One gateway for every MCP server your agents touch.
Ship MCP to your customers. Govern the MCP your teams use. Same gateway, same OAuth server, same audit trail.
AI Clients
Federated Upstreams
+12 more
Recent Calls
LiveKnow who's behind every call
Most AI gateways trust whatever the caller claims. Zuplo verifies it — and you never build or run an auth server.
One click to connect
A full OAuth server is built in. Customers click Connect — you build nothing.
Auth works on the first try
Agents negotiate auth automatically — no setup guides, no support tickets.
A leak stops at one server
A token for one MCP server is rejected at every other.
Your login, not another one
Users sign in with the account they already have — any identity provider.
Cross-App Access (ID-JAG)
IETF draftYour IdP brokers agent access to upstream servers — Zuplo is a named Okta launch partner.
Sign in with what you already run
- Okta
- Microsoft Entra ID
- Auth0
- Clerk
- WorkOS
- Amazon Cognito
- Keycloak
- Logto
- OneLogin
- PingOne
- Any OIDC provider
- OAuth 2.1
- PKCE S256
- DCR · RFC 7591
- CIMD
- RFC 8414
- RFC 9728
- RFC 8707
- RFC 7009
Federate remote MCP servers behind one gateway
Yours or third-party — you choose what each one exposes.
Wire up a virtual MCP server
Stripe, Linear, GitHub, Atlassian, or your own — configured alongside the routes you already have.
New MCP Gateway Virtual Server
Configure the upstream MCP server, tools, and authentication.
Bring your own MCP server
Point the gateway at any first-party or third-party MCP service, even one not yet in the Library.
Create a new MCP from API
Auto-generate a dynamic MCP server from any OpenAPI definition — same auth, policies, and GitOps workflow as your APIs.
Name
Path
Scope which tools each team — and each user — can call
Access is decided by policy on every call — not by scopes baked into tokens.
Expose only what you choose
Hidden tools stay blocked — even when a client calls them by name.
Fine-grained when you need it
Decide which user can call which tool on which resource — via OpenFGA, AuthZEN, or Okta FGA.
Your rules, in code
When the rules are yours alone, write them in TypeScript.
Use MCP Gateway externally to productize, or internally to govern
The MCP you ship to customers and the MCP your team uses — one gateway covers both.
Ship MCP to customer agents
Customers connect from Claude or ChatGPT with real sign-in, a curated catalog, and an audit trail.
Govern the MCP your team uses
Linear, GitHub, and internal servers behind one URL — IT keeps visibility without slowing anyone down.
Put your first MCP route in production this week
Start free and wire up your first upstream in minutes — or get a guided demo for your architecture.
See everything your agents do
Every session, tool call, and sign-in — in Zuplo or the dashboards you already watch.
Events
7.0K
Success rate
97.58%
6.9K success / 170 error
p95 latency
102ms
gw <1ms · up <1ms
Failure origins
157
gw 0 · up 0 · cl 157
MCP events over time
last 24 hoursTop Capabilities
Top Users
Top Virtual Servers
Nothing happens off the books
Every request, tool call, and sign-in lands in Datadog, New Relic, or Splunk.
Answers without stitching
Who, which client, which tool, how long, what failed — in every log row.
No opaque 500s
Every failure returns a documented code that tells clients how to recover.
Whose credentials hit the upstream?
Pick per route, mix freely across your fleet, and switch without a redeploy — per-user attribution stays in the audit log either way.
Each user brings their own login
Users sign in to the upstream themselves; the Gateway handles their tokens.
One OAuth grant for the whole gateway
Connect once for every user — the audit log still knows who did what.
A unique secret per user, vault-stored
Every user gets their own vaulted key — rotated without a redeploy.
One shared secret, rotated centrally
One vaulted key for every call. Rotate it once — no client changes, no leaks.
Hardened before your first request
The defaults that get an MCP gateway through a security review — already on.
Bad requests die at the edge
Malformed and rogue-client calls are rejected before they touch an upstream.
Tokens checked first
Verified before the upstream sees a byte; bad calls get a clean 401.
Logins can't be hijacked
Every authorization is signed, single-use, and expiring — nothing to replay.
Secrets stay sealed
Upstream credentials live encrypted in a vault, decrypted only at request time.
Runaway agents hit a ceiling
Default limits on size and time keep one misbehaving agent from taking you down.
Frequently Asked Questions
Common questions about running MCP Gateway on Zuplo.
Your MCP Gateway, in production today
OAuth, governance, and audit logs on by default. Free to start — no sales call.