claude and Cursor. Its plans include the gateway with managed server hosting, an LLM proxy, role-based bundles, user and agent identities, custom hosted connectors, 1,000+ prebuilt connectors, and audit logs; Enterprise adds SSO (SAML/OIDC), SCIM, and OTEL export. MintMCP lists SOC 2 Type II and a HIPAA BAA, and deploys in the cloud or self-hosted. Custom servers are container images (HTTP on port 8000, or stdio) from a public registry or MintMCP's managed registry, with a Private Network option (hosted connector docs).

Pros

  • Purpose-built for internal rollout, with a connector library larger than Speakeasy's catalog.
  • A self-hosted option and a HIPAA BAA.
  • LLM proxy and agent identities in the same product.

Cons

  • The focus is internal use rather than publishing a server to your customers.
  • Custom servers arrive as container images you build rather than being generated from an API spec.
  • No public pricing.

Pricing: custom per-user licensing plus a platform fee. See Speakeasy vs MintMCP.

Cloudflare: build it yourself on the edge

Best for: Cloudflare customers who want to write their own remote MCP server or front internal servers with Zero Trust.

Coverage: external hosting, yes (you build the server). Internal gateway, yes (MCP server portals).

For external hosting, you build and deploy remote MCP servers on Workers in TypeScript, using createMcpHandler for stateless servers and the Workers OAuth Provider for GitHub, Google, Auth0, WorkOS, and others, or Cloudflare Access (remote MCP server guide). For internal use, MCP server portals in Cloudflare One give each portal one /mcp endpoint, Access policies through your IdP, curated tools, Code Mode, private servers through Cloudflare Tunnel, DLP through Gateway, and logs (Logpush on Enterprise). Documented limits: up to 80 servers per portal, remote HTTP servers only, admin tokens that can expire silently, and no independent MFA through a portal.

Pros

  • A global edge runtime and a low entry cost.
  • A mature OAuth library for remote servers.
  • Portals reuse an existing Cloudflare Zero Trust deployment, including DLP.

Cons

  • A toolkit rather than a managed MCP product: you write, deploy, and maintain each server.
  • No server generation from an API spec, and the portal limits above.

Pricing: the Workers free tier includes 100,000 requests a day, and paid plans start at $5 a month (Workers pricing).

Which hosted MCP platform should you choose?

Pick by the constraint that dominates your evaluation:

  • You publish an API and also roll out MCP internally. Speakeasy generates the customer-facing server from your OpenAPI document and governs internal servers behind the same gateway.
  • Your agents need hundreds of third-party SaaS integrations. Composio.
  • Air-gapped deployment is non-negotiable. Arcade Enterprise. For self-hosted without the air gap, Composio Enterprise or MintMCP.
  • You are a Python team on FastMCP and want git-push deploys. Prefect Horizon.
  • You need an internal rollout with many prebuilt connectors and a HIPAA BAA. MintMCP.
  • You already run Cloudflare and are comfortable writing TypeScript. Workers for the server, MCP server portals for internal access.
Frequently asked questions
What is a hosted MCP platform?

A hosted MCP platform runs Model Context Protocol (MCP) servers for you, so agents reach them over a URL. It has two meanings. External hosting publishes an MCP server for your customers' agents. Internal hosting runs MCP servers for your employees behind a gateway or registry with SSO, access control, and audit logs. Speakeasy, Composio, Arcade, Prefect Horizon, and Cloudflare cover both; MintMCP focuses on internal use.

What is the difference between a hosted and a local MCP server?

A local MCP server asks every user to install a package and paste an API key into a config file, and it cannot run in web clients such as Claude.ai or ChatGPT. A hosted MCP server is a URL: users add it, sign in with OAuth, and receive every update without a reinstall.

Do I need an MCP gateway if I already host an MCP server?

A hosted MCP server is how customers reach your product. An MCP gateway decides which internal and third-party servers your employees may use, under which identity, and what gets logged. If you publish a server and nothing else, you do not need a gateway yet. Once employees use MCP servers at work, a gateway gives the security team SSO, per-team access, and one audit log. On Speakeasy, hosted servers are part of the gateway.

Can I self-host a hosted MCP platform?

Composio offers VPC and self-hosted deployment on Enterprise, Arcade offers VPC and air-gapped deployment on Enterprise, and MintMCP lists cloud or self-hosted deployment. Speakeasy runs as a managed service with no self-hosted or air-gapped option. Prefect does not publicly document self-hosting for Horizon, and Cloudflare servers run on Cloudflare's network.

If you are shipping an MCP server to customers and governing MCP for employees at the same time, start with the hosted MCP server product or the MCP gateway docs. We'd be interested to hear how you're approaching it.

Last updated on

AI everywhere.

Control here.