Zuplo
Govern AI & Agent Access

Give your teams AI access. Keep every call accountable.

One gateway in front of the MCP servers and models you approve. Teams sign in with your IdP, budgets keep spend in bounds, and every call has a name on it.

Why one gateway

Saying yes to AI shouldn't mean losing track of it.

Your teams are already wiring AI into real systems. The job isn't to slow them down — it's to give them a front door you control.

Approve once, publish one gateway

Vet a server once and every team connects through the same governed endpoint. Saying yes gets faster.

Budgets, not surprises

Teams experiment freely inside limits you set — the bill never outruns the plan.

Every call has a name on it

When someone asks who did what, you answer from a dashboard — not a shrug.

How it works

One front door for AI

01

Put the gateway in front

Add the MCP servers you approve — Linear, GitHub, your own — as routes on one gateway, with LLM traffic alongside them.

02

Teams sign in with your IdP

Claude, Cursor, and ChatGPT connect through the login you already run — no shared keys in desktop apps.

03

Policies do the governing

Per-tool allow-lists, budgets, and audit logging run on every call — written once, enforced at the edge, versioned in your repo.

Both kinds of AI traffic

The MCP your teams use and the models your apps call

Agent tool calls and LLM completions run through the same gateway and the same policy pipeline — one place to set the rules, one place to see what happened.

Web Apps
AI Agents
Mobile
API Clients
API Gateway
Routing & transformation
Auth & authorization
Rate limiting & quotas
Request validation
Developer portal
OpenAPI-native · GitOps
MCP Server Support included
AI Gateway
LLM model routing
Prompt injection protection
Semantic caching
Budget & token control
Usage tracking by team
Auto-failover
MCP Gateway
Internal & external MCP servers
Virtual MCP servers
RBAC per team
Centralized audit logs
Prevent MCP sprawl
Sensitive tool access control
Your APIs
Databases
Microservices

Each gateway runs as its own project. MCP Server Support is built directly into the API Gateway — no extra deployment, no duplicate config.

MCP

The MCP servers your teams use

One route per approved server. The gateway holds the credentials; you choose the tools each team sees.

Explore MCP Gateway
LLM

The models your apps call

Swap model providers in config, not code — with per-team budgets and guardrails attached.

Explore AI Gateway
Controls that hold up

Per-tool access. Per-user answers.

Per-tool access, enforced at the gateway

Hidden tools stay blocked even when a client calls them by name — with finer-grained rules whenever you need them.

Audited per user, not per key

Who, which tool, what happened — in Zuplo or the dashboards you already watch.

Identity

Works with the identity provider you already run

Teams sign in with the accounts they already have — no new logins to manage.

  • Okta
  • Microsoft Entra ID
  • Auth0
  • Google
  • Clerk
  • WorkOS
  • Amazon Cognito
  • Keycloak
  • Logto
  • OneLogin
  • PingOne
  • Any OIDC provider

Frequently Asked Questions

Common questions from platform and IT teams governing AI and agent access.

Give your teams AI access today

Put one governed gateway in front of the MCP servers and models you approve. The MCP Gateway and AI Gateway are included in every plan.