AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
MCP verified Apache-2.0 Self-run

Mcp Gateway

mcp-theognis1002-mcp-gateway · by theognis1002

Model Context Protocol (MCP) Gateway & Registry - Central hub for managing tools, resources, and prompts for MCP-compatible LLMs. Translates REST APIs into MCP, builds virtual MCP servers with security and observability, and bridges multiple transports (stdio, SSE, streamable HTTP).

No reviews yet
0 installs
9 views
0.0% view→install

Install

$ agentstack add mcp-theognis1002-mcp-gateway

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access Used
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets Used
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/mcp-theognis1002-mcp-gateway)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
5mo ago

Declared compatibility

Claude CodeClaude DesktopCursorWindsurf

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Mcp Gateway? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

MCP Gateway

[](https://github.com/mcp-gateway/mcp-gateway/actions) [](https://golang.org) [](LICENSE) [](https://goreportcard.com/report/github.com/mcp-gateway/mcp-gateway) [](https://codecov.io/gh/mcp-gateway/mcp-gateway) [](SECURITY.md) [](CONTRIBUTING.md)

A production-ready API gateway for Model Context Protocol (MCP) servers, providing enterprise-grade infrastructure with authentication, logging, rate limiting, server discovery, and multi-protocol transport support.

🚀 Quick Start

Get the entire MCP Gateway stack running with a single command:

# Clone the repository
git clone https://github.com/mcp-gateway/mcp-gateway.git
cd mcp-gateway

# Copy env vars
cp .env.example .env

# Option 1: Using Docker Compose directly
docker compose up --build

# Option 2: Using Makefile (automatically detects docker compose vs docker-compose)
make setup

Access the application:

  • Backend: http://localhost:8080
  • Frontend: http://localhost:3000
  • Admin user: admin@admin.com / qwerty123

Architecture

The MCP Gateway is designed with a modular architecture for scalability and maintainability:

┌─────────────────┐    ┌─────────────────┐    ┌─────────────────┐
│      Users      │    │    AI Agents    │    │     AI Agents   │
│   (Web/Mobile)  │    │    (External)   │    │    (Internal)   │
└─────────┬───────┘    └─────────┬───────┘    └─────────┬───────┘
          │                      │                      │
          └──────────────────────┼──────────────────────┘
                                 │
                   ┌─────────────▼─────────────┐
                   │    MCP Gateway    │
                   │                           │
                   │  ┌─────────────────────┐  │
                   │  │   Security Layer    │  │
                   │  │ • JWT Auth          │  │
                   │  │ • RBAC & Policies   │  │
                   │  │ • API Key Mgmt      │  │
                   │  │ • Rate Limiting     │  │
                   │  └─────────────────────┘  │
                   │                           │
                   │  ┌─────────────────────┐  │
                   │  │     Middleware      │  │
                   │  │ • Content Filtering │  │
                   │  │ • Audit Logging     │  │
                   │  │ • CORS & Headers    │  │
                   │  │ • Request Tracking  │  │
                   │  └─────────────────────┘  │
                   │                           │
                   │  ┌─────────────────────┐  │
                   │  │   Core Services     │  │
                   │  │ • Server Discovery  │  │
                   │  │ • Namespace Manager │  │
                   │  │ • Transport Proxy   │  │
                   │  │ • Virtual Servers   │  │
                   │  │ • Logging & Metrics │  │
                   │  └─────────────────────┘  │
                   └─────────────┬─────────────┘
                                 │
          ┌──────────────────────┼──────────────────────┐
          │                      │                      │
    ┌──────▼──────┐        ┌──────▼──────┐        ┌──────▼──────┐
    │ namespace-1 │        │ namespace-2 │        │ namespace-3 │
    │             │        │             │        │             │
    │┌───────────┐│        │┌───────────┐│        │┌───────────┐│
    ││MCP Server ││        ││MCP Server ││        ││Virtual    ││
    ││     A     ││        ││     C     ││        ││Server A   ││
    │└───────────┘│        │└───────────┘│        │└───────────┘│
    │┌───────────┐│        │┌───────────┐│        │┌───────────┐│
    ││MCP Server ││        ││MCP Server ││        ││Virtual    ││
    ││     B     ││        ││     D     ││        ││Server B   ││
    │└───────────┘│        │└───────────┘│        │└───────────┘│
    └─────────────┘        └─────────────┘        └─────────────┘

Features

🔐 Security & Authentication

  • Authentication - Secure authentication (JWT, OAuth2, OIDC) with RBAC
  • API Key Management - Role-based access control with fine-grained permissions
  • Rate Limiting - IP-based limiting with Redis backing and memory fallback
  • Content Filtering - PII detection, regex patterns, and custom filters

🏢 Server & Namespace Management

  • Dynamic Discovery - Automatic MCP server discovery and registration
  • Namespaces - Group servers with isolated namespaces for internal & external usage
  • Health Monitoring - Server health checks with automated failover and recovery
  • Public Endpoints - Auto-generated REST APIs for namespace access

🔌 Multi-Protocol Transport

  • JSON-RPC 2.0 - Standard synchronous RPC over HTTP
  • WebSocket - Full-duplex bidirectional communication
  • Server-Sent Events - Real-time server-to-client streaming
  • Streamable HTTP - Official MCP protocol implementation
  • STDIO - Command-line interface bridge

🌐 Service Virtualization

  • Protocol Support - REST APIs, GraphQL (coming soon), gRPC (coming soon)
  • MCP Integration - Transform any HTTP service into MCP tools with schema validation
  • Example Integrations - Internal API docs, microservers, etc.

📊 Logging, Auditing & Metrics

  • Audit Trails - Complete request/response logging with security event tracking
  • Performance Metrics - Real-time monitoring with health checks and alerting
  • External Integration - AWS CloudWatch, file-based logging, and custom exporters
  • Session Tracking - Live session management with detailed interaction logs

🛠️ Development

Quick Development Setup

Fast development with backend in Docker and frontend running locally:

# Terminal 1: Start backend services
make dev

# Terminal 2: Start frontend locally (much faster)
cd apps/frontend
bun install
bun run dev

Essential Commands

# Development
make dev              # Start backend services (postgres, redis, backend)
make setup            # Complete setup (DB + admin + orgs + namespaces)
make start            # Production-ready local setup with services
make stop             # Stop all services
make clean            # Stop and remove all data
make logs             # View service logs
make help             # Show all available commands

# Database Operations
make migrate          # Run database migrations
make migrate-down     # Rollback migrations
make migrate-status   # Show migration status
make db-shell         # Open PostgreSQL shell

# Testing & Quality
make test             # Run all tests
make lint             # Run linters

# Build & Utilities
make build            # Build containers
make rebuild          # Rebuild and restart containers
make shell            # Open shell in backend container
make bash             # Open bash in backend container

Troubleshooting

Docker Compose Issues:

# The Makefile automatically detects your Docker Compose version
# Check what it's using:
make help  # Will work with either docker-compose or docker compose

# Manual check:
docker compose version    # Modern v2
docker-compose version    # Legacy v1

# If you get "command not found":
# Install Docker Desktop (includes Compose v2) or standalone Compose

Common Issues:

  • Port conflicts: Stop other services on ports 8080, 3000, 5432, 6379
  • Permission denied: Ensure Docker daemon is running
  • Build failures: Try make clean then make setup

🤝 Contributing

  1. Fork the repository
  2. Run make dev to start backend services
  3. Run frontend locally: cd apps/frontend && bun run dev
  4. Make your changes
  5. Run make test and make lint
  6. Submit a Pull Request

Please see our [Contributing Guidelines](CONTRIBUTING.md) for details.

Code of Conduct

This project follows the Contributor Covenant Code of Conduct.

📄 License

This project is licensed under the Apache License 2.0 - see the [LICENSE](LICENSE) file for details.

🔒 Security

Security is a top priority. Please review our [Security Policy](SECURITY.md) and report vulnerabilities responsibly.

🙏 Acknowledgments


Built with ❤️ for the MCP community

⭐ Star us on GitHub • 🐛 Report Bug • 💡 Request Feature

Source & license

This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.