Paste your MCP URL
Point us at any self-hosted Streamable HTTP endpoint reachable over HTTPS.
Paste your existing MCP URL. Get a protected gateway URL for Claude, Cursor, ChatGPT, and every standards-based MCP client.
https://acme.gatekey.dev/mcp
One secure URL for every MCP client
Keep your server exactly where it is. Gatekey adds authentication and access control at the edge, without an SDK, sidecar, or rewrite.
Point us at any self-hosted Streamable HTTP endpoint reachable over HTTPS.
Enable identity providers and allowlist users, organizations, or email domains.
Use one standards-based gateway URL in Claude, Cursor, ChatGPT, or your own client.
Gatekey is a transparent Cloudflare-based proxy between your MCP clients and your existing server. It handles identity at the edge, then forwards MCP traffic to your origin.
Production-ready access controls for remote MCP, with a setup your team can understand at a glance.
PKCE, Dynamic Client Registration, token validation, and standards-based discovery. All handled for every endpoint.
GitHub, Google, or your enterprise identity provider. Allow access by user, team, or verified domain.
Use a Gatekey URL out of the box, or connect a custom hostname for a fully branded endpoint.
Set rate limits, inspect authentication events, and trace access across users and clients from one compact dashboard.
The gateway preserves Streamable HTTP semantics while enforcing authentication before a request ever reaches your origin.
Explore the technical details/mcp
34 ms
authorization: Bearer ••••••••••••
content-type: application/json
mcp-session-id: 8f2a••••••
{
"jsonrpc": "2.0",
"method": "tools/call"
}
Start small. Upgrade when your gateway becomes part of production.
For testing your first protected MCP endpoint.
For developers and small teams running in production.
For SaaS products with advanced identity needs.
All plans include OAuth 2.1, PKCE, Dynamic Client Registration, and encrypted transport. Prices are indicative B2B prices and exclude VAT.
Still evaluating your setup?
Talk to an engineerNo. Your MCP server and tools remain on your infrastructure. Gatekey is the authentication and policy proxy in front of your existing Streamable HTTP endpoint.
No. Add your current MCP URL, configure who may connect, and use the new gateway URL in your MCP client. An optional service token can protect the connection from Gatekey to your origin.
Gatekey is designed for standards-based remote MCP clients that support OAuth, including Claude, Cursor, ChatGPT, and custom clients using the MCP authorization flow.
Users authenticate with GitHub, Google, or your enterprise provider. You can then allowlist specific identities and email domains, with every authentication event recorded in the audit log.
Yes. Starter and Scale gateways can be published under a custom hostname such as mcp.yourcompany.com, with TLS handled automatically.
Join the early access list and be first to protect your endpoint.