Skip to main content

MCP Gateway

Tests Release PyPI version Python License Code Style: Ruff PyPI Downloads MCP Protocol Code Mode Local-First Security Observability Built-in

One endpoint for every MCP server your agent needs — fetch tool schemas on demand instead of loading everything upfront.

MCP Gateway aggregates multiple MCP servers behind a single headless HTTP/SSE endpoint. Its Code Mode exposes four meta-tools (listToolFiles, readToolFile, getToolDocs, executeToolCode) so agents discover signatures lazily and execute them in a hermetic Starlark sandbox.

  • CLI: mcp-gway (canonical) or mgw (alias)
  • Admin UI: mcp-gway serve --transport http → http://127.0.0.1:8080/

Why MCP Gateway

  • Fewer wasted tokens — Agents fetch only the schemas they need, when they need them.
  • One connection to manage — Add, remove, or refresh servers in a single registry; agents connect to one endpoint.
  • Safe local-first defaults — Binds to 127.0.0.1 by default, screens local commands via an allowlist, masks secrets, and CSRF-protects the admin dashboard.

Who It's For

  • Agent developers wiring Pi, Antigravity, Claude Desktop, Cursor, or any MCP-compatible client to multiple MCP servers through one gateway.
  • Operators running local-first infrastructure who want a CLI and dashboard with health probes, Prometheus metrics, and structured JSON logs.

Quick Start

  1. Install: pip install mcp-gway
  2. Add a server: mcp-gway add files --type local --command "npx -y @modelcontextprotocol/server-filesystem /path/to/dir"
  3. List servers: mcp-gway list
  4. Serve HTTP: mcp-gway serve --transport http
  5. Connect: Point your agent to http://127.0.0.1:8080/mcp

For more examples and transports, see the CLI Reference and Integrations.

Features

  • Multi-Server Aggregation — Connect to multiple MCP servers (local or remote) and expose them through a single endpoint. One URL for every agent; one registry to manage.
  • Code Mode — Four meta-tools let LLMs discover schemas on demand and execute them in a hermetic sandbox, avoiding the need to load all tool definitions upfront.
  • OAuth 2.0 Support — Built-in OAuth flow with Dynamic Client Registration (RFC 7591) and secure token storage.
  • Hermetic Sandbox — Starlark-based sandbox for safe, constrained code execution.
  • MCP Protocol Compliant — Implements the Model Context Protocol over HTTP, SSE, and stdio.
  • Local-First Security — Local-first design with SSRF guards, command allow-lists, and CSRF protection.
  • Built-In Observability — Structured JSON logs, Prometheus metrics, and health probes built in.

Documentation

Development

uv sync --all-groups
uv run pytest -v   # 647 tests

See docs/development.md for checks, probes, and pre-commit.

License

MIT

Metadata

Release files for mcp-gway 4.5.7

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for mcp-gway 4.5.7
File Size Uploaded
mcp_gway-4.5.7.tar.gz 101.2 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for mcp-gway 4.5.7
File Interpreter ABI Platform
mcp_gway-4.5.7-py3-none-any.whl Python 3 none any Details

Total release size: 223.9 kB

Release files / mcp_gway-4.5.7.tar.gz

Download URL mcp_gway-4.5.7.tar.gz
Size 101.2 kB
Tags Source
SHA-256 checksum
How to use checksums
0fe5919ef7a73b4a6972907879591dd093b135cb238e2851fac3bf077c85ec64
BLAKE2b-256 checksum
How to use checksums
f18baf12a21a68995725a8ef6d7b28f414334d6a7efe35adb8822ab58a73e144
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release files / mcp_gway-4.5.7-py3-none-any.whl

Download URL mcp_gway-4.5.7-py3-none-any.whl
Size 122.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
a951ffe99e058c158024f08cd922e2476a25800ced3315004faff3416d21f5be
BLAKE2b-256 checksum
How to use checksums
81ef1885a67e1d2e28949a07e7b5a324ff3fd3a9e9774874782155b07d0089f6
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

4.5.7 This release

2 release files

4.5.6

2 release files

4.5.5

2 release files

4.5.4

2 release files

4.5.3

2 release files

4.5.2

2 release files

4.5.1

2 release files

4.5.0

2 release files

4.4.0

2 release files

4.3.0

2 release files

4.2.0

2 release files

4.1.0

2 release files

4.0.0

2 release files

3.2.0

2 release files

3.1.0

2 release files

3.0.1

2 release files

3.0.0

2 release files

2.11.3

2 release files

2.11.2

2 release files

2.5.0

2 release files

2.4.0

2 release files

2.3.0

2 release files

2.2.1

2 release files

2.2.0

2 release files

2.1.2

2 release files

2.1.1

2 release files

2.1.0

2 release files

2.0.1

2 release files

2.0.0

2 release files

1.6.2

2 release files

1.6.1

2 release files

1.6.0

2 release files

1.5.1

2 release files

1.5.0

2 release files

1.4.2

2 release files

1.4.1

2 release files

1.4.0

2 release files

1.3.5

2 release files

1.3.4

2 release files

1.3.3

2 release files

1.3.2

2 release files

1.3.1

2 release files

1.3.0

2 release files

1.2.0

2 release files

1.1.0

2 release files

1.0.2

2 release files

1.0.1

2 release files

1.0.0

2 release files

0.9.1

2 release files

0.9.0

2 release files

0.8.0

2 release files

0.7.2

2 release files

0.7.1

2 release files

0.7.0

2 release files

0.6.0

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.4

2 release files

0.4.3

2 release files

0.4.2

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.0

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.4

2 release files

0.1.3

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page