Governed MCP Gateway
Status: Planned | Expected: Q4 2026
Not just a gateway. The Control Plane for AI capabilities. We govern the data, the tools, AND the calls.
What Is an MCP Gateway?
An MCP Gateway is to MCP servers what an API Gateway is to REST APIs. It provides:
| Capability | What It Does |
|---|---|
| Authentication | OAuth 2.0, OIDC, API keys, mTLS |
| Authorization | RBAC, per-tool permissions, policy engine |
| Rate Limiting | Token quotas, request limits, cost controls |
| Catalog/Discovery | Searchable catalog, namespacing, metadata |
| Observability | Logging, metrics, tracing, audit trails |
| Human-in-the-Loop | Approval workflows (emerging feature) |
As MCP adoption explodes (97M+ monthly SDK downloads, 5,800+ servers available), enterprises need centralized control. REST needed API management to standardize auth, rate limits, and analytics. MCP is in the same place.
The Market Challenge
The Governance Gap
Enterprises adopting MCP face critical risks:
- Shadow MCP - Unauthorized instances without audit trails
- No Authentication - Security researchers found ~2,000 MCP servers exposed to internet, all lacking authentication
- Local Deployments - No centralized governance
- Compliance Risk - No audit trails for regulated industries
"Security and compliance teams cannot allow arbitrary, unvetted 'Shadow Agents' running on developer laptops to access critical data systems."
The Context Window Problem
MCP is a "context hog" - burning through tokens at alarming rates:
| Tool Complexity | Token Cost |
|---|---|
| Simple tool | 50-100 tokens |
| Enterprise tool with detailed schema | 500-1,000 tokens |
| 15-20 tools | 10,000-15,000 tokens just for definitions |
Solutions emerging in the market:
- Dynamic Toolsets - Load tools on-demand (Speakeasy achieved 96% token reduction)
- Code Execution Pattern - Present MCP as code APIs (Anthropic approach)
- Search-then-Describe - Search tools first, describe only what's needed
- Schema Optimization - Ruthless reduction of verbose descriptions
The Competitive Landscape
MCP Gateway Players (2026)
| Competitor | Focus | Funding | Key Feature |
|---|---|---|---|
| Obot | General enterprise, K8s | $35M seed | Open source, curated catalog |
| TrueFoundry | General enterprise | Funded | Performance (sub-10ms), observability |
| Kong AI Gateway | API Gateway extended | Public company | Existing Kong ecosystem, plugins |
| IBM ContextForge | Enterprise | IBM | Protocol translation, registry |
| Azure API Management | Azure ecosystem | Microsoft | OAuth, Azure AD integration |
What They All Have in Common
Every competitor focuses on hosting MCP servers for their own ecosystems (AWS for AWS, Azure for Azure, Atlassian for Jira).
No one offers: "Bring any MCP server, we govern it - with your data, your platform, your AI."
Why OpenIndustrial Is Different
Gateway vs. Control Plane
MCP Gateways govern the CALLS to tools. OpenIndustrial is a Control Plane - we govern EVERYTHING.
| Governance Layer | MCP Gateway | Control Plane (OI) |
|---|---|---|
| Tool Calls | ✓ Governed | ✓ Governed |
| Tools Themselves | ✗ You bring them | ✓ Governed catalog, creation |
| Data Access | ✗ You bring it | ✓ Warm Queries + Surfaces |
| Data Connections | ✗ | ✓ Azure IoT Hub, Event Hub |
| Data Layer | ✗ | ✓ Built-in (ADX) |
| Platform | ✗ | ✓ Governed infrastructure |
| AI Collaborator | ✗ | ✓ Azi (governed proposals) |
| Any AI | ✓ Generic | ✓ "Bring Any AI" |
| Industrial Context | ✗ | ✓ OT/Manufacturing |
| No Lock-in | Varies | ✓ "Fire us, keep running" |
The Five Differentiators
1. Industrial/Manufacturing First
No MCP Gateway specifically targets OT/industrial. We claim:
- MCP tools that understand industrial data semantics
- Integration with Azure IoT Hub, Event Hub, OPC-UA
- Governance calibrated for mission-critical operations
2. Governance as Foundation, Not Feature
Competitors: Add human-in-the-loop as a feature OI: The entire architecture is built around governance
- MCP calls can generate proposals that require approval
- Approval history becomes training data
- "Nothing without approval" extends to every MCP tool invocation
3. Context Optimization Built-In
Apply OI's existing context window solutions to MCP:
- Dynamic Tool Loading - Only expose relevant tools based on context
- Schema Optimization - Minimal tool descriptions by default
- Warm Query Integration - MCP tools expose governed queries, not raw data
- Surface-Aware Filtering - Tools filtered by surface context
4. Integration with Control Plane Primitives
| Primitive | MCP Gateway Integration |
|---|---|
| Warm Queries | MCP tools expose governed warm queries |
| Surfaces | MCP servers scoped to surfaces |
| Proposals | MCP calls can generate proposals |
| Audit Trails | Native, not added |
| Azi | Azi can use MCP tools, governed same way |
5. "Fire Us and Keep Running"
Even the MCP Gateway:
- No vendor lock-in
- Standard MCP protocol
- Export your catalog and configurations
- Your Azure tenant, your data
Core Capabilities (Vision)
1. Governed Catalog & Discovery
| Feature | Description |
|---|---|
| Curated Catalog | IT-verified, tested MCP servers |
| Role-Based Visibility | Users see only what they're allowed |
| Search & Filter | Find tools by capability, not just name |
| Context-Aware Exposure | Only relevant tools loaded per session |
2. Governed Access Control
| Feature | Description |
|---|---|
| Per-Tool Permissions | Not just per-server |
| Parameter-Level Policy | Control what parameters can be passed |
| Surface Scoping | MCP servers inherit surface permissions |
| Identity Mediation | MCP calls carry user identity |
3. Governed Approval Workflow
| Feature | Description |
|---|---|
| Proposal Generation | MCP calls can generate proposals |
| Approval Queue | Same queue as other Azi proposals |
| Staged Writes | Read-only by default, writes require approval |
| Reflex Learning | Approved patterns become reflexes |
4. Context Optimization
| Feature | Description |
|---|---|
| Dynamic Tool Loading | Search → Describe → Execute pattern |
| Schema Optimization | Minimal descriptions, external docs links |
| Warm Query Exposure | MCP tools return governed query results |
| Result Filtering | Filter data before it hits context window |
5. Observability & Audit
| Feature | Description |
|---|---|
| Comprehensive Audit | Every MCP call logged with identity |
| Cost Tracking | Token usage by tool, user, surface |
| Usage Analytics | Which tools are used, by whom |
| Compliance Ready | Audit logs for regulated industries |
Technical Architecture (Vision)
┌─────────────────────────────────────────────────────────────┐
│ AI Clients │
│ (Claude, GPT, Copilot, Custom Agents) │
└─────────────────────────┬───────────────────────────────────┘
│
▼
┌─────────────────────────────────────────────────────────────┐
│ OI Governed MCP Gateway │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Auth/ │ │ Catalog & │ │ Context │ │
│ │ AuthZ │ │ Discovery │ │ Optimizer │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
│ ┌─────────────┐ ┌─────────────┐ ┌─────────────┐ │
│ │ Approval │ │ Audit & │ │ Rate & │ │
│ │ Workflow │ │ Logging │ │ Cost │ │
│ └─────────────┘ └─────────────┘ └─────────────┘ │
└─────────────────────────┬───────────────────────────────────┘
│
┌───────────────┼───────────────┐
▼ ▼ ▼
┌──────────┐ ┌──────────┐ ┌──────────┐
│ Built-in │ │ Custom │ │ External │
│ MCP │ │ MCP │ │ MCP │
│ Servers │ │ Servers │ │ Servers │
└──────────┘ └──────────┘ └──────────┘
│ │ │
▼ ▼ ▼
┌──────────┐ ┌──────────┐ ┌──────────┐
│ Warm │ │ Your │ │ Third │
│ Queries │ │ APIs │ │ Party │
└──────────┘ └──────────┘ └──────────┘
API Gateway vs. MCP Gateway
Understanding why traditional API gateways aren't sufficient:
| Dimension | API Gateway | MCP Gateway |
|---|---|---|
| Traffic | North-South (edge) | East-West (internal) |
| Governance | Endpoint level | Function/Parameter level |
| State | Stateless | Stateful/Session-aware |
| Human-in-the-Loop | No | Yes (critical for AI) |
| Semantic Understanding | None | Tool semantics matter |
"Traditional API gateways only allow or deny requests — they lack the pause/resume model that's critical for safe AI agent control."
API gateways govern endpoints. MCP gateways govern capabilities. Control Planes govern everything.
Key Messaging
For Prospects
Short (10 seconds):
"Not just a gateway. The Control Plane for AI capabilities."
Medium (30 seconds):
"MCP gateways govern tool calls. OpenIndustrial governs the data, the tools, AND the calls. Because we're not a gateway - we're the Control Plane."
Full (60 seconds):
"Others pitch 'MCP governance' - but they're just a gateway layer you add on top. They govern tool calls, not data. They don't have warm queries. They don't have surfaces. They don't have Azi. OpenIndustrial is different. We ARE the Governed AI Control Plane. The MCP Gateway is how we extend that governance to any capability you want to add. Same approval workflow. Same audit trails. Same 'fire us and keep running' promise. That's not a gateway feature. That's category leadership."
vs. MCP Gateways
| What Gateways Say | What OI Says |
|---|---|
| "Governance layer for agents" | "Control Plane for industrial AI" |
| "Control data access" | "We control the data itself - warm queries, surfaces" |
| "Stable place for integrations" | "We ARE the integrations - your data, governed" |
| "Future-proofing" | "Fire us and keep running - your Azure tenant" |
Current Status
| Capability | Status |
|---|---|
MCP server endpoint (mcp.openindustrial.co) | SHIPPED |
| Claude MCP integration | SHIPPED |
| GPT/Copilot via adapters | SHIPPED |
| Governed catalog | Planned |
| Context optimization | Planned |
| Approval workflow for MCP | Planned |
| Full MCP Gateway | Q4 2026 |
What You Can Do Today
The foundation is working. While the full MCP Gateway is planned:
- Connect Any AI - MCP integration is SHIPPED
- Governance Loop - "Nothing without approval" is working
- Warm Queries - Your data layer, governed
- Guides - Complete walkthroughs
The pilot is how we BOTH learn if this is right. $15K. 4 weeks. Your Azure tenant. Run an experiment, not make a bet.
Related
- Roadmap Overview - All planned features
- MCP Integration Guide - Current MCP capabilities
- Autonomous Actions - Governed automation
- Schema Promotion - Governance for structure
On this page
- FrontmatterVersion: 1 DocumentType: Guide Title: "Governed MCP Gateway" Summary: "Planned for Q4 2026: one place to authenticate, authorize, rate-limit, catalog, and observe every MCP server your organization exposes." Created: 2026-01-19
- Governed MCP Gateway