Connector Gateway
The Connector Gateway is a component of Stacklok Enterprise.
The Connector Gateway provides an identity-aware endpoint for MCP tool calls. It evaluates each connector's policy to expose the connectors available to each caller and brokers connector credentials on their behalf.
It is the counterpart to the AI Gateway. The AI Gateway governs the models your agents can call; the Connector Gateway governs the tools they can use.
Where to start
- Try it end to end. The quickstart registers a connector, grants it, and calls it from Claude Code.
- Configure and secure connectors. Manage connectors, set up their authentication, and grant access.
- Roll out and support users. Roll out gateway clients and support users' connector access.
- Operate the gateway. Review tool usage, and export telemetry and audit logs.
How it works
A connector is an MCP server registered with the gateway. Every user points their MCP client at the same gateway endpoint and signs in with their corporate identity. The gateway then serves that user only the connectors they're granted and connected to.
On each request, the gateway asks the Enterprise Manager who the caller is and which connectors their connector policies allow. For each tool call, it attaches the credential that the connector's authentication type defines and forwards the call to the connector's backend.
Two roles share the work:
- Administrators register connectors, configure how the gateway authenticates to each backend, and grant connectors to directory groups. See Manage connectors.
- Users connect their MCP client to the gateway endpoint, connect to the connectors they're granted, and choose which tools stay on. A connector that acts as the user asks them to sign in to its provider once, when they connect. The console guides users through these steps. See Support users' connector access.
What you administer
The console groups Connector Gateway administration under Connectors:
| Console area | What you do there |
|---|---|
| Connectors | Register connectors, configure connector authentication, and grant access through policies |
| Identity Providers | Register the connector identity providers that OAuth and token exchange connectors authenticate against |
| Managed Secrets | Store the API keys, tokens, and client secrets that connectors and identity providers reference |
| Tool Usage | Review tool calls by connector and tool |
Outside the console, you configure tool call recording, telemetry, and audit logs in the platform's Helm values.
Connector Gateway and vMCP
The Connector Gateway and a Virtual MCP Server (vMCP) both aggregate MCP servers behind one endpoint. They differ in who decides what each caller sees.
| Connector Gateway | vMCP | |
|---|---|---|
| Built for | People using their own MCP clients | Applications and agents with a predefined toolset |
| Who picks the tools | Administrators grant connectors in the console; each user connects to the ones they want | A fixed set of backends in the VirtualMCPServer configuration |
| Authorization | A per-connector policy evaluated for each user | Cedar policies on the vMCP, plus ToolhiveAuthorizationPolicy on MCPServer backends |
| Tool filtering | Each user turns off the tools they don't want | Administrators filter and rename tools for every caller |
In structured mode, connector policies grant access to directory groups, which are separate from the OpenID Connect (OIDC) claim groups that cluster authorization policies match. A Cedar-mode connector policy can also match claims in the caller's token. See Directory groups and OIDC claim groups.
You can run the Connector Gateway and multiple vMCP instances in the same cluster.
Prerequisites
- A deployed Connector Gateway. See Configure the Connector Gateway.
- At least one directory group to grant connectors to. See Users and groups.
- Managed secrets or identity providers for connectors whose backends need credentials. See Set up the prerequisites in order.
Next steps
- Try the Connector Gateway quickstart to register a connector and call it from an MCP client.
- Manage connectors to register the MCP servers your organization needs.