Enterprise · MCP gateway · Coming soon

One door to every MCP tool. Every call allowed, checked and logged.

People are plugging MCP servers into Claude, ChatGPT, Cursor and their own agents, each with its own tokens and no oversight. The AgentWorks MCP Gateway gives your company one MCP endpoint: admins connect servers once, every client signs in, and each tool call is checked against policy and recorded.

  • 01
    MCP tokens live on every laptopEach person connects servers with their own keys, so access can't be reviewed or revoked in one place.
  • 02
    Anyone can call any toolThere is no way to say which team may use which server, let alone which individual tool.
  • 03
    Sensitive data flows out unseenCustomer data can leave through tool arguments and results with no masking and no record.

Example goal

Every MCP tool call governed

Primary metricTool calls with a grant and an audit record
100%

of calls through the gateway, target 100%. Illustrative numbers.

How it works

Connect once. Govern every call.

  1. Connect servers once

    Admins add upstream MCP servers to the gateway, from a catalog or by pasting their config.

  2. Grant by group

    Access is deny by default. Grant a group a whole server or single tools; services use group API keys.

  3. Approve and inspect

    New tools and changed tool versions wait for approval. PII rules mask, block or send sensitive values to review.

  4. Audit everything

    Every call is logged with who, which tool and what happened, with usage history and CSV or JSON export.

What it includes

Built for your security review. From day one.

In private preview with design partners. Book a call to join and shape the first release.

  • One MCP endpoint for Claude, ChatGPT, Cursor and AgentWorks crews
  • OAuth sign-in for MCP clients, group API keys for services
  • Deny-by-default grants per group, server or single tool
  • Approval for new tools and changed tool versions
  • PII masking, blocking and a human review queue
  • Egress guards against private-network calls
  • Audit log and usage history with CSV and JSON export
  • Admin console for users, groups, servers and rules

Built for your security review

Runs in your cloud. Every action on the record.

  • Self-hosted

    Deployed in your cloud account or data center. Evidence stays in your environment.

  • Approvals

    Anything that changes production or reaches people waits for approval by default.

  • Audit trail

    Every run, tool call, decision and cost is recorded per workflow.

  • Your models

    Your enterprise Claude, ChatGPT or Gemini agreements, or private endpoints.

  • Scoped access

    Tools, folders and secrets are granted per workflow, inside an OS-enforced sandbox.

  • SSO and roles

    Sign-in through your identity provider, with roles and per-workflow access.

FAQ

Questions, answered.

When is it available?

It is in private preview with design partners now. Book a call to join, and we will tell you the release date as soon as it is set.

Which MCP clients work with it?

Any client that can connect to a remote MCP server, such as Claude, ChatGPT, Cursor and AgentWorks crews. Clients sign in with OAuth.

Does it use AI to find sensitive data?

No. PII rules are deterministic and bounded, so results are predictable. Matching values are masked, blocked, or held for a person to review.

Where does it run?

In your own cloud or data center, next to AgentWorks or on its own.

Govern MCP before it sprawls. Join the early access.

We are onboarding a small group of design partners. Tell us which MCP servers and clients you use, and we will set up the gateway with you.