Self-hosted deployment is an important option for regulated AI workloads that require greater infrastructure control, network isolation, or data sovereignty. As 86% of enterprises require tech stack upgrades to properly deploy AI agents, choosing an agent gateway that runs inside your infrastructure while maintaining enterprise-grade governance becomes critical.
The right MCP gateway should provide centralized authentication, real-time monitoring, and compliance controls without forcing you to send sensitive data through third-party clouds. For enterprises handling sensitive data, air-gapped, VPC-based, and self-hosted installations provide greater control over network access and data flows.
This guide evaluates ten agent gateways across performance, open-source licensing, self-hosted capability, and MCP protocol support to help you identify the right fit for your deployment constraints.
Key Takeaways
- MintMCP Gateway bridges MCP Gateway (governed connections to data and tools) with Agent Gateway (identities, permissions, memory, and monitoring for AI agents) in a unified architecture
- Self-hosted agent gateways keep AI traffic within your infrastructure while maintaining centralized authentication, authorization, and observability
- Open-source licensing (Apache 2.0 and MIT) dominates the self-hosted category, with varying feature availability between community and enterprise editions
- Performance characteristics vary significantly by product, configuration, enabled policies, and workload, so teams should compare gateways using equivalent benchmarks
- Authentication approaches range from basic shared credentials to full OAuth 2.1 brokering with per-agent identity management
1. MintMCP Gateway: enterprise MCP infrastructure with Agent Gateway capabilities
MintMCP Gateway provides an enterprise gateway for Model Context Protocol focused on authentication, tool-level access control, credential management, logging, rule-based policy, and agent governance. For organizations requiring infrastructure control, MintMCP offers VPC and self-hosted deployment options on request.
What makes MintMCP Gateway different
MintMCP bridges two connected categories: MCP Gateway for governed data and tool connections to AI systems like Claude, Cursor, ChatGPT, Gemini, and Copilot, and Agent Gateway for identities, permissions, memory, and monitoring of agents that work alongside users.
The platform solves the fundamental problem that 42% of enterprises face when needing access to eight or more data sources for AI agent deployment. The architecture wraps stdio, hosted, HTTP-streamable, and SSE MCP servers behind SSO-fronted remote MCP endpoints with OAuth brokering, SCIM-driven membership, and rule-based policy.
Core capabilities
MCP Gateway Foundation:
- Virtual MCP Bundles: Create team-specific, per-use-case endpoints that expose only required tools with SCIM-driven membership and role-based access
- OAuth Brokering: Add enterprise authentication to local and hosted MCP servers, including OAuth 2.x, bearer tokens, and SSO-fronted access
- Hosted MCP Connectors: MintMCP runs connector instances with auto-scaling and sandboxed execution per connector
- Custom Gateway Middleware: Runs customer-authored middleware in a JS sandbox with external DLP and guardrails integrations
Agent Gateway Layer:
- Agent Bundles: Give internal agents first-class identities with M2M auth, scoped tools, independent rotation and revocation, and an "act as agent" flow for connectors requiring per-agent OAuth
- Two-Layer Monitoring: Gateway monitoring tracks MCP traffic and tool calls, while Agent Monitor extends visibility to local non-MCP activity through Claude Code and Cursor hooks
Security and compliance
MintMCP is SOC 2 Type II audited with continuous compliance monitoring. Enterprise SSO, complete audit trails, PII detection, and role-based access control are built into every layer. MintMCP is compliant with HIPAA standards. Customers handling protected health information can request supporting documentation, and MintMCP signs BAAs.
Enterprise integrations
- Snowflake data warehouse access with natural language queries
- Elasticsearch knowledge base search for documentation
- Gmail integration for AI-driven response automation
Deployment options
- Managed SaaS-first delivery with US and EU availability
- VPC and self-hosted options available on request
Pricing
Contact for enterprise demonstration and pricing
2. Bifrost (Maxim AI)
Bifrost is an open-source AI gateway built for high-throughput, low-latency workloads. The gateway uses Go for its runtime architecture and documents 11 microsecond latency overhead at 5,000 requests per second in published benchmarks.
Bifrost's primary focus
Bifrost targets engineering teams that prioritize raw performance and require Apache 2.0 licensing for self-hosted deployment. The gateway supports 23+ LLM providers with an OpenAI-compatible API and includes native MCP gateway capabilities.
Core capabilities
- Apache 2.0 open-source licensing
- Documented 11 microsecond latency overhead at sustained load
- Air-gapped deployment support for disconnected environments
- Code Mode for reducing agent token costs at scale
- Support for 23+ LLM providers
Where Bifrost fits
Performance-critical deployments where latency overhead matters at scale. Organizations requiring full Apache 2.0 licensing and code audit capability. Air-gapped government or defense environments.
Considerations for enterprise teams
Teams evaluating Bifrost should assess whether they need operational governance layer around SCIM-driven RBAC, per-use-case tool bundles with membership sync, hosted connector management with auto-scaling, and per-agent identity with M2M auth that purpose-built enterprise gateways provide.
License: Apache 2.0 | Deployment: Self-hosted, air-gapped capable
3. Obot Platform
Obot Platform provides open-source MCP gateway capabilities as part of a broader AI agent orchestration framework from Acorn Labs. The platform is built for organizations seeking full infrastructure ownership with MIT licensing.
Obot's primary focus
Obot targets Kubernetes-fluent platform engineering teams who want to operate their own MCP gateway infrastructure. The platform includes a curated MCP catalog with self-service discovery and composite server support for combining multiple MCP servers into single logical endpoints.
Core capabilities
- MIT-licensed open-source deployment with separately available hosted MCP platform
- Curated MCP catalog with self-service discovery
- Composite servers combining multiple underlying MCP servers
- Self-hosted deployment using Docker or Kubernetes
- Agent workflow orchestration beyond basic MCP routing
Where Obot fits
Platform engineering teams with DevOps expertise who require full infrastructure ownership. Organizations building custom AI agent platforms. Teams prioritizing open-source tools for transparency.
Considerations for enterprise teams
An OSS-first, self-hosted model requires the customer to operate the runtime, Kubernetes deployment, scaling, connector lifecycle, and governance stack. Teams should evaluate whether they want self-hosted orchestration or a managed SaaS-first gateway with hosted MCP connectors and pre-configured governance controls.
License: MIT | Deployment: Self-hosted (Docker, Kubernetes)
4. TrueFoundry
TrueFoundry provides a Kubernetes-native AI platform with unified LLM, MCP, and A2A gateway capabilities in one control plane.
TrueFoundry's primary focus
TrueFoundry targets platform engineering and ML platform teams who want to consolidate gateway, model serving (vLLM, SGLang, Triton), and agent orchestration in a single platform with physical namespace isolation for multi-tenancy.
Core capabilities
- Unified LLM, MCP, and A2A gateway in one control plane
- Kubernetes-native deployment with namespace isolation
- 1,000+ model catalog with MLOps integration
- Full self-hosted control plane in customer Kubernetes
- Air-gapped deployment via forward proxy
Where TrueFoundry fits
Organizations wanting single-vendor consolidation for MLOps and gateway infrastructure. Teams already invested in Kubernetes for AI workloads. Enterprises requiring full data sovereignty with self-hosted control plane.
Considerations for enterprise teams
Teams should evaluate whether a full platform approach fits their needs, or whether a focused MCP gateway with hosted connector operations, SCIM-driven Virtual MCP Bundles, and Agent Bundles provides faster time to production governance.
Deployment: Self-hosted control plane | Compliance: TrueFoundry documents SOC 2 Type II, HIPAA, and GDPR coverage for managed infrastructure; confirm applicability for self-hosted deployments
5. NeuralTrust TrustGate
NeuralTrust TrustGate is a security-first AI gateway with a first-party detection engine called TrustGuard. The company raised $20M in funding and positions itself around runtime AI security.
TrustGate's primary focus
TrustGate targets security-led procurement and regulated industries where threat detection is the primary requirement. NeuralTrust reports 99% multilingual detection accuracy and scalability above 20,000 requests per second per node. These are vendor-published figures and should be validated under the organization's own policies.
Core capabilities
- First-party TrustGuard detection engine
- Unified LLM, MCP, and A2A governance in single policy model
- Apache 2.0 core with commercial features
- Air-gapped deployment support
- Deployment and policy controls intended to support regulated environments; specific certifications should be confirmed with NeuralTrust
Where TrustGate fits
Regulated industries prioritizing runtime security for AI deployments. Security-led procurement where threat detection is the primary evaluation criterion. Organizations requiring a first-party detection engine rather than plugin integrations.
Considerations for enterprise teams
Teams should evaluate whether their primary need is security detection or operational governance. Purpose-built MCP gateways may offer stronger primitives for SCIM-driven access control, per-use-case tool bundles, hosted connector management, and per-agent identity management.
License: Apache 2.0 core plus commercial | Deployment: Self-hosted, air-gapped capable
6. Solo.io agentgateway
Solo.io agentgateway is a Kubernetes-native multi-protocol gateway contributed to the Linux Foundation in August 2025. The project is developed under vendor-neutral foundation governance.
agentgateway's primary focus
agentgateway targets platform engineers who own the deployment layer and want Linux Foundation governance with broad industry backing. The gateway uses a Rust-based data plane for performance and CEL-based policy engine for MCP tool RBAC.
Core capabilities
- Apache 2.0 licensing under Linux Foundation governance
- Rust-based high-performance data plane
- CEL-based policy engine for tool-level RBAC
- Service mesh integration with Envoy and Istio
- Vendor-neutral foundation governance
Where agentgateway fits
Organizations requiring Linux Foundation governance for procurement. Teams already using Envoy or Istio service mesh. Platform engineers wanting protocol-level control with neutral governance.
Considerations for enterprise teams
agentgateway uses external guardrail integrations rather than first-party detection. Teams should evaluate whether they need managed deployment, hosted connector operations, and enterprise governance primitives like SCIM-driven bundles alongside the protocol-level gateway.
License: Apache 2.0 (Linux Foundation) | Deployment: Self-hosted, Kubernetes-native
7. LiteLLM
LiteLLM is an open-source Python gateway with a large documented provider catalog at 100+ LLM integrations. The project uses MIT licensing for its core and an Enterprise tier for advanced features.
LiteLLM's primary focus
LiteLLM targets developers who need the fastest path to many providers behind a single OpenAI-compatible endpoint. The gateway includes MCP gateway capabilities with per-key/team tool permissions.
Core capabilities
- 100+ LLM provider integrations
- MIT core license with active contributor base
- OpenAI-compatible proxy with minimal friction
- MCP gateway with per-key/team tool permissions
- Self-hosted deployment support
Where LiteLLM fits
Development teams prioritizing provider breadth and developer experience. Organizations requiring MIT licensing and code audit capability. Teams willing to accept Python performance characteristics for integration simplicity.
Considerations for enterprise teams
Teams should benchmark LiteLLM under their expected configuration rather than inferring production throughput from its implementation language. The project gates SSO, audit logs, and metrics behind Enterprise tier. Teams should evaluate whether core features meet enterprise governance requirements.
License: MIT core, Enterprise tier for advanced features | Deployment: Self-hosted
8. Kong AI Gateway
Kong AI Gateway extends the Kong Gateway with AI plugins for multi-LLM routing, semantic caching, and prompt transformation. Organizations already standardized on Kong can add MCP support without deploying separate infrastructure.
Kong's primary focus
Kong targets organizations with existing Kong Gateway deployments who want to extend established infrastructure with AI capabilities rather than introduce new platforms.
Core capabilities
- AI Proxy plugin for multi-LLM routing
- Semantic caching and prompt transformation
- MCP Registry in Kong Konnect
- Mature plugin ecosystem with OIDC, mTLS, rate limiting
- Hybrid deployment with Konnect SaaS or fully self-hosted
Where Kong fits
Enterprises with established Kong Gateway investments seeking unified API and MCP management. Organizations preferring to extend existing infrastructure rather than deploy purpose-built solutions.
Considerations for enterprise teams
Kong AI Gateway is not a standalone product but AI plugins on Kong Gateway. Advanced AI features require Enterprise licensing. Teams should evaluate whether a plugin-based approach provides MCP-specific governance primitives like Virtual MCP Bundles, Agent Bundles, and hosted connector runtime.
License: Apache 2.0 core, Enterprise for advanced features | Deployment: Konnect SaaS control plane or fully self-hosted
9. Apache APISIX
Apache APISIX is an Apache Software Foundation API gateway with AI plugins. All AI plugins, including security-oriented ones, are open source with no feature gating.
APISIX's primary focus
APISIX targets organizations prioritizing ASF governance and open-source licensing where all features remain available in the community edition.
Core capabilities
- All AI plugins open source under Apache 2.0
- ai-proxy-multi for multi-LLM routing
- Nginx/OpenResty with etcd for dynamic configuration
- ASF project governance with vendor neutrality
- Commercial support available via API7
Where APISIX fits
Organizations requiring all features in open source without Enterprise gating. Teams prioritizing ASF governance and vendor neutrality. Existing APISIX deployments adding AI capabilities.
Considerations for enterprise teams
APISIX provides MCP-to-HTTP conversion but may not include MCP-specific primitives like per-use-case tool bundles, agent identity management, or hosted connector runtime. Teams should evaluate whether API gateway extension provides sufficient governance depth for MCP workloads.
License: Apache 2.0 (all features) | Deployment: Self-hosted
10. Portkey
Portkey is an LLM observability and gateway platform. The platform integrates with Palo Alto Networks security and documents support for 1,600+ models across 40+ providers.
Portkey's primary focus
Portkey targets organizations with existing Palo Alto Networks investments who want LLM gateway capabilities integrated into their security platform. The Apache 2.0 gateway core remains available for self-hosted deployment.
Core capabilities
- 1,600+ models across 40+ providers
- Guardrails and PII redaction built-in
- MCP Gateway with OAuth 2.1 support
- Apache 2.0 gateway core
- Integration with Palo Alto Prisma AIRS
Where Portkey fits
Organizations with Palo Alto Networks security investments seeking integrated AI gateway. Teams prioritizing broad model catalog coverage. Enterprises wanting managed gateway with built-in guardrails.
Considerations for enterprise teams
Teams should evaluate whether the self-hosted option remains actively developed and whether it provides MCP-specific governance primitives for enterprise deployments.
License: Apache 2.0 core plus commercial | Deployment: Self-hosted option available
Selection criteria for self-hosted agent gateways
Performance vs. governance trade-offs
Some performance-focused gateways publish microsecond-overhead benchmarks, but results depend on workload, configuration, and enabled governance controls. Purpose-built MCP gateways like MintMCP provide governance primitives out of the box with self-hosted deployment options for teams requiring infrastructure control.
Licensing requirements
Apache 2.0 and MIT dominate the self-hosted gateway category. Evaluate whether all required features are available in the open-source core or gated behind Enterprise tiers that change the effective licensing model.
STDIO server support
Many community-built MCP servers use STDIO transport. Evaluate whether your gateway handles STDIO-based servers or only supports remote HTTP/SSE endpoints, which limits ecosystem access.
Authentication architecture
OAuth 2.1 support was added to the MCP specification in 2025, but implementation varies. Some gateways broker OAuth and wrap stdio servers with enterprise SSO, while others require manual configuration per server. Consider whether you need per-user authentication, per-agent identity, or shared service accounts.
Observability depth
Without comprehensive logging, organizations face visibility gaps where they cannot track which tools agents use or audit data access. Evaluate whether your gateway provides tool call tracking, latency monitoring, error rates, and cost allocation per team.
Deploy AI agents with full governance
For organizations requiring both self-hosted deployment options and enterprise-grade governance, MintMCP Gateway provides the architecture to meet both requirements. Virtual MCP Bundles create team-specific endpoints with SCIM-driven membership. Agent Bundles give each AI agent its own credential set with independent rotation. The Agent Monitor extends visibility to local agent activity in Claude Code and Cursor.
MintMCP bridges MCP Gateway (governed connections to data and tools) with Agent Gateway (identities, permissions, memory, and monitoring for agents that work alongside users). This unified architecture means organizations don't need separate platforms for tool governance and agent management.
Start with managed SaaS delivery for fast deployment, then move to VPC or self-hosted when your requirements demand infrastructure control. Visit mintmcp.com to schedule a demonstration.
Frequently asked questions
What is an agent gateway and why does self-hosted deployment matter?
An agent gateway provides centralized authentication, authorization, and observability for AI agents connecting to tools and data sources. Self-hosted deployment matters for organizations in regulated industries or handling sensitive data where sending AI traffic through third-party clouds creates compliance and security risks. Self-hosted gateways keep data within your infrastructure while maintaining enterprise governance.
How do self-hosted agent gateways handle authentication?
Authentication approaches vary significantly. Some gateways broker OAuth and wrap STDIO servers with enterprise SSO, while others require manual configuration per server. Purpose-built MCP gateways may offer OAuth 2.x, SAML, bearer tokens, and SCIM group synchronization with identity providers like Okta and Azure AD. Evaluate whether your gateway supports shared service accounts, per-user authentication, and per-agent identity based on your use cases.
Can self-hosted agent gateways detect shadow AI activity?
Gateway-only solutions provide visibility into MCP traffic routed through the gateway but cannot detect off-gateway agent activity. Solutions like MintMCP extend monitoring through Agent Monitor hooks in Claude Code and Cursor to detect local non-MCP agent activity including bash commands, file operations, and prompt submissions. This creates two-layer governance with additional visibility into supported local agent activity.
What performance overhead should I expect from self-hosted agent gateways?
Performance varies by product and configuration. For example, Bifrost reports 11 microseconds of gateway overhead at 5,000 requests per second in its published benchmark, but teams should run tests with their own routing, logging, and authentication settings. Evaluate whether your workloads require raw performance or whether governance features justify moderate overhead. High-throughput production deployments should benchmark gateway overhead under realistic load.
How do I evaluate open-source licensing for agent gateways?
Check whether all features you need are available in the open-source core or gated behind Enterprise tiers. Apache 2.0 and MIT licenses dominate the category. Some vendors maintain fully open cores while others gate SSO, audit logs, and advanced security behind commercial licenses. For self-hosted deployment, ensure the license permits modification, distribution, and commercial use within your organization.
