AgentValet vs MCP gateways
This is a category page, not a takedown of any vendor. MCP gateways solve real operational problems, and if you run a fleet of agents you’ll probably want those features from something. The narrower question here: when the job is security governance, what does a gateway enforce?
Two approaches, in plain words
What an MCP gateway is
An MCP gateway is a central proxy between agents and MCP servers. Agents connect to the gateway instead of each server, and the gateway catalogues the servers, filters which tools each client sees, rate-limits and logs.
For this page we read the public documentation for three: Docker MCP Gateway, which runs MCP servers in containers, injects their credentials and lets you enable or disable tools per profile; IBM’s ContextForge, which federates MCP servers and REST APIs behind one endpoint and encrypts the upstream credentials it stores; and Microsoft’s MCP Gateway, which handles routing and lifecycle for MCP servers on Kubernetes.
What AgentValet is
AgentValet is a credential broker. Any MCP server URL, and any of its SaaS connectors, becomes a governed platform whose tools or actions are scopes you grant per agent.
The broker holds the credential, checks the agent’s grant and your rules on the real call, holds a risky call for your approval, and signs a receipt for every decision.
The question that separates them
Does the control depend on where the traffic goes, or on who holds the key?
A gateway governs by position: its filters and logs apply to calls that pass through it. Some gateways also keep the upstream credentials, which is a real step up. Whether that closes the gap depends on your deployment: an agent that still has a direct connection, a leftover config or its own API key is outside the perimeter.
AgentValet anchors the control to the credential instead. The agent has no platform key to fall back on, so there’s no routed and unrouted traffic.
- Agent
- Gateway catalogues, filters and logs
- MCP server
- Credential with the server or the gateway
- Real platform
Traffic routed through the gateway is governed. Any key the agent still holds for itself is not.
- Agent
- Broker checks identity, grant and approval
- Credential unsealed in memory
- SaaS API or MCP server
The credential leaves the vault only in memory, for one call. There’s no route to the platform without the broker.
Gateway features, broker guarantees
One line per cell. Open the detail underneath for the longer version.
| AgentValet | Typical MCP gateway | |
|---|---|---|
| Primary job | Credential custody and enforcement on the real platform call. | A central catalogue, tool filtering, rate limits and logging for MCP traffic. |
| Where the secrets live | In the vault only, never sent to the agent. | It varies: with the MCP servers, injected by the gateway, or stored by the gateway. |
| Coverage | Every call, because an agent without the broker has no credential. | The traffic you route through it. |
| Platforms | MCP servers and SaaS APIs, through one broker. | MCP servers, and in some gateways REST APIs wrapped as MCP tools. |
| Per-agent identity | A signing keypair per agent; every row names one agent. | Varies; often client credentials or tokens per user or client. |
| Human approval on a single call | The call pauses at the broker until you approve it. | We didn’t find a per-call hold in the gateway docs we read. |
| Audit | Append-only, with a signed receipt on every decision. | Request logs and traces, as tamper-resistant as the store you send them to. |
| Revocation | Revoke the agent and its next call fails closed. | Remove the client’s access, then rotate any credential it could reach directly. |
The detail behind 3 of these rows
- Where the secrets live
AgentValet: Envelope encryption: each credential has its own key, and those keys are locked by one per organisation, held in hardware on paid plans. A credential is unsealed in memory for one call, then dropped.
Typical MCP gateway: Docker’s gateway injects credentials into the servers it runs. ContextForge stores upstream credentials encrypted. Whatever the gateway does, keys the agent holds for itself are outside it.
- Platforms
AgentValet: Paste any MCP server URL and its tools become grantable scopes. AgentValet also runs its own hosted MCP endpoint over OAuth 2.1 for agents to connect to.
- Audit
AgentValet: Rows can be added, never edited or deleted. Receipts are signed ES256 and verifiable against a published key set.
Where MCP gateways genuinely win
If your problem is running dozens of MCP servers, a gateway is the right tool: one catalogue, one endpoint for every client, containerised servers, session routing, rate limits and traces in your own observability stack. Several are open source and run on your own infrastructure.
AgentValet isn’t trying to host or orchestrate your MCP servers.
Where AgentValet wins
If your problem is what an agent is allowed to do, the control has to hold even when traffic goes somewhere unexpected. AgentValet holds the credential for MCP servers and SaaS APIs alike, pauses risky calls for a person, and signs a receipt for every decision.
A gateway for catalogue and cost control in front, a broker holding the credentials behind. The layers stack because they never touch the same seam.
Which one fits
Choose MCP gateways if
- You’re running many MCP servers and need one place to catalogue and route them.
- Your worry is operations: uptime, rate limits, observability.
- Every credential is already out of your agents’ reach.
Choose AgentValet if
- Your agents hold keys to SaaS platforms as well as MCP servers.
- You want a person to approve a risky call before it runs.
- You need per-agent identity and a signed record.
Run both if
- You want a gateway for MCP operations and a broker for the keys behind it.
Checked against Docker MCP Gateway, IBM ContextForge and Microsoft MCP Gateway on 24 September 2026. If something has changed, report a correction and we’ll fix the page.
Gateways vary a lot. If yours does something this page says a typical gateway doesn’t, tell us.
Put the keys somewhere an agent can’t hold them.
Bring one MCP server URL and one agent. The free plan vaults the token, turns the server’s tools into scopes you grant, and shows you the first audit row within minutes.
npx @agentvalet/register