Enterprise · MCP gateway · Coming soon
One door to every MCP tool. Every call allowed, checked and logged.
People are plugging MCP servers into Claude, ChatGPT, Cursor and their own agents, each with its own tokens and no oversight. The AgentWorks MCP Gateway gives your company one MCP endpoint: admins connect servers once, every client signs in, and each tool call is checked against policy and recorded.
- 01MCP tokens live on every laptopEach person connects servers with their own keys, so access can't be reviewed or revoked in one place.
- 02Anyone can call any toolThere is no way to say which team may use which server, let alone which individual tool.
- 03Sensitive data flows out unseenCustomer data can leave through tool arguments and results with no masking and no record.
Example goal
Every MCP tool call governed
of calls through the gateway, target 100%. Illustrative numbers.
How it works
Connect once. Govern every call.
Connect servers once
Admins add upstream MCP servers to the gateway, from a catalog or by pasting their config.
Grant by group
Access is deny by default. Grant a group a whole server or single tools; services use group API keys.
Approve and inspect
New tools and changed tool versions wait for approval. PII rules mask, block or send sensitive values to review.
Audit everything
Every call is logged with who, which tool and what happened, with usage history and CSV or JSON export.
What it includes
Built for your security review. From day one.
In private preview with design partners. Book a call to join and shape the first release.
- One MCP endpoint for Claude, ChatGPT, Cursor and AgentWorks crews
- OAuth sign-in for MCP clients, group API keys for services
- Deny-by-default grants per group, server or single tool
- Approval for new tools and changed tool versions
- PII masking, blocking and a human review queue
- Egress guards against private-network calls
- Audit log and usage history with CSV and JSON export
- Admin console for users, groups, servers and rules
Built for your security review
Runs in your cloud. Every action on the record.
Self-hosted
Deployed in your cloud account or data center. Evidence stays in your environment.
Approvals
Anything that changes production or reaches people waits for approval by default.
Audit trail
Every run, tool call, decision and cost is recorded per workflow.
Your models
Your enterprise Claude, ChatGPT or Gemini agreements, or private endpoints.
Scoped access
Tools, folders and secrets are granted per workflow, inside an OS-enforced sandbox.
SSO and roles
Sign-in through your identity provider, with roles and per-workflow access.
FAQ
Questions, answered.
When is it available?
It is in private preview with design partners now. Book a call to join, and we will tell you the release date as soon as it is set.
Which MCP clients work with it?
Any client that can connect to a remote MCP server, such as Claude, ChatGPT, Cursor and AgentWorks crews. Clients sign in with OAuth.
Does it use AI to find sensitive data?
No. PII rules are deterministic and bounded, so results are predictable. Matching values are masked, blocked, or held for a person to review.
Where does it run?
In your own cloud or data center, next to AgentWorks or on its own.
More use cases
Other goals agents can own.
Govern MCP before it sprawls. Join the early access.
We are onboarding a small group of design partners. Tell us which MCP servers and clients you use, and we will set up the gateway with you.