Documentation
Products
  • Gateway
    The MCP runtime — protocol, dispatch, plugin chains.
  • Control Plane
    Multi-tenant management, fleets, observability.
  • Kubernetes
    Operator + Helm chart for production deployments.
  • Plugins
    47 plugins across 12 categories. Native Rust + WASM.
Solutions
  • Self-host
    Run the OSS gateway anywhere — Apache-2.0, free.
  • Managed Cloud
    MCPG-provisioned gateways. Zero infra to run.
  • Enterprise
    SSO, BYOC, payload capture, audit, and support.
Learn
  • Architecture
    See how a request flows through the gateway.
  • Quickstart
    A governed MCP endpoint in minutes.
  • Guides
    How-tos and deployment patterns.
Company
  • About us
    Who we are and why MCPG exists.
  • Services
    Engineering, advising, training, consulting.
  • Startups
    Discounted plans for startups & non-profits.
  • GitHub
    Star the repo, file issues, contribute.
LicenseBlog
DocumentationLicense
  • Get started
    • What is MCPG?
    • Quickstart
    • Install MCPG
  • Concepts
    • Architecture
    • Governance model
  • Gateway
    • Configure the gateway
    • Configuration sources
    • Protocol versions
    • MCP federation
    • Reverse tunnelsbeta
    • Templated MCP Appsbeta
    • SQL backend cookbook
    • Migrating REST-wrapped DB tools to the SQL backend
  • Plugins
    • Plugins and the plugin protocol
    • Plugin catalogue
    • Plugin authoring
  • Self-hosting
    • Deployment topologies
    • Kubernetes install with Helm
    • Kubernetes operator
    • Clustering
    • Multi-tenant deployments
    • Air-gapped install
    • Install MCPG with Terraform
    • Terraform provider for MCPG
    • Install MCPG with OpenTofu
    • Install MCPG with Pulumi
    • Self-hosting the tunnel relaybeta
  • Cloud
    • What is mcpg.cloud?beta
    • Publish a configbeta
    • Versions and rollbackbeta
    • Custom domainsbeta
    • Tenant and fleet administrationbeta
    • Tunnels & reverse federationbeta
  • Operations
    • Observability
    • Day-2 operations and upgrades
  • Security
    • Identity and authorization
    • Identity — OIDC, JWKS, mTLS, SPIFFE, API keys
    • Policy authorization — Cedar, OPA, Casbin
    • Plugin security
    • Audit trail
    • Compliance and conformance
  • Reference
    • Configuration reference
    • Backends reference
    • Pipeline steps reference
    • Operator CRD reference
    • CLI reference
    • mcpg (gateway)
    • mcpg config (config tooling)
    • mcpg cp (control plane)
    • mcpg cloud (tenant CLI)
    • mcpg admin (platform operators)
    • mcpg plugin (plugin artifacts)
    • mcpg-operator & crdgen (Kubernetes)
    • mcpg-control-plane-server
Docs
Documentation

Security

Identity and authorization

How MCPG establishes who a caller is and decides what they may do — a three-tier trust model, native JWT/OIDC verification, and a pre-dispatch authorization chain that fails closed.

Identity — OIDC, JWKS, mTLS, SPIFFE, API keys

Configure inbound identity. The gateway verifies JWT bearers natively; richer or chained identity loads as plugins.

Policy authorization — Cedar, OPA, Casbin

Authorize tool calls, prompts, and resources. Three policy engines plus a built-in trust floor; chain them for defense-in-depth.

Plugin security

MCPG runs every backend and extension as a verified plugin. Ed25519 signatures, SHA-256 content pinning, a revocation list, and typed fail-closed capability grants gate what loads and what it can touch. Set Enforce in production.

Audit trail

A tamper-evident, hash-chained, fail-closed compliance ledger. Every authorization decision, payment, and access attempt is recorded with actor, action, resource, and outcome, fanned out to durable sinks.

Compliance and conformance

An honest statement of MCPG's MCP protocol conformance — both supported wire versions pass the upstream third-party conformance suite on every CI run, gated as a required check.

One URL for every Model Context Protocol server your team uses, with per-person permissions, full audit trail, and zero inbound ports.

v1.0.0-dev

Product
  • Gateway
  • Control Plane
  • Kubernetes
  • Plugins
Solutions
  • Self-host
  • Managed Cloud
  • Enterprise
Resources
  • Documentation
  • Quickstart
  • Install
  • Reference
  • Architecture
  • Blog
Company
  • About
  • Services
  • Startups
  • Contact
  • GitHub
  • Releases
© 2026 MCPG — Apache-2.0 core; BUSL-1.1 enterprise modules.
License