Runtime authorization & controls
agentgateway
Open-source proxy that carries service, LLM-provider, MCP and agent-to-agent traffic in one data plane, letting platform teams route agent tool calls through a single enforcement and audit point. Project documentation covers MCP proxying and routing configuration; tool-level RBAC and token exchange are described mainly on vendor product pages.
open_source · generally available · Research snapshot 2026-09-06
Visit the official product source ↗Where it fits
Runtime authorization & controls · Observability & traceability
Useful conversation with: Platform engineering lead, CISO, API platform architect.
Ask for a demonstration
Show me an MCP server proxied through agentgateway with tool-level RBAC denying one specific tool call, and the audit record it produces.
Capabilities and evidence
Support labels reflect the supplied research. Documentation and vendor claims are not independent product tests. “Not established” means the researcher did not find support; it does not prove a capability is absent.
Documented by provider
agentgateway is an open-source HTTP/gRPC gateway that handles service traffic, LLM provider traffic, MCP tool traffic and agent-to-agent communication in one data plane.
Limit: The project page does not quantify enforcement latency or list supported policy syntaxes.
Source s1
Documented by provider
Kubernetes-based configuration is documented for proxying an MCP server through agentgateway, including an MCP-specific appProtocol, MCP path annotations and an AgentgatewayBackend resource.
Limit: The MCP quickstart documents connectivity and tool invocation only; it does not document authorization policy, guardrails or human approval.
Source s2
Vendor claim
The vendor product page states agentgateway provides native MCP OAuth 2.1, tool-level RBAC, secure token exchange and cryptographic audit trails.
Limit: These controls are asserted on a marketing product page rather than in reference documentation fetched here.
Source s3
Limitations to discuss
- Authorization policy detail is thin in the fetched documentation
- Enterprise control plane features are packaged separately as Solo Enterprise for agentgateway
Sources
- agentgateway | Agent Connectivity Solved · Linux Foundation / agentgateway project · official product
Access date reported by researcher: 2026-09-06 - MCP servers | Solo.io documentation · Solo.io · official docs
Access date reported by researcher: 2026-09-06 - Agentgateway: The AI-Native Gateway · Solo.io · official product
Access date reported by researcher: 2026-09-06
Listing does not imply partnership, supplier status, a working DutyGraph integration, or a compliance certification.
Suggest a correction