Governed MCP Gateway

Thinking Tip:

Status: Planned | Expected: Q4 2026

Not just a gateway. The Control Plane for AI capabilities. We govern the data, the tools, AND the calls.


What Is an MCP Gateway?

An MCP Gateway is to MCP servers what an API Gateway is to REST APIs. It provides:

CapabilityWhat It Does
AuthenticationOAuth 2.0, OIDC, API keys, mTLS
AuthorizationRBAC, per-tool permissions, policy engine
Rate LimitingToken quotas, request limits, cost controls
Catalog/DiscoverySearchable catalog, namespacing, metadata
ObservabilityLogging, metrics, tracing, audit trails
Human-in-the-LoopApproval workflows (emerging feature)

As MCP adoption explodes (97M+ monthly SDK downloads, 5,800+ servers available), enterprises need centralized control. REST needed API management to standardize auth, rate limits, and analytics. MCP is in the same place.


The Market Challenge

The Governance Gap

Enterprises adopting MCP face critical risks:

  • Shadow MCP - Unauthorized instances without audit trails
  • No Authentication - Security researchers found ~2,000 MCP servers exposed to internet, all lacking authentication
  • Local Deployments - No centralized governance
  • Compliance Risk - No audit trails for regulated industries

"Security and compliance teams cannot allow arbitrary, unvetted 'Shadow Agents' running on developer laptops to access critical data systems."

The Context Window Problem

MCP is a "context hog" - burning through tokens at alarming rates:

Tool ComplexityToken Cost
Simple tool50-100 tokens
Enterprise tool with detailed schema500-1,000 tokens
15-20 tools10,000-15,000 tokens just for definitions

Solutions emerging in the market:

  • Dynamic Toolsets - Load tools on-demand (Speakeasy achieved 96% token reduction)
  • Code Execution Pattern - Present MCP as code APIs (Anthropic approach)
  • Search-then-Describe - Search tools first, describe only what's needed
  • Schema Optimization - Ruthless reduction of verbose descriptions

The Competitive Landscape

MCP Gateway Players (2026)

CompetitorFocusFundingKey Feature
ObotGeneral enterprise, K8s$35M seedOpen source, curated catalog
TrueFoundryGeneral enterpriseFundedPerformance (sub-10ms), observability
Kong AI GatewayAPI Gateway extendedPublic companyExisting Kong ecosystem, plugins
IBM ContextForgeEnterpriseIBMProtocol translation, registry
Azure API ManagementAzure ecosystemMicrosoftOAuth, Azure AD integration

What They All Have in Common

Every competitor focuses on hosting MCP servers for their own ecosystems (AWS for AWS, Azure for Azure, Atlassian for Jira).

No one offers: "Bring any MCP server, we govern it - with your data, your platform, your AI."


Why OpenIndustrial Is Different

Gateway vs. Control Plane

MCP Gateways govern the CALLS to tools. OpenIndustrial is a Control Plane - we govern EVERYTHING.

Governance LayerMCP GatewayControl Plane (OI)
Tool Calls✓ Governed✓ Governed
Tools Themselves✗ You bring them✓ Governed catalog, creation
Data Access✗ You bring it✓ Warm Queries + Surfaces
Data Connections✗✓ Azure IoT Hub, Event Hub
Data Layer✗✓ Built-in (ADX)
Platform✗✓ Governed infrastructure
AI Collaborator✗✓ Azi (governed proposals)
Any AI✓ Generic✓ "Bring Any AI"
Industrial Context✗✓ OT/Manufacturing
No Lock-inVaries✓ "Fire us, keep running"

The Five Differentiators

1. Industrial/Manufacturing First

No MCP Gateway specifically targets OT/industrial. We claim:

  • MCP tools that understand industrial data semantics
  • Integration with Azure IoT Hub, Event Hub, OPC-UA
  • Governance calibrated for mission-critical operations

2. Governance as Foundation, Not Feature

Competitors: Add human-in-the-loop as a feature OI: The entire architecture is built around governance

  • MCP calls can generate proposals that require approval
  • Approval history becomes training data
  • "Nothing without approval" extends to every MCP tool invocation

3. Context Optimization Built-In

Apply OI's existing context window solutions to MCP:

  • Dynamic Tool Loading - Only expose relevant tools based on context
  • Schema Optimization - Minimal tool descriptions by default
  • Warm Query Integration - MCP tools expose governed queries, not raw data
  • Surface-Aware Filtering - Tools filtered by surface context

4. Integration with Control Plane Primitives

PrimitiveMCP Gateway Integration
Warm QueriesMCP tools expose governed warm queries
SurfacesMCP servers scoped to surfaces
ProposalsMCP calls can generate proposals
Audit TrailsNative, not added
AziAzi can use MCP tools, governed same way

5. "Fire Us and Keep Running"

Even the MCP Gateway:

  • No vendor lock-in
  • Standard MCP protocol
  • Export your catalog and configurations
  • Your Azure tenant, your data

Core Capabilities (Vision)

1. Governed Catalog & Discovery

FeatureDescription
Curated CatalogIT-verified, tested MCP servers
Role-Based VisibilityUsers see only what they're allowed
Search & FilterFind tools by capability, not just name
Context-Aware ExposureOnly relevant tools loaded per session

2. Governed Access Control

FeatureDescription
Per-Tool PermissionsNot just per-server
Parameter-Level PolicyControl what parameters can be passed
Surface ScopingMCP servers inherit surface permissions
Identity MediationMCP calls carry user identity

3. Governed Approval Workflow

FeatureDescription
Proposal GenerationMCP calls can generate proposals
Approval QueueSame queue as other Azi proposals
Staged WritesRead-only by default, writes require approval
Reflex LearningApproved patterns become reflexes

4. Context Optimization

FeatureDescription
Dynamic Tool LoadingSearch → Describe → Execute pattern
Schema OptimizationMinimal descriptions, external docs links
Warm Query ExposureMCP tools return governed query results
Result FilteringFilter data before it hits context window

5. Observability & Audit

FeatureDescription
Comprehensive AuditEvery MCP call logged with identity
Cost TrackingToken usage by tool, user, surface
Usage AnalyticsWhich tools are used, by whom
Compliance ReadyAudit logs for regulated industries

Technical Architecture (Vision)

┌─────────────────────────────────────────────────────────────┐
│                   AI Clients                                 │
│         (Claude, GPT, Copilot, Custom Agents)               │
└─────────────────────────┬───────────────────────────────────┘
                          │
                          ▼
┌─────────────────────────────────────────────────────────────┐
│              OI Governed MCP Gateway                        │
│  ┌─────────────┐ ┌─────────────┐ ┌─────────────┐           │
│  │   Auth/     │ │  Catalog &  │ │  Context    │           │
│  │   AuthZ     │ │  Discovery  │ │  Optimizer  │           │
│  └─────────────┘ └─────────────┘ └─────────────┘           │
│  ┌─────────────┐ ┌─────────────┐ ┌─────────────┐           │
│  │  Approval   │ │   Audit &   │ │   Rate &    │           │
│  │  Workflow   │ │   Logging   │ │   Cost      │           │
│  └─────────────┘ └─────────────┘ └─────────────┘           │
└─────────────────────────┬───────────────────────────────────┘
                          │
          ┌───────────────┼───────────────┐
          ▼               ▼               ▼
    ┌──────────┐    ┌──────────┐    ┌──────────┐
    │ Built-in │    │ Custom   │    │ External │
    │ MCP      │    │ MCP      │    │ MCP      │
    │ Servers  │    │ Servers  │    │ Servers  │
    └──────────┘    └──────────┘    └──────────┘
          │               │               │
          ▼               ▼               ▼
    ┌──────────┐    ┌──────────┐    ┌──────────┐
    │  Warm    │    │  Your    │    │  Third   │
    │  Queries │    │  APIs    │    │  Party   │
    └──────────┘    └──────────┘    └──────────┘

API Gateway vs. MCP Gateway

Understanding why traditional API gateways aren't sufficient:

DimensionAPI GatewayMCP Gateway
TrafficNorth-South (edge)East-West (internal)
GovernanceEndpoint levelFunction/Parameter level
StateStatelessStateful/Session-aware
Human-in-the-LoopNoYes (critical for AI)
Semantic UnderstandingNoneTool semantics matter

"Traditional API gateways only allow or deny requests — they lack the pause/resume model that's critical for safe AI agent control."

API gateways govern endpoints. MCP gateways govern capabilities. Control Planes govern everything.


Key Messaging

For Prospects

Short (10 seconds):

"Not just a gateway. The Control Plane for AI capabilities."

Medium (30 seconds):

"MCP gateways govern tool calls. OpenIndustrial governs the data, the tools, AND the calls. Because we're not a gateway - we're the Control Plane."

Full (60 seconds):

"Others pitch 'MCP governance' - but they're just a gateway layer you add on top. They govern tool calls, not data. They don't have warm queries. They don't have surfaces. They don't have Azi. OpenIndustrial is different. We ARE the Governed AI Control Plane. The MCP Gateway is how we extend that governance to any capability you want to add. Same approval workflow. Same audit trails. Same 'fire us and keep running' promise. That's not a gateway feature. That's category leadership."

vs. MCP Gateways

What Gateways SayWhat OI Says
"Governance layer for agents""Control Plane for industrial AI"
"Control data access""We control the data itself - warm queries, surfaces"
"Stable place for integrations""We ARE the integrations - your data, governed"
"Future-proofing""Fire us and keep running - your Azure tenant"

Current Status

CapabilityStatus
MCP server endpoint (mcp.openindustrial.co)SHIPPED
Claude MCP integrationSHIPPED
GPT/Copilot via adaptersSHIPPED
Governed catalogPlanned
Context optimizationPlanned
Approval workflow for MCPPlanned
Full MCP GatewayQ4 2026

What You Can Do Today

The foundation is working. While the full MCP Gateway is planned:

Thinking Tip:

The pilot is how we BOTH learn if this is right. $15K. 4 weeks. Your Azure tenant. Run an experiment, not make a bet.


On this page