TL;DR
- Cloudflare MCP server portals are our first shortlist for workforce access when the company already uses Cloudflare One. Portals became generally available on 24 September 2026.
- Portkey's MCP Gateway, now presented within Prisma AIRS AI Gateway, suits teams consolidating authentication, tool permissions and call observability across existing servers.
- Composio is stronger when the buying problem includes maintaining SaaS connections and OAuth, as well as managing who can call the tools.
- Kong AI Gateway Enterprise fits existing Kong estates and API-to-MCP exposure. Its AI MCP Proxy is an Enterprise feature, not a free community plugin.
- Microsoft's open MCP Gateway project fits an engineering team that wants Kubernetes deployment and Entra-based access under its own operation.
- MCP Gateway at mcpgateway.com is a different, Kinetic Solutions Group product. Its documented session scoping is relevant, but public deployment routes are marked “Coming Soon”; it is an emerging option rather than our default new deployment.
- Compare credentials and tool authority, not just the list of tools an agent can see. A gateway must prevent unauthorised calls, while the action service still checks the client record and approved revision.
What a GTM gateway should control
An MCP gateway sits between an agent's MCP client and the servers that expose tools. For a sales operation, those tools may read a CRM account, enrich a company, retrieve documents, prepare an email or change an opportunity. Centralising the connection helps when several agents, users and client workspaces otherwise carry separate configurations and credentials.
The important purchase question is what the gateway actually enforces. Authentication establishes the caller. Authorisation determines the servers and tools that caller may use. Credential handling determines which upstream account performs the action. Observability records the request and result. Routing keeps the connection working across servers and sessions.
Those controls have different consequences. Restricting discovery can reduce clutter, but a hidden tool must also reject a direct invocation. A tool allowlist can prevent email sending, but it does not necessarily prevent a permitted CRM update from targeting the wrong client's record. A rate limit can reduce volume, but it does not decide whether one proposed discount was approved.
Use a gateway for shared access and connection management. Keep business rules in the action service: account ownership, permitted fields, suppression, approval revision and the stable action identifier. This produces a useful division of responsibility without asking the gateway to become the CRM or the agent's durable workflow engine.
The comparison
The following uses official public documentation and pricing accessed on 1 October 2026. Commercial bases are shown where supported; an adjacent platform price is not presented as the price of a complete MCP deployment.
| Option and exact identity | Deployment and availability | Relevant authentication and policy | Pricing basis | Best fit / non-fit |
|---|---|---|---|---|
| Cloudflare MCP server portals | Managed Cloudflare One feature; generally available | Access login, upstream OAuth, selected tools; optional Gateway inspection | Cloudflare One packaging; free proof-of-concept route, commercial features depend on package; Enterprise for Logpush | Existing workforce-access estate / weak fit for replacing a large SaaS connector library |
| Portkey MCP Gateway / Prisma AIRS AI Gateway | Managed platform, with enterprise deployment options | API key or IdP identity, upstream credential injection, server and tool provisioning, logs | Published Production platform base $49/month; complete enterprise MCP scope uses commercial terms | Existing MCP servers and AI platform management / base price alone does not establish private deployment or every MCP entitlement |
| Composio MCP Gateway | Managed service; enterprise private and self-hosted options | Managed OAuth, connections, action policies and enterprise identity | Pro $29/month with usage credit; metered calls and add-ons; Enterprise custom | SaaS connection maintenance and agent tool access / small Pro price is not Enterprise SSO and SCIM |
| Kong AI MCP Proxy | Kong AI Gateway Enterprise, Gateway 3.12 or newer | Kong authentication, ACL and traffic-management plugins around MCP | AI Gateway Enterprise licence and deployment; supported contract basis | Existing Kong APIs and gateway team / unsuitable as a supposedly free standalone MCP proxy |
| Microsoft/mcp-gateway | MIT-licensed Kubernetes-oriented project | Entra ID and application roles, session-aware routing, lifecycle APIs | No project licence fee; infrastructure and engineering operation | Kubernetes/Entra engineering team / not an included managed Azure gateway subscription |
| KSG MCP Gateway, mcpgateway.com | Product documentation and production-case claims; public deployment options marked coming soon | Bearer API keys, OAuth and session allow/deny tool scoping | No public numerical tariff; cluster-based marketplace model is described but forthcoming | Emerging integrated tools/skills/sandbox platform / not our immediate self-service choice |
The shortlist includes the useful names from the existing draft and research, while correcting the generic “MCP Gateway” identity. The Microsoft repository and the KSG website are separate projects. Cloudflare's workforce portal is also distinct from its model-request AI Gateway.
Six named options
1. Cloudflare MCP server portals: workforce access to existing servers
Cloudflare's portals consolidate upstream MCP servers behind one endpoint. Users authenticate through Access and separately authorise an upstream server when it requires OAuth. Administrators can customise exposed tools and prompts. The current guide supports Streamable HTTP and legacy SSE upstream connections; routing through Gateway for inspection requires Streamable HTTP. Cloudflare portal documentation.
The current product is generally available, following the 24 September 2026 announcement. That supersedes older descriptions of an open beta. Cloudflare One changelog.
For a company already using Access, a portal gives sales users a familiar identity boundary for approved internal and SaaS MCP servers. Start with a CRM read server and an account-research server, then add narrowly authorised write actions. Keep tool selection aligned with the user's job rather than exposing every server to every employee.
Optional Gateway routing adds HTTP policy and DLP inspection to real-time portal calls. Background server synchronisation does not take that path. Enterprise Logpush exports portal logs. These distinctions matter when the requirement is exported audit history or inspection of every data path, rather than just seeing calls in a dashboard.
The current public pricing page presents Cloudflare One packaging through a commercial discussion and a free proof-of-concept route; it does not establish an all-in numerical portal tariff. Use the company's existing Access/Gateway package as the cost basis and include the required logging and DLP scope. Do not import an old seat price and assume it buys Enterprise log export. Cloudflare pricing.
Choose this when workforce identity and access are already Cloudflare responsibilities. Choose Composio instead when the larger problem is maintaining application integrations and connected accounts that do not yet have suitable MCP servers.
2. Portkey MCP Gateway: permissions and visibility across servers
Portkey documents an MCP proxy that authenticates a client, checks access to the server and tool, injects upstream credentials and logs the call. It supports API keys or identity-provider tokens at the gateway, with OAuth, API keys or identity headers upstream. Tool provisioning can disable particular tools for a user. Portkey MCP Gateway documentation.
This is a concrete MCP capability, rather than simply reusing Portkey's model-routing name. The current documentation also presents Portkey as Prisma AIRS AI Gateway. We retain “Portkey” to identify the product and documentation that existing buyers will recognise.
A practical fit is an organisation with several internally maintained MCP servers and a platform team already centralising AI access. Sales research users can receive read tools, while a service identity receives a separate write capability. The gateway becomes the place to provision access and investigate calls without handing every user the underlying CRM credential.
The published Production platform price is $49/month, with 100,000 recorded logs, 30-day log retention and $9 overage per additional 100,000 requests. Enterprise uses custom terms for private deployment and more advanced requirements. Treat $49 as the supported platform base, not proof of a complete Enterprise MCP contract. Portkey pricing.
Portkey's documentation describes full request and response logging. For an agent handling client records, choose the appropriate payload retention and redaction policy rather than assuming only metadata is collected. Its strength is centralising an existing server estate; it does not eliminate the work of building a correct Salesforce or HubSpot action behind those servers.
3. Composio: managed connections alongside tool access
Composio combines its application toolkits and OAuth connection management with a gateway for managed and custom MCP servers. Its gateway page describes action-level policies, identity controls and call metadata, with enterprise private or self-hosted deployment options. That makes it relevant when connections, token refresh and access management are all part of the buying problem. Composio MCP Gateway.
For an agency, the useful unit is the authorised connected account. Each client's CRM or mail account should remain distinct; a shared gateway endpoint should not collapse those credentials into one broadly privileged service account. The operational benefit is maintaining connections centrally while the application supplies the correct client context.
The current Pro plan is $29/month, with a $29 monthly usage credit. For the own-app, API-key or MCP pricing category, the published allowance is 100,000 tool executions and 50,000 delivered trigger events per month; subsequent rates are $0.0003 per tool call and $0.003 per trigger. Composio-managed OAuth apps have a lower included allowance and different rates. SSO and SCIM belong to Enterprise. Composio pricing.
The low entry price is useful for a scoped integration, but the cost changes with architecture. Shared connections, direct execution outside Sessions, proxy execution and zero-data-retention features have separate add-on bases. A price comparison should state whether agents run in Sessions and whether each person uses their own connected account.
Choose Composio when the team would otherwise spend time maintaining multiple SaaS authorisation flows. Choose Kong or Microsoft when internally hosted APIs and platform infrastructure are the dominant requirement. A broad connector library does not, by itself, establish the permitted business fields for each client.
4. Kong AI Gateway Enterprise: MCP within an API estate
Kong's AI MCP Proxy can front upstream MCP servers, translate REST APIs into MCP tools or aggregate tool sets. It requires AI Gateway Enterprise and Kong Gateway 3.12 or newer. Authentication, ACLs, rate limiting and observability can use Kong's plugin ecosystem. The MCP request path is separate from the LLM-request plugin flow. AI MCP Proxy documentation.
This is a strong fit for a platform team already exposing sales and operations APIs through Kong. Existing resource boundaries can become narrowly defined tools: read an account, retrieve a renewal date or submit an approved change. It avoids treating the whole underlying API as an undifferentiated tool.
The commercial basis is the Enterprise feature entitlement, gateway deployment and operating scope. Kong publishes several platform meters and add-ons, but a model-proxy price is not an MCP tool-call price. Fully self-hosted Gateway Enterprise uses custom pricing. Use those supported commercial bases rather than assigning an unrelated $100-per-model amount to this deployment. Kong pricing.
For a company already operating Kong, the incremental work can be much smaller than introducing another access platform. For a small sales team with no gateway engineering capability, that advantage disappears. Composio or Cloudflare is a more practical first purchase, depending on whether connections or workforce access drive the need.
5. Microsoft MCP Gateway: operate the project yourself
Microsoft's mcp-gateway project is a reverse proxy and management layer for Kubernetes environments. It includes session-aware routing, server lifecycle management, a tool router and Entra authentication with application roles. The official repository is MIT-licensed. Microsoft project documentation, repository.
That identity matters: this is an open project maintained under Microsoft's repository, not a blanket promise that Azure includes a supported managed MCP service for free. The team owns its deployment, storage, telemetry, updates and availability.
The source describes basic role-based access for registered resources. That provides a useful platform boundary, but it does not imply every field inside an allowed CRM update has an application policy. Build the business checks in the action service and select appropriately narrow upstream credentials.
Its optional agent/session execution subsystem is separately marked preview and single-replica, with cautions for multi-tenant production. The gateway's routing role should not be confused with that optional execution feature. For the ten-client design below, the recommendation is the gateway and controlled action services, not enabling preview in-process agent execution as a tenant sandbox.
Choose this when a Kubernetes and Entra team wants to own the implementation and can maintain it. There is no project licence fee, but the example budget below shows why that does not make the complete deployment costless.
6. KSG MCP Gateway: an emerging tools, skills and sandbox platform
The product at mcpgateway.com belongs to Kinetic Solutions Group, not the Microsoft repository. Its documentation covers servers, skills, sandboxes and session-level tool scoping. Bearer API keys and OAuth are documented authentication routes. Product site, authentication documentation.
Its session scoping is particularly relevant: allow and deny patterns apply across listing, search, execution and direct tool calls, with deny taking precedence. An omitted allowlist is unrestricted within the available session scope. For a client-specific research agent, use an explicit narrow list rather than relying on the default. Session scoping documentation.
The public site claims production use in named case studies, while its self-hosted Helm, cloud marketplace and OpenShift deployment routes are marked Coming Soon. It describes flat per-cluster marketplace pricing without publishing a numerical tariff. The strongest practical interpretation is an emerging product with documented capabilities, not a currently established self-service purchase route.
We would therefore retain it as a future consideration for a team wanting tools, skills and sandbox management together. For an immediate rollout, choose one of the available managed routes or the operable Microsoft project. That resolves the buying decision without pretending the forthcoming marketplace offer already has a price or downloadable production package.
A ten-client access design
Consider an agency with ten clients, 20 staff and six tool services: CRM reading, enrichment, document retrieval, draft creation, an approved-send action and CRM updates. This is an editorial design, not a deployed comparative test.
Assign the caller a trusted client context from its authenticated identity. The research role receives read, enrichment and draft tools. It does not receive the send tool. A separate execution identity may call send_approved_message, which accepts an action ID and approved revision rather than arbitrary message text.
| Caller | Permitted work | Gateway decision | Action-service decision |
|---|---|---|---|
| North research agent | Read North accounts, retrieve evidence, create drafts | Permit listed research tools; deny send and administrative tools | Enforce North record ownership and bounded query scope |
| North approved sender | Execute a specific approved message | Permit the narrow send action | Check recipient, suppression, approval revision, expiry and prior result |
| South research agent | Read South accounts and create drafts | Apply South identity and tool scope | Reject a North account identifier even if the tool itself is permitted |
| Platform administrator | Register and revoke servers | Allow separately assigned management actions | Keep ordinary client actions distinct from administration |
The important difference is between a blocked tool and a blocked record. A gateway can reject send_email for a researcher. If get_account remains permitted, the action service must still reject another client's account ID. Hiding North tools from South does not prove that South's shared credential cannot access North data.
Keep upstream secrets out of ordinary client configurations and restrict direct upstream access wherever the hosting and provider support it. A public SaaS endpoint may remain publicly reachable, so preventing bypass also requires controlling credentials and provider permissions; a network diagram alone is insufficient.
For each accepted or denied call, retain the principal, client, server, tool, action ID, time, policy result and external outcome. Store sensitive payloads only where needed. A model's “success” message is not the CRM's accepted result. The gateway and action-service records should connect through the same action identifier.
A useful acceptance exercise has four concrete results: a researcher's direct send attempt is denied; a South request for a North record is denied; a revoked tool cannot be called through a stale client; and an approved message produces one recorded external result or a clear reconciliation state. These are proposed implementation checks, not reported product benchmark results.
Costs for 250,000 monthly calls
Use 250,000 tool executions and 10,000 delivered trigger events per month for the ten-client example. At 22 working days, that is about 11,364 executions a day. The average does not determine the peak rate, because a scheduled account-research batch can concentrate calls into a few minutes.
For a Composio Pro component calculation, assume own OAuth apps or the published API-key/MCP category, execution within Sessions, individually authorised connections and no premium tools or paid add-ons. The first 100,000 tool calls are included. The remaining 150,000 × $0.0003 = $45 in usage consumes the $29 credit and leaves $16 beyond it. The $29 subscription plus $16 overage produces $45/month for those specified components. The 10,000 triggers remain below the 50,000 allowance. This is not an Enterprise gateway quote.
If all 250,000 calls also used the optional ZDR feature at $0.0001 per call, that adds $25 of metered usage. The same credit treatment gives $70 for the illustrated components. Other architectures, shared connections or Composio-managed apps change the basis. The single brief limitation is therefore architectural: the $45 example uses the expressly stated connection and execution category, rather than every available feature.
For Portkey's published Production platform component, 250,000 requests exceed its 100,000 included amount by 150,000. Budgeting two additional 100,000-request blocks at $9 gives $49 + $18 = $67/month. This is a conservative block calculation for the public platform meter, not a certified complete MCP Enterprise deployment price. MCP commercial scope and any required private deployment remain separate from that calculation.
For an operated Microsoft-project budget, assume an incremental $120/month for hosting and shared stores, $30 for logging and backup, and six engineering hours at $75/hour. The monthly operating budget is $120 + $30 + $450 = $600. Assume a further 32 implementation hours at $75/hour: $2,400 initially, or $200/month spread over the first year. First-year allocated operating cost becomes $800/month, before underlying CRM, enrichment and model fees. These infrastructure amounts are our planning assumptions, not Azure SKU quotations or tested capacity.
For Cloudflare, Kong and KSG, use the package, Enterprise licence or prospective cluster basis described above. It would be misleading to turn unrelated seat, model or cloud compute prices into equal 250,000-call totals. The practical recommendation can still be made: an existing Cloudflare or Kong estate may have lower incremental implementation cost; a new small team should prefer an available managed route over building platform operation solely to avoid a subscription.
The labour comparison gives a useful spending threshold. If managed service reduces maintenance from six to two hours a month, it saves 4 × $75 = $300 in monthly labour under these assumptions. That is the amount available for additional subscription cost before labour savings disappear, excluding any infrastructure savings. The actual benefit depends on which work the vendor takes over, especially connector maintenance and credential refresh.
Which route to choose
Choose Cloudflare portals for employees accessing approved servers within an existing Access estate. Choose Portkey for centralising a mixed MCP-server estate alongside AI platform management. Choose Composio when maintaining SaaS connections is a substantial part of the work.
Choose Kong AI Gateway Enterprise when a platform team already owns the APIs and gateway. Choose Microsoft's project when owning Kubernetes deployment is an intentional engineering decision with an operating budget. Retain KSG MCP Gateway as an emerging option; its published deployment status makes another route the better immediate recommendation.
For the agent's execution layer, see our n8n, Zapier and Make comparison. For how those tools fit the wider operation, see running an agency on Claude Code. Our signal-based outbound playbook helps define the sales evidence and action rules that remain behind the gateway.
FAQ
Is an MCP gateway the same as an AI model gateway?
They manage different traffic. A model gateway routes requests to models and may track tokens, fallbacks or model costs. An MCP gateway manages tool-server access and calls. Some platforms offer both. Compare the specific MCP feature and its commercial entitlement instead of assuming the model gateway price covers it.
Are the two products called MCP Gateway the same project?
No. Microsoft publishes microsoft/mcp-gateway, an MIT-licensed Kubernetes-oriented project. The mcpgateway.com product is associated with Kinetic Solutions Group and has its own authentication, session-scoping and deployment documentation. Name the repository or vendor when comparing them.
Does hiding a tool prevent an unauthorised call?
Only if invocation is also checked. A client can retain an old definition or submit a call directly. The gateway should enforce permission when the call arrives, and the action service should enforce record ownership and business rules. Tool discovery is useful presentation, but it cannot carry the entire access boundary.
Can one gateway serve several agency clients?
Yes, if identity, upstream connections and record scope remain separate. Resolve the client from trusted authentication, apply the corresponding tool permissions and use the correct connected account. The ten-client example also checks record ownership in the service, so a permitted tool cannot act on an arbitrary other client's account.
Is self-hosting automatically cheaper?
It removes or changes a software subscription but retains infrastructure, updates, storage, logging and engineering work. In the example, maintenance alone is $450/month and implementation adds $200/month over the first year. Existing platform infrastructure can reduce incremental work; a team starting from scratch should compare the whole operating responsibility.
Does the gateway replace human approval for sending?
It can control which identity may call a send action. The application still needs to authorise the particular recipient, message and revision. A narrow approved-send tool should validate that decision before sending. This prevents a generally authorised tool from becoming permission to send any message the agent invents later.





