Security & trust
Written for the people who have to approve it: the control model, what we ship today, and what's roadmap — stated plainly, including what we don't claim.
Resources
Documentation, illustrated guides, and writing on the MCP ecosystem — the agent-to-tool boundary explained in whichever format works for you. Start anywhere; it all describes the same model.
Start here
The reference docs if you're installing today, the illustrated guide if you're building the mental model, the field guide if you have four minutes, the article if you're converting APIs to tools right now.
Quickstart, Helm install, the policy guide, and the gatewayctl reference — everything you need to stand up the gateway and write your first default-deny policy.
ILLUSTRATED ↗The whole model — sprawl, discovery, the credential broker, the audit ledger — explained in 13 illustrated guides.
FIELD GUIDEFive hand-drawn figures, one governed gate. Read it in four minutes, send it to your security team after.
VISUAL GUIDEFollow one request from the user to an MCP server, into an external system, and back to the model.
ARTICLEThirteen subsystems, rebuilt inside every hand-rolled server. A live model of what that costs your org — and what changes when the boundary is shared instead of repeated.
Writing on the MCP ecosystem
We build at the boundary between agents and tools, and we write down what we learn there: protocol behavior, policy design, and the failure modes we keep meeting. "How MCP works" is the latest visual guide. More is coming; leave an email and we'll send each piece as it ships.
We'll send new writing on the MCP ecosystem as it ships.
For your review cycle
When the evaluation gets serious, three questions come up: can security approve it, is it honestly better than the alternatives, and what does each stakeholder actually get. One page each.
Written for the people who have to approve it: the control model, what we ship today, and what's roadmap — stated plainly, including what we don't claim.
Build it yourself, extend your existing API gateway, use a vendor-hosted control plane — when each is the right call, and where we lose.
The boundary described operationally for each job that shares it: the security org, the platform team, and the leadership that answers for both.
Next step
A walkthrough is 25 minutes on your architecture — or open the docs and stand the gateway up yourself first.