{"repo":"openziti/mcp-gateway","free":true,"listed":false,"github":"https://github.com/openziti/mcp-gateway","clone":"git clone https://github.com/openziti/mcp-gateway.git","description":"Zero trust gateway for MCP servers. Aggregate, filter, and securely access MCP tools from anywhere without VPNs, open ports, or exposed endpoints. Built on OpenZiti, zrok, and Agora with cryptographic identity, mTLS, per-client isolation, and tool-level permission control.","language":"Go","stars":45,"topics":["mcp-gateway","zero-trust","agentic-ai","ai-infrastructure","ai-tools","e2e-encryption","mcp","mcp-aggregator","mcp-proxy","mcp-server"],"license":"Apache-2.0","category":"mcp-servers","readme_excerpt":"MCP Gateway Zero-trust access to MCP tools over OpenZiti MCP Gateway lets AI assistants securely access internal tools without exposing public endpoints. Built on OpenZiti, zrok, and Agora, it provides cryptographically secure, zero trust connectivity with no attack surface. MCP Gateway is sponsored by NetFoundry as part of its portfolio of solutions for secure workloads and agentic computing. NetFoundry is the creator of OpenZiti and zrok. The Trifecta Three simple components that work together: Component Purpose ----------- --------- mcp-tools Connects MCP clients to remote zrok shares or Agora tunnels (stdio or HTTP) mcp-gateway Aggregates multiple backends into one secure endpoint over zrok and/or Agora mcp-bridge Exposes a single MCP server to the network over zrok or Agora Why? Problem: MCP servers typically run locally via stdio. To access tools on remote machines or share them across a team, you need to expose endpoints—creating security risks. Securing exposed MCP tooling can be complicated. Solution: MCP Gateway uses OpenZiti's overlay network to create \"dark services\" that: - Never listen on public IPs - Require cryptographic identity to access - Work through NATs and firewalls without port forwarding - Can publish and serve through Agora catalogs and Layer 1 tunnels - Are incredibly simple to deploy securely Quick Start New to MCP Gateway? See the Getting Started Guide for a complete walkthrough. 1. Install 2. Enable zrok Note: mcp-gateway requires zrok v2.0.x or ","default_branch":null,"files":null,"tree":[],"storefront":"/r/openziti","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/openziti/mcp-gateway/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}