Approve and secure every agent-to-tool connection
And save a small fortune in input tokens while you’re at it
What can you do with Stacklok’s MCP gateway?
We’re so glad you asked! You can:
- Provide each user with one URL instead of multiple connections to configure
- Aggregate every MCP server behind one governed endpoint
- Build multi-step, cross-system workflows to coordinate tasks across MCP servers
- Centralize authentication and authorization (with Amazon’s Cedar policy language)
- Segment each endpoint by identity group (the engineering team sees engineering tools, the marketing team sees marketing tools, etc.)
- Maintain a full audit trail with OTel and Prometheus plug-ins to your existing observability stack
- Filter in only the tools and descriptions needed for a task to save a small fortune in input tokens
“Once we realized that we could get local MCP servers off developers’ laptops, that really became the main driver for building on Stacklok.”
Let’s get a little more technical. Here’s what separates Stacklok’s MCP gateway from alternatives.
Self-hosted
Alternatives: SaaS gateways route your MCP traffic through a third-party cloud, which violates strict data residency requirements or private cloud mandates.
Stacklok: Our MCP gateway runs entirely within your infrastructure. Your data stays inside your perimeter, and your telemetry can be neatly integrated (via OTel or Prometheus) into your existing observability stack.
Aggregation
Alternatives: Users that need multiple MCP servers to complete a task have to separately manage connectively and authentication for each server.
Stacklok: Our virtual MCP server (vMCP) aggregates all needed servers into a single endpoint, so users connect their client once instead of juggling URLs, credentials and more.
Governance
Alternatives: Most solutions stop at basic OAuth authentication; users may even be required to locally store API keys or service account tokens.
Stacklok: Beyond authentication, Stacklok enforces authorization using Amazon’s Cedar policy language, so MCP servers don’t need to implement their own OAuth. Governance for all servers is centralized and simplified.
Cost-efficiency
Alternatives: Other solutions feed dozens of unnecessary tools into your context window, driving up input token usage and costs, while degrading model performance.
Stacklok: Stacklok filters only the tools and descriptions needed to complete a task into the context window. Our customers save 85%+ on input tokens (because our filtering capability has proven more accurate than Anthropic’s own tool).
Fun fact:
Stacklok can deploy your MCP gateway with a frontier model tunnel to enable an outbound-only connection to clients.
Want to talk through your options?