MCP Gateway
One endpoint for every MCP server your agent needs — fetch tool schemas on demand instead of loading everything upfront.
MCP Gateway aggregates multiple MCP servers behind a single headless HTTP/SSE endpoint. Its Code Mode exposes four meta-tools (listToolFiles, readToolFile, getToolDocs, executeToolCode) so agents discover signatures lazily and execute them in a hermetic Starlark sandbox.
- CLI:
mcp-gway(canonical) ormgw(alias) - Admin UI:
mcp-gway serve --transport http→ http://127.0.0.1:8080/
Why MCP Gateway
- Fewer wasted tokens — Agents fetch only the schemas they need, when they need them.
- One connection to manage — Add, remove, or refresh servers in a single registry; agents connect to one endpoint.
- Safe local-first defaults — Binds to
127.0.0.1by default, screens local commands via an allowlist, masks secrets, and CSRF-protects the admin dashboard.
Who It's For
- Agent developers wiring Pi, Antigravity, Claude Desktop, Cursor, or any MCP-compatible client to multiple MCP servers through one gateway.
- Operators running local-first infrastructure who want a CLI and dashboard with health probes, Prometheus metrics, and structured JSON logs.
Quick Start
- Install:
pip install mcp-gway - Add a server:
mcp-gway add files --type local --command "npx -y @modelcontextprotocol/server-filesystem /path/to/dir" - List servers:
mcp-gway list - Serve HTTP:
mcp-gway serve --transport http - Connect: Point your agent to
http://127.0.0.1:8080/mcp
For more examples and transports, see the CLI Reference and Integrations.
Features
- Multi-Server Aggregation — Connect to multiple MCP servers (local or remote) and expose them through a single endpoint. One URL for every agent; one registry to manage.
- Code Mode — Four meta-tools let LLMs discover schemas on demand and execute them in a hermetic sandbox, avoiding the need to load all tool definitions upfront.
- OAuth 2.0 Support — Built-in OAuth flow with Dynamic Client Registration (RFC 7591) and secure token storage.
- Hermetic Sandbox — Starlark-based sandbox for safe, constrained code execution.
- MCP Protocol Compliant — Implements the Model Context Protocol over HTTP, SSE, and stdio.
- Local-First Security — Local-first design with SSRF guards, command allow-lists, and CSRF protection.
- Built-In Observability — Structured JSON logs, Prometheus metrics, and health probes built in.
Documentation
- Configuration & Usage — add servers, transports, and OAuth
- CLI Reference — commands, options, and the admin dashboard
- Code Mode — lazy-discovery meta-tools and the sandbox
- Security — local-first controls and command allow-lists
- Observability — JSON logs, Prometheus metrics, health probes
- Integrations — Claude Desktop, Pi, Antigravity, OpenCode
- Architecture — system diagram and transports
- Development — tests, lint, and pre-commit
Development
uv sync --all-groups
uv run pytest -v # 647 tests
See docs/development.md for checks, probes, and pre-commit.
License
Metadata
Release files for mcp-gway 4.5.7
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| mcp_gway-4.5.7.tar.gz | 101.2 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| mcp_gway-4.5.7-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 223.9 kB
Release files / mcp_gway-4.5.7.tar.gz
| Download URL | mcp_gway-4.5.7.tar.gz |
|---|---|
| Size | 101.2 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
0fe5919ef7a73b4a6972907879591dd093b135cb238e2851fac3bf077c85ec64
|
|
BLAKE2b-256 checksum How to use checksums |
f18baf12a21a68995725a8ef6d7b28f414334d6a7efe35adb8822ab58a73e144
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency logRelease files / mcp_gway-4.5.7-py3-none-any.whl
| Download URL | mcp_gway-4.5.7-py3-none-any.whl |
|---|---|
| Size | 122.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
a951ffe99e058c158024f08cd922e2476a25800ced3315004faff3416d21f5be
|
|
BLAKE2b-256 checksum How to use checksums |
81ef1885a67e1d2e28949a07e7b5a324ff3fd3a9e9774874782155b07d0089f6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 6, 2026.
Transparency log