Platform

Enterprise control plane for MCP servers, tools, and resources

ForgeCrux MCP Gateway is the governed fabric for Model Context Protocol: server registry, tool discovery, OAuth, RBAC, credentials, virtual servers, traffic control, and full audit of every tool call.

Reference architecture

ForgeCrux Enterprise MCP Gateway

End-to-end specification: ingress, security, transformation, MCP context sync, models, data sources, and observability.

ForgeCrux Enterprise MCP Gateway architecture: end-to-end specification

ForgeCruxProbing Deeper, Stacking Precision

Client & integrations

Mobile devices
Web apps
B2B partners
Developer tools

Traffic ingress layer

IngressWAF, DDoS, API Gateway
Authentication & authorizationmTLS, JWT, OAuth 2.0, IAM

Model & data sources · installation models

Fully managed (SaaS)

SaaS → cache

Hybrid

SaaS control plane, on-prem gateway

Self-hosted

On-prem / private cloud Kubernetes

ForgeCrux Enterprise MCP Gateway

Transformation & optimization

MCP protocol translation

Model I/O normalization

Prompt engineering & caching

Model aggregation & chaining

Data transformation (vector embeddings)

Security & data privacy

PII/PHI detection & masking

RBAC (API & model level)

DLP prevention

Secret management (vault)

Encryption at rest/transit

Governance & compliance

Policy management

Quota, rate limit, cost

Audit logs & versioning

Model monitoring

Bias, fairness, accuracy

Cost allocation & reporting

MCP context syncContextually bridging models · reused and expanding

Commercial LLMs

Azure AI, Bedrock, Vertex

Open source models

Ollama, vLLM, self-hosted

Databases

Vector, SQL, NoSQL

Legacy systems

SOAP / ESB / mainframe

Logging, observability & external integrations

Logs & APM

Datadog, Splunk

Metrics

Prometheus, Grafana

CI/CD pipelines

Actions, GitLab

Clouds

AWS, Azure, GCP, private

Unified governance, robust security, optimized multi-model integration for Agentic AIReused

Centralized tool governance

Decide which agents, apps, and users can see or invoke each MCP tool and resource.

Secrets never leak to agents

ForgeCrux injects credentials at the gateway so models and agents never hold raw keys.

One virtual catalog

Compose dozens of MCP servers into a single governed endpoint with consistent identity and audit.

Key Capabilities

MCP server registry for internal, SaaS, and partner servers
Dynamic tool, resource, and prompt discovery
OAuth 2.0, OIDC, API keys, and mTLS for MCP clients
Tool-level RBAC and ABAC authorization
Credential vault with per-tool secret isolation
Virtual MCP servers that compose many backends into one
Tool policies: allow, deny, transform, rate-limit, and approve
Traffic management, retries, and circuit breakers for tools
Audit logging of every list/call/read/subscribe
MCP observability: latency, errors, and usage analytics
Sandboxed execution and egress controls
Stdio, SSE, Streamable HTTP, and remote MCP transports

Complete MCP Gateway capabilities

Everything required to publish, secure, mediate, observe, and operate mcp gateway workloads on ForgeCrux.

Registry, discovery, and virtual servers

Make every MCP server visible, versioned, and composable.

  • Central registry for internal, SaaS, and third-party MCP servers
  • Health checks, versions, and capability advertisements
  • Dynamic discovery of tools, resources, resource templates, and prompts
  • Namespacing and aliases so tools do not collide across servers
  • Virtual MCP servers that fan-in many backends to one client endpoint
  • Allow lists and deny lists of tools per virtual server
  • Schema validation for tool input and output JSON
  • Prompt templates and resource subscriptions through the gateway
  • Stdio, SSE, Streamable HTTP, and WebSocket transports
  • On-prem, VPC, and SaaS server connectivity

Identity, OAuth, and authorization

Authenticate clients and authorize every tool invocation.

  • OAuth 2.0 and OIDC for human and workload clients
  • API keys, mTLS, and SPIFFE/workload identity
  • SSO mapping from enterprise IdP to MCP sessions
  • RBAC and ABAC at server, tool, resource, and parameter level
  • Just-in-time and human-in-the-loop approval for sensitive tools
  • Session binding so a client cannot invoke another tenant’s tools
  • Scoped down tool arguments (path, project, account) by policy
  • Delegation and on-behalf-of tokens for agent chains

Credentials, secrets, and data protection

Keep backend credentials in the vault, not in prompts or agent memory.

  • Encrypted credential vault per server and per tool
  • Automatic token refresh and rotation
  • Secret injection at invocation time
  • Egress allow lists and DLP on tool payloads
  • PII redaction on tool arguments and results
  • Data residency and environment isolation
  • Bring-your-own KMS and HSM-backed keys
  • No raw secrets in traces or logs

Policies, traffic, and safety

Treat tool calls like production API traffic.

  • Allow, deny, transform, and mock policies
  • Rate limits, concurrency limits, and quotas per tool
  • Retries, timeouts, and circuit breakers
  • Argument rewriting and response filtering
  • Dry-run and shadow mode for new tools
  • Sandboxing and network egress control
  • Malicious tool-call and prompt-injection defenses
  • Change windows and break-glass procedures

Observability and analytics

See every list, read, subscribe, and call.

  • Audit log of discovery and invocation with actor and policy
  • Latency, error, and timeout metrics per tool and server
  • Usage analytics by agent, app, team, and tool
  • Distributed traces linking agent → MCP → backend
  • Cost attribution when tools trigger paid APIs
  • Anomaly detection on unusual tool sequences
  • OpenTelemetry export
  • Retention, legal hold, and export for compliance

Platform and developer experience

Ship MCP to production with enterprise operations.

  • MCP-compatible client endpoint for Cursor, Claude, and custom agents
  • SDKs, CLI, and REST APIs to register servers
  • Terraform and Kubernetes operators
  • Environments, revisions, and promotion pipelines
  • Catalog UI for operators and a filtered catalog for agents
  • Contract tests for tool schemas in CI
  • Multi-cloud, on-prem, and air-gapped runtimes
  • High availability and horizontal scale

How teams run MCP Gateway on ForgeCrux

Register servers

Add internal and SaaS MCP servers to the registry, attach credentials, and verify health and advertised tools.

Compose virtual catalogs

Build virtual MCP servers that expose only the tools each team or agent is allowed to see.

Authorize at tool level

Map IdP groups and agent identities to RBAC/ABAC rules down to arguments and resources.

Keep secrets in the vault

Remove keys from agent configs. ForgeCrux injects them on each governed invocation.

Turn on audit

Require traces and audit logs before production agents can call mutating tools.

Operate like APIs

Apply rate limits, SLOs, and promotion workflows so MCP is a production surface, not a side channel.

Ready to get started with MCP Gateway?

Talk to our team about deploying MCP Gateway in your enterprise environment.