Distribute / MCP Gateway

Every MCP serverSecured. Governed. Efficient.

One entry point between your agents and your data. Apply OAuth 2.1 through your IdP, Scope access by team and role, Enforce security policy on every tool call.

Trusted byGoogleMoonPayLaunchDarklyCentsPlanetScalePolar

Customer stories

MoonPay brought 200+ MCP servers under the MCP Gateway, going from proof of concept to a company-wide rollout in 30 days.

MoonPay used the MCP Gateway to broker every MCP connection through its existing Okta identity, with permissions scoped per server, per tool, and per team. The security team has full visibility across 60K+ agent sessions, and unsanctioned shadow MCP servers are blocked by default.

Read the case study

01 / The problem

Agents need easy, efficient and safe data access

An MCP Gateway makes it easy.

What can AI reach?
Without the MCP Gateway

Unknown. Each team wires its own connections to production systems

Behind the MCP Gateway

One catalog of every system, server, and tool agents can touch

Who approved the access?
Without the MCP Gateway

API keys shared in DMs, allowlists nobody owns

Behind the MCP Gateway

Access granted by team and role, provisioned through your IdP

What did an agent do last quarter?
Without the MCP Gateway

A reconstruction from partial logs across every server

Behind the MCP Gateway

Every tool call in one exportable record, tied to a named employee

Employees were connecting MCP servers we had no inventory of. Now every server runs behind the gateway, scoped by team and role, and anything unsanctioned is blocked by default.

Thierry Dang

Security Operations

MoonPay

02 / The Solution

An MCP Gateway between
every agent and every server

One control point between every agent and every system. Security writes policy once at the MCP Gateway, and every team's agents inherit it. Adoption speeds up because governance stops being per-project work.

Build your own

Build your MCPs / use ours

Add GitHub, Stripe, Linear, Notion, and 200+ MCPs. Every MCP gets IdP sign-in, tool-level RBAC, and audit logs on every call. Bring your own servers, get the same controls.

Browse all MCP servers

03 / how it works

1 URL, 4 tools
Governed access to all company data

Every MCP server your team needs unified behind a single URL. Agents only ever see four tools. Servers are dynamically loaded for the task at hand.

gateway.acme.dev/mcp/eng

githubavailable
linearavailable
notionavailable
slackavailable
{}billing-apiavailable
Step 1 of 4

Agents

claude
cursor
chatgpt
copilot

MCP Gateway

  • OAuth 2.1 · SSO via your IdP
  • RBAC by team, role, and tool
  • Prompt injection detection
  • PII redaction in flight
  • Audit logs → your SIEM

gateway.acme.dev/mcp

MCP servers

github
slack
linear
{}internal-api
Works with every identity providerOktaMicrosoft Entra IDAuth0WorkOSGoogle WorkspacePing IdentityAny SAML / OIDC

03 / Enterprise support

Support that speeds up development

Rollouts move as fast as the answers you get. Support is measured against SLAs, not best effort — these are the current numbers.

100%

SLA compliance

Every response-time commitment met, across every support tier.

23.9m

p90 first response

90% of support requests answered in under 24 minutes.

98%

Satisfaction rate

Measured across every resolved support conversation.

Speakeasy's AI control plane has been indispensable in enabling Fivetran's AI transformation.

Eli Davis

Fivetran

Fivetran

Questions

What is an MCP gateway?
An MCP gateway sits in front of every MCP server and turns many ad-hoc tool connections into one governed entry point. Every agent, every prompt, and every tool call passes through the gateway, where authentication, authorization, and inspection happen consistently. Without a gateway, each MCP server has its own auth, its own audit logs, and its own way of being misconfigured.
How is the MCP Gateway different from running individual MCP servers?
Individual MCP servers solve point problems but leave you with N auth surfaces, N audit logs, and N places to enforce policy. The MCP Gateway gives you one URL for every agent, one identity surface, one policy layer, and one audit log. New servers join the catalog and inherit the MCP Gateway's controls instead of being rolled out one by one.
Which AI agents connect through the MCP Gateway?
Claude, Claude Code, ChatGPT, Cursor, Copilot, Codex, and any internal or product agents you run. Speakeasy supports OAuth 2.1 with PKCE and DCR even when the upstream MCP server does not, so the MCP Gateway works with clients that expect modern auth and servers that do not yet implement it.
What identity providers does the MCP Gateway integrate with?
Okta, Microsoft Entra ID, Auth0, WorkOS, Google Workspace, Ping Identity, and any SAML or OIDC provider. Plug your IdP in once at the MCP Gateway and every MCP server behind it inherits your auth, with SCIM and directory sync available where supported.
How does runtime guardrailing work?
Every prompt, response, and tool call is inspected in real time. PII and data exfiltration patterns are actively blocked. Prompt injection and shadow MCPs are passively detected. Alerts integrate with your existing SIEM and incident response workflows so the security team works in the tooling they already use.
What is a gateway endpoint?
A gateway endpoint is one MCP URL that sits in front of a set of MCP servers. Instead of every server's full tool catalog, the agent gets four tools: list what is reachable, describe one server, fetch schemas for the tools it needs, and execute. Tool lists stay small, agents discover tools as they go, and each member server keeps its own auth and access rules.
Can I bring my own MCP servers?
Yes. The MCP Gateway works with any MCP server: pre-built integrations from the Speakeasy catalog, MCP servers you build in-house, and third-party servers you adopt. Every server inherits the MCP Gateway's auth, RBAC, and audit logs, regardless of where it came from.
What do the audit logs capture?
Who called which tool, on which server, with what arguments, against which data, with what result, and when. Audit logs are exportable, queryable, and integrate with the same SIEM your security team already uses for the rest of the stack.
How do teams roll out the MCP Gateway across an organization?
Most teams start by routing one client (often Claude or Cursor) at one MCP server through the MCP Gateway, then expand. Per-team registries let you scope what each team sees, so engineering, sales, and security each get the right catalog without one team blocking another's adoption.

AI everywhere.

Control here.