Platform
Enterprise control plane for MCP servers, tools, and resources
Reference architecture
ForgeCrux Enterprise MCP Gateway
End-to-end specification: ingress, security, transformation, MCP context sync, models, data sources, and observability.
ForgeCrux Enterprise MCP Gateway architecture: end-to-end specification
ForgeCruxProbing Deeper, Stacking PrecisionClient & integrations
Traffic ingress layer
Model & data sources · installation models
Fully managed (SaaS)
SaaS → cache
Hybrid
SaaS control plane, on-prem gateway
Self-hosted
On-prem / private cloud Kubernetes
ForgeCrux Enterprise MCP Gateway
Transformation & optimization
MCP protocol translation
Model I/O normalization
Prompt engineering & caching
Model aggregation & chaining
Data transformation (vector embeddings)
Security & data privacy
PII/PHI detection & masking
RBAC (API & model level)
DLP prevention
Secret management (vault)
Encryption at rest/transit
Governance & compliance
Policy management
Quota, rate limit, cost
Audit logs & versioning
Model monitoring
Bias, fairness, accuracy
Cost allocation & reporting
Commercial LLMs
Azure AI, Bedrock, Vertex
Open source models
Ollama, vLLM, self-hosted
Databases
Vector, SQL, NoSQL
Legacy systems
SOAP / ESB / mainframe
Logging, observability & external integrations
Logs & APM
Datadog, Splunk
Metrics
Prometheus, Grafana
CI/CD pipelines
Actions, GitLab
Clouds
AWS, Azure, GCP, private
Centralized tool governance
Decide which agents, apps, and users can see or invoke each MCP tool and resource.
Secrets never leak to agents
ForgeCrux injects credentials at the gateway so models and agents never hold raw keys.
One virtual catalog
Compose dozens of MCP servers into a single governed endpoint with consistent identity and audit.
Key Capabilities
Complete MCP Gateway capabilities
Everything required to publish, secure, mediate, observe, and operate mcp gateway workloads on ForgeCrux.
Registry, discovery, and virtual servers
Make every MCP server visible, versioned, and composable.
- Central registry for internal, SaaS, and third-party MCP servers
- Health checks, versions, and capability advertisements
- Dynamic discovery of tools, resources, resource templates, and prompts
- Namespacing and aliases so tools do not collide across servers
- Virtual MCP servers that fan-in many backends to one client endpoint
- Allow lists and deny lists of tools per virtual server
- Schema validation for tool input and output JSON
- Prompt templates and resource subscriptions through the gateway
- Stdio, SSE, Streamable HTTP, and WebSocket transports
- On-prem, VPC, and SaaS server connectivity
Identity, OAuth, and authorization
Authenticate clients and authorize every tool invocation.
- OAuth 2.0 and OIDC for human and workload clients
- API keys, mTLS, and SPIFFE/workload identity
- SSO mapping from enterprise IdP to MCP sessions
- RBAC and ABAC at server, tool, resource, and parameter level
- Just-in-time and human-in-the-loop approval for sensitive tools
- Session binding so a client cannot invoke another tenant’s tools
- Scoped down tool arguments (path, project, account) by policy
- Delegation and on-behalf-of tokens for agent chains
Credentials, secrets, and data protection
Keep backend credentials in the vault, not in prompts or agent memory.
- Encrypted credential vault per server and per tool
- Automatic token refresh and rotation
- Secret injection at invocation time
- Egress allow lists and DLP on tool payloads
- PII redaction on tool arguments and results
- Data residency and environment isolation
- Bring-your-own KMS and HSM-backed keys
- No raw secrets in traces or logs
Policies, traffic, and safety
Treat tool calls like production API traffic.
- Allow, deny, transform, and mock policies
- Rate limits, concurrency limits, and quotas per tool
- Retries, timeouts, and circuit breakers
- Argument rewriting and response filtering
- Dry-run and shadow mode for new tools
- Sandboxing and network egress control
- Malicious tool-call and prompt-injection defenses
- Change windows and break-glass procedures
Observability and analytics
See every list, read, subscribe, and call.
- Audit log of discovery and invocation with actor and policy
- Latency, error, and timeout metrics per tool and server
- Usage analytics by agent, app, team, and tool
- Distributed traces linking agent → MCP → backend
- Cost attribution when tools trigger paid APIs
- Anomaly detection on unusual tool sequences
- OpenTelemetry export
- Retention, legal hold, and export for compliance
Platform and developer experience
Ship MCP to production with enterprise operations.
- MCP-compatible client endpoint for Cursor, Claude, and custom agents
- SDKs, CLI, and REST APIs to register servers
- Terraform and Kubernetes operators
- Environments, revisions, and promotion pipelines
- Catalog UI for operators and a filtered catalog for agents
- Contract tests for tool schemas in CI
- Multi-cloud, on-prem, and air-gapped runtimes
- High availability and horizontal scale
How teams run MCP Gateway on ForgeCrux
Register servers
Add internal and SaaS MCP servers to the registry, attach credentials, and verify health and advertised tools.
Compose virtual catalogs
Build virtual MCP servers that expose only the tools each team or agent is allowed to see.
Authorize at tool level
Map IdP groups and agent identities to RBAC/ABAC rules down to arguments and resources.
Keep secrets in the vault
Remove keys from agent configs. ForgeCrux injects them on each governed invocation.
Turn on audit
Require traces and audit logs before production agents can call mutating tools.
Operate like APIs
Apply rate limits, SLOs, and promotion workflows so MCP is a production surface, not a side channel.
Related Products
Agent Gateway
ForgeCrux Agent Gateway gives every agent an identity, permissions, routing, memory controls, guardrails, tracing, evaluation, cost limits, and lifecycle—so multi-agent systems can reach models, APIs, MCP tools, and data without unmanaged autonomy.
AI Gateway
ForgeCrux AI Gateway is the single endpoint for multi-model access, intelligent routing, prompt control, guardrails, token and cost management, evaluation, and LLM observability—across OpenAI, Anthropic, Gemini, Bedrock, Azure OpenAI, and self-hosted models.
Control Plane
ForgeCrux One is the enterprise control plane for APIs, AI models, MCP tools, and agents. Platform, security, and SRE teams use it to install, configure, govern, and operate every gateway from one catalog, one policy engine, and one audit trail—across SaaS, hybrid, and air-gapped footprints.
Ready to get started with MCP Gateway?
Talk to our team about deploying MCP Gateway in your enterprise environment.